BackupProof

Backups you can prove.

BackupProof backs up your servers, apps and databases, then restores every backup in a sandbox, checks it, and records signed proof that it works. Self-hosted, open source, one binary.

Restore testshop-db

Backup from 02:00 today, restored into a sealed sandbox

  1. Downloaded and decrypted every file (passed)
  2. Every file matches the original exactly (passed)
  3. Database structure is healthy (passed)
  4. All 600 rows are there (passed)
  5. Your check: orders exist (passed)

Time to restore41 ms

Signed proof agent:web-01, ledger entry #13 Timestamped by an independent authority
Every restore test ends like this, pass or fail, and the record can’t be quietly edited afterwards.

“Backup succeeded” only means a job ran.

It doesn’t tell you the data comes back. A dump can be empty, a password can be lost, a database can restore with half its rows. Most teams find out on the day they need it.

BackupProof shows an item as Restore tested only after it has actually been restored from storage and checked, and it keeps the receipts.

How it works

  1. Back up

    Folders, websites and databases are copied to your storage, encrypted and deduplicated. Database logins are read from Docker or WordPress on the server, so you don’t type them.

  2. Restore test

    On a schedule, the latest backup is restored into an empty folder or a database container with no network. Every file is compared with the original, databases get integrity checks and every row is counted.

  3. Sign the proof

    The result, pass or fail, is signed by the server that did the test and added to a hash-chained ledger. Deleting or editing a past result breaks the chain.

  4. Verify anywhere

    Anyone can check a proof offline with the public keys, without your storage password and without trusting the BackupProof server.

What it covers

Protects
Files and folders, websites, PostgreSQL, MySQL and MariaDB, MongoDB, SQLite, and the output of any command. Hooks can pause an app while it’s copied.
Stores to
A local or USB disk, Backblaze B2, Amazon S3, Cloudflare R2, Wasabi, any S3-compatible service, or another server over SFTP. Ransomware protection with S3 Object Lock.
Checks
File-by-file comparison with the original, PostgreSQL amcheck, MySQL CHECK TABLE, MongoDB validate, SQLite integrity_check, row counts against backup time, and your own SQL checks.
Brings in old backups
Converts existing backups so they get tested too: GPG, OpenSSL and age encrypted files in a bucket, restic, Kopia and BorgBackup repositories, and Google Drive, Dropbox or OneDrive through rclone.
Watches
Alerts when something didn’t happen: a late backup, an old proof, a server gone quiet. By email, Slack, Discord or webhook.
Runs on
One static binary for Linux, macOS and Windows on Intel or ARM, or a Docker image. The dashboard protects its own machine; other servers connect with one command and only make outbound connections.
Compared with a typical backup tool
What you getTypical backup toolBackupProof
Backups made and stored safelyYesYes
Stored data checked for damageUsually, on requestOn a schedule
Backups actually restored and testedNo, or by handAutomatically
Databases loaded and rows countedNoYes
Failed tests kept on recordLogs that can be editedSigned and chained
Proof an auditor can check aloneScreenshots or PDFsOffline verification

Tools like restic, Kopia and BorgBackup are excellent at storing backups and checking stored data. BackupProof can import their repositories and restore-test what’s already there, so you don’t have to start over.

Evidence your auditor can check

Download a proof report for any period. It maps the evidence to the controls auditors test: SOC 2 A1.2 and A1.3, ISO 27001 A.8.13, NIST CSF, DORA Article 12, NIS2 Article 21 and HIPAA.

What the proof report contains. Each proof is an in-toto statement signed with Ed25519, linked into a ledger with signed checkpoints, and optionally timestamped by an RFC 3161 authority. The checking tool is the same open-source binary.

$ backupproof proof verify drill.bundle.json --key bpkey1:server@backup:… --require-timestamp
VALID  restore-drill/v1
  signer    agent:web-01 (bp:e96a62db83be1b16)
  drill     passed=true
  ledger    entry #13, chained to signed checkpoint #14
  time      2026-10-06T22:20:28Z (RFC 3161)

Install

The installer checks the download, sets BackupProof up as a service and prints your dashboard address with a one-time setup code.

Linux or macOS

Prefer to read it first? See what the installer does. It checks the download against the published SHA-256 checksums.

Windows

In PowerShell, run as Administrator.

Docker

Then open the address shown, create your admin account and click Protect something. Other servers connect from the dashboard with one command. Prefer to download yourself? Get the binaries and checksums, or read the getting-started guide.

Questions

Is it free?

Yes. BackupProof is open source under the MIT license, with no paid tier and no feature limits.

Does my data leave my servers?

Only to the storage you choose, and it’s encrypted before it leaves. Backup data goes straight from each server to your storage and never passes through the dashboard. Nothing is sent to us.

What happens when a restore test fails?

The item turns red on the dashboard, you get an alert, and the failure is signed and recorded in the ledger like a pass. Open the item to see which check failed and why.

Can my auditor check the proof without trusting me?

Yes. Give them a proof report and your public keys. The open-source backupproof proof verify command checks the signatures, the ledger chain and the timestamps offline, without your storage password.

I already use restic, Kopia or Borg. Do I have to switch?

No. Import your existing repository and keep your current backup job. BackupProof converts each new snapshot and restore-tests it, every night if you like.

What do I need to run it?

Any Linux, macOS or Windows machine for the dashboard, or Docker. Database restore tests use Docker on the machine that runs them; file backups don’t need it.