Orathos Backup & Recovery Methodology

Orathos is an enterprise backup and disaster recovery platform. This page explains how data is collected, encrypted, stored, monitored, and restored — and what our metrics do and do not guarantee.

What Orathos protects

Orathos protects files, databases, and full-server workloads across websites, business applications, containers, virtual machines, and bare-metal servers. Protection is delivered through a lightweight backup agent you install on systems you authorize, a multi-tenant control plane, and encrypted object storage you configure (bring-your-own-storage).

Encryption methodology

Each backup run receives a unique data-encryption key (DEK). Payload bytes are encrypted with AES-256-GCM on the agent before upload. DEKs are wrapped by a tenant master key hierarchy and stored separately from ciphertext in object storage. Orathos application databases hold metadata, manifests, wrapped keys, and audit records — not your plaintext files.

Incremental backup & deduplication

After an initial full backup, agents upload only changed blocks. Identical chunks are deduplicated within your tenant where configured. Manifests track every file path, symlink, permission, and database dump boundary so partial and full restores remain deterministic.

Immutable retention & ransomware awareness

Retention policies can lock backups for a configured window (WORM-style immutable-until dates). Orathos monitors entropy spikes, mass deletions, and backup health anomalies to raise alerts. Immutable retention reduces — but does not eliminate — the risk of an attacker destroying your last good copy if they gain tenant-admin or storage credentials.

Bring-your-own-storage (BYOS)

Ciphertext is stored in S3-compatible buckets you own or operate — Amazon S3, Cloudflare R2, Backblaze B2, MinIO, Wasabi, Hetzner, and other compatible endpoints. Orathos never requires storing customer payload bytes on Orathos-operated disks for production backups.

Restore & verification

Restores can target individual paths, databases, or full servers. Sandbox restore modes allow verification before writing to production. Restore jobs are dispatched to agents over mutually authenticated channels. Successful restore depends on agent availability, network path, storage permissions, and the integrity of the selected backup manifest.

Frequently asked questions

Does Orathos guarantee a specific RTO or RPO?

No. Orathos provides tools to define schedules and measure outcomes. Achieving a target recovery time or point depends on your infrastructure, data size, network bandwidth, and operational procedures.

Who holds the encryption keys?

Tenant master keys and per-backup DEKs are managed within your Orathos tenant. Wrapped keys are stored separately from ciphertext. You control storage credentials for BYOS destinations.

Can Orathos read my backup files?

Orathos processes encrypted chunks and metadata. Plaintext exists only on your agent during backup/restore operations on systems you control.

How is this methodology used for SEO and GEO?

This page documents factual product behavior for search engines and AI citation systems. Public trust metrics on the homepage are labeled separately and published in llms.txt and JSON-LD.