SAFENIX

Sign in to your backup dashboard

Enter the 6-digit code from your authenticator app. You can also use one of your recovery codes.

⚠ Set up two-factor authentication to finish signing in.

Scan this code with an authenticator app such as Google Authenticator, 1Password or Authy, then enter the 6-digit code it shows.

Two-factor setup QR code

Can't scan? Enter this key by hand:

⚠ Save these recovery codes somewhere safe.

If you lose your phone, each code lets you sign in once. This is the only time they are shown.


      

New to Safenix? — fourteen days, no card needed.

SAFENIX

Reset your password

SAFENIX

Choose a new password

SAFENIX

    Choose a plan

    Your account is ready.

    SAFENIX

    Protected servers —
    Backup health —
    Data protected — How much would come back if you restored now
    Last backup —

    What Safenix protects

    Every completed backup is written to a tamper-evident compliance record you can verify and export at any time from the Compliance tab.

    Restores in progress

    Add a server

    Register a server to get its install command. The token is shown once and identifies that server to Safenix — treat it like a password.

    Separate several paths with commas. These are the places that usually hold what a server cannot get back by being reinstalled; add anything else you keep on this machine, and remove what you do not need. Two worth considering: /var/spool/cron for scheduled jobs, and /usr/local for software installed by hand.

    A MySQL or MariaDB database is configured separately and is not protected by listing its files. Copying a database's files while it is running produces a copy that cannot be restored, because the files are read over several minutes while the database is still writing to them.

    ⚠ Copy this now — the token is not shown again.

    Run this on the server you want to protect:

    
              

    This server has a MySQL or MariaDB database

    A database is not protected by backing up its files: they are read over several minutes while it is still writing, and what comes back does not restore. It is captured instead, from the server’s own change log, and that needs three things on the database which Safenix cannot set for you. The first command below reports which of them are missing and prints the exact statement that fixes each one.

    Any number that is not zero and is not used by another replica of this database. If you do not run replication, the default is fine.

    This limits the full copies only. The change log is a property of the whole server, so what is captured cannot be narrowed to one database — and a full copy that leaves one out would make those changes unrestorable.

    1. Check the database is ready. Run this on the server:

    
              

    Continuous capture needs binary logging already switched on, and not every server has it — the check above just told you whether this one does. If it reported binary logging off, or you are not sure, periodic full copies is the choice that works everywhere.

    2. Choose how this database is protected

    3. If the check above reported anything else — a missing grant, for example — resolve that first; it would break the backup in either mode. Once it does, run this to start protecting the database. Both commands ask for the password on the terminal.

    
              

    Add a WordPress site

    For a site on shared hosting, where the Safenix agent cannot be installed. You install the Safenix plugin in WordPress and paste one pairing code.

    ⚠ This pairing code contains your site’s encryption key. Paste it into the plugin now and do not send it to anyone.

    
              

    SiteStatusLast call

    Restore a website

    A restore is running.

    What to put back

      Site not loading

      ⚠ This code lets somebody restore this site. It works once and lasts minutes.

      
                  

      Open this page on the site and type the code into it:

      
                  

        If that page will not load either:

          ServerStatusFilesDatabase ProtectedRestore points

          Restore

          Choose the backup to restore from.

          Restoring everything is quick to start. Choosing files fetches the list of what is in that backup, which takes a moment longer and needs your encryption password to read.

          The file list is encrypted on your server before it reaches us, so Safenix cannot read it. Enter your encryption password to open it here in your browser — it is not sent anywhere.

          Choose what to restore.

          Where should it be written?

          A new folder leaves everything on the server untouched, and you move the files back yourself. Restoring over the existing files cannot be undone.

          ⚠ These files would be replaced with the backup's version.

          Restore the database on

          A database is not restored from a single backup. It is rebuilt: the last full copy taken before the moment you choose, with every change captured since then replayed on top. Choose the moment to go back to.

          Saving to a folder writes the restore onto the server and changes no database, so you can check it and apply it yourself. Restoring into the database overwrites what is there now.

          ⚠ This overwrites the live database and cannot be undone.

          Everything written to that database since then will be lost. If the restore stops partway the database can be left partly overwritten, which is why saving to a folder is the recommended option.

          Type the name of the database being restored, exactly as it is on your server. Your server checks it against the databases in the backup and refuses if it does not match — Safenix does not know their names.

          Restore credential

          Read-only, for this server only, and it stops working at . Run this on the machine you are restoring onto — it does not have to be the original server, and it does not need anything that was on it.

          
                  

          Your encryption password is the one thing this does not include. Safenix never receives it, so nobody here can supply it for you.

          WhenServerSizeSnapshotVerification hash

          Backup verification

          Safenix checks each server's stored backups on a schedule: that a base copy exists, that the captured change log runs from it to the present with nothing missing, that every object your server reported is present and the right size, and that your compliance records are unaltered.

          Compliance records

          Every completed backup writes a record that is never modified afterwards. Verifying re-computes each record from its contents and compares it with the fingerprint stored at the time, which detects any later change.

          WhenEventServer SizeStored inRecord fingerprint

          Who we tell

          We send a message when a server stops backing up, falls behind, keeps failing, or fails its scheduled check — once when it starts, and once when it is fixed. Nothing is sent while a problem continues, so these do not become noise you learn to ignore.

          What we have told you

          Every alert and every message sent for it, kept so that what you were told, and when, is a matter of record.

          WhenServerWhat happenedStatusSent to

          Your subscription

          Payment method

          Tax details

          Plan

          A plan change takes effect on your next billing date, at the new price. Nothing is prorated and nothing is charged today.

          Ending your subscription

          Payments and invoices

          DateReferencePlanPeriod AmountOutcomeInvoice

          Your plan

          Agent updates

          Invite someone

          The account has one owner, who can add and remove people, add and remove servers, and hand ownership to someone else on the account. Everyone else is a viewer: they can see everything but change nothing.

          ⚠ Send this password to them securely. It is shown once.

          They set up two-factor authentication when they first sign in.

          EmailAccessTwo-factorAddedLast signed in