Security
Where your data lives, and who can see it.
BackupSentinel holds your backup reports, your client list and your device records. This page says where they are kept, how access is controlled, and how you take them back.
Hosted in Frankfurt.
The application, its database and the mail servers that receive your backup reports all run in Frankfurt. Report emails arrive at your client addresses, are read, and are stored with the job they belong to; the raw messages are kept for 30 days.
BackupSentinel never connects to your backup servers and installs nothing on them. It only receives the reports they send.
| What | Provider | Where |
|---|---|---|
| The web application | Vercel | Frankfurt (fra1) |
| Database, sign-in and file storage | Supabase | Frankfurt (eu-central-1) |
| Incoming report emails | Amazon Web Services (SES) | Frankfurt (eu-central-1) |
| Card payments | Stripe | Card details stay with Stripe |
Who can see what.
- Roles
- Owner, admin, member and viewer. Viewers read; members work on problems; owners and admins manage settings, channels, API keys, members and billing. Only the owner changes roles.
- Sign-in
- Email and password, Microsoft or Google. Sign-in, sign-up and password reset are protected by Cloudflare Turnstile.
- Two-factor
- Codes from an authenticator app. Owners and admins can require two-factor sign-in for everyone in the workspace.
- Activity log
- Owners and admins see who changed what. Email addresses and IP addresses are not shown in it.
- Support access
- BackupSentinel support can open your workspace to help with a problem you report. Everything done that way is labelled in your activity log.
- Shared reports
- A client report link shows one client and one month, expires after 7, 30 or 90 days, can be revoked, and records when it is viewed.
How it is protected.
- In transit
- HTTPS only, with HTTP Strict Transport Security for two years. A content security policy limits what pages may load, and pages cannot be framed by other sites.
- Device logins
- Encrypted with AES-256-GCM before they are stored. Only owners and admins can reveal one, and every reveal is written to the activity log.
- Keys and links
- API keys and shared report links are stored only as hashes: each is shown once, when it is created.
- Device photos
- Kept in private storage and shown through links that expire after an hour.
Your data, your call.
- Export: owners and admins can download the workspace as JSON at any time, even after a subscription has ended.
- Delete: the owner can delete the workspace from Settings, after typing its name. The subscription is cancelled at once.
- Retention: report emails, alerts and report history are kept for your plan’s retention window.
What it does not do.
- No single sign-on (SAML): sign-in is email and password, Microsoft or Google.
- No setting for session length.
Report a security problem
Found something that looks like a vulnerability? Write to support@backupsentinel.io with “Security” in the subject. A person reads it and answers.
Questions about security?
Write to us before you start the trial, or start it and look at the activity log and settings yourself.