restowbackup

← Back to the overview

Roadmap

What Restow does today, what is being built, and what is decided but not started. The timeline moves as you scroll. No dates, except the public launch: a feature counts as shipped when it is in a released version, not before.

  1. 0.1.0 beta, available today

    Shipped

    • Microsoft 365 backup

      Exchange Online mail, calendar and contacts, and OneDrive, incremental via Microsoft Graph delta queries.

      Every edition

    • IMAP backup

      Any IMAP mailbox, password-authenticated, one login per source today.

      Every edition

    • Non-destructive restore

      A single item, a folder, a file version or a whole mailbox or OneDrive, into the original account or another one. The restore explorer has a slim timeline of restore points at the bottom.

      Every edition

    • Weekly restore check

      A sample from every backup is read back and compared byte for byte, shown as recovery readiness.

      Every edition

    • Archive

      Microsoft 365 and IMAP archive sync into an append-only store with a SHA-256 hash chain, chain verification and full-text search. In every edition.

      Every edition

    • GoBD layer for the archive

      Exchange Online journaling over SMTP, retention policies with an enforced deletion run, and legal hold. Built for German GoBD requirements.

      BusinessService Provider

    • Multiple tenants

      Many client tenants in one installation, with a cross-tenant API key.

      Service Provider

    • REST API and operations log

      OpenAPI-documented REST API with per-tenant keys and scopes; job history and errors in every edition.

      Every edition

    • Team with roles

      Several administrators, each an owner, administrator, technician or read only, with every tenant or chosen ones. Owners invite and change members; every change is audited.

      BusinessService Provider

    • Scheduled reports

      A daily, weekly or monthly summary by e-mail: success rate, failed items, share proven restorable, failure causes, storage and restores.

      BusinessService Provider

    • Alerts

      Rules that send an e-mail, a bell entry or a signed webhook when a backup fails, a restore check does not pass or storage is damaged, with a delivery log.

      Every edition

    • Server and client backup

      A Go agent for Linux and macOS on restic 0.19.1, set up with one command and a one-time token. Outbound HTTPS only, append-only, one repository per machine, restores into a new folder, restore tests that feed recovery readiness. Windows is planned.

      Every edition

    • Mail file import and export

      Import EML, MSG, MBOX and MailStore exports as a legacy mailbox you can browse, restore into Microsoft 365 or IMAP, download and optionally archive. Export mailboxes from backups, imports and the archive as EML in a ZIP or as MBOX.

      Every edition

    • Updates

      An update check that is off until you turn it on, with your own release source if you like, and an optional updater that announces maintenance, backs up the database first and rolls back if the new version does not become healthy.

      Every edition

    • Failure explanations

      Every failed job, item, sync and verification says what happened, why (88 stable cause codes) and what to do, with links and technical details for support.

      Every edition

    • Signed, verified releases

      Every release image is built for amd64 and arm64, signed with cosign, ships an SBOM and passes a release smoke run (fresh install, restores with hash comparison, endpoint backup, mail import) before it is published.

      Every edition

    • Operator notice, editions in one repository

      The setup wizard starts with an operator notice that must be accepted. The AGPL-3.0 core and the source-available Business and Service Provider modules (ee/) live in one repository and one image; contributions need the CLA and a DCO sign-off.

      Every edition

  2. 6 October 2026

    Public launch

    • Source code on GitHub

      The AGPL-3.0 core and the 0.1.0 release go public on GitHub. Every later release is published there too.

      Every edition

    • Pre-sale licenses

      Business and Service Provider at the pre-sale price until general release; every feature below is delivered as it ships.

      BusinessService Provider

  3. Being built now, not available yet

    In development

    No dates. Check the changelog for the version a feature actually ships in before relying on it.

    • Google Workspace backup

      Gmail and Google Drive, alongside Microsoft 365 and IMAP.

      Every edition

    • Audit log

      Every read and restore is recorded in a hash chain in every edition. The viewer with search, details and chain verification, and export as CSV and PDF, is the Business and Service Provider part.

      BusinessService Provider

    • Single sign-on

      Entra ID, OIDC and LDAP.

      BusinessService Provider

    • Four-eyes approval

      A second person approves restores and deletions before they run.

      BusinessService Provider

    • Signed restore report

      A restore report with a checksum and signature that anyone can verify without Restow.

      BusinessService Provider

    • Better sign-in and restore

      Microsoft sign-in for end users, per-mailbox IMAP credentials, a full test restore into a separate target, and an optional Replace mode for OneDrive files in which the current file becomes an earlier version instead of being deleted (never for mail).

      Every edition

  4. Decided, not started

    Planned

    • Delegated admins and tenant reports

      Tenant administrators with their own scope, and reports per tenant.

      Service Provider

    • OAuth2 for IMAP sources

      Sign-in with OAuth2 instead of a password for IMAP mailboxes hosted on Microsoft 365 or Google.

      Every edition

    • White label

      Your brand instead of Restow.

      Service Provider

    • Windows agent

      The agent for Linux and macOS ships. A Windows service with shadow-copy (VSS) support is planned, still file-level.

      Every edition

    • Agent mTLS and filesystem snapshots

      A client certificate per agent instead of a per-agent secret, and LVM, ZFS and btrfs snapshots for consistent backups. Today consistency comes from optional pre and post hooks.

      Every edition

    • PST and OST import

      PST and OST files are recognised today and refused with an explanation. Reading them is planned; until then, export to MSG, EML or MBOX first.

      Every edition

    • PST export

      Export as EML in a ZIP and as MBOX ships. PST export is planned. The EML export holds the same messages in their original form.

      Every edition

    • MSG export

      Planned as soon as a writer with a clear, permissive license exists. The EML export holds the same messages in their original form.

      Every edition

    • Proxmox VE via PBS

      Proxmox support through Proxmox Backup Server.

      Every edition

    • SFTP target

      SFTP as a storage target.

      Every edition

  5. Deliberate decisions

    Not in scope for now

    • SharePoint and Teams

      Not in the current phase, beyond what Graph already exports.

      Every edition

    • Also not planned

      Exchange Public Folders, eDiscovery case management and a mobile app. Restow is not an RMM or PSA tool; its API lets yours integrate.

      Every edition

    • Disk images and bare-metal restore

      The agent backs up files, by design. Restoring a whole machine means reinstalling the operating system and restoring the files.

      Every edition

For what ships today in detail, see features; for prices and what each edition unlocks, see pricing; for the archive, see GoBD and email archiving.

Get notified when any of this ships →