Can the merchant retrieve the backup if host access is lost?
Identify the actual retained backup, its authorized custodian and the complete route needed to retrieve it without access to the service being replaced. A backup listed inside the old host’s dashboard does not establish independent custody. Verify the copy’s location, permission to retrieve it, retention terms and genuine retrieval evidence. If any required login, storage location or decryption authority still depends on the departing service, record that dependency before treating the copy as independently accessible.
For: A research-only merchant preparing to replace a host or contractor and checking whether a retained recovery copy remains accessible.
WordPress recommends keeping backups in multiple locations and explains that a typical complete restoration needs database and files. A host’s offer to provide backups does not establish which versions your account retains, when they can be retrieved or whether they can recover your site. Begin with an identifiable retained set, not the marketing description of a backup plan.
Record the storage reference and the database/files identities belonging to that set. An entry that only says backups enabled does not identify a copy in the merchant’s custody. A previously downloaded copy can be independently held, but its date and scope still matter: independence from the host does not make an old or incomplete copy adequate for the planned recovery. Keep those findings separate.
Follow every dependency in the retrieval route
Name the authorized person or team that can retrieve the copy and the account or permission it uses. Then trace the prerequisites: storage access, the identity used to sign in, any approval needed to export, and any decryption access needed to use the archive. Record only the location of the access instructions and the responsible owner; never record the secrets themselves.
Assess that route against the loss you are planning for. A second storage location still leaves a dependency if its only usable sign-in or decryption route belongs to the service or contractor being replaced. A link that forwards back into the old host’s dashboard has not demonstrated independent retrieval. Conversely, a retained copy with a documented authorized access route outside that service provides concrete custody evidence, even though restoration remains a separate question.
Do not revoke access or interrupt the live service merely to demonstrate independence. Use the actual account and permission records, documented dependencies and any genuine retrieval already performed by an authorized custodian. If the merchant lacks authorization or a working access route, record the missing permission and use the relevant service’s legitimate recovery or handoff process.
Tie retention to a particular version
Record the retention term that applies to the identified copy, who can remove it, and any documented expiry or dependency on an active subscription. Distinguish the written policy from the versions actually visible in the storage record. If the policy does not explain what happens when the hosting relationship ends, that is a specific unresolved term. Do not convert a general promise into a guaranteed survival period.
Retrieval evidence should name the person, date, exact copy and observed result. A successful listing shows that an entry was visible; a completed retrieval establishes more, but neither alone proves a successful restoration. If a genuine restoration has been recorded for that same set, keep its reference separately so the handoff does not overstate what was checked. No retrieval evidence means retrieval is unverified, not that a new date should be entered.
Resolve custody before relying on it
The usable conclusion identifies who holds the copy, which independent route is established, how long the records say it will remain, and what remains unknown. When the only copy or access route is still tied to the service being replaced, make that a named dependency for the merchant’s handoff decision. The authorized owner can arrange a permitted transfer or clarify the retention/access term before relying on that copy. Preserve the existing recovery material while that issue is resolved.
This decision does not itself authorize a host cancellation or restoration. Backup consistency, restoration authority and orders received since capture need their own checks. A Prism checkout-review consultation can discuss how the unresolved custody dependency affects a proposed storefront change. Describe the website and the access question; confirm any handoff or recovery assistance, responsibilities, fees and terms before work. The public form is not a place to upload the backup, customer records or access credentials.
Backup custody record
Use one sheet for one retained recovery set and the service whose access may end. Store only references to private records. Treat custody as established only to the extent that the location, authority and retrieval evidence support it; list remaining dependencies explicitly.
Worksheet entries are not submitted by Prism’s worksheet and are not saved by the site. Use record types, availability, anonymized observations, or match/mismatch results. Do not enter government identifiers, customer names or addresses, customer messages, receipt-access links, card or bank details, passwords, or keys. Send sensitive documents only through the provider’s verified secure channel.
Backup custody record. The last column is for temporary notes.
Custody check
Evidence to record
What it establishes
Your record
Backup location reference
Evidence to recordStorage account or repository reference and exact retained set identity, without private access links.
What it establishesWhich copy exists and where it is held, rather than which service advertises backups.
Database and files covered
Evidence to recordManifest references for both components and their capture dates.
What it establishesIndependent storage is useful only for the components actually retained.
Authorized custodian
Evidence to recordPerson or team and the permission record authorizing retrieval.
What it establishesA named contact is not enough unless that contact has a usable authorized route.
Access dependency
Evidence to recordRequired storage login, identity service, export approval and decryption-access owner where applicable.
What it establishesIdentify any step that still depends on the departing host or contractor; omit secrets.
Retention term
Evidence to recordApplicable policy or agreement, actual retained versions and any stated expiry or termination condition.
What it establishesA policy promise and a particular retained version are separate evidence.
Retrieval evidence
Evidence to recordExisting dated retrieval record naming custodian, exact copy and observed result.
What it establishesDistinguish visible listing, completed retrieval and any separately documented restoration.
Custody gap and owner
Evidence to recordMissing permission, unavailable component or unresolved retention term, with its authorized owner.
What it establishesKeep reliance on the copy conditional until the specific missing evidence is resolved.
These are temporary notes. Leaving or reloading this page may clear them. Worksheet entries are not sent automatically. If you copy notes into the consultation message and submit the form, Prism receives them as part of your request.
Limits
Independent custody does not prove that database and files are consistent or that the set can restore the store.
A backup-service promise does not establish account-specific retention, retrieval speed or recovery success.
Keep passwords, decryption keys, private download tokens, configuration files and customer data out of the worksheet and public inquiry.
WordPress backups — checked 2026-09-29. WordPress recommends multiple backup locations and explains that complete restoration ordinarily requires both database and files as a consistent set. General backup guidance does not establish a particular host account’s retention, retrieval time or recoverability.
Prism solutions — checked 2026-09-21. Prism offers storefront review, processing preparation and help with provider website questions. Requested work, responsibilities, fees and terms require an agreed scope; the provider decides eligibility and account terms.
Prism contact — checked 2026-09-21. The consultation form asks for the website, products and question, excludes payment-card details, passwords and customer records, and leads to email follow-up. An inquiry is not an appointment, purchase or processing application.