Uptime and fast recovery from outages are critical parts of how Quip protects customer data. This article explains Quip's disaster recovery policy, covering crisis response timelines, backup and data restoration practices, the multi-tier disaster recovery architecture, and the ongoing testing and review process that keeps these systems reliable.
This article explains how Quip responds to production and security incidents, how customer data is backed up, how the disaster recovery system is structured, and how these procedures are tested and reviewed on an ongoing basis.
Uptime and recovering from outages is critical to Quip's success. Customers expect the highest availability possible, and Quip's policies and actions as a company are oriented around ensuring the highest possible uptime and availability for customer data.
In the case of a serious production or security issue, Quip follows internal on-call escalation procedures with a target response time of 15 minutes.
For any information security issues, in addition to escalating to the operations person on call, the issue is immediately escalated to the CEO or Head of Engineering.
After any serious security or production issue, the DevOps team conducts a post-mortem of the issue, which the on-call and engineering staff review. Results of the review are shared with the customer in question if the problem relates to customer data.
See the Information Security Policy for more details.
Quip maintains multiple, off-site backups of all user data. This includes both incremental backups (no more than 5 minutes old) and daily snapshots. For example, if a customer accidentally deletes a large batch of documents, Quip can restore from a recent incremental backup rather than waiting for the next daily snapshot.
See the Backup Policy for more information on backup policies and the availability of customer data.
The entire site can be restored from serving from any backup, whether incremental or snapshot.
To handle serving outages and disasters, Quip has implemented a multi-tier system:
Steps 1 through 5 can typically be accomplished in less than 10 minutes. In the case of a failure of all 5 layers, the final step 6 can be accomplished in approximately 1 hour.
To ensure that recovery systems are maintained and work well, Quip's Operations team tests the failover steps listed above quarterly.
To further test these systems, Quip maintains a separate internal set of servers that run in "disaster recovery" mode. These internal testing servers simulate an outage of the primary database. Quip tests these servers regularly (weekly to monthly) to confirm the site can withstand a primary database outage while still serving all user data.
All disaster recovery systems and procedures are reviewed by Quip Operations employees quarterly.
All disaster recovery policies are reviewed and updated by the Head of Engineering each quarter.
000388832

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.