SafeGrd console

Protected surfaces
Encrypted snapshots
Threat Shield status
Fire Drill restores
verified

01 / Surfaces

02 / Snapshots

03 / Fire Drills

Each drill restores a snapshot and checks what came back. The result is recorded against the surface.

05 / Access tokens

Use tokens to authenticate the SafeGrd CLI, GitHub Actions, or Kubernetes sidecars. A token can enrol a host, read, and ask for a backup or a drill. It cannot delete a backup, remove a surface or change where backups go.

Token name Key prefix Scope Created at Expires Actions

04 / Projects

Projects group database nodes, send their snapshots to SafeGrd hosted storage or to your own S3 bucket, and isolate backup domains. Projects are unlimited across all plans.

Project name Slug Status Storage sink Nodes Actions

05 / Project storage

Where this project's backups go: SafeGrd hosted storage, where your plan includes it, or your own S3-compatible bucket. Every snapshot is compressed and encrypted before it is uploaded, on your host or on the machine SafeGrd starts for a surface with no host, so either one only ever holds ciphertext.

S3 storage

Presets:
Leave blank for standard AWS S3.

Under compliance mode a backup cannot be deleted before this many days, so this is also a storage bill.

06 / Billing

Every paid plan protects as many surfaces as you have. Plans differ in how often a Fire Drill runs, whether it loads a real database, and whether you can export the evidence.

Billing

Profile

Email cannot be changed.
Change password

Two-factor sign-in

Organization

Plan
Protected surfaces
Team members
Org ID

Key access record

Every key and credential SafeGrd released, to which host and when, and every refusal.

Alerts

Failed backups, failed or blocked Fire Drills, hosts that stop checking in, surfaces that fall behind their schedule, and recoveries.

Webhook:
Email:

Compliance platform

Each Fire Drill record is sent to your compliance platform as dated evidence, signed and with the link to verify it. SafeGrd keeps the platform's API token sealed and uses it only to send.

Team members

Name Email Role Added Actions

Delete organization

Takes this organization out of SafeGrd: its projects, members and settings stop working. Backups already written stay in their storage; copy hosted ones out first with safegrd export. Decommission every host and cancel the subscription first. We keep the organization's records for 12 months so it can be restored, then erase them. To have them erased sooner, write to support@safegrd.dev.

Platform overview

Global telemetry, multi-tenant directory, and early access waitlist across all organizations.