Skip to content
Back to Security

Shared responsibility

Who owns what.

Backup-as-a-service is a partnership. We protect the backups; you control the source. This page draws the line — line by line — so vendor due diligence becomes a checklist, not a debate: use it during vendor reviews, security questionnaires, and internal audits. The split below is an illustrative guide; the binding commitments are those in our Terms of Service and DPA.

Responsibility matrix at a glance

Summary of who is responsible for what — you or AlreadyBack
AreaYou (Customer)AlreadyBack
Connected ServiceSecure the source, enforce MFAProtect and verify every backup
Identity & accessManage who has accessRun auth; restrict and log admin
Encryption & keysChoose managed or BYOKEncrypt every backup; guard keys
Backup integrityReview Fire Drill reportsVerify every job; dry-run monthly
Data residencyChoose your regionKeep backups in that region
RecoveryTest your restore flowKeep it restorable and verified
Retention & deletionSet the policyApply it; confirm deletion
Continuity & incidentsDefine RTO/RPO; notify usKeep the platform up; investigate and communicate

Responsibility split by category

Connected Service security

We protect the backups, not the source. Anything that compromises your Connected Service upstream — Airtable is our first supported one — propagates to any snapshot taken after the compromise. The same split applies to every Connected Service we add.

You (Customer)
  • Enforce MFA on every user of the Connected Service (for example, your Airtable workspace).
  • Apply least-privilege at workspace, base, and access-token level.
  • Rotate access tokens and OAuth grants on a defined cadence.
  • Notify us within 24 hours of an account compromise so we can pause backups.
AlreadyBack
  • Let you pause backups from the dashboard the moment you suspect a problem.
  • Restore to any earlier snapshot — from before the compromise.
  • Keep every snapshot verifiable, so you can trust the one you roll back to.

Identity and access on AlreadyBack

Login, sessions, roles, and admin actions inside the dashboard. Authentication is shared; authorization is yours to configure.

You (Customer)
  • Decide which teammates need access, and at what role.
  • Connect single sign-on with your identity provider (included with Resilience).
  • Revoke access when staff leave; review the team list periodically.
AlreadyBack
  • Run authentication with brute-force protection and session security.
  • Require multi-factor authentication on privileged internal accounts.
  • Restrict and log administrative access to your account.
  • Provide single sign-on for your identity provider.

Encryption and key management

Backups are always encrypted. Key custody — whether you or we hold the key — determines who can decrypt them, so who holds it is your call.

You (Customer)
  • Choose managed keys, or bring your own (BYOK) on Resilience.
  • If you bring your own key: keep it safe, and rotate it on your schedule.
  • Tell us if a customer-held key must be rotated or revoked.
AlreadyBack
  • Encrypt every backup at rest with AES-256-GCM and every byte in transit with TLS 1.3.
  • Default to managed envelope encryption; offer customer-held keys (BYOK) on Resilience.
  • Never log, cache, or persist plaintext keys server-side.

Backup integrity and verification

Every backup is verified recoverable — checked on every job and fully dry-run monthly by our Fire Drill. You decide when and how to test it in your own context.

You (Customer)
  • Review your monthly Fire Drill report.
  • Validate on your own bases that restored data matches business expectations.
  • Tell us within 7 days if a restore looks wrong so we can investigate the snapshot pipeline.
AlreadyBack
  • Verify on every Fire Drill that a full restore brings records, relationships, and computed fields back intact.
  • Run cryptographic checksums on every snapshot, verified before retention is granted.
  • Publish a written Fire Drill report after each test — evidence you can present in your own DR testing, vendor due diligence, or insurance review.

Storage region and data residency

You pick the region; we keep your backups there.

You (Customer)
  • Pick the region that matches your obligations — United States or European Union.
  • Choose it at onboarding; it applies to every backup.
  • Review the DPA and the public sub-processor list before onboarding.
AlreadyBack
  • Store your backups in the region you choose — United States or European Union.
  • Keep every backup in that region; we don’t move it across borders.
  • Maintain a public sub-processor list with 30 days’ notice before any change.

Recovery

A backup is only as good as the recovery. We make sure the one you need is there, verified, and ready to restore.

You (Customer)
  • Decide your recovery expectations and pick the plan that fits.
  • Run a test restore periodically so your team knows the flow.
  • Keep an internal runbook for your recovery process.
AlreadyBack
  • Keep your latest backup restorable at all times, verified monthly by Fire Drill.
  • Offer full and granular restore — down to the record — with a verification report on every run.
  • Put guarded recovery one flow away in the dashboard — preview, typed confirm, restore.

Data retention and deletion

Your data has a defined lifecycle. You start the timer; we honor it.

You (Customer)
  • Configure the retention window appropriate to your legal obligations.
  • Delete bases or whole tenants from the dashboard when they no longer need protection.
  • Submit a verified deletion request via the DPA process for a full account purge.
AlreadyBack
  • Apply your plan’s retention to every snapshot; expire them automatically on schedule.
  • Honor verified deletion requests within 30 days.
  • On BYOK plans, revoking your key cryptographically renders the corresponding backups permanently unrecoverable — an instant erasure you control.
  • Provide written confirmation of deletion for your records.

Business continuity and incident response

Resilience is shared. You set the recovery expectations your business needs; we keep the platform and the restore path available, and lead the response when something goes wrong.

You (Customer)
  • Define the recovery-time and recovery-point objectives your business requires.
  • Keep an internal continuity runbook and test your own procedures periodically.
  • Notify us promptly of a suspected security incident affecting your data.
AlreadyBack
  • Keep the platform and your restore path available, under continuous monitoring.
  • Investigate confirmed incidents and keep you informed throughout.
  • Notify you of a personal-data breach within 24 hours of confirming it, per the DPA.
  • Verify restorations and share the evidence for your DR and insurance reviews.

Need this in your vendor questionnaire?

Every row links to the control or contract clause that formalizes it. Send us the one your security team flagged and we’ll go deeper. Our DPA is available to read in full.

Security contact
security@alreadyback.com

For security documentation or vendor due diligence under NDA.