Endpoints · Servers · VMware · KVM · Proxmox · OpenStack

Ransomware-resilient backup for everything you run

Protect Windows, Linux, VMware and KVM workloads from one control plane. Keep independent immutable recovery points. Recover files, disks, complete VMs and whole systems when production is lost or compromised.

Immutable
WORM retention lock the backup service cannot shorten
Verified
Recovery proven by boot and mount tests, not assumed
Multi-tenant
Reseller and customer isolation enforced server-side
backupengine.webyne.com

Protected

5,225

Jobs (24h)

1,449

Contained

3

Backup activity

Successful
contoso-db-01 Transferring
DESKTOP-1054 Verifying
fabrikam-erp-07 Success

Protect

Endpoints & virtual machines

Discover every workload across your endpoints, physical servers and hypervisors, then assign protection by VM, folder, tag, cluster or resource pool.

Back up

Incremental, encrypted, deduplicated

Changed-block reads where the platform supports them, content-hashed chunking, compression before encryption, and envelope keys held in a KMS hierarchy.

Recover

Files, disks, VMs & full systems

Browse a recovery point, restore a single file, rebuild an entire VM on another host, or bring a machine back from bare metal.

Platform coverage

One control plane, every workload

Capability is negotiated per platform, version and storage backend — so the console shows what your environment can actually do, rather than assuming every hypervisor supports the same snapshot or incremental method.

VMware vCenter / ESXi

vCenter and ESXi API discovery, snapshot with guest quiescing, changed-block tracking where the version supports it.

KVM / QEMU / libvirt

libvirt discovery, QEMU guest-agent freeze/thaw, dirty-bitmap incrementals where the storage backend allows.

Proxmox VE

Proxmox API and QEMU stack, snapshot mode where supported, restore to the original or an alternate node.

OpenStack

Cinder, Glance and Nova-aware workflows for volume, image and instance recovery.

Windows

Desktops and servers: files and folders, Outlook/PST, external drives and full system images.

Linux

Desktop and server agents with file, volume and full-system protection.

macOS

Endpoint agent for files, folders and full-system recovery points.

Physical servers

Bare-metal Windows and Linux servers with bootable recovery media.

Architecture

How your data is protected

Every stage is explicit. A backup is not reported successful until its manifest is committed and verified, and a hypervisor snapshot is always released — on success, on failure and on cancellation.

  1. 01

    Sources

    Endpoints, physical servers and virtual infrastructure

  2. 02

    Connectors

    Discover, quiesce and stream changed data

  3. 03

    Orchestrator

    Policy, schedule, job state and snapshot lifetime

  4. 04

    Proxy

    High-throughput data movers with resumable transfer

  5. 05

    Chunk engine

    Dedupe, compress, then encrypt

  6. 06

    Repository

    Durable primary copy

  7. 07

    Immutable vault

    Retention-locked cyber-recovery tier

  8. 08

    DR replica

    Separate failure and security domain

Dedupe never crosses a tenant

Chunk deduplication is confined to a tenant boundary, so no customer can infer another customer's content from chunk hits.

Compression before encryption

Data is compressed while it still compresses, then sealed with per-tenant keys wrapped by a KMS-managed hierarchy.

Snapshot cleanup is a first-class state

Orphaned hypervisor snapshots degrade production storage, so a watchdog reclaims them independently of the job process.

We detect. We stop. You recover.

Behaviour-based detection scores each workload against its own baseline. When something crosses the line, containment freezes destructive retention work and pins the last known-good recovery point.

A compromised source credential cannot shorten an active retention lock, because the vault holds its own credentials in a separate security domain.

View the Protection Center

Mass encryption

Abrupt high-entropy rewrites across protected files are scored, not just logged.

Extension anomaly

Rapid unusual rename and extension patterns raise the workload risk score.

Deletion velocity

Bulk deletion beyond the device baseline triggers review.

Canary objects

Unauthorised modification of protected decoys fires immediately.

Clean-point marking

Recovery points are marked either side of a suspicious event boundary.

Containment

Destructive retention work is frozen and the last known-good point is pinned.

Recovery

Recovery is tested, not assumed

Every restore is authorised separately from being requested, and has to pass a boot or mount test before it is reported complete. Scheduled verification re-reads and hashes samples of your recovery points on its own cadence.

File-level

Mount and browse a recovery point, restore individual files and folders.

Disk-level

Restore a virtual disk or recover a volume in its native format.

Full VM

Rebuild the VM configuration and disks on the original or an alternate host.

Bare metal

Full-system recovery to replacement hardware from bootable media.

Alternate host

Map compute, storage and network to a different host, cluster or node.

Cross-hypervisor

VMware to KVM and back as an explicit, auditable conversion workflow.

For MSPs & resellers

Multi-tenancy that actually isolates

A super-admin, reseller and customer hierarchy with tenant-scoped repositories, quotas and policies. Tenant authorization is enforced on every resource server-side — one customer cannot enumerate, read or restore another's data, even by guessing an identifier.

  • Delegated tenant administrators and scoped API keys
  • Per-tenant metering for protected VMs, endpoints and stored bytes
  • Separate audit trail and reporting for every tenant
  • White-label branding and custom domains as a commercial option

Tenant hierarchy

Webyne platform
Northwind MSP reseller
Contoso Manufacturing customer
Fabrikam Health customer
Adventure Logistics customer

Be ready for anything.

Back up today. Recover tomorrow. Bring your endpoints, servers and virtual infrastructure under one control plane with an independent immutable copy.