Encrypted backups: the honest guide.
The uncomfortable question
Who can read your backups? If they sit in a cloud service without encryption on your side, the answer includes the provider — and anyone who breaches them. A properly made backup travels and is stored encrypted, and you hold the key.
The three conditions
- Automatic: every night, with no human involvement, and an alert if something fails. Backups made “when I remember” fail on exactly the day you need them.
- Encrypted end to end: with tools like BorgBackup, the copy leaves your server already encrypted. Even if the off-site store is in another country, nobody can read it without your key.
- The 3-2-1 rule: three copies of the data, on two different types of media, with at least one off your premises. A fire or a ransomware attack should not be able to reach all of them.
What GDPR says
The regulation requires appropriate technical measures to protect personal data — and backups are personal data. An unencrypted off-site copy is a problem; an encrypted copy with the key under your control is a safeguard you can put in writing. More context in the GDPR and AI guide.
And above all: tested
A backup that has never been restored is a promise, not a backup. Under AUREA's maintenance plans restores are tested regularly, so that the bad day is only a bad afternoon.
Quick questions
At minimum, one automatic daily copy of your working data. On busy systems — heavy invoicing, production — incremental copies are scheduled several times a day.
On a backup server away from your premises, always encrypted at source with a key only your company controls. That way the physical location matters little: nobody without the key can read it.
