Backup and recovery for MSPs · Coming soon

Set up backups once. Stop worrying about them.

MoorNest backs up your clients' file servers and Hyper-V hosts every night on its own, tells you only when something needs you, and restores any night in a few clicks. Everything is encrypted before it leaves the server.

  • Automatic, every night
  • Restore any night in one step
  • End-to-end encrypted
  • Ransomware-protected
Tonight · FS0102:00 · example
  • accounts.dbchanged
your NAS
or S3
Read 1 of 5 filesSent 1 of 6 blocksRestore point complete

Ticked blocks are already stored, so they stay put.

How it works

Set up in three easy steps.

No VPN and no firewall changes at the client's site. Most servers are protected in one sitting.

  1. 1

    Add a server in the console

    Click Add server and copy the one-time code. Nothing to set up on the client's network.

  2. 2

    Run the agent on the server

    One signed program. Enter the code and it installs itself as a service and connects out to MoorNest.

  3. 3

    Backups run on their own

    Pick folders or Hyper-V VMs and a schedule. Each night keeps a fast local copy on the client's NAS and a second copy in MoorNest Cloud, encrypted all the way.

TLS 1.3 encrypted, secure only encrypted blocks leave 3 · MoorNest Cloud2nd copy · offsite ✓ Backup complete Servers Add a server Run the agent, then enter this code K7QF-2M9D 1 · Your console code $ moornest-agent install Code: K7QF-2M9D ✓ Installed as a service ✓ Connected (outbound only) ✓ Protecting D:\Shares 2 · Client's server LAN Local NAS 1st copy · fast local restores

In 60 seconds

See a server protected, start to finish.

Install the agent, two copies every night, end-to-end encryption and ransomware protection.

Watch the setup video · 1:00

Two copies, every night

A fast local copy, and a second copy offsite.

One plan writes both. Restore quickly from the client's own NAS, and keep a copy away from the building in case the worst happens.

Local NAS

Restores at LAN speed from a NAS or disk at the client's site, through a MoorNest gateway.

MoorNest Cloud

A second copy outside the building, encrypted and locked.

Your own S3

Prefer your own bucket? Use S3 storage with Object Lock.

Restores

Restore any night in one step.

Every backup is a complete restore point. There's no chain of incrementals to replay, so a restore is one choice: which night.

Files and folders

Browse any night and pick a file, a folder or everything. Files come back with their permissions.

Hyper-V VMs

A VM comes back as a new, disconnected VM, so the original is never touched.

Every night stands alone

Losing one backup never breaks the others.

Protected by a second factor

Restores need your password and an authenticator code.

Less data, less network

Only what changed leaves the server.

Both start with the same full copy. After that, a traditional schedule sends another full copy every week. MoorNest sends only what changed.

8.48 TBtraditional: 4 fulls + 24 incrementals
2.54 TBMoorNest: 1 full + 27 nights of changes
~12×less data over a year

Illustration, not a measurement: a 2 TB server with about 1% of its data changing each night.

In 60 seconds

Backups, redesigned from scratch.

How a traditional schedule works, what MoorNest does instead, and what it saves.

Watch the 60-second explainer · 1:03

Security

Encrypted at the source. Encrypted all the way.

Every block is encrypted on the client's server before it moves, and stays encrypted through the gateway, across the network and in storage.

CLIENT'S SITE MOORNEST CLOUD YOUR TEAM agent control · TLS · outbound only gateway tunnelTLS 1.3 · outbound verifies every backup encrypted blockspinned TLS encrypted blocks · TLS · end to end Customer serverMoorNest agent encrypted at source · AES-256-GCM Gatewayoptional, for a NAS NAS or local diskat the client's site encrypted at rest Console & portaljobs, status, alerts 2FA · Argon2id sign-in Cloud storageS3 with Object Lock encrypted at rest Techniciansany browser HTTPS · TLS · 2FA Backup data, encrypted at source Control channel, outbound only TLS on every channel Encrypted at rest
  • Encrypted at sourceEach block is sealed with AES-256-GCM under a fresh key on the server, before it is sent.
  • Encrypted in transitEvery channel runs over TLS: 1.3 for gateway tunnels, never below 1.2.
  • Encrypted at restThe NAS and MoorNest Cloud only ever hold encrypted blocks. Object Lock stops early deletes on S3.
  • Outbound onlyAgents and gateways connect out. Nothing to open on the client's firewall, no VPN.

Built on standard, proven cryptography

No home-made crypto. These are the names you can check.

  • TLS 1.3Every connection encrypted in transit; TLS 1.2 is the minimum anywhere
  • AES-256-GCMEach block sealed under its own fresh key
  • X25519Key exchange for every object's key
  • HMAC-SHA-256Keyed block names, so contents can't be guessed
  • S3 Object LockCompliance mode: no early delete or change
  • AWS KMSManaged keys wrapped by a key service, never stored in the clear
  • Code signingAuthenticode on Windows, Ed25519 on Linux
  • Argon2idPasswords stored with a memory-hard hash
  • TOTP 2FAAuthenticator codes for sign-in and restores

Ransomware protection

A hacked server can't touch your backups.

The agent on each server can only add new backups. If ransomware takes over the server, the backups you already have stay out of its reach.

Write-only agent

The agent can add new backups, but can't read, change or delete the ones already stored.

Write-once storage

Nothing is overwritten, and on S3 Object Lock blocks deletion.

Restores from the console only

Restores start in the console with your password and an authenticator code, never from the server.

Clean recovery

Restore a night from before the attack.

Alerts and live status

You'll know when a backup needs you.

No daily report to read through. MoorNest tells you when something is wrong, and shows you what's happening right now.

Email alerts

An email when a backup fails or misses its schedule, and another when it's fixed.

Live status

Every server and backup in one view, with percent done, speed and time left.

Clear next steps

Each problem says in plain words what to do next.

Built for MSPs

All your clients in one console.

Look after every client from one place, with each one kept apart.

Separate workspaces

Each client has its own workspace and its own storage.

Team access

Your team signs in once and sees only what it's allowed to.

Agent updates

Update one server, one client or all at once. A failed update rolls itself back.

Questions

Questions MSPs ask first.

Is it a full backup or an incremental?

  • After the first full copy, only changed data is sent each night.
  • Every night is a complete restore point you can restore on its own.
  • Every backup is checked before it counts as a restore point.

Do I still need a weekly full?

  • No. MoorNest takes one full copy at the start.
  • Once a week it re-reads all files to catch missed changes, and still sends only what changed.

What if a client's server gets ransomware?

  • The agent can only add new backups. It can't read, change or delete the ones you already have.
  • Restores start only from the console, never from the server.
  • You restore a clean night from before the attack.

Where is the data stored?

  • On a NAS or disk at the client's site, through a MoorNest gateway.
  • In your own S3 bucket, with Object Lock.
  • In MoorNest Cloud.

What can it back up?

  • Windows file servers, including open files and permissions.
  • Hyper-V virtual machines.
  • Files on Linux servers.

How much does it cost?

  • Pricing will be published at launch.
  • Everyone on the waiting list gets early pricing.

Waiting list

Don't miss it. Join the waiting list.

We're opening MoorNest to MSPs in small groups. Add your name and we'll tell you as soon as there's a place for you.

  • Be first to know when MoorNest opens
  • Get set up with help from the team that builds it
  • Early pricing for everyone on the list

We use these details only to tell you about MoorNest. Privacy notice

Look