How it works

Outbound agents → encrypted safes → restore

No vendor cloud in the data path. You run the server; agents dial out.

1. Install rubixd

Deploy the Linux server package from the Hub stable channel. Create safes, set GFS retention, enable schedules and alerting.

2. Enroll agents

Install the Windows or Linux agent. Agents connect outbound to rubixd — NAT-friendly, no inbound firewall holes on protected hosts. Windows uses VSS volumes; Linux backs up file trees. Run the agent as a service.

3. Backup into safes

Block-efficient chunk backup lands in deduplicated AES-256-GCM safes. Optional E2E mode keeps plaintext and keys off the server.

4. Restore and verify

Restore from safes. Run verify jobs. GC reclaims space under retention. Hub online updates keep server and agents current without baking CDN secrets into this site.

Download · Install docs · Request access