Backup Pro: you always see what Domma did
Scheduled, encrypted backups of every site, restores that are tested in a sealed-off copy - and a record the site owner can read of every backup and every restore, including the ones we started.

A backup you have never restored is a hope, not a backup. And a host who can restore your site without telling you is a host you have to take on trust. Backup Pro is built around both of those ideas.
What it does
Every site we host is backed up on a schedule. A backup holds the site's content, configuration, Tools' data and media, and - for sites that use MongoDB - a dump of the site's own database, taken with the site's own database login. Each one carries a manifest: the versions of the CMS and every Tool, and a size and fingerprint for every file.
Backups are encrypted and stored without duplication, so an unchanged site costs almost nothing to back up again. By default each site keeps 14 daily, 8 weekly and 12 monthly backups.
The work is done by its own service, separate from the Manager that runs the sites, so a restart of one never interrupts the other.
Restores that are tested
Once a month, each site's latest backup is restored into a sealed-off copy: its own folder, its own throwaway database, no way to send mail and no way to reach anything outside the server. The copy is started, every published page is checked, the admin is checked, and the database counts are compared with the manifest. Then everything is deleted. The result is a date - "restore tested on" - that both we and the site owner can see.
If a site goes more than a day without a good backup, or a restore test fails, we are alerted.
The part we care most about
We can back up and restore any site we host; that is the job. But the site belongs to its owner, and the owner should never have to wonder what was done to it. So:
- Every backup, failure, restore, prune, schedule change and restore test is notified to the site's own admins, in their own admin.
- Every one is written to an activity log the owner can read and cannot hide - for example, "Restored by Domma (Darryl): the page prices.md from the backup of 28/09/2026, reason: ...". The log is chained, so an entry cannot be quietly removed.
- A restore we start must give a reason, and the owner is told before and after.
Owners cannot block us from protecting their site. They can always see exactly what we did.
For the site owner
With the Backup Pro Tool, a site's own admins get a Backups screen: when the last good backup was taken, when the next one is due, the retention, the last restore test and a Back up now button. They can restore the whole site or just chosen collections, pages or media folders. A restore always takes a safety backup first, and it never touches the site's secrets, database connection or licences. Downloads leave secrets out.
Restore permission is separate from backup permission, so not every admin who can take a backup can roll the site back.
Off-site copies
Today the backups are kept on our own server, in an encrypted store apart from the sites' folders - but on the same machine. Copies to a second, off-site provider are built in and are being switched on next; until then the Tool says so plainly rather than implying otherwise.
How to get it
Backup Pro is a Pro Tool for sites we host. Ask us about Backup Pro, or read Running nine sites on one server for the story of why it exists.


