MultiCmsManager

Client-held keys

Backups encrypted with the client’s own key

Clinics, law firms, accountants: some clients want to be sure no supplier can open their data. With client-held keys, they keep the key to their backups.

The problem

Whoever holds the key holds the data.

Most backup services keep the keys themselves. If the supplier is breached, the backups can be opened.

For anyone handling health or confidential data, and under GDPR, being able to say “we hold the key” makes a difference.

How it works

The client can make the key.

  1. 1

    Made by the client

    The client gets a link with a guide for Windows, Mac and Linux, creates the keys on their own computer and sends only the public one. Or you make them in one click in the browser.

  2. 2

    Sealed on the site

    Every backup has its own AES-256 key, which the site seals with the client’s public key before sending it.

  3. 3

    Opened only by the client

    To restore, the client uploads a restore file to the site and chooses their private key there: it goes only to their own server, never to us. Or they choose it in the dashboard, for that one operation.

In detail

Clear about how it works.

  • The platform stores only the public key and its fingerprint
  • The private key is never saved: it arrives only for the download or restore you ask for
  • Same AES-256-GCM encryption and the same deletion lock as other backups
  • The client’s key is confirmed by comparing its fingerprint, over the phone for instance
  • Keys from ssh-keygen or OpenSSL, passphrase-protected too
  • Turned on site by site; earlier backups keep their key
  • Always full backups: without the key we can’t read the file list to make incrementals
  • If the key file is lost, those backups can’t be opened any more: there is no back door

FAQ

Frequently asked questions

What if the client loses the key?

Those backups can no longer be opened, by anyone. That’s why the key must be saved before it is turned on, ideally in two places. New backups can switch back to the platform key at any time.

Does the private key pass through your servers?

Not with the restore file: it is a PHP file the client uploads to their site, opens in the browser and uses with their key, which goes only to their own server. The file is readable, so it can be checked before uploading. It works on a broken site or empty hosting too. In the dashboard, for a download or restore, the key does pass through the platform: it is used in memory and never saved.

Can the client make the key themselves?

Yes. You send a one-time link: the page explains how to create the keys with tools already in Windows, macOS and Linux, and they send only the public key. You compare the fingerprint before it is used, so a link in the wrong hands is useless.

Can I use a key I made myself?

Yes: upload or paste an RSA public key of 3072 bits or more, ssh-rsa format included.

Try it on your clients’ sites.

During the beta we welcome agencies in small groups and set up the first sites together.