🔐 AES-256 🔑 BYOK — Your Key 🚫 No Back Door 📦 No Vendor Lock-In 🔐 AES-256 🔑 BYOK — Your Key 🚫 No Back Door 📦 No Vendor Lock-In
Encrypted Backup

Your Backup Should Leave Your Server Encrypted
AES-256 · Client-Side · Your Own Key (BYOK)

In most backup services data reaches the provider in the clear and is encrypted there. With Yedekalma, encryption happens on your own server before the backup leaves it. Choose BYOK and the key is yours too — which means we cannot open your backup either.

No credit card required · 14-day free trial

Architecture

How the Encryption Chain Is Built

Order matters: data must be encrypted before it touches the network.

1️⃣

Packaged on your server

Files, the database dump and messages are archived on your own machine.

2️⃣

Encrypted there

The archive is encrypted with AES-256. This step happens on your server, not ours.

3️⃣

Transferred encrypted

By the time it reaches the network it is already encrypted; transport is additionally protected by TLS.

4️⃣

Written to your storage

The encrypted file goes straight to your storage target and never passes through us.

Key Management

Who Should Hold the Key?

🔑

BYOK — you hold it

Use your own key and only you can open the contents. The strongest privacy model available.

🛡

Key rotation

You can rotate your key; older backups remain openable through the transition.

🚫

No back door

If you lose your key we cannot open it either. That is not a shortcoming — it is the consequence of the design.

📦

No lock-in

Standard algorithm and standard archive formats; your backups stay readable even if you leave.

Do not lose your key — really

We have to be blunt about this: if you use your own key and lose it, your encrypted backups become permanently unopenable. Because there is no back door, we have no way to recover them.

Store your key somewhere independent of the server — ideally in a password manager and additionally in an offline copy. In a disaster where the server is lost entirely, recovery is only possible if the key was kept elsewhere.

FAQ

Encrypted Backup — Frequently Asked Questions

On your own server, before the backup leaves it (client-side). From the moment the file touches the network it is already encrypted. This differs from models where encryption happens on the provider side, because there the data arrives in the clear.
BYOK means using your own encryption key. When the key is yours, only you can open the backup contents — we cannot, as your service provider. It is the strongest privacy model, and in exchange, keeping the key safe is entirely your responsibility.
Your encrypted backups become unopenable and there is no way around it. That is the unavoidable consequence of strong encryption: because we leave no back door, we cannot recover a lost key. Always store it independently of the server.
AES-256, the symmetric encryption standard widely adopted at enterprise level today.
No. The backup is packaged and encrypted on your server and uploaded directly to the storage target you chose. Nothing is stored on our infrastructure — we call this zero-server-storage.
Yes. The encryption uses a standard method that common tools can decrypt, and the archives are standard formats: zip for files, an SQL dump for the database and .eml for messages. Your backups remain readable even after your subscription ends.

Back Up Without Entrusting Your Data to Anyone

Encryption on your server, key in your hands, backup in your cloud. 14 days free.

Create Free Account

See pricing →