RestoreDrill backup verification & audit evidence
Join the waitlist
Not launched yet · built in the open

A backup you have never restored is a rumor.

RestoreDrill pulls your real backups into a throwaway sandbox, restores them for real, checks that the data actually came back, then burns the sandbox down. You get a timestamped report your auditor will accept.

DRILL #0428 postgres-prod · restic → s3
Fetch snapshot
Boot isolated sandbox
Restore database
Verify integrity
Tear down sandbox
PASSED measured RTO 4m 12s 2026‑08‑25 03:00 UTC

Sample drill output. Every line is evidence — and the RTO is measured, not estimated.

The gap

Everyone checks that the backup job ran. Almost nobody checks that the data comes back.

Three failures that look identical from the outside — a green checkmark on last night’s job — right up until the day they don’t.

The most common audit finding

Teams can produce a backup policy. Very few can produce evidence that a restore was ever tested. A policy without test evidence is not an operating control — it is paperwork, and auditors treat it that way.

Silent corruption

The job exits 0 every night for eight months. The dump has been truncated since March, because a schema change broke one flag. Nobody notices until the restore that finally matters.

Your RTO is a guess

Someone wrote “4 hours” in the DR plan. Nobody has measured it. The real number is whatever it turns out to be, on the worst possible day, while customers wait.

How a drill runs

Four steps, on a schedule, on your own hardware.

Nothing about how you back up has to change. RestoreDrill only exercises what you already have.

01 Connect

Point the agent at backups you already produce — restic, kopia, borg, pg_dump, mysqldump, or a plain S3 bucket. Read-only credentials are enough.

02 Drill

On your schedule, the agent restores a real snapshot into a disposable sandbox on your own infrastructure. Your data never leaves your network, and production is never touched.

03 Verify

Row counts, table counts, file checksums, and a real health check against the restored service — not just “the archive extracted”. Then the sandbox is destroyed.

04 Evidence

A timestamped report: what was restored, what was verified, what failed, and the measured RTO. Export it for your auditor, or give them read-only access to the history.

Who this is for

People who will be asked to prove it.

Small SaaS teams in SOC 2 or ISO 27001

Restore testing is an explicit control. You need evidence on a schedule, not a screenshot from last quarter.

MSPs and agencies

You back up for twenty clients. Proving it per client, every month, is currently a manual afternoon.

Anyone self-hosting for real

No auditor, no compliance deadline — just no appetite for discovering the truth during an outage.

Provisional pricing

What we think it costs. Tell us where we are wrong.

Solo $9 per month
  • 1 backup target
  • Weekly drill
  • 90 days of history
  • Email alert on failure
Most teams Team $99 per month
  • 10 backup targets
  • Daily drills
  • Full history, exportable
  • Slack and webhook alerts
  • Custom verification scripts
Compliance $299 per month
  • Unlimited targets
  • SOC 2 & ISO 27001 evidence pack
  • Read-only auditor access
  • Signed, tamper-evident reports
  • RPO / RTO trend reporting

These numbers are a starting hypothesis, not a price list — there is nothing to buy yet. If a tier is priced wrong for the job it does, that is exactly the kind of thing we want to hear on the waitlist form.