Installnet IT & Technology Weekly

July 20 – July 26, 2026
Prepared by Aaron Weinberg, CTO
Covers: Facilitynet · Installhub · API · Notifications · Corporate IT
Platform Availability30 DAYS
99.89%
Worst production system (API) · target 99.9%
API clean for 12 straight days
RoadmapSNAPSHOT
5
Active high-priority features, 1 ready to deploy
1 shipped this week
Portfolio MixSNAPSHOT
18%·59%·23%
Share of active investment: Grow · Do · Run (targets 25% · 50% · 25%)
Grow: 18% vs 25% target
Security FindingsSNAPSHOT
90% in SLA
123 open: 7 Critical, 34 High, 82 Med/Low
Backlog grew; second tool added findings
Recover — DR & BCPSTATUS
15 min RPO ✓
Verified by test July 26; recovery took 17.5 minutes
DR exercise is the last open item

Operate — System Availability & Incidents

Uptime per production system (trailing 30 days) and every customer-visible incident of 5+ minutes in the last 4 weeks
Facilitynet99.94%
Installhub99.99%
API99.89%
Notifications100.00%
Marketing sites99.99%
One tick per day, June 27 – July 26. Green = clean day · faded green = brief blips, minutes total, site stayed up · amber = site-level outage · red = major outage (hours) · gray = planned maintenance. Target: 99.9% per system; values exclude planned maintenance.
DateSystemImpactDurationStatus
No customer-facing incidents this week — the third clean week in a row.
06/30Installnet.comPlanned hosting migration (GoDaddy) overran its window; monitored throughout9h 41mResolved · planned
06/30Ecoserv siteSame hosting migration; overran planned window, monitored8h 57mResolved · planned
The last unplanned customer-facing outage was June 24, 32 days ago. Saturday's brief server blips were scheduled patching in the maintenance window, absorbed by high availability with no site impact. The API recorded no downtime at all this week; its 30-day figure still carries the early-July interruptions, which are aging out.

Build — Roadmap Delivery & Investment

Where development investment is going (Grow / Do / Run), and the active high-priority features
Grow the business18% (target 25%)
Do the business59% (target 50%)
Run the business23% (target 25%)
Grow is running at 18% of investment against the 25% target; Do is absorbing the difference. Full scoring refresh at the start of August.
FeatureOwnerStageTargetStatus
Company Pages - Hierarchy Updates (PROD-382)DoAaronReady to shipAug 10, 2026Ready to deploy
HubSpot Integration (PROD-480)GrowEricIn developmentAug 10, 2026In development
Market Segment tagging in SP Locator (PROD-513)DoAaronReady to developQ3 2026Queued
Functions & Permissions Overhaul (PROD-536)DoAaronIn designQ3 2026In design
Digital signature workflow (PROD-43)DoAaronReady to developQ4 2026Queued
Chips show each feature's dominant investment bucket from its value scorecard. Shipped this week: Project scope standardization (PROD-416). Q3 value shipped: 20 points.

Secure — Risk Posture

Open security findings across application code and third-party software, measured against the resolution SLA
SeverityOpenPast SLASLA Target
Critical7114 d
High34930 d
Medium64290 d
Low180180 d
90% of open findings are still inside their resolution window.
This week

Leveraging a secondary tool found additional findings, and we are slowly working through the backlog of security tickets.

Third-party software: no newly exploitable items.

Server patching

On policy All servers current; no security patches overdue. Last scan July 26.

Corporate IT & People — endpoints from June vendor reports; phishing and training live
Devices ProtectedExternal Weak PointsSecurity EscalationsPhishing Test FailuresTraining CompleteSystems Current
68 of 68 all devices protected 0 found in external scans 2 investigated · 0 needed action 3.4% July test · 2 of 58 staff clicked 100% monthly, all users 100% supported Windows 11 versions
Multi-factor sign-in is enforced for every account. July's phishing test click rate (3.4%) remains far below the roughly 30% benchmark for untrained organizations.

Recover — Backup & Continuity Readiness

Can we come back from a bad day, and how much would we lose? Proven by tests, not job logs.
AssetOwnerBackup HealthRPOLast Verified RestoreStatus
Production databaseCTODaily full + 15-min log copies, offsite15 min ✓Jul 26 · point-in-timeVerified · 17.5 min
Server imagesCTOApp servers weekly; database & utility monthlyLayer beneath live backupsOn schedule
Document storageCTO / AWSVersioned, continuousContinuousHealthy
M365 (email, files, Teams)XPERTECHS / DattoAutomaticPer Datto scheduleJul 21, 2026Restore verified
Disaster-recovery exerciseCTONone on recordSchedule H2
RPO = maximum data loss if the system failed right now. The July 26 test restored the database from a full backup plus transaction-log replay to a specific point in time, completing in 17 minutes 33 seconds and confirming the 15-minute data-loss target is achievable. The test ran against the staging server; a restore to a production target remains part of the planned disaster-recovery exercise. Work is underway to run this restore test automatically on a recurring basis.

Decisions & Risks — What Needs Exec Attention

DRAFT — written from this week's data, reviewed with the CTO

Progress: database recovery verified end to end

A test restore on July 26 rebuilt the database to a specific point in time and completed in 17.5 minutes, confirming our 15-minute data-loss target is real and recoverable. Work is underway to run this test automatically on a recurring basis. No action needed.

Heads up: security backlog grew as a second tool was added

Leveraging a secondary tool found additional findings, and we are slowly working through the backlog of security tickets.

Progress: third consecutive week with no customer-facing incidents

Availability continues to improve as the early-July API instability ages out of the reporting window. The API itself recorded no downtime this week. No action needed.