All postsSecurity

Keep the data in your own bucket

For a compliance-heavy buyer, "the data never leaves an account we control" is often the only acceptable shape. It is also the highest-margin thing we can sell, and those two facts are not in tension.

saved.sh

There is a question that ends backup vendor evaluations at regulated companies, and it usually arrives about twenty minutes in:

Does the data leave our cloud account?

For most vendors the honest answer is yes, and the conversation is effectively over regardless of how good the product is. Encryption helps. It does not always help enough, because the requirement is frequently about custody and jurisdiction rather than confidentiality.

Point it at your own storage

one artifactencrypted onceOUR CUSTODY, BILLED AS STORAGEPrimaryrestores prefer thisSecondarya different providerYour own bucketyour account, your custodyoutside our custody, so wecharge nothing to store it
Two destinations sit inside our custody and are billed as stored bytes. The third does not, and is not.

An artifact can land in several destinations at once. Our primary storage, our storage at a second provider, and a bucket you own in an account you control.

On the third, we orchestrate, verify and track every run, and we store nothing. The bytes go from your machine to your bucket. What you are buying is the scheduling, the encryption boundary, the retention policy and the run history, which is the part that is actually hard.

The incentives, stated out loud

This is the highest-margin thing we can sell, because it removes our largest recurring cost. We are telling you that because it is the reason to trust the offer rather than a reason to doubt it.

0

Bytes we store on this path

0USD

Charged by us for that storage

1

Procurement objection this removes entirely

Secondary is not a cold tier, deliberately

The middle option deserves a note, because it looks like a place to save money and is not.

A secondary copy lives at a different provider, and it is ordinary storage rather than a cold or archival class. Cold tiers charge for retrieval, and the deep ones charge heavily, so a single legitimate disaster-recovery restore can cost more than a year of storage.

That cost does not track anything we would bill you for, because a retrieval fee is a function of the storage class rather than of the bytes moved. What secondary sells is provider independence: if one provider has a bad day, or a bad year, the copy is somewhere else.

What you still get

Everything except the storage:

  • Encryption applied on your machine with your key, unchanged
  • Retention enforced against your bucket, under a hold you cannot later shorten
  • A run history you can audit, with sizes and checksums
  • The same artifact format, restorable by hand with no vendor involved

Which one to pick

If nobody is asking where the data lives, use our primary storage. It is simpler, and simpler is worth something.

If somebody is asking, the answer is available, and it does not cost you features to take it.