{
  "is": "issue",
  "title": "Unicis Platform Service Disruption - RESOLVED",
  "body": "\u003ch2 id=\"status--resolved\"\u003eStatus: ✅ RESOLVED\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eIncident Duration:\u003c/strong\u003e ~25 hours 28 minutes (11:24 UTC July 30 - 12:52 UTC July 31)\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eResolution Time:\u003c/strong\u003e 2026-07-31 13:00 UTC\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eService:\u003c/strong\u003e Fully operational on alternative infrastructure\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003e\u003cstrong\u003eUpdate, August 19, 2026:\u003c/strong\u003e Following a full forensic review of the affected server, we have corrected the timeline and root-cause details below, which differ from what we initially reported. We have also completed data recovery for the affected window (see \u0026ldquo;Data Recovery Update\u0026rdquo;).\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003chr\u003e\n\u003ch2 id=\"what-happened\"\u003eWhat Happened\u003c/h2\u003e\n\u003cp\u003eOur production VPS on Scaleway became unreachable starting at \u003cstrong\u003e11:24 UTC on July 30, 2026\u003c/strong\u003e (corrected from the 13:24 UTC originally reported).\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eRoot Cause:\u003c/strong\u003e Server logs show the instance was shut down by a hypervisor-initiated poweroff at 11:24 UTC, preceded by roughly 23 hours of abnormal network conditions: our systems logged sustained connection-table exhaustion beginning July 29 at 12:00 UTC, and outbound connectivity began failing in stages starting around 06:00 UTC on July 30, several hours before the shutdown.\u003c/p\u003e\n\u003cp\u003eWe have not been able to confirm the specific trigger for this traffic pattern. Our forensic review found:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eNo evidence of unauthorized access, admin-account misuse, or local configuration/firewall changes around the time of the incident\u003c/li\u003e\n\u003cli\u003eWazuh file-integrity and rootcheck scans, run in the hours immediately preceding the shutdown, completed with no findings\u003c/li\u003e\n\u003cli\u003eNo corroborating evidence for a container port-binding change as the trigger — this was our initial working theory, but we were unable to substantiate it against the server\u0026rsquo;s own logs\u003c/li\u003e\n\u003cli\u003eClear evidence of sustained, elevated connection volume in the ~23 hours before the shutdown, which we believe is what our hosting provider\u0026rsquo;s automated systems responded to\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eWe are continuing to work with Scaleway to determine the underlying source of that traffic and will update this notice if we learn more.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"recovery-actions-taken\"\u003eRecovery Actions Taken\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003e✅ \u003cstrong\u003eEmergency deployment\u003c/strong\u003e - Deployed to Hetzner Cloud infrastructure at 22:00 UTC July 30\u003c/li\u003e\n\u003cli\u003e✅ \u003cstrong\u003eData restoration\u003c/strong\u003e - Initial restoration from backup dated July 26, 2026 (latest available at the time)\u003c/li\u003e\n\u003cli\u003e✅ \u003cstrong\u003eData recovery\u003c/strong\u003e - Subsequently recovered data from the original Scaleway disk covering the gap between the July 26 backup and the outage (see below)\u003c/li\u003e\n\u003cli\u003e✅ \u003cstrong\u003eService verification\u003c/strong\u003e - All systems operational and tested\u003c/li\u003e\n\u003cli\u003e✅ \u003cstrong\u003eMonitoring enabled\u003c/strong\u003e - Full monitoring stack active on new infrastructure\u003c/li\u003e\n\u003c/ol\u003e\n\u003chr\u003e\n\u003ch2 id=\"data-recovery-update\"\u003eData Recovery Update\u003c/h2\u003e\n\u003cp\u003eAt the time of initial resolution, we restored service from a backup dated July 26, 2026, resulting in a data gap covering \u003cstrong\u003eJuly 26 12:00 UTC – July 30 13:34 UTC (~4 days)\u003c/strong\u003e.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eWe have since recovered this data\u003c/strong\u003e from the original Scaleway disk and merged it back into the production database. This covers:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eCompliance assessments created during this period\u003c/li\u003e\n\u003cli\u003eUser profile updates\u003c/li\u003e\n\u003cli\u003eData modifications and uploads made during this window\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eIf you notice any records from this period that appear missing or inconsistent, please contact us so we can investigate and reconcile individually — for a recovery of this kind, we recommend spot-checking critical records.\u003c/p\u003e\n\u003chr\u003e\n\u003ch2 id=\"infrastructure-improvements\"\u003eInfrastructure Improvements\u003c/h2\u003e\n\u003cp\u003eMoving forward:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003ePrimary:\u003c/strong\u003e Hetzner Online GmbH, Cloud location Falkenstein (BSI C5 Type 2 certified)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eSecondary failover:\u003c/strong\u003e Additional provider for redundancy (planned)\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eBackup strategy:\u003c/strong\u003e Hourly snapshots + geographic replication\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eMonitoring:\u003c/strong\u003e Enhanced incident detection and automated failover\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"scaleway-incident-status\"\u003eScaleway Incident Status\u003c/h2\u003e\n\u003cp\u003eWe remain in contact with Scaleway regarding this incident:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eTicket:\u003c/strong\u003e #1606734\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eStatus:\u003c/strong\u003e Escalated to product team; under joint review given the corrected timeline and mechanism described above\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eExpected resolution:\u003c/strong\u003e Full incident report and remediation plan\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLegal follow-up:\u003c/strong\u003e Discussing compensation for the service disruption\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr\u003e\n\u003ch2 id=\"thank-you\"\u003eThank You\u003c/h2\u003e\n\u003cp\u003eWe appreciate your patience during this incident, and your patience with the correction to this report. Your trust in Unicis is important to us, and we are taking this seriously to ensure it doesn\u0026rsquo;t happen again.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAny questions or data recovery needs?\u003c/strong\u003e Contact: \u003ca href=\"mailto:support@unicis.tech\"\u003esupport@unicis.tech\u003c/a\u003e\u003c/p\u003e\n\u003chr\u003e\n\u003cp\u003e\u003cstrong\u003eLast Updated:\u003c/strong\u003e 2026-08-19\u003c/p\u003e\n",
  "createdAt": "2026-07-30 11:24:00 +0000 UTC",
  "lastMod": "2026-08-19 10:35:48 +0300 +0300",
  "permalink": "https://status.unicis.tech/issues/2026-30-07-platform/",
  "severity": "down",
  "resolved": true,
  "informational": false,
  "resolvedAt": "2026-07-31 12:52:00",
  "affected": ["Unicis Platform Application"],
  "filename": "2026-30-07-platform.md"
}