Every claim on this page is something the product does, not something we intend to do.
We do not hold your key
Your data is encrypted on your own server, with a password that never reaches us. There is no escrow, no recovery path, no support ticket that gets you back in. If a court asks us for your files, all we have to give is ciphertext.
The other side of that: lose your key and nobody can recover your backups. Not even us.
You can prove your backups happened
Every completed backup is written to a tamper-evident record — append-only and cryptographically chained, so a single altered entry breaks the chain for everyone in it. Export the whole thing yourself, whenever an auditor asks.
A compromised server cannot delete its own backups
The agent on your machine can write, and only write. It holds no storage credentials and cannot list, read or remove what it has already sent. Every object is locked for the length of your retention window. Ransomware that owns your server does not own your backups.
Everything stays in Germany
Storage in Falkenstein, control plane in a German data centre, both under signed data processing agreements. No American cloud, no onward transfer to work around.
Restore to the minute, not to last night
For MySQL and MariaDB we capture the transaction log continuously. Pick the moment before the mistake — not the backup that ran eight hours earlier.
You pay for what changes, not for what repeats
Only the blocks that changed leave your machine, and identical blocks are stored once no matter how many servers they came from. Fifteen machines running the same operating system store those system files once between them — which is the difference between an allowance that lasts and one that runs out on the third server.