Security
Defense in depth, from the agent to the bucket
Minu Backup assumes any single layer can fail — the network, a credential or even the control plane — and is designed so your backups survive it.
01
Network
One public entry point
A single IP on port 443. An SNI router passes TLS straight through to the right service — it never decrypts traffic.
Unknown hosts dropped
Connections with a missing or unknown server name are dropped, and connection rates are limited per IP.
Storage never exposed
Object storage has no public address; only tenant Kopia servers reach it.
Agents never listen
The agent only makes outbound connections. There is no port to scan or attack.
02
Identity and jobs
Mutual TLS
Agent and orchestrator both present certificates. The agent trusts only the Minu CA, not the system store.
ed25519-signed jobs
Every job is signed. A broken network or API gateway can't inject a forged job.
No remote commands
Jobs are typed (engine, action, parameters). The agent builds commands itself and never uses a shell.
Identity and replay checks
Agent ID, tenant ID, expiry and replay are checked before any engine runs.
03
Data
Your allowlist wins
Backup paths, restore targets, namespaces and stanzas are set by you in the agent config. A compromised orchestrator still can't back up /etc/shadow or restore into /etc.
Keys stay with you
The Kopia repository password lives in your password file and is never sent to the orchestrator or written to logs.
Append-only writers
Agent repository users can add snapshots but cannot delete them.
Object Lock COMPLIANCE
Buckets use S3 Object Lock in COMPLIANCE mode: data can't be changed or deleted before its lock expires.
04
Platform
Tenant isolation in the database
PostgreSQL Row Level Security is forced on every tenant table.
Append-only audit log
Updates and deletes on the audit log are blocked at the database level.
Hardened runtime
Pods run under the restricted Pod Security standard with default-deny network policies.
Sandboxed agent service
On Linux the agent runs under systemd with a read-only system and writes limited to restore targets.
Roles and access
Sign in with your identity provider (OIDC) and MFA. Give each person only what they need.
Admin
Manages users, agents, policies and encryption settings.
Operator
Runs backups, requests restores and manages policies.
Viewer
Read-only access to jobs, restore points and usage.
Ready to protect your data?
Our team will set up your tenant, issue agent certificates and help with your first backup policy.