Skip to content

Status and roadmap

Restow is in beta; 0.1.0 is the first public release. This page states plainly what exists today and what does not, instead of leaving it implied.

  • First-run setup wizard: operating mode, public URL, first administrator (passkey-first, emergency password with mandatory TOTP as fallback), notification mail transport (SMTP or Microsoft Graph sendMail) with a test send.
  • Sign-in with passkeys once the installation is verifiably reachable over HTTPS, an emergency email-and-password path with a mandatory authenticator app, and per-user account management (passkeys, authenticator, sessions). Signing in with a Microsoft 365 account directly is built but not yet enabled for end users.
  • Multi-tenancy with PostgreSQL Row Level Security isolating every tenant’s data.
  • Microsoft 365 sources via the Entra admin-consent flow, with an explicit permission check; the app registration itself is entered and tested under Settings → Microsoft 365, no .env editing required.
  • Protection scope per source: everyone in the directory, one group, or individually selected objects, with bulk include/exclude/“follow the rules again” actions. Connecting a source queues its first directory sync immediately, and a newly protected object’s first backup queues automatically instead of waiting for a schedule.
  • IMAP sources (password-authenticated; one login per source, applied to every mailbox under it). OAuth2 sign-in for IMAP sources comes in a later release.
  • Backup for Exchange Online (mail, calendar, contacts), OneDrive, and IMAP mailboxes, deduplicated and encrypted.
  • Restore, non-destructive by default (recovered items are written alongside what is already there); there is no mode that overwrites. Automated weekly restore verification (a sampled read-back, not yet a full test restore).
  • Configurable storage targets.
  • Archive, in every edition: Graph and IMAP archive sync into an append-only store with a SHA-256 hash chain and chain verification, and full-text search. Business and Service Provider add the layer built for German GoBD requirements: Exchange Online journal receipt over SMTP, retention policies with an enforced deletion run, and legal hold. See Archiving.
  • The integration REST API.
  • Team with roles (Business and above): several administrators as owner, administrator, technician or read only, with every tenant or chosen ones. See Team and roles.
  • Alerts and reports: alerts by e-mail, in the bell and by webhook when a backup fails, a restore check does not pass or storage is damaged, with a delivery log. See Alerts and reports.
  • Scheduled reports (Business and above): daily, weekly or monthly summaries by e-mail. See Alerts and reports.
  • Endpoint backup for servers and clients (every edition): an agent for Linux and macOS backs files up with restic into the tenant’s storage. It is append-only (it can add backups but never delete one), with retention, repository checks and restore tests on the server that feed recovery readiness. See Endpoint backup.
  • Mail file import and export (every edition): EML, MSG, MBOX, ZIP and MailStore exports become an imported mailbox that you can browse, restore, download and optionally archive. Mail can be exported as EML in a ZIP or as MBOX. See Mail file import and export.
  • Updates: an update check that is off until an administrator turns it on, and an optional updater (opt-in, it mounts the Docker socket) that announces maintenance, dumps the database first and rolls back when the new version does not start. See Updates.
  • Failure explanations: every failed job, item, sync and verification says what happened, why and what to do. See Failure explanations.
  • Operator notice: the first step of the setup wizard, accepted before anything else. See Operator notice.
  • Restore explorer timeline: a slim timeline of restore points at the bottom of the explorer, the newest one centred. A folder without subfolders says so.
  • Signed release images for amd64 and arm64 with an SBOM, and a release smoke run before every release is published. See Verifying a release.
  • Editions layout: the Business and Service Provider features live under ee/ in the same repository, image and release. Contributions need the CLA and a DCO sign-off, both checked automatically on pull requests. See License and editions.

Backup and restore have been tested against simulated Microsoft Graph and IMAP servers; testing against a live Microsoft 365 tenant is ongoing, not yet complete. Every release runs a smoke test before it is published: a fresh install, health checks, passkey sign-in, IMAP backup and restore with a hash comparison, journal receipt and chain check, a restore without the server, several storage targets, a vulnerability scan, endpoint backup and restore, and mail import and export. Its Microsoft 365 check runs only when credentials for a development tenant are configured, and it has not been run against a real tenant yet.

  • Google Workspace backup: Gmail and Google Drive, alongside Microsoft 365 and IMAP. Not available yet.
  • Audit log (Business and above): tamper-evident and hash-chained, exportable as CSV and PDF. Recording already runs in every edition (every read and restore is written to the log); the viewer is what is in development. See Audit log.
  • Archive evidence: auditor export with a manifest and checksums, a signed evidence report, and Object Lock (WORM) as the default archive target. See Archiving.
  • Self-service archive search: end users searching their own long-term mail history (for example, everything older than 365 days, 2 years, or 10 years) and restoring or downloading what they find. Builds on the archive; see Usage.
  • Replace for OneDrive files is planned for a later release: an optional restore mode in which the current file becomes an earlier version in OneDrive’s own version history instead of being deleted. Mail, calendar and contacts will never be overwritten.
  • OAuth2 for IMAP sources is planned for a later release, not in development yet.
  • Microsoft sign-in for end users: end users signing in directly with their Microsoft 365 account, without a Restow passkey or password. See Get started as an end user.

Decided, not started. No dates.

  • Windows agent for endpoint backup. The web interface shows Windows as “Planned” today.
  • PST and OST import. The files are recognised and refused with an explanation. Until then, export from Outlook as MSG or EML, or convert to MBOX.
  • PST export and MSG export of mail. Export as EML in a ZIP and as MBOX is available.
  • Agent mTLS and filesystem snapshots (LVM, ZFS, btrfs) for endpoint backup. Today each agent authenticates with its own secret over HTTPS, and consistency comes from optional pre and post commands.
  • Proxmox VE via Proxmox Backup Server (PBS).
  • SFTP as a storage target.

These are deliberate scope decisions, not oversights: Microsoft Teams and SharePoint, Public Folders, e-discovery case management, a mobile app, and disk images or bare-metal restore of servers and clients (endpoint backup is file-based by design). Server and client backup on Linux and macOS is no longer on this list: it ships with 0.1.0 (see Shipped). PST import is not on it either: it is planned (see Planned). Some of these are planned for after v1; none of them are silently “coming soon” without a stated plan.

Community is the AGPL-3.0 core: backup, restore and the archive (Microsoft 365 and IMAP sync, hash chain, full-text search), endpoint backup for servers and clients, mail file import and export, failure explanations and the opt-in update check, with a basic operations log (job history, errors). Every read and restore is recorded in the audit log in every edition. Restore is never limited by edition or mailbox count. Business adds the archive’s layer built for German GoBD requirements (journal receipt, enforced retention, legal hold; available since 0.1.0), plus the audit log viewer with CSV and PDF export, single sign-on, four-eyes approval and a signed restore report (in development), and several administrators with roles (available since 0.1.0). Service Provider adds multiple tenants and the cross-tenant API (available today); delegated administrators, tenant reporting and white label are planned. The Business and Service Provider features live under ee/ in the same repository and image and are unlocked by a license key. Business and Service Provider are sold now at a pre-sale price until general release; see pricing on restowbackup.com and License and editions. A live demo with synthetic data runs at demo.restowbackup.com.