NIS2, PCI-DSS, and ISO 27001 compliant backup — Client encryption + air-gap
Your backups check all the boxes: encrypted by your servers, inaccessible to our team, physically isolated from the network.
3 security pillars
Each protection layer works independently. Even if one is compromised, the other two protect your data.
Client-side encryption
AES-256 — the key never leaves your Proxmox servers. NimbusBackup stores data it cannot read.
- AES-256 encryption by Proxmox VE before sending
- Encryption key exclusively on the client side
- NimbusBackup never has access to data in clear text
Zero admin client option
Your PBS account is in append-only mode: you can backup, read, and restore, but you cannot add accounts or delete backups.Why this segregation matters →
- Deletions only via support ticket + validation
- Protection against malicious insider on client side
- No backup modification without validation process
Physical air-gap
2 disks are physically disconnected from the network at all times, i.e. 2 months of offline backups. Even in case of complete RDEM infrastructure compromise, these copies are intact.
- Guaranteed monthly rotation, 2 disks offline (M-1 and M-2)
- Network-inaccessible — no ransomware can reach them
- Offline backup: "indispensable" per ANSSI (R12)
Already with a Single Drive PBS
Even our entry-level plan (Single Drive PBS at 12EUR/TB) with the zero admin client option already provides very satisfactory guarantees:
To go further: the air-gapped plans add an ultimate physical protection layer.
Compliance mapping — NIS2, PCI-DSS, ISO 27001
| Requirement | NIS2 | PCI-DSS | ISO 27001 | NimbusBackup |
|---|---|---|---|---|
| Data encryption | Art. 21 | Req. 3.4 | A.10.1 | Client-side AES-256 via PVE |
| Access separation | Art. 21 | Req. 7 | A.9.1 | Append-only client account, zero admin |
| Malicious insider protection | Art. 21 | Req. 7 | A.9.2 | Deletions via ticket + validation |
| Ransomware protection | Art. 21 | Req. 5 | A.12.2 | Immutability + physical air-gap |
| Offsite backup | Art. 21 | Req. 9.5 | A.12.3 | Separate Equinix datacenter |
| Business continuity | Art. 21 | Req. 12.10 | A.17.1 | PBS restore < 4h |
| Data integrity | Art. 21 | Req. 10 | A.12.4 | Checksums re-verified every 30d |
| Data sovereignty | Art. 26 | — | A.18.1 | Infrastructure in France (Equinix Paris) + 2nd EU site, no transfer outside EU |
The evidential value of these controls — logging and traceability (PCI Req. 10, ISO A.12.4) — relies on trustworthy, NTP-synchronised timestamps: see the NTP audit checklist for CISOs.
What ANSSI actually asks for: R11 and R12
ANSSI's recommendations carry no normative force — the guide says so itself — but they are the yardstick auditors and cyber-insurers reach for in France. Two of them bear directly on an offsite backup offering, in the guide "Sauvegarde des systèmes d'information — Les fondamentaux" (ANSSI-BP-100, v1.1, 27 November 2025; quotations are our translation).
"3 distinct copies of the data, i.e. the production data plus 2 backups stored on different media, of which 1 offline." Three digits, not five: the 3-2-1-1-0 extension comes from CISA and ENISA, not from ANSSI.
"An offline backup is indispensable (or at least an online off-site one, under certain conditions), even if it is less frequent than regular local online backups." Indispensable, not recommended — and offline first, online off-site as the fallback.
The direct consequence for our own plans, and we would rather write it ourselves: an online-only backup, immutable or not, ranks second in the guide — "an offline backup solution is still considered more robust than an online WORM solution". The very next sentence of the same table opens the door, and that is the one to keep:
"Nevertheless, an acceptable compromise can be to run regular backups with a WORM solution and to run offline backups at a lower frequency."
That is word for word the architecture we deploy: an immutable PBS datastore for the daily cadence, and on top of it a rotation of disconnected media — AirGapped Drive, Drive Bank, Magnetic Bank — at a lower frequency. An offering that stops at online WORM only ticks R12 through the "online off-site, under certain conditions" fallback.
Scenario: compromise
Level 1 — Attacker compromises the client
They take control of your Proxmox servers, encrypt your VMs with ransomware.
They try to delete your NimbusBackup backups — impossible (append-only account, no deletion rights).
They cannot read the backups — AES-256 encrypted client-side.
Result: restore possible from NimbusBackup.
Level 2 — Attacker compromises RDEM Systems
In the unlikely event that RDEM admin workstations are compromised.
The attacker destroys online backups.
But: air-gapped disks are physically disconnected from the network — inaccessible, intact.
Result: air-gapped copies allow restore.
Which plan for which compliance level
| Protection | Single Drive | Double Drive | AirGapped | Drive Bank | Magnetic | Magnetic Bank |
|---|---|---|---|---|---|---|
| Client AES-256 encryption | ||||||
| Append-only + insider protection | option | option | option | option | option | option |
| Offsite separate datacenter | ||||||
| 2-site geo-replication | — | — | — | — | ||
| Physical air-gap | — | — | — | |||
| Bank vault | — | — | — | — | ||
| LTO 30+ year archiving | — | — | — | — | ||
| Hosting provider compromise protection | — | — | — | |||
| Ultimate protection | — | — | — | — |
Compare in detail: All pricing | Managed Proxmox Backup
FAQ — Compliance
Secure your backups — the technical building blocks of compliance
Client-side encryption, append-only, physical air-gap. NIS2, PCI-DSS, ISO 27001.
