Backup & disaster recovery

Nothing irreplaceable lives in only one place.

Skans gets every store on the appliance — the CA key, the databases, the directory, and every camera, PLC and network config — encrypted and off the source box on a daily schedule. It ships to an off-box target you own; nothing goes to a cloud. And a backup you've never restored is only a hope, so Skans verifies restores for you and lets you rehearse the real thing without touching production.

Skans console · Backup
The Skans backup and recovery view — the restore-point catalog with CA key, database and directory points, off-box target status, and read-only restore-verify.

What gets protected

Every store on the enclave — off the box, encrypted.

Six scheduled lanes run inside the always-on control plane, each capturing a different store on its own timer, encrypting it, and shipping it off the source machine before it lands. Here's what ends up protected — the certificate authority's own key material included — so the box that holds your root of trust is never the only place your state lives.

  • CA key + database — the crown jewel: the certificate authority's private-key material and its database, so identity is rebuildable from media, not from nothing.
  • Control-plane database — devices, config, RBAC, the agent registry, credential-vault references and the audit trail, taken as a daily full backup.
  • Directory system-state — NTDS.dit, every GPO and SYSVOL, so the enclave's sole domain controller can be rebuilt from media rather than from scratch.
  • Camera, PLC & network configs — each device's running-config pulled over its native interface, versioned only when it actually changes, with golden-baseline drift detection.
  • Telemetry store — events, Windows logs, metrics, inventory and offline CVE data, taken as a daily deduplicated snapshot.
  • Endpoint backups — full and differential of config files and SQL databases on servers and workstations, shipped off the source host over the agent's mutual-TLS channel.
Skans console · Devices
The Skans device inventory — cameras, switches and firewalls whose running-configs are versioned and backed up off-box

RPO by design

A day's RPO where it's cheap. Restore-on-demand where it's big.

Skans keeps its state in two stores with opposite characteristics, so it uses two mechanisms — each matched to how valuable, how large, and how re-derivable the data is. There is no single 'back everything up the same way' knob; the asymmetry drives the design.

  • Small and irreplaceable — the control-plane database is a few megabytes, so it takes a daily full backup with keep-last-N retention (ten by default). A day's RPO is the deliberate trade for a store this small.
  • Large but re-derivable — telemetry is bigger but append-only, so it takes a daily incremental snapshot. After an outage, agents resume shipping and only the outage gap is lost.
  • An off-box target you own — point Skans at a UNC share and it ships there from the next run. Until you set one, off-box egress stays inert — an unattended install never writes to a share that isn't there.
  • Nothing leaves the wire — the target is yours, on your network. There is no Skans cloud and no third party anywhere in the path.
Skans console · Home
The Skans console home — a correlated triage worklist showing at a glance whether last night's backup ran

Why it holds

Built for a disconnected, regulated site.

Off the source, always

Every artifact leaves the box it protects — off the source host and off the appliance — so a single machine failure never takes your only copy with it.

Encrypted and key-escrowed

Each artifact is AES-256 encrypted before it leaves. The backup master key is sealed to the appliance and escrowed for a rebuilt box, and the vault's keys ride to an operator-held recovery key — so a standby can decrypt what it's given, and no one else can.

Restore-verify, daily

A scheduled check proves the crown-jewel backups would actually restore — the database, the directory and the CA — and raises a Critical alert if one wouldn't. You learn a backup is bad before a crisis, not during one.

Evidence for CP-9 / CP-10

Off-box backup maps to NIST CP-9 and tested manual restore to CP-10, with golden-baseline drift covering CM-2 / CM-6 — technical support for the controls, never a certification.

Recovery

A backup you've never restored is a hope, not a plan.

Restore is a deliberate, admin-run break-glass procedure — there is no blind one-click button. What Skans automates is the proof: it verifies restores on a schedule, lets you rehearse the real thing side-by-side, and guides the destructive steps when a real recovery comes.

  • Verify, read-only — prove a backup opens end-to-end without writing anything; the database engine, the CA key material and the directory header are each checked against a real restore.
  • Rehearse, non-destructive — restore SQL into a side-by-side standby database while the live one keeps serving, proving the whole log chain restores on this exact appliance.
  • Promote, guarded — swapping the standby in as live sits behind a break-glass capability, a typed confirmation, and a preserved rollback copy of the old database — never a drop.
  • CA & AD runbooks — directory and certificate-authority restore stay operator-driven, with guided steps and the backup filename pre-filled, because an authoritative restore of a sole domain controller is done by hand.
  • Optional automatic failover — sites that need it can point Skans at a customer-owned SQL Always On availability group and fail over transparently; the cluster is yours to run, not a Skans dependency.
Skans console · Backup
The Skans backup and restore view — the restore-point catalog with read-only verify, standby rehearsal, and disaster-recovery status

Talk to us

See Skans on your network.

Built for the teams running networks the cloud can't reach. Email us for a technical walkthrough — architecture, controls, and exactly how it stays offline.