Encrypts files first
Your files are encrypted before they leave the computer, so the stored backup cannot be read without its key.
CloudCastle Secure Cloud
CloudCastle keeps encrypted copies of your files on fast storage, saves older versions and regularly restores sample files to prove the backup will work when you need it.
Flash-backed recovery
Verified recovery
Integrity check plus restored-file proof
The short version
It gives you a clean, tested copy of your files when a computer fails, a file is deleted or ransomware strikes.
Your files are encrypted before they leave the computer, so the stored backup cannot be read without its key.
Versioned backups let you go back to a clean point before an accidental change, hardware failure or ransomware damage.
CloudCastle restores sample files and compares them with the originals. A completed upload alone is never treated as proof.
Storage architecture
CloudCastle uses self-hosted SSD-class primary storage rather than making your recovery path depend on a hyperscaler’s object-storage tier.
The agent snapshots configured paths into a password-protected, restic-compatible repository. Encryption belongs to the repository, so stored data is not readable without its key.
Content-addressed snapshots preserve file history while deduplication avoids storing the same blocks again across repeated runs and related versions.
High-speed flash-backed primary capacity keeps backup ingestion and interactive restore work responsive without pushing active customer data onto an archival tier.
A second self-hosted offsite copy is the disaster-recovery target, separating the recovery path from the primary storage location and its local failure domain.
Repository integrity is checked, sample files are restored to temporary storage, and their SHA-256 hashes are compared with the snapshot contents.
Versioned snapshots give technicians a clean recovery point after accidental deletion, disk failure or ransomware containment, without treating the latest copy as the only copy.
High-speed flash
CloudCastle Secure Cloud is designed around SSD-class primary arrays. Flash eliminates the seek latency of spinning disks when a restore reads many small files spread across a snapshot.
Verified recovery
CloudCastle marks a backup verified only when both repository integrity and a real sampled restore succeed.
restic check validates repository structureRansomware recovery
CloudCastle Defender supplies the endpoint evidence. Secure Cloud supplies the clean history. The management plane keeps the actions and recovery evidence together.
Ransomware canaries and correlated file activity raise a loud endpoint event before a traditional signature catalog necessarily has a family name.
Safety-gated process containment and network-isolation playbooks limit additional damage while preserving an evidence trail for review.
Versioned snapshots let the technician select a point before the first malicious change rather than blindly restoring the newest encrypted copy.
Repository-backed recovery runs without sending someone to the endpoint. Restore operations can be directed from the same management surface that holds the device and incident record.
Integrity result, sampled files, expected hashes, actual hashes and the final verified state are written into structured backup-run evidence.
The audit trail ties automated and technician actions to the endpoint and time, so recovery does not become an undocumented side channel.
Built for real operations
Reliable recovery is an operating discipline, not one storage device.
The endpoint uses the mature restic CLI and repository format instead of inventing custom encryption, chunking or snapshot semantics.
Sample selection sorts paths and chooses evenly spaced entries. Re-running verification against the same snapshot produces the same evidence set.
An unconfigured repository is reported as unconfigured. Missing samples, mismatched hashes and failed integrity checks cannot become a verified result.
Business and provider allocations pool across the organization, so quieter endpoints can leave headroom for systems with larger working sets.
Windows, macOS and Linux endpoints report backup status and evidence into the same control plane, alongside security and maintenance state.
CloudCastle technicians can monitor failures, review verification evidence and run recovery as an add-on to any plan.
Tell us how much data you have, how quickly it must return and which failures you need to survive. We will size the storage and recovery path around that objective.