Trust Center

Recovery trust should be inspectable

See the controls XReplicator implements, the infrastructure you retain control of, and the recovery work that still belongs in your operating process.

Transport security

TLS protects agent, backup server, and dashboard gRPC traffic. Optional mTLS adds client-certificate authentication.

Retention and immutability

Local immutable retention windows and object-storage retention controls reduce unauthorized deletion and overwrite risk.

Restore verification

Metadata, deterministic sample, and full checksum verification provide clearly labeled levels of restore-point assurance.

Recovery signals

Block-churn anomaly detection, last-known-clean suggestions, operation history, and audit events help teams investigate recovery choices.

Customer-controlled data

Deploy the backup server and repository in infrastructure you control, with local or supported object-storage targets.

Signed licensing

Signed license files remain the local trust anchor. Portal validation supports lifecycle enforcement without moving backup data into the marketing site.

Shared responsibility

Product controls do not replace recovery operations

01XMigrate provides

Product security controls, signed software and licensing, public configuration guidance, and documented verification modes.

02You control

Deployment access, identity, certificates, storage policies, encryption keys, network boundaries, monitoring, and recovery exercises.

03You should verify

Restore-point integrity, isolated recovery, application readiness, operator access, retention behavior, and incident runbooks.

Public technical evidence

Review exact settings, verification modes, object-storage controls, and operational caveats in the product documentation.

Read security and verification docs

Prove recovery in your environment

Run one verification and one isolated file restore with the free Community Edition before making a larger deployment decision.

Take the Restore Challenge

Evaluation questions

  • Can we deploy the repository inside our infrastructure boundary?
  • Can we require TLS or mTLS for product traffic?
  • Can we prevent routine deletion during the retention window?
  • Can we distinguish metadata, sample, and full verification evidence?
  • Can we recover to a safe isolated target?
  • Can another operator repeat the recovery from the recorded evidence?