Protect Windows, Linux, VMware and KVM workloads from one control plane. Keep independent immutable recovery points. Recover files, disks, complete VMs and whole systems when production is lost or compromised.
Protected
5,225
Jobs (24h)
1,449
Contained
3
Backup activity
SuccessfulProtect
Discover every workload across your endpoints, physical servers and hypervisors, then assign protection by VM, folder, tag, cluster or resource pool.
Back up
Changed-block reads where the platform supports them, content-hashed chunking, compression before encryption, and envelope keys held in a KMS hierarchy.
Recover
Browse a recovery point, restore a single file, rebuild an entire VM on another host, or bring a machine back from bare metal.
Platform coverage
Capability is negotiated per platform, version and storage backend — so the console shows what your environment can actually do, rather than assuming every hypervisor supports the same snapshot or incremental method.
vCenter and ESXi API discovery, snapshot with guest quiescing, changed-block tracking where the version supports it.
libvirt discovery, QEMU guest-agent freeze/thaw, dirty-bitmap incrementals where the storage backend allows.
Proxmox API and QEMU stack, snapshot mode where supported, restore to the original or an alternate node.
Cinder, Glance and Nova-aware workflows for volume, image and instance recovery.
Desktops and servers: files and folders, Outlook/PST, external drives and full system images.
Desktop and server agents with file, volume and full-system protection.
Endpoint agent for files, folders and full-system recovery points.
Bare-metal Windows and Linux servers with bootable recovery media.
Architecture
Every stage is explicit. A backup is not reported successful until its manifest is committed and verified, and a hypervisor snapshot is always released — on success, on failure and on cancellation.
Endpoints, physical servers and virtual infrastructure
Discover, quiesce and stream changed data
Policy, schedule, job state and snapshot lifetime
High-throughput data movers with resumable transfer
Dedupe, compress, then encrypt
Durable primary copy
Retention-locked cyber-recovery tier
Separate failure and security domain
Chunk deduplication is confined to a tenant boundary, so no customer can infer another customer's content from chunk hits.
Data is compressed while it still compresses, then sealed with per-tenant keys wrapped by a KMS-managed hierarchy.
Orphaned hypervisor snapshots degrade production storage, so a watchdog reclaims them independently of the job process.
Behaviour-based detection scores each workload against its own baseline. When something crosses the line, containment freezes destructive retention work and pins the last known-good recovery point.
A compromised source credential cannot shorten an active retention lock, because the vault holds its own credentials in a separate security domain.
View the Protection CenterAbrupt high-entropy rewrites across protected files are scored, not just logged.
Rapid unusual rename and extension patterns raise the workload risk score.
Bulk deletion beyond the device baseline triggers review.
Unauthorised modification of protected decoys fires immediately.
Recovery points are marked either side of a suspicious event boundary.
Destructive retention work is frozen and the last known-good point is pinned.
Recovery
Every restore is authorised separately from being requested, and has to pass a boot or mount test before it is reported complete. Scheduled verification re-reads and hashes samples of your recovery points on its own cadence.
Mount and browse a recovery point, restore individual files and folders.
Restore a virtual disk or recover a volume in its native format.
Rebuild the VM configuration and disks on the original or an alternate host.
Full-system recovery to replacement hardware from bootable media.
Map compute, storage and network to a different host, cluster or node.
VMware to KVM and back as an explicit, auditable conversion workflow.
For MSPs & resellers
A super-admin, reseller and customer hierarchy with tenant-scoped repositories, quotas and policies. Tenant authorization is enforced on every resource server-side — one customer cannot enumerate, read or restore another's data, even by guessing an identifier.
Tenant hierarchy
Back up today. Recover tomorrow. Bring your endpoints, servers and virtual infrastructure under one control plane with an independent immutable copy.