Tools, keys, and signatures.

Everything we publish that you might want to verify, inspect, or run alongside your backups. Setup instructions live on the setup guide.

Featured

restic-toolkit

Open-source helper scripts for running Restic against a ServerCrate vault: scheduled backup wrappers, sane retention defaults, healthcheck pings, and systemd unit templates. MIT-licensed, audit-friendly, no vendor binaries.

Latest releaseView source
$ git clone https://github.com/servercrate/restic-toolkit
PGP public key

For verifying signed release artifacts and our warrant canary, and for encrypting security disclosures. RSA-4096, valid through May 2028.

AAB2 A06A E5F9 187B 9565 4584 C1B0 7D4D F41C B15F
View key + fingerprint
servercrate-team.asc
Warrant canary

PGP-signed statement that we've received no secret subpoenas, gag orders, or compelled-access requests. Refreshed on a public schedule.

Read the canary
canary.asc (signed)
Security & compliance

Public security model, threat model, and incident response policy. SOC 2 audit underway; BAA available for HIPAA-adjacent workloads on the Enterprise tier.

Security model
Request compliance docs

Looking for install instructions? The 5-minute setup guide walks you through installing Restic, pointing it at your vault, and running your first backup on Linux, macOS, Windows, and Docker.