FOR RESTIC BACKUPS · SELF-HOSTED

Know your backups restore — before you need them.

"Backup finished" doesn't mean you can get your files back. Vaultwitness regularly reads a real file back out of your backups, checks the repository, and tells you in plain words what broke and how to fix it.

Free for 2 servers, forever. All features free for 14 days — no sign-up.

Vaultwitness dashboard: a repository whose backups can't be restored, with the reason for each snapshot

The real dashboard: every snapshot is restore-tested, and a broken one says what failed.

A green checkmark is not a restore.

Most backup monitoring only checks that the job ran. The problems that lose data are quieter.

✗ What "backup OK" misses

  • A damaged file in the repository — you find out on restore day
  • The backup job stopped running three weeks ago
  • A database dump that is suddenly empty or half the size
  • A file you rely on quietly dropped out of the backup
  • Old backups deleted by a wrong cleanup rule — or by ransomware

✓ What Vaultwitness does

  • Reads a real file back out of each checked backup, in full
  • Runs restic check, and can re-read every byte, spread over nights
  • Learns how often backups happen and warns when one is late
  • Reads the backup job's log and says why it failed
  • Checks each new backup for the files you marked as must-have
  • Keeps a dated record you can hand to an auditor

Running in ten minutes

One server with the dashboard, one small agent on each machine that has backups.

01

Install the server

Unpack, run sudo sh install.sh. You get the dashboard address and a password. HTTPS is set up for you.

02

Add your servers

Press + in the dashboard and paste one command on each machine. No config files to write.

03

It finds the backups

The agent finds your restic repositories from cron and systemd jobs and starts checking. Results show in minutes.

What it checks

Every problem is shown as one line — what broke — and one line — what to do.

✓
Restore testReads a real file back out of the backup, in full, on a schedule you choose.
✓
Repository integrityrestic check, plus a full data re-read spread over 7–60 nights.
✓
Late backupsLearns each repository's rhythm and warns when a backup is overdue.
✓
Failed backup jobsFinds the cron or systemd job, reads its log, explains the error.
✓
Database dumpsReads dumps back from the backup and flags ones that shrank or are empty.
✓
Files that must be thereList paths like /etc or your app config — get alerted if one goes missing.
✓
Mass deletionWarns when many old backups disappear at once.
✓
Disk spaceForecasts when the backup disk will be full.
✓
Silent serversIf an agent stops reporting, you hear about it.
✓
Alerts & reportsEmail, Telegram or webhook. A printable report of every check for audits.

Your data never leaves your network.

Vaultwitness runs on your own server. No cloud account, no telemetry. Restored test files stay on the machine they came from, and the agent never opens a port.

Works on servers with no internet at all: licenses can be activated with a file. Agents update themselves from your server, not from us.

# on the dashboard server
$ tar xzf vaultwitness-106-linux-amd64.tar.gz
$ sudo sh vaultwitness-106-linux-amd64/install.sh
Dashboard: https://backup-mon:47000
 
# on each machine with backups
$ curl -fsSLk … /install/agent.sh | sudo sh

Free for 2 servers. Everything free for 14 days.

No sign-up, no card. Buy a license when you need more servers.