Managed Backup
your infrastructure, backed up and verified
Managed backup of your virtualization servers: TruoCloud designs the policy, runs the jobs, watches the results, verifies integrity, tests restores and delivers periodic evidence. This is not disk space, it is demonstrable recovery capability.
→ reading only the changed blocks on the hypervisor…
→ encrypting at source and replicating off-site…
✓ recovery point verified
ISOLATION
A dedicated space
Your data lives in its own namespace, with its own access control lists and independent retention policies.
NO DELETION
Write, and nothing else
The credentials installed on your server can only create backup points. They cannot list, read, modify or delete what is already stored.
ENCRYPTION
At source, with key escrow
Data is encrypted on your hypervisor before it leaves, and the key is held in an escrow separate from the storage.
VERIFICATION
With deliverable evidence
Automated integrity validation and real test restores, each one with a report covering date, scope, duration and result.
A backup that cannot be deleted from the server it protects
An agent installed on your virtualization server coordinates the capture with the guest operating system, reads only the changed blocks, encrypts them before they leave and sends them to the TruoCloud repository. Pruning and retention run from our infrastructure, with credentials that never live in your environment.
The path of every recovery point
3-2-1
up to three copies, with off-site replica and archive
30 days
of immutable retention on the Crítico plan
15 min
loss window with continuous Service Protection
0
read or delete permissions from your environment
TECHNICAL FLOOR
Four principles, no exceptions and no plan that negotiates them
These are not contractable options: all four apply to every plan. Each one answers a known, preventable failure mode.
Per-client isolation
A dedicated namespace inside the backup platform, with its own access control lists and independent retention policies. No other client, and no staff member without explicit authorisation, has visibility into that space.
Write without delete
Even if an attacker gains full administrative control of the virtualization server —including the backup agent credentials— there is no technical path to destroy the history of copies.
Encryption at source with key escrow
Industrial-grade symmetric encryption applied before transmission. Data travels and rests encrypted, and TruoCloud keeps a protected copy of the key in an escrow physically and logically separate from the storage.
Verification with deliverable evidence
Automated integrity validation, plus actual recovery of virtual machines in an isolated environment to confirm that they boot and are functional. The restore test is the only mechanism that turns an expectation into a verified fact.
An operational implication worth knowing before you sign
This design means you cannot browse, download or delete your own backups on your own. Every restore is formally requested and executed by the TruoCloud team. It is a deliberate limitation: the same barrier that stops an attacker from deleting the copies stops direct access from your environment.
SELF-ASSESSMENT
Six signs that your operation is exposed
Every statement you recognise maps to a concrete failure mode, not to an abstract worry. We do not use industry statistics: the calculation is done with your own numbers.
| Situation | What it means |
|---|---|
| Nobody remembers the date of the last end-to-end tested restore | You do not know whether the backups work. A backup that has never been restored is an assumption, not a protection. |
| Backups live on a disk attached to the same server, or on a network share reachable from the domain | An attack that reaches the servers reaches the copies too. The protection disappears in the very event it was meant to protect against. |
| The credentials that administer virtualization can also delete the backups | Anyone who compromises an administrative account destroys the history. There is no technical barrier. |
| Nobody is alerted when a backup job stops running | A stopped job is silent. The failure is discovered on the day of the incident. |
| You cannot say how long it would take to be operational again if the main server were lost today | Recovery time is unknown and therefore impossible to plan for or report to management. |
| There is no record of how much data would be lost in the worst case | The loss window is neither defined nor agreed with the people who bear the consequence. |
Three or more matches point to an exposure this service is designed to close.
PLANS
Three plans
They share the same technical floor and differ in frequency, retention, number of copies, immutability and verification intensity. All three include incident restores at no additional cost.
Esencial
Secondary workloads
USD 99
per month · setup USD 149
- 3 virtual machines and 500 GB included
- Backup once a week
- Retention of 4 weeks and 3 months
- One copy, no off-site replica
- Monthly shallow verification
- Restore response within 8 business hours
Protegido
Baseline for production infrastructure
USD 179
per month · setup USD 299
- 3 virtual machines and 500 GB included
- Backup once a day
- Retention of 14 days, 8 weeks and 6 months
- Second off-site copy, 14 days immutable
- One hot-protected service, 12-hour loss window
- Quarterly restore test, with report
- Restore response within 4 business hours
Crítico
Systems whose outage stops the company
USD 349
per month · setup USD 549
- 3 virtual machines and 500 GB included
- Backup twice a day
- Retention of 30 days, 12 weeks, 12 months and 3 years
- Third copy in archive storage, 30 days immutable
- Two services in continuous shipping, 15-minute window
- Monthly restore test, with report
- Restore response within 1 hour, 24/7 coverage
RECOMMENDATION
For an organisation whose operation depends on its virtualized servers, TruoCloud recommends the Protegido plan as the baseline, because it adds the second off-site copy with immutable retention and documented quarterly restore tests. The Esencial plan keeps a single copy and has no immutability: it is not recommended as the only protection for production systems.
When each plan applies
INVESTMENT
Managed Backup pricing
The service is billed in four components —base fee, additional virtual machine, additional terabyte and additional protected service— so that growth of the environment is reflected proportionally and predictably.
The full plan
| Esencial | Protegido | Crítico | |
|---|---|---|---|
| The complete virtual machine— The whole server: operating system, applications and data | |||
| Virtual machines included | 3 | 3 | 3 |
| Data capacity included | 500 GB | 500 GB | 500 GB |
| Backup frequency | Once a week | Once a day | Twice a day |
| Daily retention | — | 14 days | 30 days |
| Weekly retention | 4 weeks | 8 weeks | 12 weeks |
| Monthly retention | 3 months | 6 months | 12 months |
| Yearly retention | — | — | 3 years |
| The services running inside— Databases (MySQL, MariaDB, PostgreSQL), mail servers, stateful applications | |||
| Services included | — | 1 | 2 |
| Protection level for those services | — | Consistent | Continuous |
| Service backup frequency | — | Twice a day | Continuous shipping |
| Service loss window | — | 12 hours | 15 minutes |
| Restore of an individual database or mailbox | — | Yes | Yes |
| Durability, verification and coverage— Applies to everything above | |||
| Number of copies | 1 | 2 | 3 |
| Off-site copy | No | Yes | Yes |
| Copy in archive storage | No | No | Yes |
| Immutable retention | No | 14 days | 30 days |
| Integrity verification | Monthly (shallow) | Monthly (full) | Weekly (full) |
| Real restore test | On request (chargeable) | Quarterly, with report | Monthly, with report |
| Incident restores | Included | Included | Included |
| Restore coverage | Business hours | Business hours + on-call | 24 / 7 |
| Status report | Monthly automatic | Monthly annotated | Monthly + quarterly review |
| Price— In United States dollars, excluding any applicable taxes | |||
| Monthly base fee | USD 99 | USD 179 | USD 349 |
| Additional virtual machine / month | USD 9 | USD 15 | USD 24 |
| Additional terabyte / month | USD 20 | USD 35 | USD 60 |
| Setup (one-off) | USD 149 | USD 299 | USD 549 |
These figures are the starting point. The final quote is issued after the technical assessment, with the real inventory and volumes of your environment. The additional terabyte is measured on source data —not on the storage consumed after compression— and is billed pro rata, not per whole terabyte.
Complementary services
Prepayment discount
Commercial terms
- Billed monthly in advance. Setup is invoiced at the start of the service.
- No minimum term: it can be cancelled with thirty days' notice.
- Capacity consumption and the number of protected machines are measured monthly and reflected in the following period's invoice.
- The discount applies to the recurring fee, not to setup. Prepayment does not constitute a minimum term either: if the service is cancelled before a paid period is used up, the unused portion is refunded.
COMMITMENTS
What is committed, and what is not
TruoCloud does not commit to a fixed recovery time: that figure depends on the volume of data, the available bandwidth and the existence of destination hardware, none of which we control. What is committed are the numbers below, and the existence of valid, verified recovery points.
| Esencial | Protegido | Crítico | |
|---|---|---|---|
| Backup platform availability | 99.5 % | 99.7 % | 99.9 % |
| Response to a restore request | 8 business hours | 4 business hours | 1 hour |
| Failed job notification | 24 hours | 8 hours | 2 hours |
| Notification when the agent goes silent | 48 hours | 24 hours | 8 hours |
| Monthly report delivery | First 10 days | First 5 days | First 5 days |
| Support channel | Email and phone | Email, phone and permanent on-call |
Response times are counted from the formal request through the agreed channel. Failure to meet the committed levels for reasons attributable to TruoCloud gives rise to the compensations set out in the service agreement.
What the monthly report contains
- Result of every backup job in the period and the successful execution rate.
- Recovery points available per virtual machine and the age of the most recent one.
- Result of the integrity verifications performed.
- Status of the off-site replica and of immutable retention, where applicable.
- Capacity consumption against the contracted amount and a growth projection.
- Incidents in the period and the actions taken.
- The restore test report, in the periods where one applies.
SCOPE
What the service does not include
A precisely bounded scope is part of a serious commercial relationship. This is what the service does not do, stated before the meeting rather than after the signature.
Scope exclusions
Transactional consistency of databases
Virtual machine backup does not guarantee it: that requires Service Protection, included in the Protegido and Crítico plans and available separately on Esencial.
Undeclared virtual machines
Only what is formally added to the inventory is protected. Machines created afterwards are not protected until they are notified and incorporated.
Infrastructure monitoring
We monitor the backup service, not the availability, performance or general health of your servers or applications.
Administration of the virtualization platform
It does not cover operation, updates, tuning or support of the hypervisor or the guest systems.
Perimeter security and incident response
It does not cover firewalls, antivirus, intrusion detection, forensics or containment of security incidents.
Provision of hardware or connectivity
The destination server for a restore, as well as the data link, are the client's responsibility.
Migration of historical backups
Importing copies previously generated with other tools is quoted as a separate project.
Remediation of pre-existing conditions
Infrastructure problems found during onboarding that prevent delivery of the service are quoted separately.
Operational limits
- You have no direct read or delete access over your backups. Every restore is formally requested and executed by TruoCloud.
- Restores are included at no cost, but their duration depends on the volume of data, the available bandwidth and the existence of operational destination hardware.
- TruoCloud backs up the state of the data as it stands at capture time. It does not detect or correct corruption originating in your applications before the backup.
- Availability of recovery points is limited to the contracted retention. Past that period, points are deleted according to the agreed policy and are unrecoverable.
About the encryption key
Data is encrypted at source. If your key and the escrow are lost simultaneously, the backed-up data is unrecoverable by any technical means. That is why TruoCloud expressly recommends the escrow; anyone who chooses not to set one up signs the corresponding waiver provided for in the agreement.
When this service is not justified
It is worth ruling out first the cases where contracting it would be spending without a return. We prefer to state them explicitly.
The environment's data is not the source of truth
These are replicas, labs or systems whose original data lives elsewhere, or all critical workloads run on third-party managed services that already assume their protection contractually.
The capability already exists inside the organisation
There is staff dedicated to continuity, documented restore tests are run regularly and immutable off-site copies are kept. If none of the six situations in the self-assessment applies, the service would duplicate an existing capability.
ONBOARDING
Five phases, and the service is not live until the fifth
Activation ends with a documented real recovery and a recovery manual written for your environment, not with a welcome email.
Assessment
2 to 3 business days
Inventory of virtual machines, measurement of volumes, evaluation of the link, definition of the backup window and designation of contacts.
Provisioning
1 to 2 business days
Creation of the isolated space, generation of write-only credentials, encryption setup and constitution of the key escrow.
First full backup
3 to 7 days, depending on volume and link
Agent installation, validation of the integration with the guest systems and execution of the initial backup.
Verification
2 business days
Integrity check, activation of the off-site replica and start-up of monitoring and alerts.
Test restore
2 to 3 business days
Documented real recovery, delivery of the environment-specific recovery manual and handover session.
Total estimated time
Between ten and fifteen business days, for environments of up to twenty virtual machines. Larger environments or those with particular requirements are quoted specifically.
What we need from your side
- A technical contact responsible during onboarding.
- Administrative access to the virtualization server.
- Authorisation of the maintenance window to install the agent and the integration components.
- Validation and signature of the inventory of virtual machines to protect.
- Signature of the key escrow record.
- Participation in the handover session and formal acceptance of the test restore.
NOT THE SAME AS VPS BACKUP
Which of the two do you need?
Managed Backup protects the virtualized infrastructure you operate yourself: your own hypervisor, on your premises or wherever you keep it, with an agent we install and a service agreement. VPS Backup protects the VPS we host here, is enabled from the panel and restores without a ticket. If your server runs on TruoCloud, what you want is VPS Backup.
See VPS Backup