Incident Response & Business Continuity
Primary / standby data-centre DR + clear RTO/RPO targets + 24×7 tiered incident response — with affected customers notified within 24 hours of a confirmed security incident.
- RTO
- ≤ 4 hours
- RPO
- ≤ 15 minutes
- Availability
- Monthly ≥ 99.9%
- Notification
- Within 24h of confirmation
Disaster-recovery architecture
- Primary / standby DC
A Shanghai primary plus an off-site DR centre, with key services across availability zones.
- Real-time replication
Key data is replicated in real time to minimise the loss window.
- Regular DR drills
Scheduled failover drills with post-exercise reviews.
Service-level objectives (SLA)
AMT commits to the following continuity targets; contractual SLAs are governed by the signed agreement.
Target time to restore service
Max acceptable data-loss window
Core-service availability target
Security-incident response
- 24×7 on-call
Round-the-clock security and operations on-call to detect and respond quickly.
- Tiered response P0/P1/P2
Severity-based response with clear escalation paths and timeframes.
- Customer notice within 24h
Affected customers are notified within 24 hours of confirmation, with ongoing updates.
Incident-response lifecycle
- 1Detect & alert
Monitoring and on-call staff surface anomalies and raise alerts.
- 2Triage & contain
Assess impact, assign severity and contain to limit blast radius.
- 3Eradicate & recover
Remove root cause, restore service and verify system integrity.
- 4Notify & review
Notify affected customers, run a post-mortem and track improvements.
Customer continuity support
- Data export
Customers can export their data on a schedule or on demand for local backup.
- Post-termination handling
After termination, data is retained for the agreed window, then securely deleted with confirmation.

