Everything we protect
Backup services across five platforms — Microsoft 365, Google Workspace, IMAP, WordPress and VM infrastructure. Each one backed up automatically, encrypted independently, and verified to be restorable before you ever need it.
Covered services by platform
Connect once per platform — all services in that platform back up automatically.
Microsoft 365
-
Exchange OnlineMail, calendar and contacts. Per-mailbox or all-users backup, with MIME-compliant .eml files.
-
OneDrive for BusinessFull file tree with all versions. Delta sync — only changed files are fetched on each cycle.
-
SharePoint OnlineSite document libraries and list attachments. All sites or specific site collections.
-
Microsoft TeamsChannel messages, posts and file attachments stored in SharePoint behind the team.
Google Workspace
-
GmailAll mailboxes in the domain via Domain-Wide Delegation. Messages stored as .eml with full headers.
-
Google DriveMy Drive and Shared Drives. Google Docs/Sheets/Slides exported to Office-compatible formats.
-
Google Calendar & ContactsAll calendars and contact groups exported to standard iCal and vCard formats.
IMAP Mail
-
Any IMAP serverConnect any mailbox over IMAP — including on-premises Exchange, Zimbra, Roundcube or hosted providers not on Microsoft or Google.
VM Infrastructure
- AegisProx™ — Proxmox Backup
-
Proxmox VM backup (CBT)Agent-less backup using Changed Block Tracking — only modified blocks transferred on incremental runs. Typically 90–99 % less data than recurring full backups.
-
Point-in-time restoreRestore to any backup point — not just the latest. Full and incremental restore chains built automatically from stored deltas.
-
File-level restoreBrowse and download individual files from inside the disk image — without restoring the full VM. Supports NTFS, ext2/3/4 and FAT.
- AegisShift™ — VMware Migration
-
VMware → Proxmox migrationStream VMware ESXi disk images to Proxmox VE via the vSphere HttpNfcLease API. No VDDK license, no agents, no downtime beyond the final cutover.
-
Windows & Linux — all versionsAuto-selects OS-compatible hardware (LSI+E1000 for Windows, VirtIO for Linux). Supports Windows Server 2008–2025 and all major Linux distros.
WordPress
- Backup
-
Posts, pages, media & commentsIncremental daily backup via the WP REST API — only changed items are fetched each run. Categories and tags included. No plugin needed.
-
MySQL database (optional)Full database dump via a lightweight companion plugin. Install once — daily encrypted SQL backups from that point on.
- Restore
-
Self-service restore from portalPosts and pages are restored as new wp-admin drafts — the site editor reviews and publishes. Live content is never overwritten automatically.
-
Cross-site migrationRestore a backup from one WordPress site to a different one — staging to production, disaster recovery to a clean install, or full site move.
- Security
-
Daily CVE security scanEvery plugin, theme and WordPress core version checked daily against NVD and WPScan. Instant email alert on critical vulnerabilities (CVSS ≥ 7.0).
-
Admin account monitoringTracks all administrator accounts on the site. Immediate alert if a new admin user appears — a common first sign of a compromised site.
Proven Restorability
We don't just back up your data — we prove every backup actually works.
Most backup services tell you that your data is safe. 365B proves it.
Every week, we automatically restore a random sample of backed-up items from each of your sources — email, files, calendars and contacts. The restore is a real decryption and integrity check: we verify that the stored data matches exactly what was backed up. No manual effort required from you.
Each month you receive a signed integrity certificate for your records, showing which sources were tested, how many items were verified, what your achieved recovery point objective (RPO) was, and that zero integrity failures were found.
This is exactly what auditors, insurers, and NIS2 supervisory authorities ask for — not a promise, but documented proof.
Weekly automated checks
Every week, a random sample from each source is restored and verified. Fully automatic — you do not need to schedule or trigger it.
Signed monthly certificate
Every calendar month, you receive a signed integrity report: sources tested, items verified, RPO achieved, zero failures recorded. Show it to your auditor.
RPO you can measure
The certificate shows the actual recovery point objective achieved — not a marketing number, but measured from your real backup history.
NIS2 & audit-ready
NIS2 Article 21(2)(c) requires organisations to test their backup and recovery capabilities. 365B's weekly verification and signed certificates give you the evidence to demonstrate compliance.
Security Insights
Backup protects you after something goes wrong. Security Insights helps you see the warning signs before it does.
A backup is your last line of defence. But the best outcome is never needing it.
Alongside every backup, 365B continuously monitors the security posture of your Microsoft 365 environment and surfaces the findings that matter — without requiring a separate security tool or a dedicated IT team.
Included at no extra charge with every Microsoft 365 backup subscription.
Secure Score
Your Microsoft Secure Score — tracked over time, with the specific recommendations that will move the needle most for your organisation.
OAuth App Risk
Every third-party app that has been granted access to your Microsoft 365 data is listed, with its permission level and risk rating. Spot over-privileged apps before they become a problem.
Account Hygiene
Inactive accounts, accounts without MFA, stale guest users and service accounts with excessive permissions — identified automatically and listed for your review.
Privileged Access
A live view of every account with admin or elevated permissions across your Microsoft 365 environment. Know exactly who can do what — at all times.
WordPress — Backup, Restore & Security
Complete lifecycle protection for every WordPress site: automated daily backup, self-service restore, and continuous CVE security scanning.
365 Backup connects to your WordPress sites via the REST API - no plugin installation required for the core backup. Every day we pull all content types incrementally: only changed items are fetched, keeping the load on your site minimal.
What we back up
- Posts and pages (all statuses: published, draft, private)
- Media library (binary files with original filenames)
- Comments, categories and tags
- MySQL database full dump (optional - requires a lightweight companion plugin, installed once)
Restore Items are restored via the WordPress REST API to the same site - or to a different site in the same account (cross-site migration). Posts and pages are always created as new wp-admin drafts with an [Aterstalld] prefix. Live content is never overwritten automatically: a site editor reviews and publishes. Media is re-uploaded as a new attachment; categories and tags that already exist count as restored.
Security scanning Every WordPress source is scanned once every 24 hours:
- Plugin, theme and WordPress core versions cross-referenced against NVD and WPScan
- Immediate email alert on any vulnerability with CVSS score >= 7.0
- Admin account list checked on every scan - alert fired the moment a new administrator appears (a common early indicator of site compromise)
Daily automatic backup
Posts, pages, media, plugins, theme and database — all captured every day, automatically, without touching your site configuration.
No plugin required
365B connects through the WordPress REST API and an application password. Nothing is installed on your site; your attack surface does not increase.
Point-in-time restore
Restore a single post, roll back a plugin update, or recover the whole database from any previous backup. Granular restore without a full site rollback.
Cross-site migration
Moving to a new host or domain? Restore your backup directly to the new environment. No manual export/import — just select the target and confirm.
Microsoft Directory Backup
Your user accounts, groups and access policies — versioned and restorable in minutes.
Your Microsoft Entra ID directory is the backbone of your organisation's security. It controls who has access to what — and when it changes, the consequences can be immediate and serious.
365B takes a daily snapshot of every user account, group, conditional access policy and role assignment in your directory. Changes are detected automatically and classified by severity:
- Critical — a Global Administrator was added, an account was deleted or disabled (you are alerted immediately by email).
- Warning — a privileged role was changed or a group membership was altered.
- Info — a licence was assigned, a contact field was updated.
If something changes that should not have — whether by mistake, a disgruntled employee, or an attacker — a SuperAdmin or TenantAdmin can restore attributes, group memberships or licences from any previous snapshot in seconds.
This feature is included at no extra charge and requires no additional setup beyond your existing Microsoft 365 connection.
Daily directory snapshots
Every day, 365B records the state of every user, group, conditional access policy and role assignment in your Entra ID.
Instant alerts on critical changes
When a Global Admin is added or an account is disabled, your administrators receive an email immediately — not at the next morning's report.
Point-in-time restore
Mistakenly removed someone from a group? Reset a conditional access policy by accident? Restore any attribute, group membership or licence from any snapshot in seconds.
NIS2 identity protection
Identity compromise is the leading cause of cloud data breaches. Versioned directory backups with instant change alerts give you both detection and recovery — two of the three pillars NIS2 requires.
Six layers of protection
Each layer is active independently. Disabling one does not weaken the others. Together they form a defence-in-depth architecture designed so that no single failure — technical, human or organisational — can expose your data.
Every backed-up item is encrypted with AES-256-GCM before it touches disk. The encryption key is unique per tenant and never stored alongside the data it protects.
We connect using read-only permissions only — Microsoft Graph and Google Workspace APIs are called with the minimum scopes required. 365B cannot create, modify or delete items in your live environment.
All backup data is stored on servers physically located in Sweden. No data is transferred to or processed in a third country — ever. Fully compliant with GDPR Chapter V.
Every customer's data is stored in a logically isolated namespace with a unique encryption key. A query bug or a misconfigured permission can never return another tenant's data.
Multi-factor authentication is required for all portal users — no exceptions. Login history is logged per session and kept for 90 days for audit and incident-response purposes.
Login endpoints are rate-limited and honeypot-protected. Aggressive credential-stuffing and bot traffic is trapped and blocked automatically before it reaches application logic.
Ready to protect your data?
Tell us about your environment and we'll get you started.