Documentation

Security model

Encrypted safes, optional E2E, self-hosted boundary.

At rest

Safes use AES-256-GCM. Storage is deduplicated. You control the host and disks.

E2E mode

When E2E is enabled, rubixd does not hold plaintext backup contents or the keys required to decrypt them. Metadata and job status remain visible to operators.

Self-hosted

This is not a Rubix-hosted SaaS backup product. You run rubixd. See also /security.

Claims we do not make here

  • HIPAA or SOC 2 certified
  • Microsoft 365 backup
  • Linux LVM block-volume backup
  • Complete peer replication