One control plane for
all your customers' backups

Backup Control Plane is a self-hosted orchestration platform built for managed service providers. Schedule, run and monitor backups across every customer, server and hypervisor — from a single pane of glass, on your own infrastructure.

Explore the platform

Self-hosted or managed SaaS · Multi-tenant by design · Powered by proven engines · White-label ready

Works with the infrastructure you already run

  • restic
  • Proxmox VE
  • VMware vSphere
  • Microsoft Hyper-V
  • Microsoft 365
  • Amazon S3
  • Wasabi
  • MinIO
  • SFTP
  • SMB/CIFS
  • LDAP / Active Directory
  • Slack · Teams · n8n
3
hypervisor platforms — Proxmox VE, VMware vSphere, Hyper-V
1
isolated PostgreSQL database per customer
customers managed from one pane of glass
0
backup bytes routed through the control plane

Why a backup control plane?

Most MSPs run backups with a patchwork of scripts, vendor tools and manual checks — one setup per customer, no shared overview, and audits that take days. Backup Control Plane replaces the patchwork with one consistent operating model.

End the tool sprawl

One platform handles file backups on Linux and Windows, whole-VM backups on three hypervisor platforms, scheduling, retention, monitoring and restores — instead of five disconnected tools with five different states of documentation.

Know the state of every backup

Dashboards per customer, e-mail reports per run or as a daily digest, webhooks into your monitoring — a failed job never goes unnoticed until the day you need the data back.

Isolation your customers can verify

Every company lives in its own PostgreSQL database. Credentials, policies, run history and audit logs are physically separated — a clear answer to the data-separation question in every audit.

Everything an MSP backup operation needs

From onboarding a new customer to restoring a VM at 3 a.m. — the complete lifecycle in one place.

True multi-company isolation

Each company gets its own database, its own encryption keys per repository and its own audit trail. Team members only see the companies they are assigned to — with per-company roles.

Proven engines, no reinvention

Backups are executed by a proven open-source engine directly on the client host: encrypted end-to-end, deduplicated, incremental. The backup data never flows through the control plane.

Hypervisor backups

Whole-VM backups on Proxmox VE, VMware vSphere and Microsoft Hyper-V — discovered automatically, selected per policy, restorable as complete VMs.

Push and pull connectivity

Hosts you can reach are driven over SSH. Clients behind NAT or firewalls run a lightweight agent that phones home and fetches its jobs itself — no inbound ports at the customer site.

Visual scheduling & retention

Cron-based policies with a live visual preview — week, month and year at a glance. Retention from daily to yearly, enforced automatically. Storage targets: any S3-compatible object storage, SFTP or SMB/CIFS — including backup nodes at the customer site.

Restore built in

Pick a recovery point on a visual calendar, then restore single files or a whole VM from the UI — VM restores prefill the target storage and the next free VM ID automatically. Rebuild a failed physical Linux server straight into a bootable Proxmox VM (P2V). For disaster recovery, administrators can reveal the repository password — your data stays restorable even without the platform.

Application-consistent backups

Run pre- and post-backup hooks around any job — dump a database, quiesce an application, then clean up afterwards — with strict failure handling so a broken dump never hides behind a green backup. On Windows, file backups use VSS snapshots so open files are captured cleanly.

Offsite copies, 3-2-1 ready

Mirror every repository to a second, offsite target and verify both on a rotation. Pruning the source pauses automatically until the copy is current — so a stalled offsite link can never silently erode your second copy.

Disaster-recovery kit

Export a per-job recovery kit — repository address, password and storage credentials — so your backups can be restored with plain open-source tooling even if the control plane itself is gone. No lock-in, ever.

Dashboards, reports & webhooks

Build the overview your team needs: modular widgets — KPIs, success rates, recent runs, per-target growth and live host metrics (CPU, memory, disk, network) — across multiple boards per company, arranged by drag & drop. Plus branded e-mail reports per run or as a daily digest, run timelines and a one-year heatmap per job, and JSON webhooks into Slack, Teams or automation platforms like n8n.

White-label branding

Your logo across the UI and every outgoing e-mail — with separate light/dark variants and optional per-company overrides. Your customers see your brand.

Site connectivity, alerted

Each customer tile shows a live VPN status indicator (gateway ping) — and when a site goes offline, the company's report recipients get an e-mail alert on the state change, plus one when it comes back.

Built for support cases

Every failure carries a stable error code (BCP-E…), a dedicated error log shows full per-run logs one click away, and runs, reports and the filterable audit log export to CSV and branded PDF — tickets get answers, not guesswork.

Microsoft 365 backup & restore New

Back up OneDrive, SharePoint document libraries and Exchange mailboxes — agentless, straight over the Microsoft Graph API into your own encrypted storage. Tenants connect via Entra ID, certificate-based (recommended) or client secret. Restore is built in: pick a point in time, then export and download the data in the archive format you prefer — ZIP, tar.gz, tar, tar.bz2 or 7z.

Team access that scales

Assign people to the companies they manage with per-company roles — admin, operator or read-only viewer. Groups grant access in bulk and sync from your LDAP directory, so onboarding a new technician is one assignment, not a checklist.

How it works

From zero to monitored backups in three steps.

Connect your infrastructure

Create a company — its database is provisioned automatically. Register Linux/Windows clients (SSH or pull agent) and hypervisors. Host keys are scanned, verified and pinned before anything runs.

Define backup policies

Pick sources (paths or VMs), a schedule, retention rules and a storage target. The platform creates the encrypted repositories, installs the backup engine where needed and takes it from there.

Monitor and restore

Reports, digests and webhooks keep your team informed. When something goes wrong, restore files or whole VMs straight from the UI — with every action recorded in the audit log.

A look inside the platform

Clean, fast and to the point — here with demo data: the company overview your team starts the day with, and the per-company dashboard.

Per-company dashboard with KPIs, recent runs and live host metrics
Per-company dashboard you arrange yourself: KPIs, recent runs and live host metrics as modular widgets.
Company overview with live VPN status per customer
Company overview: one tile per customer with live VPN status.
Run history with a week and month timeline
Run history — one row per job run, with a week/month timeline and live progress.

View all screenshots →

Security is the default, not an add-on

A backup platform holds the keys to your customers' data. This one is built accordingly.

Host-key pinning (TOFU)

SSH host keys are scanned, confirmed by a human and pinned. If a key ever changes, the connection is refused — man-in-the-middle attempts stop cold.

Encrypted secrets at rest

SSH keys, storage credentials and repository passwords are encrypted with a dedicated master key before they touch the database. Plaintext secrets are never returned by the API.

End-to-end encrypted backups

Every backup repository is encrypted with its own password. Data is encrypted on the client before it leaves — your storage provider only ever sees ciphertext.

MFA, passkeys, LDAP & roles

Two-factor authentication (TOTP) with single-use recovery codes, passwordless sign-in via passkeys (FIDO2 / WebAuthn), sign-in against your LDAP / Active Directory, and granular roles: admin, operator and read-only viewer — assignable per company.

Complete audit trail

Every security-relevant action — host-key confirmations, restores, user changes, password reveals — is recorded with user, time and target, per company.

Your infrastructure, your data

Fully self-hosted. No SaaS dependency, no third party holding your customers' backups, no per-gigabyte cloud bill — and no vendor lock-in thanks to open, standard repository formats.

Run it your way: self-hosted or as a managed service

Same platform, two ways to get it. And one principle that holds in both: your backup data flows directly from your clients to your storage — it never passes through the control plane.

Self-hosted

Maximum sovereignty — runs entirely on your infrastructure.

  • Deployed on your servers (Docker Compose), in your network
  • Full data sovereignty: platform, databases and secrets stay in-house
  • Works in isolated environments — no internet dependency
  • Guided installation and onboarding by us
  • Updates delivered via your private Git remote
  • Optional support & maintenance contract
Talk to us
Managed

Managed SaaS

We run the control plane for you — you run the backups.

  • Fully hosted and operated for you — we run the platform
  • Updates, monitoring and platform backups included
  • Your backup data still goes to your storage targets — never through our servers
  • Per-company isolation and white-label branding as always
  • Start in days, scale per customer
  • Migration path to self-hosted at any time — no lock-in
Book a demo

Starter

up to 10 managed hosts

For getting started: one team, first customers, all features included.

Pricing on request
Get a quote

Professional

up to 50 managed hosts

For growing MSPs: more customers, more hypervisors, same control plane.

Pricing on request
Get a quote

Enterprise

50+ managed hosts

Custom volume, custom SLAs — let's talk about your environment.

Pricing on request
Get a quote

Licensing is based on the number of managed hosts — counted as clients, hypervisors and every VM known to the platform (inventory and backup policies, each VM once) — and applies to both editions. Not sure which fits? We'll figure it out together in the demo — switching later is always possible.

Frequently asked questions

Where does the backup data go?

Wherever you decide: any S3-compatible object storage (Wasabi, MinIO, AWS S3, …) or SFTP targets — including backup nodes you place at the customer site. Data flows directly from the client to the storage target, encrypted before it leaves the machine. The control plane only orchestrates; it never stores backup data.

What happens if the control plane itself fails?

Your backups remain safe and restorable. Repositories use an open, widely-used format; administrators can reveal each repository password, so a restore is always possible with freely available open-source tooling — independently of the platform.

Which systems can be backed up?

File-level backups on Linux and Windows (over SSH or via pull agent), and whole-VM backups on Proxmox VE, VMware vSphere and Microsoft Hyper-V — including full-VM restore.

Can it back up Microsoft 365?

Yes. Connect customer tenants via an Entra ID app — certificate-based authentication recommended, no third-party engine, straight over the Microsoft Graph API — and back up OneDrive, SharePoint document libraries and Exchange Online mailboxes into your own encrypted storage, on a schedule with retention. Restoring is built in too: choose a point in time and export the data as an encrypted download in the archive format you prefer (ZIP, tar.gz, 7z and more). Teams backup and in-place restore back into Microsoft 365 are on the roadmap — ask us in the demo for the current state.

Do customer sites need open inbound ports?

No. Sites you reach via VPN/SSH are driven directly; everything else runs the pull agent, which initiates all connections outbound to the control plane.

Can my team sign in with Active Directory?

Yes — LDAP / Active Directory sign-in with automatic user provisioning, group requirement, LDAPS with your internal CA, plus optional TOTP two-factor authentication. Local accounts keep working in parallel.

How do I get it?

Two ways: as a self-hosted installation on your own infrastructure, or as a managed SaaS where we operate the control plane for you — in both cases your backup data goes directly to your storage. Book a demo and we will walk you through the platform and the onboarding.

SaaS — what do you see of our data?

Only metadata: companies, schedules, run results, audit events. The backup payload is encrypted on your clients and flows directly to your storage targets — it never touches our servers. Repository passwords are stored encrypted, and you can migrate to self-hosted at any time.

Book your demo

Pick a slot that suits you — we'll walk you through the platform with your use cases: your hypervisors, your storage, your customer structure.

Booking window doesn't open? Open the booking page  ·  Prefer e-mail? info@inal-it.de

Or send us a message

Questions about features, sizing or onboarding — we usually reply within one business day.