Encrypted backups in minutes.Start free →
Encrypted · Scheduled · Verifiable

One backup.
Everywhere you keep it.

Capture any source — databases, servers, sites, repos, Kubernetes — encrypt it in one engine, and replicate it to every destination you own at once. End to end, on your schedule, restorable in a click.

11 source types AES-256 encrypted Multi-destination
app.xbackupman.com/dashboard live
128
Backups
100%
Success · 30d
32 GB
Stored
production-dbnow
  • Backup initiated09:32
  • Encrypted · SHA-256 verified10:18
  • Replicated to 3 targets10:18
  • Notified #backups10:18
Backup health
Restorable
production-db+1 replicated
PostgreSQLMySQLMongoDBRedisWordPressDockerSSH / FilesGitHubGitLabGiteaNotionKubernetesStorage syncAmazon S3Cloudflare R2Backblaze B2MinIOAES-256-GCMSHA-256PostgreSQLMySQLMongoDBRedisWordPressDockerSSH / FilesGitHubGitLabGiteaNotionKubernetesStorage syncAmazon S3Cloudflare R2Backblaze B2MinIOAES-256-GCMSHA-256
01Back up everything

Eleven source types.
One engine.

Databases, servers, sites, containers, repos, Notion and object storage — protected the same way, on the same schedule, in the same encrypted vault.

01

PostgreSQL

Logical dumps via pg_dump, any version, streamed and encrypted.

02

MySQL / MariaDB

Consistent single-transaction dumps, ready to restore anywhere.

03

MongoDB

Native archive dumps with safe namespace remapping on restore.

04

Redis

Point-in-time RDB snapshots pulled straight from the instance.

05

Servers & files

Any directory over SSH — key or password auth, tarred and sealed.

06

WordPress

Site files and the database, captured together in one snapshot.

07

Docker volumes

Named volumes backed up straight from the daemon, no downtime.

08

Git repositories

Every repo on GitHub, GitLab or Gitea, mirror-cloned and archived.

09

Notion

Every page and database exported to one encrypted JSON snapshot.

10

Kubernetes

Every cluster manifest — workloads, config, RBAC — archived as YAML.

11

Storage replication

Replicate an S3 bucket to another provider, incrementally, off-site.

02How it works

Sealed before a byte leaves.

Encryption happens inside the worker. We orchestrate the machinery — you hold the keys and the data.

01

Source

DB, server, site or volume

02

Encrypt

AES-256-GCM in the worker

03

Verify

SHA-256 integrity check

04

Your storage

Your bucket, your keys

03Why switch

Stop babysitting backups.

The old way
  • Cron jobs that silently stop
  • Dumps that error at 3am
  • A file exists — is it restorable?
  • One script per database
The xbackupman way
  • Scheduled, monitored, retried
  • Email + dashboard on every run
  • SHA-256 verified, every time
  • Eleven sources, one engine
04See it in action

xbackupman, live.

The real console — schedule, replicate, watch it run, and know it's restorable.

New schedule
Source
hedonic-treadmill
Destination
lunar-empire-452
Cadence
OnceDailyWeeklyCustom
SMTWTFS03:00
Activity live
  • Backup initiated09:32
  • Encrypted · SHA-256 verified10:18
  • Replicated to 3 targets10:18
  • Notified #backups10:18
running
Backup health
Last restore point
25 Dec, 10:18
Stored
32 GB
Storage replication
Source storage
storage-acme
Destination
prod-corp
Or connect any S3-compatible provider
···
05Every surface

Wherever you work.

A polished dashboard for humans, an API and CLI for machines, a native desktop app — one encrypted core.

Web dashboard

A polished console for sources, schedules, restores and your team.

REST API

Trigger and list backups from CI or your own tooling with a token.

CLI (xbm)

Automate from any shell — a single static binary, no runtime.

Desktop app

Native window and tray for macOS, Windows and Linux.

06Security first

Your data, yours alone.

Ciphertext leaves, keys never do. Backups land in your own bucket — we orchestrate, you own.

Protect your data

Zero-knowledge encryption

Every backup is sealed with AES-256-GCM inside the worker. Ciphertext leaves; keys never do.

Your storage, your keys

Backups land in your own S3-compatible bucket. We orchestrate — you always own the data.

Integrity verification

Each backup carries a SHA-256 checksum you can re-verify on demand. Know it's intact.

Tenant isolation

Connections, targets and history are scoped to your organization from the first byte.

07The whole toolkit

Everything xbackupman does.

Far more than a dump on a timer. A complete, secure backup platform — here's the full surface area.

Security8 capabilities

Envelope encryption

Per-tenant data keys, AAD-bound, wrapped by a master key.

AES-256-GCM

Zero-knowledge sealing in the worker — only ciphertext leaves.

SHA-256 integrity

Every backup is auto-verified — decrypted and checked — right after it lands.

Two-factor auth

TOTP-based 2FA to lock down every account.

Audit log

Sensitive actions recorded and attributable to a member.

Role-based access

Owners, admins and members with scoped permissions.

Tenant isolation

Sources, targets and history scoped to your org.

Your storage · your keys

Backups land in your bucket; keys never leave.

Automation6 capabilities

Cron schedules

Daily, hourly or any expression. Set once and forget.

GFS retention

Grandfather-father-son tiers — daily, weekly, monthly, yearly.

Multi-destination

Replicate every backup to more than one storage target.

One-click restore

Replayed into an empty target, never overwriting live data.

Automatic retries

Transient failures never become a lost backup.

Authenticated download

Pull any backup over a signed, authenticated link.

Insight5 capabilities

Analytics dashboard

Success rate and storage growth at a glance.

Anomaly detection

Flags backups that shrink or swell against their trend.

Public status pages

Share a read-only backup-health page per project.

Email + webhook alerts

Slack, Discord or any webhook, on every run.

Live job activity

Watch backups encrypt, verify and upload in real time.

Teams3 capabilities

Projects

Group sources per client or environment, isolated cleanly.

Per-project access

Scope members to only the projects they should see.

Roles & audit log

Owners, admins, members — every sensitive action recorded.

Everywhere5 capabilities

Web dashboard

A polished console for sources, schedules, restores and team.

REST API

Trigger and list backups from CI or your own tooling.

xbm CLI

Automate from any shell — one static binary, no runtime.

Server agent

Headless enroll-and-back-up for machines behind firewalls.

Desktop app

Native window and tray for macOS, Windows and Linux.

0 types
sources, one engine
0-bit
AES-GCM encryption
0%
in your own storage
08Who it's for

Built for teams like yours.

From a single side project to a regulated fleet — the same encrypted engine, tuned to how you ship.

01

Freelancers & indie makers

Protect the side project that pays your rent — free, in one click.

02

Startups & agencies

Automate backups across every client and environment. Sleep through deploys.

03

Engineering teams

Schedules, retention and restores that fit how you already ship — auditable.

04

Enterprises & regulated

Encryption in your own storage, isolation and full history compliance asks for.

09Pricing

Start free. Scale up.

Free
$0/ forever
  • 1 source
  • Daily backups
  • 7-day retention
  • Email notifications
  • API + CLI access
Get started
Popular
Pro
$19/ per month
  • Unlimited sources
  • Hourly & custom schedules
  • GFS & 10-year retention
  • Anomaly detection
  • Team members & roles
  • Priority support
Start 14-day trial
Enterprise
Custom/ contact us
  • Everything in Pro
  • SAML SSO & audit exports
  • SLA & uptime guarantee
  • Custom contracts & DPA
  • Dedicated support
Contact sales
10Questions

Everything you're wondering.

Where are my backups stored?+

In your own S3-compatible bucket — AWS, Cloudflare R2, Backblaze B2 or self-hosted MinIO. We orchestrate the backups; the data never lives on our servers.

Can you read my backups?+

No. Every backup is encrypted with AES-256-GCM inside the worker before upload. Only ciphertext leaves, and the encryption key stays out of your storage.

How do restores work?+

Pick a snapshot and a target from the dashboard, confirm, and we decrypt, decompress and replay it — into a separate, empty destination by default so nothing is overwritten by accident.

What can I actually back up?+

PostgreSQL, MySQL/MariaDB, MongoDB, Redis, any directory over SSH, full WordPress sites (files + database), Docker volumes, every repository on GitHub/GitLab/Gitea, your Notion workspace, Kubernetes cluster manifests, and bucket-to-bucket storage replication — all on one schedule.

Do you have an API and CLI?+

Yes. Trigger and list backups over a REST API with a token, or use the xbm CLI — a single static binary — to automate from any shell or CI pipeline.

How do I know a backup is good?+

We verify it for you automatically. Right after every backup lands, the worker re-downloads it, checks its SHA-256, then decrypts and decompresses it to prove it's genuinely restorable — not just present. You can also re-verify any backup on demand, and failures alert you immediately.

Your next outage is coming.
Be ready for it.

Set up your first automated, encrypted, verifiable backup in under five minutes.

Create your free account
Get product updates

New sources, releases and the occasional deep-dive — straight to your inbox.

Product updates and the occasional deep-dive. No spam, unsubscribe anytime.