The events that put a backup to the test are rarely dramatic. A mass update writes the wrong value across thousands of records. A user with delete permission removes a transaction that closed a period. An integration reposts and duplicates a month of activity. In each case the question is the same: what did this record look like before, and can we prove it? A control that cannot answer that from the organisation's own copy is not the control the retention rule had in mind.
What does a retention rule actually ask a backup to prove?
Retention obligations under company law, tax law, SOX, GDPR, PIPEDA and sector rules run for years, and they are written in terms of producing records, not of storing files. Read as a control, they ask for four things: a copy taken on a known schedule, so a record can be seen as it stood on a given day; the relationships kept, so an invoice still resolves to its customer, its order, its payments and its GL impact; evidence that the copy is complete, compared against the source rather than against itself; and a record of who has accessed the copy and what they exported. A backup that meets those four can answer an auditor. One that meets none of them is a file.
Why is a native export not enough?
A saved search exported to a spreadsheet is a copy of selected data at a point in time, produced by a search that decides what is included. If the search excludes inactive records, the export excludes them too, and the row count agrees with the search that produced it. The export is flat, so the relationships between records are gone; it does not carry the File Cabinet documents attached to the transactions; and it exists only if somebody ran it that day. The export verification guide sets out the checks that separate a complete copy from a plausible one. The distinction that matters is between the platform's own resilience, which protects the service, and the organisation holding an independent copy of its own records that it controls, can query and can export; the commitments that come with the NetSuite service are set out in your own service agreement, and that document is the place to check what it covers.
What does the daily copy cover, and what does it not?
Blueacrobat's continuous backup service takes one full copy of the account at implementation and then captures each day's changes into a relational copy on DBVault, held off-site, encrypted in transit and at rest, with the relationships between records kept and every record indexed. An authorised user can find a customer, an invoice, a journal or a custom record as it stood on a given day and export it as CSV for re-entry or for an auditor. Access is role-based, read-only viewers see only what they are permitted to see, and logins and downloads are logged; Blueacrobat is ISO/IEC 27001:2022 certified and SOC 2 Type II audited, and the Trust Centre describes the controls. The hosting region is agreed for each engagement, and the records can be exported to CSV or taken as a MySQL database at any point, so the copy stays portable whatever happens to the subscription.
- Covered: transactional, entity and accounting records; sublists, custom records and custom fields; File Cabinet content, with the link to each record.
- Not covered: metadata objects such as scripts; workflows locked in the NetSuite interface, which cannot be backed up; sandboxes, since coverage is scoped to the production account. File Cabinet content is backed up but is not hosted on your own infrastructure.
- Not a one-click restore. Recovering records, sublists and files selectively is what the service is built for. Restoring an entire NetSuite account is a re-implementation followed by manual re-import, and a continuity plan that assumes otherwise should be tested against the service agreement before it is relied on.
The most recent day of activity is the exposure to plan around, and it is the figure a continuity policy should be written against. If the question in your organisation is who could produce a verified copy of the account on the day it is needed, a review of the backup position is the place to start.