We treat your backups the way you'd expect a disaster-recovery platform to. Here's how the architecture protects you — without revealing anything exploitable.
Every customer gets a dedicated PBS instance, a dedicated datastore and dedicated storage credentials. No customer can ever access another's data, credentials or metrics.
All backup and management traffic is protected with TLS. Optional WireGuard adds a private encrypted tunnel between your Proxmox host and your backup server.
We strongly recommend Proxmox client-side backup encryption. Your encryption key belongs to you — ZettaKeep never automatically possesses it. Without your key, encrypted backups cannot be restored.
Argon2id password hashing, TOTP MFA, role-based access, scoped API tokens, session and device management, rate limiting and secure HTTP headers throughout.
We continuously verify snapshot integrity so you know your backups are actually restorable — not just present.
Continuous heartbeat, storage, API, DNS, TLS-expiry and job-worker monitoring prevents silent failures across the platform.
Separate, restricted per-customer storage credentials mean an attacker who compromises only your Proxmox host cannot delete your cloud backups. Designed for object-lock immutability.
Server deletion is phased with cool-down and typed + MFA confirmation. We never destroy backup data solely because a billing webhook arrived.
Centralized security logging and audit trails, with a public status page and documented control-plane disaster recovery.
Without your encryption key, encrypted backups cannot be restored. Store your Proxmox client-side encryption key somewhere safe and independent of your infrastructure.