During this week's sweep of every web property we operate, we found one of our own sites — the founder's personal site — live in production with exactly one deployment on record: a direct upload, no git branch, no repository behind it. An exhaustive search of every machine, including trash and archived staging sets, found no file containing the page source. Deleting that single deployment record would have destroyed the site permanently, with no way to rebuild it.
A deploy artifact is not a backup. We know that. We wrote it down before. And a property still slipped through, because nothing was enforcing it.
The recovery
Everything was recovered from the live origin, byte for byte: the page itself, robots, sitemap, the custom 404, and the images — which survived only because they were embedded in the served HTML and could be decoded back out of it.
The sharpest edge was the headers file. The hosting platform consumes it at build time and never serves it, so it cannot be downloaded — it had to be reconstructed field by field from the live responses. Had anyone redeployed from the recovered HTML alone, every security header on the site — CSP, HSTS, the whole set — would have silently disappeared, and nothing would have flagged it.
The rule it produced
Every property we operate now has its full source under version control, with the serving surface diffed against the tree before any deploy. Not as a habit — as a gate. The same sweep is what produced this week's homepage rework you're reading now.
If we'll publish this about our own infrastructure, you can trust the case studies about yours.
