Self-hosted · AES-256-GCM · outbound agents

Backup you run. Safes the server cannot read in E2E mode.

Rubix Backup is a self-hosted platform: Linux rubixd plus outbound Windows and Linux agents. Block-efficient chunk backup, deduplicated encrypted-at-rest safes, GFS retention, verify, and Hub online updates. Agents dial out — NAT-friendly.

Windows VSS volumes · Linux file trees · E2E mode keeps keys off the server
Self-hosted rubixdOutbound Win / Linux agentsAES-256-GCM safesE2E mode availableHub online updates
Capabilities

What ships today

Concrete scope for IT, MSP, and security buyers. No suite-parity claims against Veeam, Acronis, or Datto.

Linux rubixd

Self-hosted server on infrastructure you control. Safes, schedules, GC, verify, Hub online updates.

Outbound agents

Windows and Linux agents dial out to rubixd. NAT-friendly — no inbound ports on protected hosts.

Block-efficient chunks

Changed-block style chunk backup with deduplicated storage in encrypted safes.

AES-256-GCM safes

Encrypted at rest. Optional E2E mode so the server never holds plaintext or decryption keys.

Windows VSS · Linux trees

Windows volumes via VSS. Linux file-tree backup. Scoped honestly — not a full suite claim.

Retention and verify

GFS retention, garbage collection, backup verify, schedules, and alerting. Agent as a service.

How it works

Outbound agents → safes → restore

Four steps from empty host to verified restore. No vendor cloud in the data path.

  1. 01

    Install rubixd

    Deploy the Linux server on a host you control. Create safes and set retention.

  2. 02

    Enroll outbound agents

    Install Windows or Linux agents. They dial out to rubixd — works behind NAT.

  3. 03

    Backup into encrypted safes

    Chunk backup lands in AES-256-GCM safes. Deduplicated at rest. Optional E2E mode.

  4. 04

    Restore and verify

    Restore from safes. Run verify jobs. GFS retention and GC keep storage honest.

Security

Keys you hold. Ciphertext on the server.

Built for teams that want self-hosted backup with a clear confidentiality boundary. We do not claim HIPAA or SOC 2 certification on this page.

Encrypted at rest

Safes use AES-256-GCM. Deduplicated ciphertext lives on storage you control.

E2E mode

In end-to-end mode the server does not hold plaintext or decryption keys. Compromise of rubixd yields ciphertext.

What the server sees

Metadata, schedules, job status. In E2E mode it does not see readable backup contents.

You host it

Not a Rubix-hosted SaaS backup service. You run rubixd on your infrastructure.

Security overview · Docs: security model

Deploy

Three public download channels

Server and agents publish through the Rubix Hub public latest/download APIs. No baked CDN secrets in this site package.

stable — rubixd

Linux server package. Channel stable.

agent-win-x64

Windows agent. VSS volumes. Outbound to your rubixd.

agent-linux-x64

Linux agent. File-tree backup. Service install.

Go to downloads Install guide

Who it is for

IT, MSP, and security buyers

B2B scope. Technical, calm, specific — not consumer backup fluff.

IT and internal ops

Protect Windows and Linux servers you already run. Keep backup storage on your network.

MSP and multi-tenant ops

Self-hosted control plane per customer or shared rubixd with clear safe boundaries. Keys stay with you.

Security-minded teams

E2E mode for backups where the backup server must not be able to read contents.

Pricing

Soft pricing

No invented tiers or dollar amounts on this site. Soft note: no list prices until Hub plans ship. Prefer interest / sales capture for now.

Request access · Contact sales · sales@secure-store.io.

Install on your host. Enroll agents. Verify a restore.

Request access for evaluation. Soft pricing — no list prices until Hub plans ship.