MultiCmsManager

Your own key

Backups encrypted with a key only you hold

Some of your clients keep health records or legal files and ask who can open their backups. With your own key the answer is your agency, and nobody else.

The problem

Whoever has the key can read the data.

Most backup services keep the keys themselves. If the supplier is attacked, the backups can be opened.

An agency whose clients handle health or confidential data, and answer to GDPR, wants to be able to say "we hold the key".

How it works

You make the key, the site locks every backup with it.

  1. 1

    Made by you

    Generate the key pair in one click in your browser, or with ssh-keygen or OpenSSL on your computer, and give us only the public key. If a client wants to hold the key, send them a one-time link with a guide for Windows, Mac and Linux.

  2. 2

    Sealed on the site

    Every backup has its own AES-256 key, which the site seals with your public key before sending it.

  3. 3

    Opened with your key

    To restore, upload a restore file to the site and choose your private key there: it goes only to the site's server. Or choose it in the dashboard, for that one operation. To open a backup on your computer, download it as a .zip and open the decryption page inside in Google Chrome: nothing to install.

In detail

Exactly how it works.

  • The platform keeps only the public key and its hash
  • We never store the private key. It only arrives for a download or a restore from the dashboard, if you go that way
  • Same AES-256-GCM encryption and the same deletion lock as other backups
  • A key sent through the link is confirmed by comparing its fingerprint, over the phone for example
  • Keys from ssh-keygen or OpenSSL work, with or without a passphrase
  • It's turned on site by site, and existing backups keep their key
  • These backups are always full: without the key we can't read the file list to make incrementals
  • If the key file is lost, those backups can't be opened again. There's no back door

FAQ

Frequently asked questions

What if I lose the key?

Those backups can no longer be opened, by anyone. That's why the key has to be saved before it's turned on, ideally in two places. New backups can go back to the platform key whenever you like.

Does the private key pass through your servers?

Not with the restore file. It's a PHP file you upload to the site, open in the browser and use with your key, which goes only to the site's server. The file can be read and checked before uploading, and it works on a broken site or empty hosting too. In the dashboard, for a download or restore, the key does pass through the platform: we use it in memory and don't store it.

Can a client hold the key instead of us?

Yes, for a client who wants to be the only one able to open their backups. You send a link that works once: the page explains how to create the keys with tools already in Windows, macOS and Linux, and they send us only the public key. Before it's used you compare the fingerprint, so a link in the wrong hands does no harm. From then on every download or restore needs their key.

Can I use a key I made myself?

Yes, upload or paste an RSA public key of at least 3072 bits, ssh-rsa format included.

Try it on your clients' sites.

During the beta we let in a few agencies at a time and set up the first sites with you.