Embedding Pipeline Service · View 11 of 22 · Data
The zone that decides the recovery plan
- Authoritative and ours: the chunk ledger, the contract registry, the index catalogue and the deletion log. RPO 0, RTO 15 minutes. These are backed up as truth.
- Disposable and ours: every vector index, lexical index and cache. Rebuildable from the ledger plus retained text plus a pinned contract.
- Not ours: content and permissions. The platform cannot restore a corpus and does not try.
Why snapshot a rebuildable store
- A from-scratch rebuild takes 3 to 14 days, which satisfies no recovery-time objective anyone would sign.
- So index snapshots exist for recovery time, not durability: RTO 4 hours from the latest snapshot versus days from the ledger.
- A restored snapshot is not trusted until the deletion log has been replayed over it — otherwise a restore resurrects an erased document.
Retention (assumptions)
- Normalised text 30 days. Chunk ledger for the life of the document. Deletion log 13 months.
- A superseded index 21 days past cutover for rollback, then reclaimed within 7 days.
- Evaluation runs and drift series 13 months, so two consecutive migrations can be compared.