Installnet IT & Technology Weekly

July 13 – July 19, 2026
Prepared by Aaron Weinberg, CTO
Covers: Facilitynet · Installhub · API · Notifications · Corporate IT
Platform Availability30 DAYS
99.84%
Worst production system (API) · target 99.9%
API stable since July 14
RoadmapSNAPSHOT
6
Active high-priority features, 2 nearing release
No change
Portfolio MixSNAPSHOT
18%·59%·23%
Share of active investment: Grow · Do · Run (targets 25% · 50% · 25%)
Grow: 18% vs 25% target
Security FindingsSNAPSHOT
73% in SLA
46 open: 1 Critical, 10 High, 35 Med/Low
Improving; 1 Critical left
Recover — DR & BCPSTATUS
15 min RPO
Backups healthy; max data loss 15 minutes
2 verification items open (was 3)

Operate — System Availability & Incidents

Uptime per production system (trailing 30 days) and every customer-visible incident of 5+ minutes in the last 4 weeks
Facilitynet99.95%
Installhub100.00%
API99.84%
Notifications100.00%
Marketing sites99.96%
One tick per day, June 20 – July 19. Green = clean day · faded green = brief blips, minutes total, site stayed up · amber = site-level outage · red = major outage (hours) · gray = planned maintenance. The API's faded-green run ends around July 14 — brief interruptions stopped after the platform fixes landed. Target: 99.9% per system; values exclude planned maintenance.
DateSystemImpactDurationStatus
No new site-level incidents this week — the second clean week in a row.
06/30Installnet.comPlanned hosting migration (GoDaddy) overran its window; monitored throughout9h 41mResolved · planned
06/30Ecoserv siteSame hosting migration; overran planned window, monitored8h 57mResolved · planned
06/24Ecoserv siteSite unreachable (last unplanned site outage, 26 days ago)18 minResolved
Only site-level events appear here; single app-server issues absorbed by high availability show as faded-green days on the left, not incidents. The API interruptions that ran through early July have stopped: no downtime events since July 14, following the platform fixes (mod-72, mod-73) and the Notification Center performance work.

Build — Roadmap Delivery & Investment

Where development investment is going (Grow / Do / Run), and the active high-priority features
Grow the business18% (target 25%)
Do the business59% (target 50%)
Run the business23% (target 25%)
Grow is running at 18% of investment against the 25% target; Do is absorbing the difference. Based on 54 active scored features (April scoring baseline; full refresh at the start of August).
FeatureOwnerStageTargetStatus
Company Pages - Hierarchy Updates (PROD-382)DoAaronFinal QAJul 27, 2026In final testing
HubSpot Integration (PROD-480)GrowEricIn developmentJul 27, 2026In development
Digital signature workflow (PROD-43)DoAaronReady to developQ4 2026Queued
Project scope standardization (PROD-416)DoAaronReady to shipQ3 2026Ready to deploy
Market Segment tagging in SP Locator (PROD-513)DoAaronReady to developQ3 2026Queued
Functions & Permissions Overhaul (PROD-536)DoAaronIn designQ3 2026In design
Chips show each feature's dominant investment bucket from its value scorecard. Project scope standardization is ready to deploy; Company Hierarchy is in final testing. Q3 value shipped: 0 points (quarter began July 1); this counter accumulates as features ship. Full Do/Run/Grow portfolio detail moves to the quarterly report.

Secure — Risk Posture

Open security findings across application code and third-party software, measured against the resolution SLA
SeverityOpenPast SLASLA Target
Critical1114 d
High10930 d
Medium22290 d
Low130180 d
Open findings: 61 → 50 → 46 over the last three weeks. Criticals: 6 → 2 → 1.
This week

Progress Down to a single open Critical (from six two weeks ago) and 73% of findings within their SLA window, up from 66%.

Attention The one remaining Critical (Installhub sign-in flow) has been open well past its 14-day target for nearly two months and still needs a fix date or a formal risk acceptance.

Third-party software: no newly exploitable items this week.

Server patching

On policy All servers current; no security patches overdue. Scanning went live this week. Last scan July 19.

Corporate IT & People — endpoints from June vendor reports; phishing and training live
Devices ProtectedExternal Weak PointsSecurity EscalationsPhishing Test FailuresTraining CompleteSystems Current
68 of 68 all devices protected 0 found in external scans 2 investigated · 0 needed action 3.4% July test · 2 of 58 staff clicked 100% monthly, all users 100% supported Windows 11 versions
Multi-factor sign-in is enforced for every account. Endpoint, protection, and escalation figures are from the June managed-security reports; phishing and training are live. July's phishing test click rate (3.4%) remains far below the ~30% untrained-organization benchmark.

Recover — Backup & Continuity Readiness

Can we come back from a bad day, and how much would we lose? Proven by tests, not job logs.
AssetOwnerBackup HealthRPOLast Verified RestoreStatus
Production databaseCTODaily full + 15-min log copies, offsite15 min ✓No recent testRecovery test overdue
Server imagesCTOApp servers weekly; database & utility monthlyLayer beneath live backupsNo test on recordOn schedule
Document storageCTO / AWSVersioned, continuousContinuousHealthy
M365 (email, files, Teams)XPERTECHS / DattoAutomaticPer Datto scheduleJul 21, 2026Restore verified
Disaster-recovery exerciseCTONone on recordSchedule H2
RPO = maximum data loss if the system failed right now. The database is protected by daily full backups plus copies every 15 minutes to protected offsite storage (versioned, cannot be silently deleted); server images are a slower rebuild layer beneath that — weekly for the application servers, monthly for the database and utility servers. All scheduled backup jobs completed this week.

Decisions & Risks — What Needs Exec Attention

DRAFT — written from this week's data, pending CTO review

Progress: API stability much improved

The brief interruptions that ran through early July have largely stopped following the platform fixes and the Notification Center performance work. API has been mostly stable for users. Still working through some final points to get back to normal.

Decision needed: one Critical security finding remains, well past deadline

Security cleanup is nearly complete — down from six open Criticals to one over two weeks. The last one, on the Installhub sign-in flow, has been open close to two months against a 14-day target. Commit a fix date, or formally accept the risk with a documented rationale.

Heads up: database recovery test still to be scheduled

Backups are healthy and data-loss exposure is 15 minutes, but the full recovery procedure has not been timed recently. A timed test restore is planned as part of the H2 disaster-recovery exercise.