Shared responsibility
Who owns what.
Backup-as-a-service is a partnership. We protect the backups; you control the source. This page draws the line — line by line — so vendor due diligence becomes a checklist, not a debate: use it during vendor reviews, security questionnaires, and internal audits. The split below is an illustrative guide; the binding commitments are those in our Terms of Service and DPA.
Responsibility matrix at a glance
| Area | You (Customer) | AlreadyBack |
|---|---|---|
| Connected Service | Secure the source, enforce MFA | Protect and verify every backup |
| Identity & access | Manage who has access | Run auth; restrict and log admin |
| Encryption & keys | Choose managed or BYOK | Encrypt every backup; guard keys |
| Backup integrity | Review Fire Drill reports | Verify every job; dry-run monthly |
| Data residency | Choose your region | Keep backups in that region |
| Recovery | Test your restore flow | Keep it restorable and verified |
| Retention & deletion | Set the policy | Apply it; confirm deletion |
| Continuity & incidents | Define RTO/RPO; notify us | Keep the platform up; investigate and communicate |
Responsibility split by category
Need this in your vendor questionnaire?
Every row links to the control or contract clause that formalizes it. Send us the one your security team flagged and we’ll go deeper. Our DPA is available to read in full.
Security contact
security@alreadyback.comFor security documentation or vendor due diligence under NDA.