Minu Backup test environment is open for early customers.Talk to us

Security

Defense in depth, from the agent to the bucket

Minu Backup assumes any single layer can fail — the network, a credential or even the control plane — and is designed so your backups survive it.

01

Network

  • One public entry point

    A single IP on port 443. An SNI router passes TLS straight through to the right service — it never decrypts traffic.

  • Unknown hosts dropped

    Connections with a missing or unknown server name are dropped, and connection rates are limited per IP.

  • Storage never exposed

    Object storage has no public address; only tenant Kopia servers reach it.

  • Agents never listen

    The agent only makes outbound connections. There is no port to scan or attack.

02

Identity and jobs

  • Mutual TLS

    Agent and orchestrator both present certificates. The agent trusts only the Minu CA, not the system store.

  • ed25519-signed jobs

    Every job is signed. A broken network or API gateway can't inject a forged job.

  • No remote commands

    Jobs are typed (engine, action, parameters). The agent builds commands itself and never uses a shell.

  • Identity and replay checks

    Agent ID, tenant ID, expiry and replay are checked before any engine runs.

03

Data

  • Your allowlist wins

    Backup paths, restore targets, namespaces and stanzas are set by you in the agent config. A compromised orchestrator still can't back up /etc/shadow or restore into /etc.

  • Keys stay with you

    The Kopia repository password lives in your password file and is never sent to the orchestrator or written to logs.

  • Append-only writers

    Agent repository users can add snapshots but cannot delete them.

  • Object Lock COMPLIANCE

    Buckets use S3 Object Lock in COMPLIANCE mode: data can't be changed or deleted before its lock expires.

04

Platform

  • Tenant isolation in the database

    PostgreSQL Row Level Security is forced on every tenant table.

  • Append-only audit log

    Updates and deletes on the audit log are blocked at the database level.

  • Hardened runtime

    Pods run under the restricted Pod Security standard with default-deny network policies.

  • Sandboxed agent service

    On Linux the agent runs under systemd with a read-only system and writes limited to restore targets.

Roles and access

Sign in with your identity provider (OIDC) and MFA. Give each person only what they need.

Questions about security? Talk to us
  • Admin

    Manages users, agents, policies and encryption settings.

  • Operator

    Runs backups, requests restores and manages policies.

  • Viewer

    Read-only access to jobs, restore points and usage.

Ready to protect your data?

Our team will set up your tenant, issue agent certificates and help with your first backup policy.