NewTruo Deploy and DBaaS PostgreSQL, live in the TruoCloud panelSee the catalog
Managed Backup · for your own infrastructure

Managed Backup

your infrastructure, backed up and verified

Managed backup of your virtualization servers: TruoCloud designs the policy, runs the jobs, watches the results, verifies integrity, tests restores and delivers periodic evidence. This is not disk space, it is demonstrable recovery capability.

→ reading only the changed blocks on the hypervisor…
→ encrypting at source and replicating off-site…
✓ recovery point verified

ISOLATION

A dedicated space

Your data lives in its own namespace, with its own access control lists and independent retention policies.

NO DELETION

Write, and nothing else

The credentials installed on your server can only create backup points. They cannot list, read, modify or delete what is already stored.

ENCRYPTION

At source, with key escrow

Data is encrypted on your hypervisor before it leaves, and the key is held in an escrow separate from the storage.

VERIFICATION

With deliverable evidence

Automated integrity validation and real test restores, each one with a report covering date, scope, duration and result.

HOW IT WORKS

A backup that cannot be deleted from the server it protects

An agent installed on your virtualization server coordinates the capture with the guest operating system, reads only the changed blocks, encrypts them before they leave and sends them to the TruoCloud repository. Pruning and retention run from our infrastructure, with credentials that never live in your environment.

The path of every recovery point

Where it is encryptedOn your server, before it leaves
What is transmittedOnly the changed blocks
Who can deleteTruoCloud only
Who holds the keyA separate escrow

3-2-1

up to three copies, with off-site replica and archive

30 days

of immutable retention on the Crítico plan

15 min

loss window with continuous Service Protection

0

read or delete permissions from your environment

TECHNICAL FLOOR

Four principles, no exceptions and no plan that negotiates them

These are not contractable options: all four apply to every plan. Each one answers a known, preventable failure mode.

01

Per-client isolation

A dedicated namespace inside the backup platform, with its own access control lists and independent retention policies. No other client, and no staff member without explicit authorisation, has visibility into that space.

02

Write without delete

Even if an attacker gains full administrative control of the virtualization server —including the backup agent credentials— there is no technical path to destroy the history of copies.

03

Encryption at source with key escrow

Industrial-grade symmetric encryption applied before transmission. Data travels and rests encrypted, and TruoCloud keeps a protected copy of the key in an escrow physically and logically separate from the storage.

04

Verification with deliverable evidence

Automated integrity validation, plus actual recovery of virtual machines in an isolated environment to confirm that they boot and are functional. The restore test is the only mechanism that turns an expectation into a verified fact.

An operational implication worth knowing before you sign

This design means you cannot browse, download or delete your own backups on your own. Every restore is formally requested and executed by the TruoCloud team. It is a deliberate limitation: the same barrier that stops an attacker from deleting the copies stops direct access from your environment.

SELF-ASSESSMENT

Six signs that your operation is exposed

Every statement you recognise maps to a concrete failure mode, not to an abstract worry. We do not use industry statistics: the calculation is done with your own numbers.

SituationWhat it means
Nobody remembers the date of the last end-to-end tested restoreYou do not know whether the backups work. A backup that has never been restored is an assumption, not a protection.
Backups live on a disk attached to the same server, or on a network share reachable from the domainAn attack that reaches the servers reaches the copies too. The protection disappears in the very event it was meant to protect against.
The credentials that administer virtualization can also delete the backupsAnyone who compromises an administrative account destroys the history. There is no technical barrier.
Nobody is alerted when a backup job stops runningA stopped job is silent. The failure is discovered on the day of the incident.
You cannot say how long it would take to be operational again if the main server were lost todayRecovery time is unknown and therefore impossible to plan for or report to management.
There is no record of how much data would be lost in the worst caseThe loss window is neither defined nor agreed with the people who bear the consequence.

Three or more matches point to an exposure this service is designed to close.

PLANS

Three plans

They share the same technical floor and differ in frequency, retention, number of copies, immutability and verification intensity. All three include incident restores at no additional cost.

Esencial

Secondary workloads

USD 99

per month · setup USD 149

  • 3 virtual machines and 500 GB included
  • Backup once a week
  • Retention of 4 weeks and 3 months
  • One copy, no off-site replica
  • Monthly shallow verification
  • Restore response within 8 business hours

Protegido

Baseline for production infrastructure

USD 179

per month · setup USD 299

  • 3 virtual machines and 500 GB included
  • Backup once a day
  • Retention of 14 days, 8 weeks and 6 months
  • Second off-site copy, 14 days immutable
  • One hot-protected service, 12-hour loss window
  • Quarterly restore test, with report
  • Restore response within 4 business hours

Crítico

Systems whose outage stops the company

USD 349

per month · setup USD 549

  • 3 virtual machines and 500 GB included
  • Backup twice a day
  • Retention of 30 days, 12 weeks, 12 months and 3 years
  • Third copy in archive storage, 30 days immutable
  • Two services in continuous shipping, 15-minute window
  • Monthly restore test, with report
  • Restore response within 1 hour, 24/7 coverage

RECOMMENDATION

For an organisation whose operation depends on its virtualized servers, TruoCloud recommends the Protegido plan as the baseline, because it adds the second off-site copy with immutable retention and documented quarterly restore tests. The Esencial plan keeps a single copy and has no immutability: it is not recommended as the only protection for production systems.

When each plan applies

EsencialSecondary workloads, test or development environments, and systems whose prolonged unavailability does not affect the operation.
ProtegidoProduction infrastructure. Second off-site copy with immutable retention, full monthly verification, documented quarterly tests and hot protection for one service.
CríticoSystems whose interruption halts the company, or environments with long retention requirements for regulatory, contractual or audit reasons.

INVESTMENT

Managed Backup pricing

The service is billed in four components —base fee, additional virtual machine, additional terabyte and additional protected service— so that growth of the environment is reflected proportionally and predictably.

The full plan

EsencialProtegidoCrítico
The complete virtual machine— The whole server: operating system, applications and data
Virtual machines included333
Data capacity included500 GB500 GB500 GB
Backup frequencyOnce a weekOnce a dayTwice a day
Daily retention14 days30 days
Weekly retention4 weeks8 weeks12 weeks
Monthly retention3 months6 months12 months
Yearly retention3 years
The services running inside— Databases (MySQL, MariaDB, PostgreSQL), mail servers, stateful applications
Services included12
Protection level for those servicesConsistentContinuous
Service backup frequencyTwice a dayContinuous shipping
Service loss window12 hours15 minutes
Restore of an individual database or mailboxYesYes
Durability, verification and coverage— Applies to everything above
Number of copies123
Off-site copyNoYesYes
Copy in archive storageNoNoYes
Immutable retentionNo14 days30 days
Integrity verificationMonthly (shallow)Monthly (full)Weekly (full)
Real restore testOn request (chargeable)Quarterly, with reportMonthly, with report
Incident restoresIncludedIncludedIncluded
Restore coverageBusiness hoursBusiness hours + on-call24 / 7
Status reportMonthly automaticMonthly annotatedMonthly + quarterly review
Price— In United States dollars, excluding any applicable taxes
Monthly base feeUSD 99USD 179USD 349
Additional virtual machine / monthUSD 9USD 15USD 24
Additional terabyte / monthUSD 20USD 35USD 60
Setup (one-off)USD 149USD 299USD 549

These figures are the starting point. The final quote is issued after the technical assessment, with the real inventory and volumes of your environment. The additional terabyte is measured on source data —not on the storage consumed after compression— and is billed pro rata, not per whole terabyte.

Complementary services

Service Protection · ConsistentUSD 60 per protected instance / month
Service Protection · ContinuousUSD 145 per protected instance / month
Long-term archivingUSD 15 per terabyte / month
Additional restore testUSD 200 per exercise
Initial seeding on physical mediaUSD 350 plus logistics

Prepayment discount

Annual10 %
Two years15 %
Three years20 %

Commercial terms

  • Billed monthly in advance. Setup is invoiced at the start of the service.
  • No minimum term: it can be cancelled with thirty days' notice.
  • Capacity consumption and the number of protected machines are measured monthly and reflected in the following period's invoice.
  • The discount applies to the recurring fee, not to setup. Prepayment does not constitute a minimum term either: if the service is cancelled before a paid period is used up, the unused portion is refunded.

COMMITMENTS

What is committed, and what is not

TruoCloud does not commit to a fixed recovery time: that figure depends on the volume of data, the available bandwidth and the existence of destination hardware, none of which we control. What is committed are the numbers below, and the existence of valid, verified recovery points.

EsencialProtegidoCrítico
Backup platform availability99.5 %99.7 %99.9 %
Response to a restore request8 business hours4 business hours1 hour
Failed job notification24 hours8 hours2 hours
Notification when the agent goes silent48 hours24 hours8 hours
Monthly report deliveryFirst 10 daysFirst 5 daysFirst 5 days
Support channelEmailEmail and phoneEmail, phone and permanent on-call

Response times are counted from the formal request through the agreed channel. Failure to meet the committed levels for reasons attributable to TruoCloud gives rise to the compensations set out in the service agreement.

What the monthly report contains

  • Result of every backup job in the period and the successful execution rate.
  • Recovery points available per virtual machine and the age of the most recent one.
  • Result of the integrity verifications performed.
  • Status of the off-site replica and of immutable retention, where applicable.
  • Capacity consumption against the contracted amount and a growth projection.
  • Incidents in the period and the actions taken.
  • The restore test report, in the periods where one applies.

SCOPE

What the service does not include

A precisely bounded scope is part of a serious commercial relationship. This is what the service does not do, stated before the meeting rather than after the signature.

Scope exclusions

Transactional consistency of databases

Virtual machine backup does not guarantee it: that requires Service Protection, included in the Protegido and Crítico plans and available separately on Esencial.

Undeclared virtual machines

Only what is formally added to the inventory is protected. Machines created afterwards are not protected until they are notified and incorporated.

Infrastructure monitoring

We monitor the backup service, not the availability, performance or general health of your servers or applications.

Administration of the virtualization platform

It does not cover operation, updates, tuning or support of the hypervisor or the guest systems.

Perimeter security and incident response

It does not cover firewalls, antivirus, intrusion detection, forensics or containment of security incidents.

Provision of hardware or connectivity

The destination server for a restore, as well as the data link, are the client's responsibility.

Migration of historical backups

Importing copies previously generated with other tools is quoted as a separate project.

Remediation of pre-existing conditions

Infrastructure problems found during onboarding that prevent delivery of the service are quoted separately.

Operational limits

  • You have no direct read or delete access over your backups. Every restore is formally requested and executed by TruoCloud.
  • Restores are included at no cost, but their duration depends on the volume of data, the available bandwidth and the existence of operational destination hardware.
  • TruoCloud backs up the state of the data as it stands at capture time. It does not detect or correct corruption originating in your applications before the backup.
  • Availability of recovery points is limited to the contracted retention. Past that period, points are deleted according to the agreed policy and are unrecoverable.

About the encryption key

Data is encrypted at source. If your key and the escrow are lost simultaneously, the backed-up data is unrecoverable by any technical means. That is why TruoCloud expressly recommends the escrow; anyone who chooses not to set one up signs the corresponding waiver provided for in the agreement.

When this service is not justified

It is worth ruling out first the cases where contracting it would be spending without a return. We prefer to state them explicitly.

The environment's data is not the source of truth

These are replicas, labs or systems whose original data lives elsewhere, or all critical workloads run on third-party managed services that already assume their protection contractually.

The capability already exists inside the organisation

There is staff dedicated to continuity, documented restore tests are run regularly and immutable off-site copies are kept. If none of the six situations in the self-assessment applies, the service would duplicate an existing capability.

ONBOARDING

Five phases, and the service is not live until the fifth

Activation ends with a documented real recovery and a recovery manual written for your environment, not with a welcome email.

1

Assessment

2 to 3 business days

Inventory of virtual machines, measurement of volumes, evaluation of the link, definition of the backup window and designation of contacts.

2

Provisioning

1 to 2 business days

Creation of the isolated space, generation of write-only credentials, encryption setup and constitution of the key escrow.

3

First full backup

3 to 7 days, depending on volume and link

Agent installation, validation of the integration with the guest systems and execution of the initial backup.

4

Verification

2 business days

Integrity check, activation of the off-site replica and start-up of monitoring and alerts.

5

Test restore

2 to 3 business days

Documented real recovery, delivery of the environment-specific recovery manual and handover session.

Total estimated time

Between ten and fifteen business days, for environments of up to twenty virtual machines. Larger environments or those with particular requirements are quoted specifically.

What we need from your side

  • A technical contact responsible during onboarding.
  • Administrative access to the virtualization server.
  • Authorisation of the maintenance window to install the agent and the integration components.
  • Validation and signature of the inventory of virtual machines to protect.
  • Signature of the key escrow record.
  • Participation in the handover session and formal acceptance of the test restore.

NOT THE SAME AS VPS BACKUP

Which of the two do you need?

Managed Backup protects the virtualized infrastructure you operate yourself: your own hypervisor, on your premises or wherever you keep it, with an agent we install and a service agreement. VPS Backup protects the VPS we host here, is enabled from the panel and restores without a ticket. If your server runs on TruoCloud, what you want is VPS Backup.

See VPS Backup

Frequently asked questions

Let's talk about your infrastructure.