saved.sh
DocsPricingDownloadBlog

By source

  • Database backupsPostgres today, on any of the three paths.
  • Files and foldersDirectories on your own hardware. Local path only.
  • Anything you can scriptThe escape hatch, with no reduced guarantees.

By how it runs

  • Backups you driveCLI or API, driven by whatever you already run.
  • Backups on your infrastructureOur worker, your hardware. We never hold the credential.
  • Fully managed backupsWe execute and orchestrate. Nothing to host.
  • Compliance and custodyYour bucket, your account, our orchestration.

Understand it

  • How it worksThree paths, one artifact lifecycle
  • SecurityWhat we can and cannot see
  • CompareAgainst snapshots, cloud-native and scripts
Get started
saved.sh

External backups for the systems a business actually runs on.

A product of reops.

Product

  • Documentation
  • Solutions
  • Compare
  • How it works
  • Security
  • Pricing
  • Download

Developers

  • CLI
  • REST API
  • Recover

Company

  • Blog
  • Privacy
  • Terms

© 2026 saved.sh

Your data survives what holds it.

All postsEngineering

How to back up a managed database you do not control

RDS, Neon, Supabase and PlanetScale all take snapshots for you. Those snapshots live in the provider's account, in the provider's format, and usually cannot be restored anywhere else. Here is what to do about it.

8 August 2026·saved.shView as Markdown

Every managed database provider takes automatic backups, says so on the pricing page, and is telling the truth. Then a team reads that line, ticks the backup box on their compliance questionnaire, and stops thinking about it.

The gap between "the provider takes snapshots" and "we have backups" is where most of the bad days live.

What a provider snapshot actually is

A provider snapshot is a copy of your data, held by the provider, in the provider's own format, inside the provider's account, restorable only into that same provider.

Read that sentence again with an incident in mind. Every clause is a dependency on the exact organisation whose failure you are trying to survive.

SNAPSHOTEXTERNAL COPYSurvives a dropped tableSurvives a bad migrationSurvives a deleted cloud accountSurvives stolen production credentialsSurvives ransomware with admin accessReadable without the vendorTHE FIRST TWO ROWS ARE THE ONES PEOPLE PLAN FOR. THE REST ARE THE ONES THAT END COMPANIES.
A snapshot lives inside the boundary it is supposed to protect you from. A copy leaves it.
ScenarioProvider snapshotPortable dump in your bucket
You dropped a tableWorks well, often the fastest optionWorks
Provider has a regional outageUnavailable exactly when neededWorks
Your account is suspended or the payment failsUsually inaccessibleWorks
You want to move to another providerNot restorable elsewhereWorks
An auditor asks for a copy outside the vendorCannot produce oneWorks
Someone deletes the instanceSnapshots frequently go with itWorks

Provider snapshots are genuinely good at the first row. They are structurally incapable of the rest, and no amount of provider durability changes that, because durability was never the problem. Custody was.

The fix is a logical dump you own

For anything Postgres-compatible, which now covers Neon, Supabase, RDS, and most of the newer entrants, the portable copy is a logical dump:

pg_dump "$DATABASE_URL" \
  --format=custom --no-owner --no-privileges \
  | gzip -9 \
  | aws s3 cp - "s3://${BUCKET}/pg/$(date -u +%Y-%m-%dT%H-%M-%SZ).dump.gz"

--no-owner and --no-privileges matter more here than on self-hosted Postgres. Managed providers invent their own role names, and a dump that carries them will fail to restore anywhere except back into the same provider, which defeats the entire point.

For MySQL-compatible providers including PlanetScale, the equivalent is mysqldump --single-transaction --set-gtid-purged=OFF, where the second flag is what stops the dump refusing to load into a different topology.

1

Row in that table a snapshot covers

5

Rows it does not

2flags

Between a portable dump and a stuck one

Where the connection-limit problem bites

Serverless Postgres providers pool aggressively and cap connections, and a long pg_dump holds one open for the duration. On Neon and Supabase specifically, run the dump against the direct connection string rather than the pooled one. The pooler will terminate a long transaction, and you will get a truncated dump that exits zero.

That failure mode is worth stating plainly because it is the single most common way a managed-database backup is silently broken: the dump succeeds, the file lands, and it contains part of your data. A size comparison against the previous run catches it. Nothing else will.

What we do

We run exactly the dumps above, on a schedule, from a worker with the right network path to your database, and we write the result to a bucket you own.

The parts that are ours rather than yours are the parts that are annoying: holding the credential in a secret store instead of an env file, retrying a run that died halfway, recording what each run produced so a truncated dump shows up as a size anomaly instead of a surprise, and applying a retention policy that knows whether a newer good copy exists before it expires an older one.

The five minute version

Whatever you do about all of this, do one thing today: take your provider's most recent snapshot and try to restore it somewhere that is not your provider. If you cannot, you have learned that your backup strategy and your vendor strategy are the same strategy.

The summary

Keep the provider snapshots. They are fast, they are cheap, and they are the right tool when someone drops a table at 11am.

Then add one portable dump, in an open format, in an account the provider does not control. That copy is the one that answers every other row in the table.

Read next

How to back up PostgreSQL to S3, and what the cron job leaves out

A working pg_dump to S3 script you can paste today, followed by the six failure modes it cannot see. The script is not wrong. It is just much smaller than the problem.

Backups that survive the thing that took out production.

How it worksStart free