Sikurd's managed backups are captured, stored encrypted offsite, restore-tested on isolated hardware, and certified. PASS or FAIL, in writing, with a hash chain behind it.
A backup is a hypothesis
Every MSP has a backup story. Very few have a restore story, because restore testing is manual, slow, and nobody bills for it. So the industry runs on green checkmarks that mean "a file was written," not "this customer's phone system can come back." The gap between those two sentences is where the worst week of your year lives.
Sikurd closes the gap by making restore testing a scheduled, automated part of the backup itself. If a capture cannot actually be restored, you find out from a FAIL certificate on a quiet Tuesday, not from a dead PBX on a Friday afternoon.
Managed backups across the fleet: capture status, verification state, and certificates in one view. Demo data shown.
What the certificate says, and why it can be trusted
Each restore test produces a certificate recording the instance, the backup's SHA-256 and size, when it was captured and tested, how long the restore took, and a table of production-versus-restored counts for the data that matters: extensions, trunks, queues, ring groups, receptionists, and voicemail boxes. The record hash chains to the previous certificate, so the history is tamper-evident, and each certificate has a public verification page plus a PDF.
Do not take the description's word for it: view a real certificate (PDF), generated by an actual restore test in our demo fleet.
Two layers, one price
Managed verified backups pair with SFTP remote storage, which streams the PBX's own scheduled backups offsite. Both are opt-in per instance and both are included in the flat per-instance price: offsite for every instance, verification for the customers who need you to prove it.
Frequently asked questions
What does a restore test actually check?
The captured backup is restored on an isolated machine matched to the PBX's 3CX version, with no internet access. Sikurd then counts what came back, extensions, trunks, queues, ring groups, digital receptionists, voicemail boxes, and compares each count against production at capture time. Matching counts and a clean restore produce a PASS; anything else is a FAIL you hear about immediately, while it is still an inconvenience instead of an incident.
What makes the certificate tamper-evident?
Each certificate records the backup's SHA-256, its size, the restore results, and a record hash that chains to the previous certificate's hash. Editing any historical certificate would break every hash after it. Each certificate also has a public verification page and a PDF you can send to a client or an auditor.
How is this priced?
Managed verified backups are included in the flat per-instance price and are opt-in: enable them on the instances where proof matters. They stack with the simpler SFTP remote storage option, which streams the PBX's own scheduled backups offsite.
Turn 'we back it up' into 'here is the certificate.'
Managed verified backups are opt-in per instance and included in the flat price. Open the live demo to see the whole flow against a real fleet.