Security

What the server sees — and what it does not

Self-hosted backup with a clear boundary: ciphertext in safes, optional E2E so keys stay with you.

Encrypted-at-rest safes

Backup chunks land in safes protected with AES-256-GCM. Storage is deduplicated. You own the host and the disks.

E2E mode

In end-to-end mode, rubixd does not hold plaintext backup contents or the keys needed to decrypt them. A compromised backup server yields ciphertext and metadata, not readable files.

Self-hosted, not SaaS backup

Rubix Backup is software you run. This product is not a Rubix-hosted SaaS backup service.

Honest scope

We do not claim HIPAA or SOC 2 certification here. Windows coverage is VSS volumes; Linux coverage is file trees. Peer replication is not presented as complete.

Security docs · How it works · Download