Hosted Borg repositories your server has no way to wipe.

BorgBackup over SSH in Los Angeles. The backup key is append-only, enforced on our side. Pruning runs from a separate key, inside a window you open from the portal, and closes itself.

  • Append-only backup key
  • Borg 1.x, borgmatic, Vorta
  • No egress or restore fees
bash, on the server you back up
# export BORG_REPO=ssh://ACCOUNT@borg.servercrate.net/./repo
# borg init --encryption=repokey-blake2
 
# borg create --stats ::'{hostname}-{now}' \
/etc /home /var/www
 
# append-only on our side: a delete sent with this
# key is logged, and no data leaves the disk

Append-only key

The backup key adds archives. A delete sent with it never removes data from disk.

Timed prune windows

A second key gets full access for 1 to 24 hours, then closes itself.

Zero-knowledge

repokey-blake2 encryption on your machine. We store ciphertext only.

ZFS hard quota

Checksummed storage with a hard cap, plus Borg's own storage quota.

Plans

Pick the repository that fits your data

A hosted BorgBackup repository over SSH with an append-only backup key. Every plan gets the same protections. What changes is how much history you keep.

Borg-100
One server's configs, app data and database dumps
$20/yr
$1.67/mo effective · save $4
  • 100 GB repository, hard quota
  • Fits /etc, /home, /var/www and nightly database dumps of a typical VPS*
  • Monthly billing from $2, no annual prepay required
  • An easy offsite copy for a 3-2-1 setup
30-day money-back guarantee
Best fit for one machine
Borg-250
A workstation with Vorta, or a busy app server
$30/yr
$2.50/mo effective · save $6
  • 250 GB repository, hard quota
  • Fits a 50 to 100 GB working set with months of daily archives*
  • Room to keep monthly archives for a year or more
  • 2.5 times the room of Borg-100 for $1 more
30-day money-back guarantee
Borg-1T
A NAS share, a photo library or a file server
$90/yr
$7.50/mo effective · save $18
  • 1 TB repository, hard quota
  • Fits a 300 to 600 GB share with deep daily and weekly history*
  • $7.50 per TB per month on yearly billing
  • Large first uploads are fine: Borg checkpoints and picks up where it stopped
30-day money-back guarantee
Borg-2T
Large archives and multi-year retention
$170/yr
$14.17/mo effective · save $34
  • 2 TB repository, hard quota
  • Keep years of monthly archives next to your dailies*
  • Lowest price per TB in the lineup: $7.08 on yearly billing
  • Fits media and photo archives that only grow
30-day money-back guarantee

Every Borg plan includes

  • Append-only backup key, enforced server-side
  • Separate prune key in a 1 to 24 hour window
  • Client-side encryption, zero-knowledge
  • Borg 1.x, borgmatic and Vorta
  • SSH with post-quantum hybrid key exchange
  • No egress or restore fees
  • Repository kept 14 days after cancel
  • 30-day money-back, cancel from the portal

Yearly billing is 10 times monthly, two months free. Your price stays locked for as long as your subscription is active.

*Estimates assume typical file data after Borg deduplication and compression. Already-compressed media (video, JPEG) shrinks little. Run borg info after your first archive to see your real ratio.

When things go wrong

Built for the day the client is the problem.

Borg's append-only mode only helps if the server enforces it. Ours does, on every plan.

Archives recoverable

The server is compromised

The attacker runs borg delete with your backup key. In append-only mode no data leaves the disk, and our team can roll the repository back to before the attack.

Under your control

You need to prune

Run borg list first to confirm every archive you expect is there, then open a window for a key on your laptop and prune. The window closes on its own.

Restore any time

The disk on your side dies

Restore from any machine with your passphrase and key export. No restore fees, no egress fees.

Set it up in 2 minutes

From checkout to the first archive.

  1. After checkout, open Borg repositories in the portal.
  2. Paste the SSH public key of the server you back up (for example cat ~/.ssh/id_ed25519.pub) and click Create repository.
  3. Run borg init --encryption=repokey-blake2 with the repository URL the portal shows.
  4. Run borg key export and keep the key and your passphrase somewhere off the server.
  5. Schedule borg create with borgmatic, Vorta, cron or a systemd timer.
  6. When you want to prune, open a maintenance window for a key on a trusted machine and run borg prune and borg compact from there.
borgmatic config.yaml
repositories:
- path: ssh://ACCOUNT@borg.servercrate.net/./repo
label: servercrate
encryption_passcommand: cat /root/.borg-passphrase
keep_daily: 7
# pruning runs from your trusted machine, not here
bash, on your laptop, during a maintenance window
# check first that every archive you expect is there
$ borg list $BORG_REPO
$ borg prune --keep-daily 7 --keep-weekly 4 \
--keep-monthly 6 $BORG_REPO
$ borg compact $BORG_REPO
# the window closes itself; the backup key stays append-only
Verify on first connect

Our host key fingerprints.

Check these when SSH asks to trust borg.servercrate.net for the first time.

ED25519

SHA256:uiEkumUC5r5/dfb/kFdMW8XyI/rGcC0UAnSIrOJtKYs

RSA

SHA256:l5DWdkQGFkcAzB90CghOWprl7pWuamNxACkO7ST8Y+Q
Specifications

Everything in one place.

RepositoryOne Borg repository account per plan, stored on ZFS with a hard per-repository quota and Borg's own --storage-quota guard on top.
Backup keyAppend-only, enforced server-side with borg serve --append-only --restrict-to-path. Key-only SSH, no shell, no port forwarding. A delete or prune sent with this key never removes data from disk, and our team can roll the repository back.
PruningOpen a maintenance window of 1 to 24 hours from the portal for a separate SSH key on a trusted machine. That key may run borg prune and borg compact until the window closes itself through OpenSSH key expiry.
EncryptionClient-side, with repokey-blake2 or keyfile. Our team never sees your passphrase, key or data. Zero-knowledge by design.
TransportSSH to borg.servercrate.net on port 22. Modern OpenSSH clients negotiate post-quantum hybrid key exchange (sntrup761x25519).
Borg versionBorgBackup 1.2 on the server. Use Borg 1.x clients. Borg 2 is not offered yet.
ClientsAny Borg 1.x client, including the borg CLI, borgmatic and Vorta.
LocationLos Angeles, California, US West Coast.
FeesNone beyond the plan. No egress fees, no restore fees. Monthly or annual billing.
After cancelWe keep the repository for 14 days after a subscription ends, then delete it.
FAQ

Questions from Borg users.

The SSH key on the server you back up is locked server-side to borg serve --append-only --restrict-to-path. It can add new archives and read them back for restores, and in append-only mode a delete, prune or rewrite sent with it never removes data from disk: the server keeps every transaction, so our team can roll the repository back to any point before the change. If an attacker gets root on that server, your existing archives stay intact. The key is key-only SSH with no shell and no port forwarding.
From the portal, open a maintenance window of 1 to 24 hours for a separate SSH key on a trusted machine, such as your laptop. During the window that key may run borg prune and borg compact. The window closes itself automatically through OpenSSH key expiry, and the backup key stays append-only the whole time.
Not yet. The server runs BorgBackup 1.2 and accepts Borg 1.x clients. Use any Borg 1.x release on the machines you back up.
No. Encryption happens on your machine with repokey-blake2 or keyfile mode before anything leaves it. Our team never sees your passphrase, key or data, so the repository holds only ciphertext. Keep a copy of your key and passphrase somewhere safe, because without them the archives are unrecoverable.
Yes. Any Borg 1.x client works, including borgmatic and Vorta. Point it at ssh://<account>@borg.servercrate.net/./repo on port 22 with the account name shown in the portal.
Each plan has one repository with a hard quota on ZFS, plus Borg's own --storage-quota guard. When the quota is reached, new writes are refused and your existing archives stay readable. Prune during a maintenance window or move to a larger plan to free space.
borg transfer is a Borg 2 feature and is not available in Borg 1.x. Run a fresh borg init against your ServerCrate repository and start creating new archives there. If you need the old history, keep the old repository until its archives age out.
Cancel from the portal at any time. Billing is monthly or annual. After a subscription ends we keep the repository for 14 days, then delete it.
Get started

Put your Borg history out of a compromised server's reach.

Hosted Borg repository. Append-only backup key. No restore fees.

Los Angeles, California. Cancel from the portal.