Capabilities
Everything Nyx Backup does
51 capabilities, grouped and plainly described - for when you have a specific requirement and want to know whether it is met. If you would rather read why any of it matters, start with Features.
Everything listed here is in the shipped product. Where support is partial - one provider rather than all of them, or a setting that is not yet in the interface - the row says so.
Protecting what is stored
| Reed-Solomon parity | Recovery data written alongside backups on SMB, SFTP, AFP and WebDAV, so a damaged file can be rebuilt. 10+2 by default; never used on cloud object stores, which replicate internally. Details. |
|---|---|
| Immutability | Versioning-based protection so deletion is recoverable at the provider. Backblaze B2 today; Object Lock not yet implemented. Details. |
| Quick integrity audit | Confirms every pack is present and unchanged in size. HEAD requests only, so no download and no egress cost. Can run on a schedule. Details. |
| Deep integrity check | Downloads a sample of chunks, decrypts them and verifies their hashes - proof the data is not just present but readable. Details. |
| Per-chunk authentication | Every chunk is bound to its position in the manifest by AES-256-GCM, so substituted or reordered data fails to decrypt rather than restoring silently wrong. Details. |
Where backups go
| Object storage | Amazon S3, Backblaze B2, Azure Blob, Google Cloud Storage, Wasabi, Cloudflare R2, MinIO and any S3-compatible service. Details. |
|---|---|
| Consumer clouds | Google Drive, OneDrive and Dropbox, each into its own app folder. Details. |
| Network and local | SMB / CIFS, SFTP, WebDAV, and local or external drives. Details. |
| Archive tiers | Glacier, Deep Archive and Azure Archive, with the retrieval step handled rather than reported as a failure. Glacier Instant Retrieval reads directly. Details. |
| Shared destinations | Several sets, and several machines, can safely use one bucket. Each writes to its own namespaced folder and retention only ever removes its own data. Details. |
| Multiple destinations | A set can have more than one endpoint, and separate sets can target different providers for a second copy. Details. |
| You pay the provider | No markup and no resale - storage is billed to your own account at their prices. Details. |
How backups run
| Content-defined chunking | Files are split on content boundaries, so inserting bytes near the start of a large file does not re-upload the rest of it. Details. |
|---|---|
| Deduplication | Identical content is stored once per set, whether it repeats within a file, across files, or across machines sharing a destination. Details. |
| Compression | zstd before encryption, so backups are smaller on the wire and at rest. Details. |
| Open and locked files | Volume Shadow Copy on Windows and APFS snapshots on macOS, so files in use are captured consistently. Filesystems without snapshot support fall back to direct reads and say so. Details. |
| Automatic tuning | Pack size and upload concurrency are chosen from the machine’s available RAM and CPU at the start of each run. Details. |
| System exclusions | Over 180 built-in rules skip caches, temp files, page files and other things that should never be backed up - including rules read from Windows’ own registry list. Details. |
| Cloud-only files | Online-only OneDrive and Dropbox placeholders are skipped by default rather than silently downloading your whole cloud drive; you can opt in per set. Details. |
| Removable drives | A set whose source is a removable volume recognises the disk when it returns, instead of treating an unplugged drive as deleted files. Details. |
| Bandwidth limits | Cap upload rate so a backup does not saturate the connection. Details. |
| Resume after interruption | A run stopped by shutdown, sleep or cancellation resumes rather than restarting. Details. |
Getting data back
| Point-in-time restore | Browse any snapshot and restore the whole set, a folder, or one file, as it was at that time. Details. |
|---|---|
| Previous versions | Restore an earlier version of a single file without hunting through snapshots. Details. |
| Restore anywhere | Original locations, the desktop, or any folder you choose. Details. |
| Search | Find a file by name across snapshots when you do not remember where or when it was. Details. |
| Restore reports | A per-file record of what was restored, skipped, or failed, browsable after the run. Details. |
| Sparse file handling | Files with large empty regions are restored without writing the zeroes, where the destination filesystem supports it. Details. |
| Damaged-pack repair | A pack that fails to decrypt is rebuilt from its parity file and the restore continues. Details. |
| Free Recovery Tool | A separate, free, open-source reader for your archives - no licence, and no dependence on this company existing. Details. |
| Restores are always free | No egress charge from us, no restore fee, no tier that has to be paid to read your own backup. Details. |
Keys and encryption
| End-to-end encryption | AES-256-GCM, applied on your machine before anything is uploaded. Details. |
|---|---|
| Your keys only | Keys are derived from your passphrase and never leave the machine. We cannot read your backups, and cannot help you if the passphrase and recovery phrase are both lost. Details. |
| Vendor-validated crypto | FIPS-validated providers per platform - CNG on Windows, CoreCrypto on macOS, AWS-LC on Linux. Details. |
| Keys sealed at rest | Stored in the operating system’s credential store, and zeroed from memory when no longer needed. Details. |
| Documented format | The on-disk format is published, so archives can be read from the specification rather than only by this app. Details. |
| No phone-home | Backups and restores need no contact with us. Licence checks are periodic and tolerate being offline. Details. |
Automation and operations
| Schedules | Manual, hourly, daily or weekly per set, run by a background service whether or not the app is open. Details. |
|---|---|
| Power and network guards | Skip scheduled runs on battery or on metered connections, so a laptop backup does not drain either. Details. |
| Retention policies | Keep daily, weekly and monthly snapshots for the periods you choose; storage no longer referenced is reclaimed. Details. |
| Hook scripts | Run your own script before a backup, after it, or when one fails - from an administrator-controlled directory, so configuring a backup is not a way to run code as SYSTEM. Details. |
| Desktop notifications | Every run reports what happened, including files that could not be read. Details. |
| Missed-backup alerts | Told when a set has not succeeded within a period you set. Details. |
| External dead man’s switch | Ping healthchecks.io, Cronitor or similar on each run, so a machine that has gone silent raises an alarm from outside itself. Details. |
| Rebuild from storage | Local state can be rebuilt from what is in the bucket, so a lost or reset machine is not a lost backup history. Details. |
Platforms and interfaces
| Windows, macOS, Linux | Windows 10/11 and Server, macOS on Apple silicon and Intel, and Linux on x86-64 and ARM64. Details. |
|---|---|
| Desktop app | A native application, with a system tray presence and a background service that runs without it. Details. |
| Terminal UI | A full-screen terminal interface for servers and headless machines. Details. |
| Command line | Scriptable CLI with JSON output and documented exit codes. Details. |
| 24 languages | The interface is translated into 24 languages. Details. |
| Machine seats | One licence covers several machines depending on edition; a seat can be released and reused. Details. |