Capture any source — databases, servers, sites, repos, Kubernetes — encrypt it in one engine, and replicate it to every destination you own at once. End to end, on your schedule, restorable in a click.
Databases, servers, sites, containers, repos, Notion and object storage — protected the same way, on the same schedule, in the same encrypted vault.
Logical dumps via pg_dump, any version, streamed and encrypted.
Consistent single-transaction dumps, ready to restore anywhere.
Native archive dumps with safe namespace remapping on restore.
Point-in-time RDB snapshots pulled straight from the instance.
Any directory over SSH — key or password auth, tarred and sealed.
Site files and the database, captured together in one snapshot.
Named volumes backed up straight from the daemon, no downtime.
Every repo on GitHub, GitLab or Gitea, mirror-cloned and archived.
Every page and database exported to one encrypted JSON snapshot.
Every cluster manifest — workloads, config, RBAC — archived as YAML.
Replicate an S3 bucket to another provider, incrementally, off-site.
Encryption happens inside the worker. We orchestrate the machinery — you hold the keys and the data.
DB, server, site or volume
AES-256-GCM in the worker
SHA-256 integrity check
Your bucket, your keys
The real console — schedule, replicate, watch it run, and know it's restorable.
A polished dashboard for humans, an API and CLI for machines, a native desktop app — one encrypted core.
A polished console for sources, schedules, restores and your team.
Trigger and list backups from CI or your own tooling with a token.
Automate from any shell — a single static binary, no runtime.
Native window and tray for macOS, Windows and Linux.
Ciphertext leaves, keys never do. Backups land in your own bucket — we orchestrate, you own.
Protect your dataEvery backup is sealed with AES-256-GCM inside the worker. Ciphertext leaves; keys never do.
Backups land in your own S3-compatible bucket. We orchestrate — you always own the data.
Each backup carries a SHA-256 checksum you can re-verify on demand. Know it's intact.
Connections, targets and history are scoped to your organization from the first byte.
Far more than a dump on a timer. A complete, secure backup platform — here's the full surface area.
Per-tenant data keys, AAD-bound, wrapped by a master key.
Zero-knowledge sealing in the worker — only ciphertext leaves.
Every backup is auto-verified — decrypted and checked — right after it lands.
TOTP-based 2FA to lock down every account.
Sensitive actions recorded and attributable to a member.
Owners, admins and members with scoped permissions.
Sources, targets and history scoped to your org.
Backups land in your bucket; keys never leave.
Daily, hourly or any expression. Set once and forget.
Grandfather-father-son tiers — daily, weekly, monthly, yearly.
Replicate every backup to more than one storage target.
Replayed into an empty target, never overwriting live data.
Transient failures never become a lost backup.
Pull any backup over a signed, authenticated link.
Success rate and storage growth at a glance.
Flags backups that shrink or swell against their trend.
Share a read-only backup-health page per project.
Slack, Discord or any webhook, on every run.
Watch backups encrypt, verify and upload in real time.
Group sources per client or environment, isolated cleanly.
Scope members to only the projects they should see.
Owners, admins, members — every sensitive action recorded.
A polished console for sources, schedules, restores and team.
Trigger and list backups from CI or your own tooling.
Automate from any shell — one static binary, no runtime.
Headless enroll-and-back-up for machines behind firewalls.
Native window and tray for macOS, Windows and Linux.
From a single side project to a regulated fleet — the same encrypted engine, tuned to how you ship.
Protect the side project that pays your rent — free, in one click.
Automate backups across every client and environment. Sleep through deploys.
Schedules, retention and restores that fit how you already ship — auditable.
Encryption in your own storage, isolation and full history compliance asks for.
In your own S3-compatible bucket — AWS, Cloudflare R2, Backblaze B2 or self-hosted MinIO. We orchestrate the backups; the data never lives on our servers.
No. Every backup is encrypted with AES-256-GCM inside the worker before upload. Only ciphertext leaves, and the encryption key stays out of your storage.
Pick a snapshot and a target from the dashboard, confirm, and we decrypt, decompress and replay it — into a separate, empty destination by default so nothing is overwritten by accident.
PostgreSQL, MySQL/MariaDB, MongoDB, Redis, any directory over SSH, full WordPress sites (files + database), Docker volumes, every repository on GitHub/GitLab/Gitea, your Notion workspace, Kubernetes cluster manifests, and bucket-to-bucket storage replication — all on one schedule.
Yes. Trigger and list backups over a REST API with a token, or use the xbm CLI — a single static binary — to automate from any shell or CI pipeline.
We verify it for you automatically. Right after every backup lands, the worker re-downloads it, checks its SHA-256, then decrypts and decompresses it to prove it's genuinely restorable — not just present. You can also re-verify any backup on demand, and failures alert you immediately.
Set up your first automated, encrypted, verifiable backup in under five minutes.
Create your free accountNew sources, releases and the occasional deep-dive — straight to your inbox.