L lionbackup CLOUD
SIGN UP LOGIN

Cloud data protection

Two different problems share the name: keeping data lawful, and keeping it recoverable. A backup has to answer both.

Two meanings, one requirement

In European usage, data protection is the legal discipline: lawful basis, purpose limitation, processor contracts, data subject rights. In security usage it is the technical one: confidentiality, integrity, availability. A backup is one of the few systems that has to satisfy both at once — it holds a complete copy of everything sensitive you own, and it is the last thing standing between an incident and a total loss.

Which is why the answer here is architectural rather than contractual. Data is encrypted on your machine before it is transmitted, with keys that never reach us. We store ciphertext. That single property settles most of the legal questions — there is no meaningful transfer of personal data to a party that cannot read it — and it settles the confidentiality requirement at the same time.

The controls, concretely

Client-side encryption

Encrypted before upload, keys held by you. The provider cannot read the data and cannot be compelled to produce it in readable form.

Immutability during retention

No overwrite, no early delete, by anyone — the property that makes a backup survive the credentials the attacker already has.

European residency

European data centres, European providers, the zone of your choosing. Not "an EU region" of a non-EU company.

Least privilege

Separate write and read tokens per project, granular roles, and revocation that takes effect immediately.

Complete audit log

Every access and every administrative change is recorded and visible in the portal — the raw material for an audit.

Auditable client

The client is open source. Encryption you can read is a guarantee; encryption you cannot is a promise. See security.

Where backup sits in cloud security

Worth being precise about, because the market is not. Cloud security covers identity, network controls, workload and application security, posture management, detection and response — and recovery. lionbackup is the recovery control: it does not scan your applications, filter your traffic or manage your identities, and any vendor telling you one product covers all of it is selling you something.

What recovery contributes is the floor. Prevention and detection change how often an incident happens; the backup decides what it costs when prevention has already failed — which, given enough time, it does. That is why restorability appears as an explicit requirement in Article 32 of the GDPR, in ISO 27001, and in NIS2: not as an afterthought to security, but as the part of it that still works after everything else has been bypassed.

Evidence you can hand an auditor

Claims are cheap; documents are not. What you get: a data processing agreement under Article 28, written technical and organisational measures under Article 32, named locations and providers for every storage zone, defined retention and deletion behaviour, and an audit log that shows who accessed what and when. The German-language legal documents are binding and available at AVV, TOMs and Compliance.

Start free · Cloud backup services · Security architecture

Frequently asked questions

What are cloud data protection solutions?

Tools and controls that keep data confidential, available and recoverable while it lives in or moves through cloud services. In practice that means encryption with customer-held keys, access control and logging, a defined location and legal basis for the data, and a recoverable copy that an incident cannot reach.

Is backup part of cloud security?

Yes — it is the recovery control. Prevention and detection reduce how often you are breached; backup determines what a breach costs once prevention has failed. Under a framework such as NIS2, ISO 27001 or the GDPR's Article 32, restorability is an explicit requirement, not a nice-to-have.

Does GDPR allow backups with a US cloud provider?

It is not forbidden, but it puts the burden of proof on you: a transfer mechanism, a transfer impact assessment, and an answer to lawful-access powers that reach data held by US companies wherever it is stored. Encrypting client-side with keys the provider never sees, and keeping the data with European providers, removes the question instead of documenting it.

What evidence do we get for an audit?

A data processing agreement under Article 28, documented technical and organisational measures under Article 32, named data centre locations and providers, and an audit log in the portal that records every access and every administrative change.