Demo with example data: look around, nothing you change is saved. Restorly launches soon.

AE
Signed in as Alex Example · Admin
Account and two-factor
Theme
Density

Settings

Every capability is a module. A module works only when this build has it, your licence includes it and it is switched on here. Changes are written to the configuration and audited.

Backup locations

ModuleStateNeeds and connects toSwitch
Local / NFS-mounted directory
source.local
Backups in a directory on the validation host, including NFS or SMB mounts made by the host.
OnNo network connections
S3-compatible object storage
source.s3
AWS S3, Cloudflare R2, Wasabi, Backblaze B2, MinIO, VersityGW and other S3-compatible services.
OnConnects to: customer-configured S3 endpoint (HTTPS unless configured otherwise)
SFTP
source.sftp
SFTP servers and NAS devices, with a pinned host key.
OnConnects to: customer-configured SFTP server
SMB / CIFS share
source.smb
Windows shares and NAS devices over SMB 2/3.
OnConnects to: customer-configured SMB server

Database engines

ModuleStateNeeds and connects toSwitch
MySQL and MariaDB
engine.mysql
Restores mysqldump / mariadb-dump logical backups (.sql, .sql.gz, .sql.zst) and MariaDB physical backups (mariadb-backup xbstream or tar) in a version-matched container.
OnNo network connections
PostgreSQL
engine.postgres
Restores pg_dump plain, custom (-Fc) and directory (-Fd) backups in a version-matched container.
OnNo network connections
MongoDB
engine.mongodb
Restores mongodump archives (--archive, --gzip) and directory dumps in a version-matched container, replaying a --oplog dump's oplog.
OnNo network connections
Microsoft SQL Server
engine.mssql
Restores SQL Server full database backups (.bak) in Microsoft's SQL Server image, under the licence terms and edition the customer sets in mssql: (Express for databases up to 10 GB, or a licensed edition).
OnNo network connections

Checks

ModuleStateNeeds and connects toSwitch
Level 1: integrity
check.integrity
Backup exists and is fresh, size trend, format, checksum sidecar, entropy.
OnNo network connections
Backup copies and the 3-2-1 rule
check.copies
Checks each copy listed in targets[].copies is present and fresh, and warns when the 3-2-1 rule is not met (two backups on two devices, one off site).
Off
Off until you switch it on.
Needs check.integrity
Connects to: customer-configured backup locations holding the copies (listing only)
Encrypted backups
check.encrypted
Validates backups encrypted by other tools or by backup mode: age, GnuPG, OpenSSL enc, ZIP and 7-Zip passwords, SQL Server certificates; decrypted in memory into the restore only (targets[].encryption).
OnNeeds check.integrity
No network connections
Recovery key test
check.key_test
On demand: proves an age recovery (escrow) key, given at the time and never stored, decrypts a database's newest encrypted backup.
OnNeeds check.integrity
No network connections
Level 2: restore
check.restore
Restores into a version-matched sandbox and records the duration (RTO trend).
OnNeeds check.integrity
No network connections
Level 3: consistency
check.consistency
CHECK TABLE / amcheck, row counts, schema drift and emptied tables versus the previous run.
OnNeeds check.restore
No network connections
Live row count comparison
check.live_compare
Row counts of the restored copy versus the production server, over a read-only connection (outbound to the configured host).
Off
Off until you switch it on.
Needs check.consistency
Connects to: customer-configured production database (read-only session, from a probe container on an egress network)
Level 4: custom SQL checks
check.custom_sql
Customer SQL with typed expectations, run read-only on the restored copy.
OnNeeds check.restore
No network connections

Addon

ModuleStateNeeds and connects toSwitch
Point-in-time restore test
addon.pitr
Replays the archived PostgreSQL WAL on top of the newest base backup, to its end, and records the last transaction it reached (targets[].pitr).
Off
Off until you switch it on.
Needs check.restore
Connects to: customer-configured backup location holding the WAL archive (read only)
Sanitised staging copies
addon.staging
After a validation, masks personal data in the restored copy by rules and writes it as a dump for development and test (targets[].staging).
Off
Off until you switch it on.
Needs check.restore
Connects to: customer-configured backup location the staging copies are written to

Reports

ModuleStateNeeds and connects toSwitch
Canonical JSON reports
report.core
RFC 8785 canonical JSON reports and per-target history.
OnNo network connections
Signed, hash-chained reports
report.signing
Ed25519 signature and hash chain on every report (needs a master key for the signing key).
OnNeeds report.core
No network connections
PDF reports
report.pdf
PDF renderings of signed reports: per run and monthly per target or site.
OnNeeds report.core
No network connections
NIS2 / ISO 27001 report templates
report.templates.nis2
Backup controls evidence for a period, mapped to NIS2 (Implementing Regulation 2024/2690, point 4.2) and ISO/IEC 27001:2022 (A.8.13, A.5.30).
OnNeeds report.pdf
No network connections
Co-branded reports
report.branding
A managed IT provider's name, contact and logo on monthly and evidence PDFs (branding: in the configuration).
OnNeeds report.pdf
No network connections

Metrics

ModuleStateNeeds and connects toSwitch
Prometheus metrics
metrics.prometheus
/metrics on the agent listener: last outcome, last success, restore duration and backup age per target.
OnNo network connections
Provider dashboard
metrics.dashboard
Sends this site's status every 15 minutes to a managed IT provider's central dashboard: outcomes, times and sizes per database; no hostnames, paths, check details or data.
Off
Off until you switch it on.
Connects to: provider dashboard: POST <dashboard.url>/v1/dashboard/push (HTTPS; default the licence server); none with agent.network: offline

Notifications

ModuleStateNeeds and connects toSwitch
Email notifications
notify.email
Run outcomes and weekly summaries by SMTP (STARTTLS or implicit TLS).
OnNo network connections
Slack notifications
notify.slack
Run outcomes and weekly summaries to a Slack incoming webhook.
OnNo network connections
Microsoft Teams notifications
notify.teams
Adaptive Card messages to a Teams Workflows webhook.
OnNo network connections
Webhook notifications
notify.webhook
JSON (restorly.notification/v1) POSTed to a URL of your choice.
OnNo network connections

API

ModuleStateNeeds and connects toSwitch
REST API
api.rest
Token-authenticated JSON API on the agent listener: status, targets, runs, reports, modules, config, secrets.
OnNo network connections

Backup mode

ModuleStateNeeds and connects toSwitch
Backup mode
backup
Takes logical dumps of production in a version-matched container and writes them to the target's location.
Off
Off until you switch it on.
Needs check.integrity
Connects to: customer-configured production database (backup user); customer-configured backup locations (write)

Panel

ModuleStateNeeds and connects toSwitch
Local web panel
panel
Browser panel and Admin console on the agent listener: sign-in with two-factor codes, status, runs, reports, settings.
OnNo network connectionsAlways on: this screen needs it.
Sign-in with your identity provider (OIDC)
auth.oidc
Keycloak, Entra ID, Google and other OpenID Connect providers: code flow with PKCE, groups mapped to roles, MFA required for admins.
Off
Off until you switch it on.
Needs panel
Connects to: customer-configured OpenID Connect provider (https)
Import many databases at once
targets.bulk_import
Adds every database found in a backup location (by the {db} in a naming pattern) at once, copying an existing database's settings: in the panel (Databases → Import databases) and with restorly import databases.
OnNo network connections

Platform

ModuleStateNeeds and connects toSwitch
Clients (managed IT providers)
multisite
Databases belong to clients; a client switcher filters every screen, and reports are produced per client.
Off
Off until you switch it on.
Needs panel
No network connections
Update check
update.check
Checks daily for a new signed release and, by agent.update_policy, offers it to admins or installs it with restorly update apply. Off with agent.network: offline or update_policy: pinned.
OnConnects to: update manifest: GET <agent.update_url>/stable/latest.json (HTTPS)
Online licence
license.online
Renews the licence once a day from the licence server (online lease) and starts the 14-day trial from the setup wizard. Sends the licence ID, an install ID and the version; nothing about databases or backups.
Off
Off until you switch it on.
Connects to: licence server: POST <agent.licence_url>/v1/lease and /v1/trial (HTTPS); none with agent.network: offline

Core

ModuleStateNeeds and connects toSwitch
Capacity view
capacity
Whether the schedules fit in a day on the runners online, from real run times (ADR 0081)
OnNo network connections
Validate new backups at once
schedule.watch
Schedule on_new_backup: list the location every agent.watch_interval and validate a new backup once it is complete (ADR 0082)
OnNo network connections

Runners

ModuleStateNeeds and connects toSwitch
Remote runners
runners.remote
Runners on other hosts, sites or VLANs join this hub and validate backups there; they dial out over mutual TLS.
Off
Off until you switch it on.
Needs panel
Connects to: inbound only: customer's own runners dial the hub (hub.listen, mutual TLS)