saved.sh
DocsPricingDownloadBlog

By source

  • Database backupsPostgres today, on any of the three paths.
  • Files and foldersDirectories on your own hardware. Local path only.
  • Anything you can scriptThe escape hatch, with no reduced guarantees.

By how it runs

  • Backups you driveCLI or API, driven by whatever you already run.
  • Backups on your infrastructureOur worker, your hardware. We never hold the credential.
  • Fully managed backupsWe execute and orchestrate. Nothing to host.
  • Compliance and custodyYour bucket, your account, our orchestration.

Understand it

  • How it worksThree paths, one artifact lifecycle
  • SecurityWhat we can and cannot see
  • CompareAgainst snapshots, cloud-native and scripts
Get started
saved.sh

External backups for the systems a business actually runs on.

A product of reops.

Product

  • Documentation
  • Solutions
  • Compare
  • How it works
  • Security
  • Pricing
  • Download

Developers

  • CLI
  • REST API
  • Recover

Company

  • Blog
  • Privacy
  • Terms

© 2026 saved.sh

Your data survives what holds it.

All postsSecurity

Keep the data in your own bucket

For a compliance-heavy buyer, "the data never leaves an account we control" is often the only acceptable shape. It is also the highest-margin thing we can sell, and those two facts are not in tension.

2 August 2026·saved.shView as Markdown

There is a question that ends backup vendor evaluations at regulated companies, and it usually arrives about twenty minutes in:

Does the data leave our cloud account?

For most vendors the honest answer is yes, and the conversation is effectively over regardless of how good the product is. Encryption helps. It does not always help enough, because the requirement is frequently about custody and jurisdiction rather than confidentiality.

Point it at your own storage

one artifact

encrypted once

Our custody, billed as storage

Primary

restores prefer this

Secondary

a different provider

Your own bucket

your account, your custody

Outside our custody, so we charge nothing to store it

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.
Two destinations sit inside our custody and are billed as stored bytes. The third does not, and is not.

An artifact can land in several destinations at once. Our primary storage, our storage at a second provider, and a bucket you own in an account you control.

On the third, we orchestrate, verify and track every run, and we store nothing. The bytes go from your machine to your bucket. What you are buying is the scheduling, the encryption boundary, the retention policy and the run history, which is the part that is actually hard.

The incentives, stated out loud

This is the highest-margin thing we can sell, because it removes our largest recurring cost. We are telling you that because it is the reason to trust the offer rather than a reason to doubt it.

Where a vendor's incentives usually point

Most storage-backed products want your bytes on their infrastructure, because storage is the recurring revenue. A vendor offering to hold none of your data is either confused about their business model or selling you something other than storage. We are selling something other than storage.

0

Bytes we store on this path

0USD

Charged by us for that storage

1

Procurement objection this removes entirely

Secondary is not a cold tier, deliberately

The middle option deserves a note, because it looks like a place to save money and is not.

A secondary copy lives at a different provider, and it is ordinary storage rather than a cold or archival class. Cold tiers charge for retrieval, and the deep ones charge heavily, so a single legitimate disaster-recovery restore can cost more than a year of storage.

That cost does not track anything we would bill you for, because a retrieval fee is a function of the storage class rather than of the bytes moved. What secondary sells is provider independence: if one provider has a bad day, or a bad year, the copy is somewhere else.

What you still get

Everything except the storage:

  • Encryption applied on your machine with your key, unchanged
  • Retention enforced against your bucket, under a hold you cannot later shorten
  • A run history you can audit, with sizes and checksums
  • The same artifact format, restorable by hand with no vendor involved

The trade, so you can weigh it

You take on the bucket. Its lifecycle policy, its access controls, its bill and its regional configuration are yours, and a misconfiguration there is not something we can see or fix for you. That is the actual cost of custody, and anyone who tells you custody is free is selling something.

Which one to pick

If nobody is asking where the data lives, use our primary storage. It is simpler, and simpler is worth something.

If somebody is asking, the answer is available, and it does not cost you features to take it.

Read next

We do not delete your backups when your card fails

The moment a customer most needs their data is often the moment their billing broke. So a failed payment starts a ladder, not a deletion, and downloads keep working the whole way down.

Backups that survive the thing that took out production.

How it worksStart free