NIS2, PCI-DSS, and ISO 27001 compliant backup — Client encryption + air-gap

    Your backups check all the boxes: encrypted by your servers, inaccessible to our team, physically isolated from the network.

    NIS2PCI-DSSISO 27001GDPR

    3 security pillars

    Each protection layer works independently. Even if one is compromised, the other two protect your data.

    Client-side encryption

    AES-256 — the key never leaves your Proxmox servers. NimbusBackup stores data it cannot read.

    • AES-256 encryption by Proxmox VE before sending
    • Encryption key exclusively on the client side
    • NimbusBackup never has access to data in clear text

    Zero admin client option

    Your PBS account is in append-only mode: you can backup, read, and restore, but you cannot add accounts or delete backups.Why this segregation matters →

    • Deletions only via support ticket + validation
    • Protection against malicious insider on client side
    • No backup modification without validation process

    Physical air-gap

    2 disks are physically disconnected from the network at all times, i.e. 2 months of offline backups. Even in case of complete RDEM infrastructure compromise, these copies are intact.

    • Guaranteed monthly rotation, 2 disks offline (M-1 and M-2)
    • Network-inaccessible — no ransomware can reach them
    • Offline backup: "indispensable" per ANSSI (R12)

    Already with a Single Drive PBS

    Even our entry-level plan (Single Drive PBS at 12EUR/TB) with the zero admin client option already provides very satisfactory guarantees:

    Configured retention (30 days default)
    Append-only client account
    Client-side AES-256 encryption
    Offsite data in separate datacenter

    To go further: the air-gapped plans add an ultimate physical protection layer.

    Compliance mapping — NIS2, PCI-DSS, ISO 27001

    RequirementNIS2PCI-DSSISO 27001NimbusBackup
    Data encryptionArt. 21Req. 3.4A.10.1Client-side AES-256 via PVE
    Access separationArt. 21Req. 7A.9.1Append-only client account, zero admin
    Malicious insider protectionArt. 21Req. 7A.9.2Deletions via ticket + validation
    Ransomware protectionArt. 21Req. 5A.12.2Immutability + physical air-gap
    Offsite backupArt. 21Req. 9.5A.12.3Separate Equinix datacenter
    Business continuityArt. 21Req. 12.10A.17.1PBS restore < 4h
    Data integrityArt. 21Req. 10A.12.4Checksums re-verified every 30d
    Data sovereigntyArt. 26A.18.1Infrastructure in France (Equinix Paris) + 2nd EU site, no transfer outside EU

    The evidential value of these controls — logging and traceability (PCI Req. 10, ISO A.12.4) — relies on trustworthy, NTP-synchronised timestamps: see the NTP audit checklist for CISOs.

    What ANSSI actually asks for: R11 and R12

    ANSSI's recommendations carry no normative force — the guide says so itself — but they are the yardstick auditors and cyber-insurers reach for in France. Two of them bear directly on an offsite backup offering, in the guide "Sauvegarde des systèmes d'information — Les fondamentaux" (ANSSI-BP-100, v1.1, 27 November 2025; quotations are our translation).

    R11 — the "3 - 2 - 1" rule

    "3 distinct copies of the data, i.e. the production data plus 2 backups stored on different media, of which 1 offline." Three digits, not five: the 3-2-1-1-0 extension comes from CISA and ENISA, not from ANSSI.

    R12 — bold in the guide, therefore a priority

    "An offline backup is indispensable (or at least an online off-site one, under certain conditions), even if it is less frequent than regular local online backups." Indispensable, not recommended — and offline first, online off-site as the fallback.

    The direct consequence for our own plans, and we would rather write it ourselves: an online-only backup, immutable or not, ranks second in the guide — "an offline backup solution is still considered more robust than an online WORM solution". The very next sentence of the same table opens the door, and that is the one to keep:

    "Nevertheless, an acceptable compromise can be to run regular backups with a WORM solution and to run offline backups at a lower frequency."

    That is word for word the architecture we deploy: an immutable PBS datastore for the daily cadence, and on top of it a rotation of disconnected media — AirGapped Drive, Drive Bank, Magnetic Bank — at a lower frequency. An offering that stops at online WORM only ticks R12 through the "online off-site, under certain conditions" fallback.

    Scenario: compromise

    Level 1 — Attacker compromises the client

    They take control of your Proxmox servers, encrypt your VMs with ransomware.

    They try to delete your NimbusBackup backups — impossible (append-only account, no deletion rights).

    They cannot read the backups — AES-256 encrypted client-side.

    Result: restore possible from NimbusBackup.

    Level 2 — Attacker compromises RDEM Systems

    In the unlikely event that RDEM admin workstations are compromised.

    The attacker destroys online backups.

    But: air-gapped disks are physically disconnected from the network — inaccessible, intact.

    Result: air-gapped copies allow restore.

    Which plan for which compliance level

    ProtectionSingle DriveDouble DriveAirGappedDrive BankMagneticMagnetic Bank
    Client AES-256 encryption
    Append-only + insider protectionoptionoptionoptionoptionoptionoption
    Offsite separate datacenter
    2-site geo-replication
    Physical air-gap
    Bank vault
    LTO 30+ year archiving
    Hosting provider compromise protection
    Ultimate protection

    Compare in detail: All pricing | Managed Proxmox Backup

    FAQ — Compliance

    Yes. NimbusBackup meets NIS2 requirements (article 21): client-side AES-256 encryption, hosting in sovereign datacenter (Equinix France), air-gapped options compliant with ANSSI recommendations, full traceability, and automatic integrity verification every 30 days. Learn more: NIS2 and backups — obligations and best practices.

    NimbusBackup covers PCI-DSS backup requirements: stored data encryption (Req. 3.4), access separation with append-only account (Req. 7), malware protection via immutability and air-gap (Req. 5), and secure offsite storage (Req. 9.5). The bank vault option provides an additional level of physical protection.

    The zero admin client option means your PBS account is in append-only mode: you can backup, read, and restore, but you cannot add accounts or delete backups. RDEM Systems keeps an admin account (required for infrastructure), but any deletion or retention modification must go through a support ticket with a validation process. This is the most effective protection against a malicious insider on the client side.

    Yes. AES-256 encryption is managed by your Proxmox VE. During restore, your PVE automatically decrypts the data with your key. NimbusBackup never sees your data in clear text — the key remains exclusively on your servers. The process is transparent and does not extend restore time.

    Yes, on air-gapped plans. Even if an attacker compromises RDEM Systems admin workstations and destroys online backups, air-gapped disks are physically disconnected from the network and remain intact. Furthermore, your data is AES-256 encrypted client-side — the attacker cannot read it. Recommended plans: AirGapped Drive PBS, Drive Bank PBS, Magnetic Bank PBS. Learn more: complete air-gapped guide.

    For basic NIS2 compliance, the Single Drive PBS with the zero admin client option already covers essential requirements (encryption, offsite, immutability). For essential entities or critical sectors, we recommend air-gapped plans ( AirGapped Drive or Drive Bank PBS) for maximum protection including physical isolation. See also our guide on immutable backup.

    Secure your backups — the technical building blocks of compliance

    Client-side encryption, append-only, physical air-gap. NIS2, PCI-DSS, ISO 27001.