Skip to content
Anasemble

Evidence-bound disaster recovery

Regrow function from surviving meaning.

Anasemble reconstructs a lost service component from evidence stored beyond its failure domain, independently certifies the candidate, restores state, and activates only with operator approval.

Current boundary: fail closed by design. Anasemble complements backups and replication; it does not replace them.

The recovery path

Recovery is a chain of bounded decisions.

The control plane never turns missing evidence, unsupported infrastructure, a timeout, or ambiguous external state into success. Each stage produces an identity-bound receipt for the next.

  1. 01

    Collect

    Authenticate independently retained contracts, traces, policies, and snapshots.

  2. 02

    Reconstruct

    Search a finite typed grammar under explicit time, memory, and candidate budgets.

  3. 03

    Certify

    Use a separate checker and held-out obligations. Any ambiguity becomes refusal.

  4. 04

    Recover

    Restore state, publish an immutable artifact, and stage it inside isolation.

  5. 05

    Decide

    Activate with signed approval, then preserve a sealed acceptance or rollback path.

Architecture

Surviving meaning becomes recoverable function.

Independent evidence enters a bounded Rust recovery pipeline. A separate checker certifies or refuses the candidate, and an operator controls restoration, activation, acceptance, and rollback.
Committed evidence and state remain distinct from the untrusted candidate. Refusal stays available through every boundary.

Supported release-candidate profiles

Narrow evidence. Explicit promises.

Support exists only where implementation and retained destructive validation agree. Unlisted combinations are never inferred.

Inspect the complete contract ↗

Local operator path

macOS arm64, Docker 29, PostgreSQL 18, S3-compatible storage, and Redis Streams 8.8.

Native Linux

Exact Amazon Linux 2023 arm64 and x86_64 profiles with locked Rust 1.97.0 builds.

AWS managed recovery

RDS PostgreSQL 18.3, S3, ElastiCache Redis 7.1, and EKS 1.36 in eu-west-1.

Everything else

Experimental or refused until its own exact profile has retained evidence.

Refusal is a product result

When evidence or boundaries are insufficient, Anasemble says no.

It does not reconstruct arbitrary software, recover from no information, replace native backups, or silently promote an experimental platform into support.

  • No source, binary, image, or identical replica required
  • Independent evidence domains required
  • One certified candidate or explicit refusal
  • Operator approval before activation

Inspect the recovery boundary

A recovery should be able to explain why it deserves traffic.