Company / Changelog
Changelog
What has shipped, newest first. CLI releases are at github.com/safegrd/cli/releases.
4 October 2026: incremental PostgreSQL and SQLite backups
New
safegrd doctoropens every surface with the credential its backup will use, a credential SafeGrd holds included, and on an enrolled host reports the result to the console, which shows the host as Checked or what failed. The setup page's host step asks for it before the first backup. Needs CLIv0.0.14.- A connection string for a database SafeGrd backs up is opened from SafeGrd when it is entered. A wrong password, an unknown database or a host that does not answer is shown as a warning in the server's own words. The surface is still added, because backups connect from different machines than the check.
- PostgreSQL backups are incremental: each run uploads only the chunks of each table that changed since the last run of the month. Every run is a restore point.
--format tarkeeps one archive per backup. Needs CLIv0.0.12. safegrd restore --tableloads chosen tables from one backup into a database that is running, andsafegrd find --tablelists a table's versions.safegrd backup --change-logskips reading tables nothing wrote since the last run, from a trigger on each table (how it works).- The console's table breakdown shows what each table uploaded in a run.
- Backups SafeGrd takes of a PostgreSQL surface are incremental too.
- SQLite backups are incremental as well: the database is copied page for page, and a run uploads only the chunks whose pages changed. Needs CLI
v0.0.12. - Adding a surface in the console asks for its Backup type, Incremental or Full, for PostgreSQL, SQLite and files. Full is one archive per backup.
3 October 2026: drills on every plan, incremental file backups, two-factor sign-in
Plans
- Every plan runs Fire Drills. Free drills each surface once a month, in memory. Starter drills weekly and adds sandbox drills and the remote MCP server. Growth and Scale drill daily. Prices are unchanged.
- On paid plans, hosted storage past the included amount is billed per GB-month instead of refusing backups. The rate is on the pricing page.
New
- File backups are incremental: after the first run of the month, only changed files are uploaded.
safegrd findandrestore --versionbring back one version of one file. Needs CLIv0.0.10. - SafeGrd can back up a database that has no server beside it, such as Supabase, Neon or RDS: Back up on SafeGrd under Surfaces takes the connection string, which SafeGrd holds sealed, and a machine SafeGrd starts for each backup dumps the database, encrypts it and writes it to hosted storage. Drills follow on the plan's cadence. PostgreSQL, MySQL and MongoDB, on paid plans and the trial.
- SafeGrd can run a surface's drills for you, with Drill on SafeGrd in the console, so the host needs no database server to restore into. PostgreSQL, MySQL, MariaDB, MongoDB and SQLite restore into a throwaway database; files and mailboxes are read back in memory. Each drill runs on its own machine, deleted when the drill ends. Available for surfaces whose key SafeGrd keeps, with backups on hosted storage.
- Sign in with Google or GitHub.
- Two-factor sign-in with an authenticator app. A browser can be remembered for 30 days, and an organization can require the code at every sign-in.
safegrd guardtakes a locked snapshot before a destructive command, with hook recipes for Claude Code, Cursor and Codex on /docs/agents.safegrd doctor --agent-proofchecks what an agent on the host could delete.- Key custody is chosen per host. SafeGrd keeps a new host's key sealed unless you enrol it with
--key-custody local(orSAFEGRD_KEY_CUSTODY=local), and the installer no longer asks. Each surface in the console says who holds its key, and the organization page no longer has a custody setting. - A PostgreSQL sandbox drill needs no setup on a host with PostgreSQL installed: the daemon starts a temporary server and removes it afterwards.
- The CLI as a signed container image,
ghcr.io/safegrd/cli, with a Compose file, a Kubernetes CronJob and a Helm chart. - A GitHub Action,
safegrd/backup-action, backs up and drills a database, a folder or a mailbox with no server of your own. - A backup on hosted storage can be downloaded from the console, under Telemetry. It arrives encrypted, with its metadata file, and
safegrd restore --fromrestores it. - An organization can be deleted from Settings.
- Trust and security, compliance, about, security.txt and this changelog. Sample drill records and a sample Evidence Pack are on the attestation record page.
Changed
- Setup asks who keeps the key. Managed custody, the default, keeps your key sealed and releases it only to your enrolled hosts. The terms and sub-processor list describe both modes.
- Every account confirms its email address with a code. An account that has not yet is sent one at its next sign-in.
- The console says why a drill ran in memory or did not run, for example a host short of disk space.
- The Evidence Pack states the evidence for each control and says it is not a certification.
- The sub-processor list, the DPA and the privacy notice add Fly.io, which runs drills on SafeGrd.
Fixed
- A member with the viewer role could enroll a host.
- A replacement host could not restore a lost host's snapshots under managed custody.
- A database that does not answer now fails the backup after 30 seconds instead of holding it open.
safegrd daemon installstarts the service, anduninstallstops it.- A README badge for a drill under an hour old showed as a broken image.
29 September 2026: the daemon, agents and Supabase
- The host process is the daemon. It runs every surface on its schedule and checks in with the console.
safegrd claimadds surfaces named in the console to a host that is already enrolled.- Gmail is backed up once with its labels, and a mailbox restores from an export.
- A guide for backing up and drilling Supabase from GitHub Actions, with no server of your own.
- CLI
v0.0.6tov0.0.9.
28 September 2026: guided setup and custody
- Setup is two short wizards in the console: storage, then the surfaces to protect.
- SafeGrd can hold a surface’s credentials and your Age key, sealed and released only to your enrolled hosts.
- The storage step writes a least-privilege bucket policy and AWS templates that create the bucket locked.
- Every backup and drill request records who asked, and how.
- CLI
v0.0.5.
25 September 2026: hosted storage, MCP and Fire Drills from the console
- Hosted storage: back up into SafeGrd’s locked bucket, with no bucket of your own. Hosts upload through presigned URLs and never hold a storage key.
- The remote MCP server: an AI agent can read backups and drills and ask for a backup or a drill. No agent token can delete one.
- Ask for a Fire Drill from the console, and read its record there.
- CLI
v0.0.1tov0.0.4.