Customer-side encryption
Backup chunks and manifests are encrypted before they leave the customer network. Recovery keys are not silently escrowed as plaintext at ZCHPC.
Enterprise backup & disaster recovery
Protect servers, files, databases and branch workloads through encrypted outbound connections to ZCHPC. Customer recovery keys remain customer-side, while the Recovery Fabric stays private behind the service edge.
Built for organisations that cannot afford to discover their backup problem during an incident.
A practical protection model
ZCHPC Backup uses a site gateway or host connector inside the customer network. It reaches the service over an outbound encrypted connection, receives short-lived backup authorization and sends ciphertext only.
A one-time bootstrap token is exchanged for a tenant-and-site-bound device certificate.
Source paths stay on the connector. The central service only needs the protected asset identity.
Policies schedule unattended encrypted backups when the Recovery Fabric admission gate is genuinely open.
Portal authorization is followed by connector-side restore execution and terminal proof.
Security is in the architecture
Backup chunks and manifests are encrypted before they leave the customer network. Recovery keys are not silently escrowed as plaintext at ZCHPC.
Short-lived enrollment tokens bootstrap device identity; routine connector traffic uses mTLS-bound certificates rather than permanent shared passwords.
The portal signs backup authorization. Ingress independently signs storage receipts. Neither authority can impersonate the other.
If disk admission or InfiniBand convergence is not proven, the data plane rejects production backup movement instead of staging customer data optimistically.
Recovery is the product
Every recovery point belongs to one organisation, site and asset. Restores name an approved target, are claimed by the correct site connector and remain “running” until connector-side execution reports a terminal result.
ZCHPC Backup
Activate the service for operator setup, or sign in to manage an existing organisation.
Customer & operator portal
Sign in to your ZCHPC Backup account.
Need first-time setup?
First-time secure setup
Create the initial platform operator. The activation token is supplied out-of-band by the deployment administrator.
Already activated?
Operations
Loading secure workspace…