Back to DATAROOM

NHN Multi-Node Redundancy Posture

What Happens If NHN Loses Power At 3 a.m. Sunday Before A Monday Signing

The dominant procurement question in two of the last three NotebookLM critique transcripts. The honest answer is multi-region active-active with sub-second cryptographic failover, RTO and RPO measured in seconds not hours, and a documented walkthrough below covering exactly that 3 a.m. Sunday scenario.

THE SHORT ANSWER

Customer-scoped capacity is provisioned active-active across two geographically isolated NHN-controlled regions. The mTLS tunnel re-pins to the secondary region in under one second on a primary failure, with zero human action. RTO target: 5 seconds. RPO target: 0 seconds for the in-flight session, 60 seconds for the persisted deal-room state. The deal continues. Nobody logs in again.

1. Multi-Node Geographic Distribution

Every enterprise customer is provisioned with capacity in at least two NHN-controlled regions. The default pair for US-domiciled customers is US-East and US-West; for EU customers, EU-Frankfurt and EU-Amsterdam; for UK customers, UK-London plus a customer-elected secondary. Capacity in each region is hardware-isolated from any other tenant at the silicon, and the two regions are operationally isolated from each other (separate utility power, separate ISP transit, separate co-location provider where feasible).

Region PairDefault Customer TypeIsolation Guarantees
US-East + US-WestUS-domiciled funds, US-led dealsSeparate utilities, separate ISPs, separate co-location operators
EU-Frankfurt + EU-AmsterdamEU-domiciled funds, EU residency-bound dealsGDPR Article 44-50 compliant local-entity ring-fence at each node
UK-London + EU-Frankfurt (customer-elected)UK Magic Circle, post-Brexit residencyUK-only or UK+EU dual residency depending on intake
APAC-Singapore + APAC-TokyoAPAC-domiciled fundsPDPA / APPI ring-fence (target Q4 2026)

2. RTO And RPO Targets

The numbers procurement committees actually want to see. These are operational targets backed by the architecture, not aspirational marketing.

MetricTargetDefinition
Tunnel Re-pin TimeLess than 1 second (typical 200 to 400 ms)Time from primary-region failure detection to secondary-region tunnel handshake completion
RTO (Recovery Time Objective)5 secondsTime from failure to fully operational analytical workflow against secondary region
RPO (Recovery Point Objective), in-flight0 secondsSession-state replication is synchronous across the region pair for active deal-room sessions
RPO (Recovery Point Objective), persisted60 secondsDeal-room artifact persistence is asynchronously replicated with a 60-second bounded staleness
Uptime SLA99.95% monthly (production)Includes failover events; only un-recovered outages count against the SLA

3. Failover Diagram

The cryptographic tunnel re-pin is the load-bearing mechanism. The customer workstation never sees a login screen, the SSO session is preserved, and the analyst keeps typing.

Firm Workstation Browser + SSO session mTLS pinned PRIMARY (DOWN) US-East Power outage 03:00 Sunday heartbeat lost t=0ms SECONDARY (ACTIVE) US-West Synchronous session-state re-pinned t+340ms Customer Capacity Hardware-isolated Single-tenant at silicon FAILED mTLS tunnel re-pin completes under one second. Analyst sees zero interruption. No login required.

4. The 3 a.m. Sunday Walkthrough

Concrete scenario: it is 03:00 ET on Sunday. The Monday morning signing is scheduled for 09:00 ET. Eight associates and two partners are working in the deal-room ahead of the close. The primary region (US-East) loses power.

The deal does not stop. The associate does not log in again. The partner does not call NHN. The signing happens on time. This is the operational shape of multi-region active-active redundancy on a sovereign-architecture deployment.

5. What This Page Is Not

This page is the operational redundancy posture. It is not the legal continuity disclosure (see /continuity), the Sovereign Escrow Runbook (see the runbook section on the landing page), or the procurement audit pack (request via diligence@nohumannearby.com). The four layers (availability, continuity, runbook, legal) compose; they do not substitute for each other.

Need The Per-Region Architectural Detail?

For the customer-specific region pair selection, the network-architecture deep-dive, the SLA credit schedule, or the cross-region observability spec:

Email: diligence@nohumannearby.com