Offsite Vault
The Offsite Vault is storage Skans Labs hosts for your site’s backups, somewhere other than the building the appliance is in. The appliance encrypts every backup before it leaves, with a key that never leaves your site, so Skans Labs stores ciphertext it cannot read — and it encrypts each backup’s name as well, so Skans Labs cannot read file names, host names or database names either. Restoring is a download from the portal, decrypted on site with the recovery kit, which also puts the original names back.
Shipping backups off the box is free in every edition — to your own share, as described in Backup & recovery. The Vault does not replace that; it adds a copy you do not have to host.
If you lose both the appliance and its printed recovery sheet, your Vault backups cannot be restored — by you or by Skans Labs. The key exists on the appliance and on the sheet, nowhere else; Skans Labs keeps no copy and has no way to decrypt. Print the recovery sheet, store it away from the appliance, and keep the appliance’s data volume BitLocker-protected (the console warns you if it isn’t).
Before you start #
- Storage. Each paid edition includes some Vault storage; the Offsite Vault subscription adds more. See How storage is counted.
- Region. Decide whether the site’s backups are stored in the United States or the European Union. You choose once, in the portal, before the site’s first enrol; it is fixed from that enrol and cannot be changed afterwards. An EU site’s backups are stored only in the EU.
- Recovery sheet. Make sure you have printed the appliance’s recovery sheet and know where it is. The Vault is only as recoverable as that sheet.
- Network. The appliance talks to
msp.skanslabs.comover HTTPS (TLS 1.2 minimum, TLS 1.3 negotiated). If the site allowlists egress, allow that hostname. Nothing else is needed; the appliance never connects to a storage provider directly.
1. Issue an enrol code in the portal #
The code is issued by the licence owner, or by an MSP technician whose assigned customers include this site’s licence.
- Sign in to portal.skanslabs.com, open the site, and go to Offsite backups.
- If this is the site’s first enrol, choose the storage region.
- Choose Issue enrol code. The code is single-use and valid for 24 hours. Issuing it switches nothing on.
2. Enrol the appliance #
A local administrator at the appliance’s console adds the Offsite Vault as a backup destination, reads and accepts the key-loss acknowledgement, and enters the enrol code. Accepting the acknowledgement at the appliance is the site’s consent. The appliance redeems the code for its own vault credential, which it seals in its local vault. The credential is not your licence key, and it only ever works for this site.
Enrolment happens at the appliance on purpose: an enrol code does nothing until someone at the site enters it, so nobody in the portal — including an MSP that manages the site — can switch the Vault on for a site. The site decides to start shipping.
Re-enrolling the site (for example after replacing the appliance) revokes the previous credential. You can also revoke the credential from Offsite backups in the portal at any time; the appliance then stops shipping to the Vault and carries on backing up locally.
What ships #
The appliance ships the same encrypted artifacts it already produces — the control-plane database chain, the directory system-state, the CA backup, the configuration set, device configs and endpoint backups — to the Vault as well as to any share you have set.
- Encrypted or refused. Every object must already be an encrypted Skans backup (AES-256 with an HMAC integrity tag). Anything that is not is refused with a reason, not sent. Endpoint backups are encrypted by default for this reason.
- Never shipped: the appliance’s
secretsdirectory and the backup master key itself. - Integrity. Each object’s SHA-256, as the appliance computed it, is recorded when it is stored, and the appliance adds the offsite copy to its tamper-evident backup ledger. As each object is uploaded, Skans Labs also records a SHA-256 for every 16 MiB part of it. Every week Skans Labs reads back a random sample of stored parts and checks each against its recorded part SHA-256; a mismatch is recorded in the site’s audit log and raised to Skans Labs operations.
- No readable names leave the site. The appliance encrypts each backup’s original name with the site key before upload, and identifies its backup set, and the chain a database backup belongs to, only by keyed codes Skans Labs cannot reverse. What Skans Labs holds per backup is that encrypted name, the set and chain codes, whether it is a full, differential, log or self-contained backup, a coarse type (
config,database,drordevice), the size, the SHA-256 and the timestamps. - Each name is bound to its file. The encrypted name also carries the file’s SHA-256, and the recovery kit refuses to restore a file whose SHA-256 does not match the one sealed in its name. Nobody can swap the names of two stored backups to make you restore the wrong one. Each site’s objects live in their own storage folder named by a random identifier, never by the site, host or set name.
Retention and deletion #
- Every stored backup is locked for 14 days. Nobody — you, an MSP, Skans Labs, or a compromised appliance — can delete a backup before its 14-day lock expires. After that, only three things remove it: the retention you set, the end of the subscription (see If the subscription ends), or your own Delete my vault.
- Retention is set in the portal, per backup set, by calendar — the number of backups never pushes anything out:
- Full backups and self-contained backups (a configuration set, a device config, a CA backup): the default keeps 14 daily, 8 weekly and 12 monthly copies. The copy kept for each day, week or month is the earliest complete backup in it.
- Differential and log backups are kept per database backup series so that the whole daily window (14 days by default) stays restorable. For each series, the base is the most recent full taken on or before the start of the daily window (if there is none, the series’ first full). The base full is kept, and every differential and log backup taken after it is kept — including those older than the window — so you can restore the database to any backup point from the start of the window to now (the base full plus its logs, or the base full plus a differential plus its logs). Differential and log backups older than the base full are removed. Any full backup that a kept differential or log backup depends on — the most recent full before it in its series — is always kept too, even if the calendar alone would not keep it. For points older than the window you restore from the weekly and monthly fulls that are kept.
- Who can change it. Only the licence owner, after a multi-factor check, can reduce retention, and a reduction takes effect only after existing locks expire. An MSP’s technicians can increase retention, never reduce it.
- The appliance cannot delete anything and cannot change retention. There is no such function. Backups are deleted only by Skans Labs’ retention process, after the lock.
How storage is counted #
| Edition | Included Vault storage |
|---|---|
| Community | 0 GB |
| Essential | 10 GB |
| Professional | 25 GB |
| Business | 50 GB |
| Enterprise | 100 GB |
The Offsite Vault subscription adds 250 GB for $49 per site per month; each further 100 GB is $19 per month on the same site. Annual prepay is ten months ($490 and $190). Any edition can buy the Vault, Community included. Storage belongs to one site and is never pooled with another site — not even another site of the same MSP. GB means 10^9 bytes.
- What counts: everything stored for the site, including backups that were deleted but are still inside their 14-day lock.
- At the limit: new uploads are refused, the appliance raises an alert and the portal shows a banner. Nothing already stored is deleted to make room. Raise the limit by adding storage, or have the licence owner lower retention in the portal (which frees space as locks expire).
- Interrupted uploads: storage is reserved when an upload starts. An upload that receives no data for 24 hours is abandoned and its reservation released; an upload that fails at the last step stays reserved and the appliance retries it.
- Daily ceiling: to stop a runaway job filling the site, uploads are also capped per UTC day. Until the site has stored its first backup, the cap is the site’s storage; after that it is the larger of 10 GB and twice the largest backup the site has ever stored. Above it, uploads are refused until the next day.
Usage — stored, locked, limit and today’s uploads — is shown in the portal under Offsite backups and on the appliance.
Restore from the Vault #
Restore is download, then decrypt on site. The appliance never pulls backups back from the Vault by itself, and there is no other way to get a backup out: Skans Labs cannot send you a readable copy.
Getting the recovery kit. The kit is on every Skans appliance, and it is also published for anyone to download — from Offsite backups and from Downloads in the portal — so losing the appliance does not lose the kit. You still need the site key from the recovery sheet.
- In the portal, open the site → Offsite backups. Backups are grouped by series — one per database backup chain, labelled
Seriesand six characters of its code (for exampleSeries 3fa9c1) — and each row shows its kind (full, diff, log or single), class, date, size and SHA-256. Names are not shown, because Skans Labs cannot read them. For a database point in time, pick in one series the latest full at or before that point, the latest diff after that full and at or before the point (if any), and every log after that diff (or after the full, if you took no diff) up to and including the first log taken after the point — that log is the one that covers it, so without it the restore stops short. For anything else, pick the single or full from the date you want. - Choose Download manifest. The manifest (
manifest.json) lists every stored backup’s identifier, encrypted name, set code, series code, kind, class, size, SHA-256 and date; it is what lets the recovery kit give each file its original name back. - Download the backups you need. Each file arrives as
<identifier>.skb2, streamed through skanslabs.com — you never get a storage link. - Check the SHA-256 of each downloaded file against the one listed (the recovery kit does this too).
- On site, run the recovery kit (PowerShell or bash) with the site key, the manifest and the downloaded files. It decrypts each file, decrypts its name from the manifest, refuses any file whose SHA-256 does not match the one sealed in its name, and writes the rest back under their original names. On a rebuilt appliance, first import the key from the recovery sheet.
- Restore the decrypted artifacts through the normal paths — see Restore from backup.
Every download and every manifest download is a privileged action. It needs a portal role that is allowed to download and a fresh multi-factor check; an MSP’s users can download only for the customers assigned to them. Each one is written to the site’s audit log, and the licence owner can choose to be emailed each time.
If you are rebuilding after losing the appliance, issue a new enrol code for the replacement box once it is running and enter it at its console; enrolling it revokes the old box’s credential.
If the subscription ends #
When the Offsite Vault subscription ends — cancelled by whoever pays for it (you or your MSP), or payment still failing after the card retries — the site becomes read-only for 30 days: downloads work, new uploads are refused.
- The licence owner is emailed at once, with the date read-only ends and a link to take the subscription over. The lapse is written to the site’s audit log.
- The licence owner can take it over. Starting your own Offsite Vault subscription on the licence at any time during the 30 days ends the lapse: uploads start again and nothing is deleted. This is how a customer keeps their backups when an MSP relationship ends or an MSP stops paying.
- The take-over keeps the storage you had. The take-over checkout is filled in with the number of extra 100 GB blocks that were cancelled when the subscription ended. You can buy fewer, but then the site may already hold more than its new limit: it becomes active again, nothing is deleted, and new uploads are refused until what is stored fits (as locks expire and your retention removes older backups). The take-over page tells you this before you pay.
- Otherwise, download anything you need during this period.
After the 30 days the site goes back to the storage its edition includes (see the table above):
- The site keeps its newest backups that fit in the included storage, in whole restorable units: a database full backup together with every differential and log backup of its series taken after it, up to the next full. Units and self-contained backups are kept newest first while they fit. A unit that does not fit is removed whole — Skans Labs never keeps a full without its logs, or logs without the full they start from, because a chain with a gap cannot be restored. Everything not kept is marked for deletion and removed as its 14-day lock expires.
- Uploads start again, within the included storage.
- Community includes no storage, so a Community site’s stored backups are all deleted and its vault is closed.
The site’s storage blocks are cancelled with the subscription, at the end of their current period. A site has one Vault subscription; to add storage, add blocks — a second subscription is refused. Nothing on the appliance is affected at any point: it keeps taking backups and shipping them to your own share exactly as before.
Delete your vault #
The licence owner can delete the site’s Vault from Offsite backups in the portal, after a multi-factor check. What happens:
- At once: the site’s vault credentials are revoked, so the appliance can no longer upload, and every stored backup is marked for deletion.
- When you destroy the site key (on the appliance and the recovery sheet), what Skans Labs holds is unreadable to anyone from that moment — this is crypto-shredding, and it is the erasure that matters.
- Within 14 days: Skans Labs’ retention process physically removes each backup as its lock expires. Until then nobody, Skans Labs included, can remove it early.
Audit #
The portal keeps an append-only audit log for each site — every download and manifest download, retention change, credential issue or revocation, subscription lapse, vault deletion and failed integrity check, with who, when and from where — for one year.
For MSPs #
An MSP’s users can see each managed site’s Vault usage, list its backups, issue an enrol code for a site whose licence is assigned to them, increase its retention, and download backups and the manifest for a restore — each download after a multi-factor check, only for customers assigned to them, and recorded where the customer can see it. An MSP that pays for a site’s Vault can cancel that subscription, but a cancellation only starts the 30-day read-only lapse: the licence owner is emailed at once and can take the subscription over with nothing deleted. An MSP cannot read the contents or the names, reduce retention, delete a backup, delete the vault, pool one customer’s storage with another’s, or switch the Vault on from the portal — the code does nothing until a local administrator enters it at the customer’s appliance and accepts the key-loss acknowledgement.
Next #
- Backup & recovery → — what the appliance backs up and how it ships to your own share
- Restore from backup → — restoring a decrypted artifact
- Editions, pricing & support → — the Vault on the price list