Changelog
Only released versions appear here. What is still being built is on the Roadmap.
0.1.0 beta · 6 October 2026
First public release.
- Microsoft 365 backup: Exchange Online mail, calendar and contacts, and OneDrive, incremental via Microsoft Graph delta queries.
- IMAP backup: Any IMAP mailbox, password-authenticated, one login per source today.
- Non-destructive restore: A single item, a folder, a file version or a whole mailbox or OneDrive, into the original account or another one. The restore explorer has a slim timeline of restore points at the bottom.
- Weekly restore check: A sample from every backup is read back and compared byte for byte, shown as recovery readiness.
- Archive: Microsoft 365 and IMAP archive sync into an append-only store with a SHA-256 hash chain, chain verification and full-text search. In every edition.
- GoBD layer for the archive: Exchange Online journaling over SMTP, retention policies with an enforced deletion run, and legal hold. Built for German GoBD requirements. (Business, Service Provider)
- Multiple tenants: Many client tenants in one installation, with a cross-tenant API key. (Service Provider)
- REST API and operations log: OpenAPI-documented REST API with per-tenant keys and scopes; job history and errors in every edition.
- Team with roles: Several administrators, each an owner, administrator, technician or read only, with every tenant or chosen ones. Owners invite and change members; every change is audited. (Business, Service Provider)
- Scheduled reports: A daily, weekly or monthly summary by e-mail: success rate, failed items, share proven restorable, failure causes, storage and restores. (Business, Service Provider)
- Alerts: Rules that send an e-mail, a bell entry or a signed webhook when a backup fails, a restore check does not pass or storage is damaged, with a delivery log.
- Server and client backup: A Go agent for Linux and macOS on restic 0.19.1, set up with one command and a one-time token. Outbound HTTPS only, append-only, one repository per machine, restores into a new folder, restore tests that feed recovery readiness. Windows is planned.
- Mail file import and export: Import EML, MSG, MBOX and MailStore exports as a legacy mailbox you can browse, restore into Microsoft 365 or IMAP, download and optionally archive. Export mailboxes from backups, imports and the archive as EML in a ZIP or as MBOX.
- Updates: An update check that is off until you turn it on, with your own release source if you like, and an optional updater that announces maintenance, backs up the database first and rolls back if the new version does not become healthy.
- Failure explanations: Every failed job, item, sync and verification says what happened, why (88 stable cause codes) and what to do, with links and technical details for support.
- Signed, verified releases: Every release image is built for amd64 and arm64, signed with cosign, ships an SBOM and passes a release smoke run (fresh install, restores with hash comparison, endpoint backup, mail import) before it is published.
- Operator notice, editions in one repository: The setup wizard starts with an operator notice that must be accepted. The AGPL-3.0 core and the source-available Business and Service Provider modules (ee/) live in one repository and one image; contributions need the CLA and a DCO sign-off.
Known limits
- SharePoint and Teams are not part of version 1.
- An IMAP source currently uses one login for all mailboxes under it.
- The first backup of a large tenant can take days because Microsoft throttles the Graph API; Restow shows that wait.
- The endpoint agent backs up files on Linux and macOS: no Windows yet, no mTLS, no filesystem snapshots, no disk images.
- PST and OST import and PST and MSG export are planned. An imported mailbox cannot be deleted in this release, and calendar and contacts from MSG are not imported.
- Beta: do not use it as your only backup.
Verification
Before a version is tagged, the release smoke run checks a fresh install, health, passkey sign-in, IMAP backup and restore with hash comparison, journal receipt and chain check, standalone restore, storage targets, an image scan, endpoint backup and restore, and mail import and export. The release notes on GitHub carry the result and say what was not run. Microsoft 365 against a test tenant runs only when credentials are configured.
Full release notes on GitHub ↗
Full release notes go public on GitHub on 6 October 2026.