ContinueOpsProduct overview
    DR automation · Privacy-first · Auditor-defensible

    Make critical-system recovery testable, evidenced and board-defensible.

    ContinueOps automates DR runbook execution with tamper-evident evidence chains, human-on-the-loop approvals and a zero-egress architecture - without standing up an internal platform team.

    Explore the product

    Deployment options, the live Windows product demo, and our security model - in one place.

    Proven in production

    ContinueOps already runs in regulated production environments. These are the customers whose runbooks fire today, whose evidence packs go to auditors, and whose teams will join a reference call on request.

    SOC 2

    SAI Group

    Retail

    Production runbooks, weekly DR validation, full evidence chain.

    ISO 27001

    Message Matrix

    Media / TelCo

    Operational runbooks across AWS workloads with HOL approvals.

    NIS2

    Syndic8

    E-commerce

    Multi-region failover rehearsals + auditor-ready evidence packs.

    "We replaced a quarterly 2-day fire-drill with a one-click rehearsal we can defend to our auditors. The evidence pack is the bit that sold it internally."

    - Reference customer, available on request
    Deployment

    For regulated environments and strict data-residency requirements, the self-hosted appliance runs entirely inside your VPC with no inbound ports and no data egress. A managed SaaS option is also available.

    Read the full deployment guide

    For regulated environments

    Self-hosted appliance.

    A signed virtual appliance you deploy inside your own VPC. Outbound-only mTLS to the control plane. Runbook outputs, captured variables and credentials never leave your environment.

    Reference appliance specification
    vCPU
    8
    RAM
    32 GB
    Disk
    200 GB SSD
    Network
    Air-gapped
    Supported formats

    Ships in your preferred platform.

    • OVA / OVF
      VMware vSphere, ESXi 7+
    • Hyper-V VHDX
      Windows Server 2019/2022
    • QCOW2 / KVM
      Proxmox, OpenStack, libvirt
    • AMI / GCE
      AWS · Azure · GCP marketplace
    • Helm chart
      Kubernetes 1.27+ · OpenShift
    • Docker Compose
      Single-host air-gapped lab
    Air-gapped install supported · Signed images · SHA-256 + GPG verified
    Or take the managed SaaS instead
    Same evidence chain, hosted by ContinueOps · ideal for teams without an internal platform function.
    Read deployment docs
    Privacy baked in

    No credential storage on the agent, runtime secret injection and data that does not leave the customer environment. That is the default with no additional cost.

    No credential storage on the agent

    Single stripped Rust binary. Cloud credentials are never persisted. mTLS client cert lives in the OS keystore, never on disk in plaintext.

    Secrets injected at runtime

    Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager or CyberArk. Per-step fetch, zeroised on completion.

    Data does not leave your environment

    Outbound-only mTLS to the control plane. Runbook outputs and captured vars stay inside your VPC.

    Local LLM option

    Ships with our proprietary self-hosted model, reasoning runs on your hardware.

    RFC 3161 trusted timestamps

    Every runbook step, evidence artefact and approval is sealed with an RFC 3161 timestamp from a trusted TSA. Tamper-evident, auditor-defensible, and verifiable years later - no need to trust ContinueOps' clock or storage.

    ISO 27001 - certification in progressDORA-alignedFCA / PRA operational resilience
    Optional capabilities

    Capabilities that are toggled on per tenant via feature flags - enabled only where they fit your operating model and compliance posture.

    Feature flag · per tenant

    Inter-user messaging

    Direct, tenant-scoped conversations between members of the same tenant - useful for runbook hand-offs, incident chatter and approval context. Off by default; enabled per tenant via a feature flag, with full RLS isolation, attachment storage and audit trail.

    Tenant-controlled

    Per-tenant feature flags

    Every optional capability - messaging, compliance dashboards, integrations - is gated by a per-tenant feature flag. Operators decide what's on for whom, with no code changes and no cross-tenant leakage.

    First runbook live in week 2
    1. 01
      Week 1

      Kick-off + agent enrolment

      License issued, agent deployed in your VPC, mTLS handshake confirmed. Zero inbound ports.

    2. 02
      Week 2

      First runbook live

      We co-author your highest-value DR runbook. First successful tamper-evident run logged.

    3. 03
      Week 3

      HOL + evidence wired

      Human-on-the-loop approvals into your channel of choice. Evidence pack auto-generated.

    4. 04
      Week 4

      Hand-over + sign-off

      Top-5 critical systems covered. RFC 3161 timestamped certificates ready for your auditor.

    Get started

    See ContinueOps in your environment.

    1. 01

      30-minute working session - walk through the agent architecture and answer credential / data-residency questions live.

    2. 02

      Reference call with one of SAI Group (Retail), Message Matrix (Media / TelCo) or Syndic8 (E-commerce) - your choice of sector and framework.

    3. 03

      Pilot kick-off the following week - fixed-fee setup, first runbook live in week 2.

    Contact us

    Typical pilot time-to-value: 4 weeks