# SafeGrd > SafeGrd backs up PostgreSQL, MySQL, MongoDB and SQLite databases, file trees and IMAP mailboxes. Each backup is encrypted with age on the customer's host, locked with S3 Object Lock in compliance mode so nothing can delete it early, and restored on a schedule (a Fire Drill) to test that it works. Backups and restores run on the customer's host with the `safegrd` CLI, and the backup data never passes through SafeGrd's control plane. The customer chooses who holds the private key. With a customer-managed key only the customer can decrypt the backups. With a SafeGrd-managed key SafeGrd keeps the key sealed and releases it only to the organization's enrolled hosts, so the customer can restore even after losing a host. Agents can operate SafeGrd but cannot destroy anything: a personal access token cannot delete, disable, re-route or re-key a backup, through MCP or the REST API. ## Connect an agent Remote server, for any machine (any paid plan; on the free plan it answers 402). Create a personal access token in the console under Tokens, then: claude mcp add --transport http safegrd https://safegrd.dev/mcp --header "Authorization: Bearer sg_pat_..." Or the Claude Code plugin, which asks for the token and adds skills that back up and run a Fire Drill before a risky change (https://github.com/safegrd/agent-plugins): /plugin marketplace add safegrd/agent-plugins /plugin install safegrd@safegrd It lists organizations, projects, surfaces, snapshots and Fire Drills, and asks for a backup or a drill now. The host's daemon picks a request up at its next check-in; a surface SafeGrd backs up or drills is queued on SafeGrd and needs no daemon. Start with `list_organizations` and `list_surfaces`. The tools are listed without a token at https://safegrd.dev/.well-known/mcp/server-card.json. Local server, on a host that runs the `safegrd` CLI (no plan needed). It backs up, verifies and restores into an empty target with that host's config and key: claude mcp add safegrd -- safegrd mcp Any client that speaks Streamable HTTP with a bearer header, or stdio, works the same way. ## Agents - [AI agents (MCP)](https://safegrd.dev/docs/mcp): the remote MCP server at https://safegrd.dev/mcp (Streamable HTTP, bearer personal access token) and the local `safegrd mcp` (stdio) - [Agent guard](https://safegrd.dev/docs/agents): `safegrd guard` takes a locked snapshot before a destructive command; hook recipes for Claude Code, Cursor and Codex; `safegrd doctor --agent-proof` - [OpenAPI](https://safegrd.dev/openapi.json): the /api/v1 routes an agent needs - [API reference](https://safegrd.dev/docs/api): the same document as a page, rendered from it - [MCP server card](https://safegrd.dev/.well-known/mcp/server-card.json): the remote server's tools and their arguments, readable without a token ## Docs - [Overview](https://safegrd.dev/docs) - [Install and enrol](https://safegrd.dev/docs/install) - [Command reference](https://safegrd.dev/docs/cli) - [Config file reference](https://safegrd.dev/docs/config) - [Surfaces](https://safegrd.dev/docs/surfaces) - [Databases](https://safegrd.dev/docs/surfaces/databases) - [Files](https://safegrd.dev/docs/surfaces/files) - [Email](https://safegrd.dev/docs/surfaces/email) - [Storage and retention](https://safegrd.dev/docs/storage) - [Daemon](https://safegrd.dev/docs/daemon) - [Restore and Fire Drills](https://safegrd.dev/docs/verify) - [Recovery runbooks](https://safegrd.dev/docs/runbooks) - [Security and key custody](https://safegrd.dev/docs/security) ## By database and platform - [PostgreSQL backup](https://safegrd.dev/postgresql-backup): pg_dump schema and binary COPY rows from one snapshot, restored on a schedule - [MySQL and MariaDB backup](https://safegrd.dev/mysql-backup): mysqldump --single-transaction, loaded into a scratch database to test it - [MongoDB backup](https://safegrd.dev/mongodb-backup): mongodump --archive, document counts checked on restore - [Supabase backup](https://safegrd.dev/supabase-backup): from GitHub Actions, outside the project, restored into Supabase's PostgreSQL image - [Coolify backup](https://safegrd.dev/coolify-backup): beside Coolify's own backups, encrypted, locked and restore-tested - [Backup verification](https://safegrd.dev/backup-verification): what each kind of check proves, and what a Fire Drill checks per database ## Free tools - [Backup file checker](https://safegrd.dev/tools/backup-file-checker): reads a pg_dump, mysqldump, mongodump or SQLite file in the browser; reports format, versions, whether it was cut short, and the restore command - [pg_dump command builder](https://safegrd.dev/tools/pg-dump-command-builder): a pg_dump command and the matching pg_restore or psql command - [Object Lock cost calculator](https://safegrd.dev/tools/object-lock-cost-calculator): locked copies held at once and their monthly cost, with daily, weekly and monthly tiers ## Guides - [How to back up PostgreSQL to S3 with pg_dump](https://safegrd.dev/guides/postgres-backup-s3) - [Immutable backups with S3 Object Lock](https://safegrd.dev/guides/immutable-backups-s3-object-lock) - [How to test that a PostgreSQL or MySQL backup restores](https://safegrd.dev/guides/test-database-backup-restore) - [SafeGrd vs AWS Backup](https://safegrd.dev/compare/aws-backup) - [SafeGrd vs SimpleBackups](https://safegrd.dev/compare/simplebackups) - [SafeGrd vs pgBackRest](https://safegrd.dev/compare/pgbackrest) - [How to back up Supabase with GitHub Actions](https://safegrd.dev/guides/supabase-backup-github-actions) - [SafeGrd vs BackupDrill](https://safegrd.dev/compare/backupdrill) - [SafeGrd vs Databasus](https://safegrd.dev/compare/databasus) ## Optional - [Pricing](https://safegrd.dev/pricing) - [AI agents: backups an agent cannot delete](https://safegrd.dev/#ai-agents) - [Threat Shield](https://safegrd.dev/docs/threat-shield) - [The attestation record](https://safegrd.dev/docs/attestation) - [Alerts](https://safegrd.dev/docs/alerts) - [Organizations and billing](https://safegrd.dev/docs/account) - [Troubleshooting](https://safegrd.dev/docs/troubleshooting) - [Source (BSL 1.1)](https://github.com/safegrd/cli)