Enterprise backup & disaster recovery

Your organisation’s recovery plan, off-site and under control.

Protect servers, files, databases and branch workloads through encrypted outbound connections to ZCHPC. Customer recovery keys remain customer-side, while the Recovery Fabric stays private behind the service edge.

Client-side encryptionTenant-isolated vaultsAuditable restores
Customer site
Production systemsServers · NAS · databases
ZCHPC Backup ConnectorEncrypts locally · outbound only
ZCHPC service edge
Secure ingressSigned authorization · exact accounting
Private Recovery FabricEC2+2 / degraded RF3 policy
Checking Recovery Fabric state…

Built for organisations that cannot afford to discover their backup problem during an incident.

Encrypted before transferOutbound customer connectivityExplicit restore authorizationServer-side tenant isolation

A practical protection model

No stretched VLAN. No public storage nodes. No inbound customer firewall rule.

ZCHPC Backup uses a site gateway or host connector inside the customer network. It reaches the service over an outbound encrypted connection, receives short-lived backup authorization and sends ciphertext only.

  1. 01
    Enroll the site

    A one-time bootstrap token is exchanged for a tenant-and-site-bound device certificate.

  2. 02
    Bind local sources

    Source paths stay on the connector. The central service only needs the protected asset identity.

  3. 03
    Protect automatically

    Policies schedule unattended encrypted backups when the Recovery Fabric admission gate is genuinely open.

  4. 04
    Recover with evidence

    Portal authorization is followed by connector-side restore execution and terminal proof.

Security is in the architecture

Control-plane convenience without custody shortcuts.

01

Customer-side encryption

Backup chunks and manifests are encrypted before they leave the customer network. Recovery keys are not silently escrowed as plaintext at ZCHPC.

02

Certificate-bound connectors

Short-lived enrollment tokens bootstrap device identity; routine connector traffic uses mTLS-bound certificates rather than permanent shared passwords.

03

Signed data-plane authority

The portal signs backup authorization. Ingress independently signs storage receipts. Neither authority can impersonate the other.

04

Fail-closed infrastructure gates

If disk admission or InfiniBand convergence is not proven, the data plane rejects production backup movement instead of staging customer data optimistically.

Recovery is the product

A backup is only useful when the restore path is explicit.

Every recovery point belongs to one organisation, site and asset. Restores name an approved target, are claimed by the correct site connector and remain “running” until connector-side execution reports a terminal result.

Portal-authorized restore request Site-bound connector execution Ciphertext retrieved from private fabric Customer-side decryption Auditable completion or failure

ZCHPC Backup

Build recovery readiness before the incident.

Activate the service for operator setup, or sign in to manage an existing organisation.