CloudCastle Secure Cloud

Fast enough to use. Proven when it matters.

CloudCastle keeps encrypted copies of your files on fast storage, saves older versions and regularly restores sample files to prove the backup will work when you need it.

Flash-backed recovery

The short version

What Secure Cloud does for you

It gives you a clean, tested copy of your files when a computer fails, a file is deleted or ransomware strikes.

Protect

Encrypts files first

Your files are encrypted before they leave the computer, so the stored backup cannot be read without its key.

Remember

Keeps earlier versions

Versioned backups let you go back to a clean point before an accidental change, hardware failure or ransomware damage.

Prove

Tests real restores

CloudCastle restores sample files and compares them with the originals. A completed upload alone is never treated as proof.

Storage architecture

Cloud convenience. Infrastructure we control.

CloudCastle uses self-hosted SSD-class primary storage rather than making your recovery path depend on a hyperscaler’s object-storage tier.

Endpoint

Encrypt before transfer

The agent snapshots configured paths into a password-protected, restic-compatible repository. Encryption belongs to the repository, so stored data is not readable without its key.

Snapshot

Store only what changed

Content-addressed snapshots preserve file history while deduplication avoids storing the same blocks again across repeated runs and related versions.

Primary

SSD-class flash storage

High-speed flash-backed primary capacity keeps backup ingestion and interactive restore work responsive without pushing active customer data onto an archival tier.

Offsite

Independent recovery copy

A second self-hosted offsite copy is the disaster-recovery target, separating the recovery path from the primary storage location and its local failure domain.

Verify

Restore and hash-compare

Repository integrity is checked, sample files are restored to temporary storage, and their SHA-256 hashes are compared with the snapshot contents.

Recover

Choose a clean version

Versioned snapshots give technicians a clean recovery point after accidental deletion, disk failure or ransomware containment, without treating the latest copy as the only copy.

High-speed flash

Recovery storage should not be the slowest machine in the room

CloudCastle Secure Cloud is designed around SSD-class primary arrays. Flash eliminates the seek latency of spinning disks when a restore reads many small files spread across a snapshot.

  • Fast random access: responsive browsing and restoration across large file trees.
  • Parallel workloads: backup ingestion, integrity verification and recovery can share the storage system without a single mechanical head becoming the bottleneck.
  • Owned capacity: self-hosted infrastructure keeps the storage path and operating model under CloudCastle control.
  • Honest performance: we do not publish an unmeasured latency or throughput number; sizing is based on the endpoint count, working set and recovery objective.
Verified backup and restore records with timestamps and evidence

Verified recovery

Uploaded is not the same as recoverable

CloudCastle marks a backup verified only when both repository integrity and a real sampled restore succeed.

Upload-only backup

  • The transfer completed, so the dashboard turns green
  • No file is restored until the incident
  • Repository corruption stays hidden
  • An empty or unreadable sample can still look successful
  • The operator has no evidence beyond a timestamp

CloudCastle verified restore

  • restic check validates repository structure
  • A deterministic sample spans the sorted snapshot file list
  • Each sampled file is restored to temporary storage
  • Expected and restored SHA-256 hashes must match
  • Zero sampled files is a failure, never a pass

Ransomware recovery

Detection and recovery belong in the same workflow

CloudCastle Defender supplies the endpoint evidence. Secure Cloud supplies the clean history. The management plane keeps the actions and recovery evidence together.

Detect

Catch encryption behavior

Ransomware canaries and correlated file activity raise a loud endpoint event before a traditional signature catalog necessarily has a family name.

Contain

Stop the spread

Safety-gated process containment and network-isolation playbooks limit additional damage while preserving an evidence trail for review.

Select

Choose the recovery point

Versioned snapshots let the technician select a point before the first malicious change rather than blindly restoring the newest encrypted copy.

Restore

Recover remotely

Repository-backed recovery runs without sending someone to the endpoint. Restore operations can be directed from the same management surface that holds the device and incident record.

Prove

Keep verification evidence

Integrity result, sampled files, expected hashes, actual hashes and the final verified state are written into structured backup-run evidence.

Review

Know what changed

The audit trail ties automated and technician actions to the endpoint and time, so recovery does not become an undocumented side channel.

Built for real operations

The details that make backup dependable

Reliable recovery is an operating discipline, not one storage device.

Battle-tested format

Restic-compatible repositories

The endpoint uses the mature restic CLI and repository format instead of inventing custom encryption, chunking or snapshot semantics.

Repeatable evidence

Deterministic sampling

Sample selection sorts paths and chooses evenly spaced entries. Re-running verification against the same snapshot produces the same evidence set.

Fail honestly

No false green states

An unconfigured repository is reported as unconfigured. Missing samples, mismatched hashes and failed integrity checks cannot become a verified result.

Pooled capacity

Storage follows the organization

Business and provider allocations pool across the organization, so quieter endpoints can leave headroom for systems with larger working sets.

Cross-platform

One policy surface

Windows, macOS and Linux endpoints report backup status and evidence into the same control plane, alongside security and maintenance state.

Managed option

We can operate it for you

CloudCastle technicians can monitor failures, review verification evidence and run recovery as an add-on to any plan.

Design for the restore, not the checkbox

Tell us how much data you have, how quickly it must return and which failures you need to survive. We will size the storage and recovery path around that objective.