Why does it matter?

When someone picks a cloud service – Google Drive, iCloud or any other – one of the most important things is data safety. The question is not whether someone can get at our data, but whether it survives.

The big providers solve this with billion-dollar infrastructure: several data centres, redundant storage, automatic backups. But can a home server be just as safe?

The answer: yes. With the right backup strategy, your home server can be as safe as any cloud provider – and you are in charge of everything.

The 3-2-1 backup rule

The industry standard that professional system administrators and companies use around the world

3

Three copies of your data

Always keep at least three copies of everything important: the original and two backups. If one is damaged or lost, there are still two in reserve.

Example

Your family photos are on the server (1), on an external hard drive (2), and in a remote place (3).

2

Two different kinds of storage

Keep your data on at least two kinds of storage device. Different devices fail in different ways – if one kind breaks, the other is probably fine.

Example

You keep your data on the server's internal SSD, and the backup goes to an external HDD or a NAS.

1

One off-site (remote) copy

Keep at least one copy in a different physical place. That protects against local disasters: a fire, a flood, a burglary or even a lightning strike cannot put all your data at risk.

Example

The backup is copied on its own to a friend's or relative's server, or goes encrypted into the cloud.

What it looks like in practice

Server
Original data
→
Local backup
External HDD/NAS
→
Off-site backup
Remote place

Off-site backup options

The "1" in the 3-2-1 rule – the most important, and often the most neglected

The "buddy system"

The simplest and cheapest option: swap backups with someone you trust. You back up to their server, they back up to yours.

  • No monthly fee
  • Full control over the data
  • Safety for both of you
  • End-to-end encryption is possible
How does it work?

Encrypted backups sync on their own over a VPN connection.

Home ↔ Office

If you have a workplace or your own office, use it! Two sites give you natural distance.

  • Uses what is already there
  • A safe, familiar place
  • Quick to recover from when needed
Tip

A small, quiet mini PC in a corner of the office can be a perfect backup target.

Encrypted cloud backup

If there is no trusted friend or second site, the cloud is the answer. Important: the data is encrypted before it is uploaded!

  • Professional infrastructure
  • Storage spread across places
  • No hardware needed
  • A monthly or yearly fee (depending on how much is stored)
Note

The storage fee depends on how much data is backed up. This is the option a Felhom box uses.

How we do it

Backups are set up by default on every server we install

Automatic backups

Every night the server makes backups by itself, on three levels: on the box, on a second drive (if there is one), and encrypted on remote storage. You do not have to remember anything – the system takes care of it.

The backups are incremental: only the changes are saved. That saves space and time, and a full restore is still there when you need it.

Not only the data: thanks to the Proxmox base, not only your files and databases are backed up but your whole system too — the whole box goes into a backup, and it can be restored from it. If the box itself breaks, your apps' data can be brought back from the encrypted remote backup onto the reinstalled system — with the recovery code.

Where the remote backup goes: on a Felhom box the remote copy goes, encrypted, to storage we provide. The "buddy system" and the office are general options for the 3-2-1 rule — we do not set them up today.

The recovery code — only you know it

Your remote backup is encrypted, and the key to the encryption is a recovery code. The code appears exactly once: on your screen, when it is set up. We keep no copy of it.

This is a deliberate choice, and it has two sides. One: nobody but you can read your remote backup — not even us. The other: if the box is destroyed and the code is lost too, then we cannot restore the remote backup either. So the code goes on paper, and somewhere safe.

Monitoring and notifications

We watch the backups all the time. If there is a problem – a failed backup, storage filling up, a connection fault – it shows up in our monitoring, and an e-mail goes out about it. One aim of the closed test is to polish these notifications in real use.

A question about backups?

Let's talk about what is best in your situation. We help you find the balance between safety and cost.

Get in touch →