BackupProof

Import old backups

Already have backups in a bucket, on a disk or on another server? BackupProof reads them, decrypts them, stores them in its own format and restore-tests them. Your old backups are only read, never changed or deleted.

What it can import

Your old backups are…ChooseYou need
Files from a script or tool: database dumps, .zip or .tar.gz archives, possibly encryptedBackup files in a bucket or folderThe storage keys, and the password or key used to encrypt them
A restic repositoryresticThe restic program on the converting server
A Kopia repositoryKopiaThe kopia program on the converting server
A Borg repositoryBorgBackupThe borg program on the converting server
Files on Google Drive, Dropbox, OneDrive and 70+ other servicesGoogle Drive, Dropbox, OneDrive…rclone, set up once with rclone config

Start from Import in the dashboard. Every converted copy keeps its original date and is restore-tested like any other backup, so you finally know whether those old backups actually work.

Backup files and encryption

BackupProof recognises the encryption from the file contents, so you only give it the password or key:

  • GPG (.gpg, .pgp, .asc, also used by duplicity), with a passphrase or a private key.
  • OpenSSL (openssl enc, files starting with Salted__), including both the modern and the older key-derivation settings.
  • age (.age), with a passphrase or an AGE-SECRET-KEY identity.
  • Encryption done by the storage itself (S3 or B2 server-side encryption) needs nothing extra.

Archives can be opened during import, so the restore test checks every file inside, not just the archive. Files with dates in their names, like shop-2026-09-01.sql.gz.gpg or folders like 2026-09-01/, become one backup copy per day, each with its own date.

restic

If a script already runs restic on one of your servers, choose Use the restic settings already on that server and give the paths of its settings and password files, for example /etc/restic/env and /etc/restic/password. The server reads them itself, so the storage keys and restic password never reach the dashboard.

Or enter the repository details yourself: the bucket or SFTP server, the restic password, and optionally a native address like b2:my-bucket:server1.

Kopia and BorgBackup

For Kopia, reuse the connection already on the server (its repository.config and a password or password file), or connect read-only to the bucket, folder or SFTP server holding the repository.

For Borg, give the repository address you already use, such as ssh://u123456@u123456.your-storagebox.de:23/./backups, with the passphrase or a passphrase file and, if needed, an SSH key file. Each archive is streamed straight out of Borg, so no extra disk space is needed.

Cloud drives

Set up the drive once on the converting server with rclone config, then enter its name and folder, like gdrive:Backups. rclone-encrypted folders are decrypted automatically, and all the options for backup files apply.

Keep your current backup job

For restic, Kopia and Borg you can choose Convert new snapshots every night. Your existing backup job keeps running as it is; each night BackupProof converts the newest snapshot and restore-tests it. You get proof without changing what already works.