For your IT team
A technical overview of the tools, architecture, and standards powering our Backup-as-a-Service platform. No marketing, just the stack.
Veeam Backup & Replication
The industry standard for enterprise-grade backup and recovery. We use Veeam as the core engine for all backup jobs across image level, file level, and application aware workloads spanning physical, virtual, and cloud environments. Every client environment is managed through a dedicated or shared VBR instance. Shared instances are fully isolated at the job and repository level with no cross-tenant data access.
Technical details
- →Image-level and file-level backup support
- →Application-aware processing (VSS)
- →Granular recovery to bare metal
- →Retention policy management
- →Encrypted backup chains
FortiGate
All managed environments are connected to our infrastructure via FortiGate site-to-site VPN. This creates an encrypted persistent tunnel between the client's network and our backup infrastructure. Backup traffic never traverses the public internet unprotected.
Technical details
- →Site-to-site IPsec VPN tunnels
- →Encrypted backup transport path
- →Network segmentation and isolation
- →Managed firewall policies
- →Remote access control
Block Storage
Fast block storage is used as the primary backup target for short-retention backup chains. This provides the speed needed for quick restores and frequent restore point access. Retention is typically 7 days, ensuring rapid access to recent recovery points without the cost of long-term block storage.
Technical details
- →High-IOPS primary backup landing zone
- →Configurable retention window, default 7 days
- →Optimized for Veeam backup chains
- →Fast restore point access
- →Tiered automatically to object storage
Object Storage
Long-term backup copies are tiered to object storage, providing cost-effective, durable offsite retention. Object storage serves as the secondary copy in our 3-2-1 backup strategy, ensuring a clean copy exists separate from the primary target and from the client's local environment.
Technical details
- →30-day retention (configurable)
- →Scale-out capacity without complexity
- →Supports WORM / immutability policies
- →Data remains exclusively within US borders
- →Veeam Scale-Out Backup Repository integration
Immutable Backups
All offsite backup copies are written to immutable storage targets using object-lock policies. Once written, backup files cannot be modified, encrypted, or deleted for the defined retention period regardless of what happens to the source environment, even if source credentials are compromised.
Technical details
- →Object lock (WORM) on all offsite copies
- →Ransomware-proof recovery points
- →Independent of source environment state
- →Tamper-evident audit trail
- →Supports immutability requirements commonly requested in audits
Data Encryption
All backup data is encrypted at rest and in transit, using strong industry-standard encryption — primarily AES-256, though other comparable standards may be used depending on the environment. Encryption keys are managed per-client and never stored alongside backup data. Backup jobs are configured with encryption enabled at the job level within Veeam, and data in transit travels over TLS or the encrypted VPN tunnel.
Technical details
- →Backup jobs encrypted at rest, primarily with AES-256 (Veeam job-level)
- →TLS encryption in transit
- →Per-client key management
- →Keys never co-located with backup data
- →Architecture supports auditability and data residency requirements
US-Based Data Centers
All client data is stored exclusively in United States data centers, within Tier III facilities. All data remains on US soil. No exceptions, no offshore replication, no third party cloud handoffs.
Technical details
- →Tier III data centers, located in the USA
- →Data residency: United States only
- →No offshore replication or storage
- →Physically redundant infrastructure
- →US-based operations and support team
Architecture approach
3-2-1 Backup Strategy
Three copies of data, on two different media types, with one copy offsite. Block storage (primary) + object storage (offsite) + optional local copy.
RPO & RTO by design
Recovery Point Objective and Recovery Time Objective are defined before architecture is built, not treated as afterthoughts.
Isolation by default
Backup infrastructure is logically and physically separated from production environments. A compromised production environment cannot reach backup data.
Documentation-first operations
Every environment has a complete runbook. Every change is logged. Nothing undocumented runs in production.
Have technical questions?
We're happy to get into the details. Talk directly with someone who knows the stack.