Security & governance

Built for environments where backups get audited

Banks and regulated organisations need more than a copy of the data. They need to know it’s complete, untouched and stored where it should be, and they need to prove it. Here is every control Zigguard has today.

Data stays with you

On-premise by design

Zigguard runs entirely on your Windows servers. Backups, logs and the audit trail never leave your network.

No phone-home

Licences are activated offline with a Request Code. The software never contacts ByteTIQ or anyone else.

Signed, machine-bound licences

Licence files are ECDSA-signed and bound to the machine, so they can’t be forged or reused on another machine.

Secrets and access

DPAPI-encrypted passwords

Database passwords are encrypted with Windows DPAPI. They are never passed on a command line and never written to logs.

Locked-down configuration

Configuration files are readable only by Administrators and SYSTEM.

Restricted local channel

The Manager talks to the agent over a local named pipe limited to Administrators and SYSTEM, after checking the agent’s identity.

Integrity of every backup

Atomic writes

Backups are written as .partial and renamed only once complete. There are no half-written “good” files.

Verification on every run

Each backup is verified with a pg_restore check (or plain-SQL markers). A run only succeeds after verification.

SHA-256 checksums

Every backup and every second copy is checksummed and re-checked.

Tool integrity checks

The bundled PostgreSQL tools are checked against a SHA-256 manifest before every run, blocking tampered or planted DLLs.

Evidence and audit

Tamper-evident audit trail

A hash chain links every run record. “Verify audit trail” reports the first broken record.

Complete run logs

Every run has a full log, plus a service log and Windows Event Log entries for your SIEM.

History and CSV export

Filter run history and export it to CSV for audit packs.

Retention safety

Never deletes the newest verified backup or files Zigguard didn’t create. A clock-safety guard blocks mass deletion when the system date is wrong.

What you can hand to an auditor

  • Run history with result, duration, size and checksum, exported to CSV
  • Full logs for every run
  • Windows Event Log entries
  • A “Verify audit trail” result showing the chain is intact
  • Proof that each backup was verified before it was accepted

A note on certifications

Zigguard is not certified under ISO 27001, SOC 2, PCI DSS or any central-bank regulation, and we don’t claim compliance. It provides technical controls and evidence that support your own compliance programme.

Security features on the roadmap

  • Coming soon Backup encryption at rest
  • Coming soon SSO / LDAP sign-in for the Manager
  • Coming soon Compliance reports
  • Coming soon Code-signed installers

Ready to prove your backups?

Get a lifetime licence for US$150 per server, or ask ByteTIQ for a quote for your organisation.