Docs menu

Get started

How MoorNest works

MoorNest has three parts: an agent on each server you protect, the console you use in a browser, and the storage that holds the backups. This page explains how they fit together and what happens during a backup, so the rest of the docs make sense.

The parts

The agent

The MoorNest agent is one program that runs as a service on each server. There is one download for 64-bit Windows and Windows Server, and one for 64-bit Linux with systemd.

  • It connects out to MoorNest over HTTPS. Nothing needs to be opened in the client's firewall, and there is no VPN.
  • It runs as LocalSystem on Windows and as root on Linux, so it can read any folder you pick and use Windows snapshots and Hyper-V.
  • It encrypts every block on the server before anything is sent. It can add new backups, but it cannot read, change or delete the backups already stored.
  • It never receives storage passwords or the keys that unlock old backups.

See Add a server to install it.

The console

The console at https://app.moornest.com/ is where you add servers, choose what to back up, watch backups run, read alerts and start restores. It shows live status and updates every few seconds while the page is open.

Each workspace in the console is separate: its servers, storage, backups and people cannot be reached from another workspace. See Clients and team.

Storage

A backup plan sends its backups to one storage destination:

  • MoorNest Cloud: storage managed by MoorNest, outside the client's building.
  • A NAS at the client site: reached through a site gateway, a small MoorNest service on a machine next to the NAS. See Set up a site gateway.
  • Your own S3 bucket: S3 storage with versioning and Object Lock, connected under Settings > Storage.

Storage only ever holds encrypted blocks. To keep two copies, for example a fast local copy on the NAS and a second copy in MoorNest Cloud, you add one plan for each destination. See Storage: MoorNest Cloud and NAS.

How a backup runs

The schedule

Each backup plan has a schedule. The default is Once a day at 22:00 on the server's own clock. You can also choose Every hour, Every 6 hours or Only when I start it, and change the time. Each server runs one job at a time, so if two plans are due together, the second starts when the first finishes.

The first backup and the nights after it

The first backup of a plan copies everything. After that, MoorNest works like this:

  1. For each file, the agent compares its size, modified time and file ID with the last checked backup. Files that match are not read again; the new backup reuses their blocks.
  2. Changed files are read and cut into blocks.
  3. Only blocks the storage does not already have are encrypted and sent.

Every backup is still a complete restore point. There is no chain of incrementals to replay, so a restore reads one night and nothing else, and losing one backup never breaks the others.

For Hyper-V VMs, each backup reads the whole VM.

The weekly full re-read

A program can change a file and keep its old size and modified time, so a quick check could miss the change. To catch that, each file plan re-reads and checks every file on a regular cycle: every 7 days by default. A full re-read takes longer on the server, but it still sends only blocks the storage does not have. You can change the cycle under More options > Read everything again on the plan, or click Re-read all next time on a plan to force one on its next backup.

Checks: every backup is read back

A backup only counts once MoorNest has checked it. Right after each backup finishes, MoorNest reads it back in full. Restore points that passed show as Readable; ones not checked yet show as Not checked.

MoorNest also re-checks kept backups on a cycle, every 7 days by default (More options > Check backups can be restored). Re-checks run when nothing else is running. On cloud storage, re-reading backups can cost storage fees.

How long backups are kept

Every backup is kept. Automatic clean-up of old backups is not available yet, so nothing is ever deleted by MoorNest. On storage with a deletion lock, each backup also cannot be deleted by anyone until its lock ends. The Deletion lock column under Settings > Storage shows each destination's lock period.

Restores

Restores start only in the console. Starting one needs an administrator account, its password and a fresh authenticator code, and the server receiving the data must have restores allowed. Files are restored to a new folder and never overwrite the originals; a Hyper-V VM comes back as a new VM, switched off and not connected to any network. See Restore files and folders and Restore a Hyper-V VM.

When something goes wrong

MoorNest tells you when a backup fails, when a scheduled backup does not run and when a problem clears. Each problem says in plain words what happened and what to do next. See Alerts and status and Troubleshooting.

Last updated 4 October 2026.

Look