Security

Built as critical infrastructure.

We treat your backups the way you'd expect a disaster-recovery platform to. Here's how the architecture protects you — without revealing anything exploitable.

Tenant Isolation

Every customer gets a dedicated PBS instance, a dedicated datastore and dedicated storage credentials. No customer can ever access another's data, credentials or metrics.

Encryption in Transit

All backup and management traffic is protected with TLS. Optional WireGuard adds a private encrypted tunnel between your Proxmox host and your backup server.

Client-Side Encryption

We strongly recommend Proxmox client-side backup encryption. Your encryption key belongs to you — ZettaKeep never automatically possesses it. Without your key, encrypted backups cannot be restored.

Access Controls

Argon2id password hashing, TOTP MFA, role-based access, scoped API tokens, session and device management, rate limiting and secure HTTP headers throughout.

Backup Verification

We continuously verify snapshot integrity so you know your backups are actually restorable — not just present.

Infrastructure Monitoring

Continuous heartbeat, storage, API, DNS, TLS-expiry and job-worker monitoring prevents silent failures across the platform.

Ransomware Resistance

Separate, restricted per-customer storage credentials mean an attacker who compromises only your Proxmox host cannot delete your cloud backups. Designed for object-lock immutability.

Data Deletion

Server deletion is phased with cool-down and typed + MFA confirmation. We never destroy backup data solely because a billing webhook arrived.

Incident Response

Centralized security logging and audit trails, with a public status page and documented control-plane disaster recovery.

Without your encryption key, encrypted backups cannot be restored. Store your Proxmox client-side encryption key somewhere safe and independent of your infrastructure.