Docs menu

Back up

Storage: MoorNest Cloud and NAS

Every backup plan sends its backups to one storage destination. This page explains the destinations you can use, how the data is protected there, and how to keep a fast local copy and an offsite copy of the same server.

The destinations

DestinationWhere it isSet up with
MoorNest CloudStorage managed by MoorNest, outside the client's building.Nothing to set up. It is listed as Managed by MoorNest.
NAS at the client siteA NAS or disk at the client's site, reached through a site gateway. Restores run at local network speed.Set up a site gateway.
Your own S3 bucketAn S3 bucket with versioning and Object Lock.Settings > Storage > Add storage > Cloud storage (S3), after we set up a cloud connection for your workspace.

Whether a destination is available can depend on your subscription. If the console says a kind of storage is not included, contact us at admin@devsmooth.com.

Check your storage

Settings > Storage lists every destination in the workspace:

  • Space: used and total space. For a disk or NAS this is the whole volume, not only MoorNest's share of it.
  • Deletion lock: how many days each backup is locked against deletion, or None.
  • Status: Working, Online (a site gateway that is connected), Almost full (more than 85% used), Refusing backups, Offline or Not measured.

Administrators can click Test on a destination they added to check that it answers. The Storage panel on Home shows the same status at a glance.

Encryption

  • The agent encrypts every block on the server before it is sent. Each block is sealed with AES-256-GCM under its own fresh key, so storage only ever holds encrypted blocks.
  • Each block's key is wrapped with a public key, so the agent can encrypt but cannot decrypt. For MoorNest Cloud the matching private key is held in AWS KMS and cannot be exported.
  • Blocks are named with a keyed HMAC-SHA-256, so a block's name says nothing about what is in it.
  • Every connection uses TLS. When an agent sends backups to a NAS through a site gateway, it checks the gateway's pinned certificate.

See Security for more detail.

Deletion locks

MoorNest Cloud uses S3 Object Lock in compliance mode: until a backup's lock ends, nobody can delete it or shorten how long it is kept, including us. On your own S3 bucket, each backup is locked for the number of days you set when you connect it. The Deletion lock column under Settings > Storage shows each destination's lock, and the Restore points tab on a server shows Locked until and the date for each locked backup.

A NAS or disk is not locked this way. Keep another copy somewhere else.

Keep two copies

One plan writes to one destination. To keep a fast local copy on the client's NAS and a second copy offsite, set up two plans for the same folder or VM:

  1. Set up the first plan with the NAS (through its site gateway) under Where to keep it.
  2. On the server page, click Add backup plan, pick the same folders or VMs, and choose MoorNest Cloud (or your S3 bucket).

Each plan reads the server and sends its own backup, and each destination has its own keys and its own copy of every block, so damage at one destination does not reach the other. MoorNest does not copy backups from the NAS to the cloud; the server writes to each destination itself.

Each server runs one job at a time. If both plans are due at the same time, the second starts when the first finishes, and that does not count as a missed backup.

Space and the safety reserve

Every backup is kept, and automatic clean-up of old backups is not available yet, so used space only grows. Plan for that when you size a NAS.

Each destination keeps a safety reserve of free space. Backups stop when free space drops below it, and the console raises a storage issue as it gets close. Free up space or add capacity.

Connect your own S3 bucket

You can connect an S3 bucket once we have set up a cloud connection for your workspace. Without one, Add storage says No cloud connection yet.

  1. Go to Settings > Storage and click Add storage.
  2. Choose Cloud storage (S3) and click Continue.
  3. Fill in Name in MoorNest, pick the Cloud connection, and choose Connect an existing locked bucket or Create a new locked bucket.
  4. Enter the Bucket name. When creating one, type it again to confirm.
  5. Set Lock each backup against deletion for (days): 1 to 3,650, default 30.
  6. Click Continue and confirm with your password and a fresh code.

The bucket must have versioning and Object Lock. MoorNest checks this before saving. If the setup is interrupted, Storage setup history lets you Resume the same setup; do not start a second one.

Last updated 4 October 2026.

Look