Every feature in Grovia Vault is designed around one principle: your data must survive anything — ransomware, human error, cloud provider outages, or compliance audits.
Nine production-grade capabilities, all included. No add-on modules, no surprise pricing.
Every backup chunk is encrypted client-side before transmission using AES-256-GCM — the same standard used by financial institutions globally. Your encryption key is derived from your passphrase using SHA-256, which means the server never sees plaintext data, ever.
A 5-layer detection engine scores every file change before it reaches the backup pipeline. Files that look suspicious are flagged, threat alerts are fired, and backups can be paused automatically to prevent encrypting a poisoned dataset.
Your data lives in three geographically and vendor-isolated locations. Even if one provider is compromised or suffers an outage, your data remains safe and recoverable from the others.
Browse your backup history, choose any point in time, select specific files or trigger a full restore. Recovery begins immediately from the closest replica — Wasabi hot-tier for speed or B2 for resilience.
Microsoft only retains deleted items for 93 days. Grovia Vault creates an independent, encrypted, air-gapped copy of your entire Microsoft 365 estate — separate from Microsoft's infrastructure.
Only changed file blocks are transferred after the initial full backup. SHA-256 change detection identifies exactly what's new, minimising bandwidth usage and backup time — critical for low-bandwidth environments.
Purpose-built for managed service providers. Manage every client from one dashboard with complete tenant isolation enforced at the database level via PostgreSQL Row-Level Security.
Define backup policies centrally and push them to any number of agents in under 60 seconds. Set backup paths, cron schedules, retention windows, bandwidth limits, and threat response actions — all from the cloud dashboard.
Real-time threat notifications via email and webhook when the detection engine scores a file above the alert threshold. A complete, tamper-evident audit trail of every backup, restore, and policy change — essential for DPDP and RBI compliance.
Five detection layers run in sequence on every file change. A composite threat score determines whether a backup proceeds, alerts fire, or the process is halted.
Encrypted ransomware payloads have very high information entropy. Any file scoring above 7.5 bits/byte (random-looking content) is flagged as high-risk. Normal document files typically score 3–6.
threshold: 7.5 bits/byteRansomware often disguises encrypted files with innocent extensions (.pdf, .docx) while the actual file header doesn't match. Vault reads the magic bytes of every file and flags mismatches between the real type and the extension.
libmagic + MIME registry18 known ransomware extensions are blocked outright: .locked, .encrypted, .crypted, .enc, .crypto, .vault, .cerber, .locky, .wannacry, .petya, .zepto, .thor, .aesir, .zzzzz, .osiris, .lnk, .micro, .ttt. Any match triggers an immediate alert.
18 ransomware signaturesRansomware always leaves instructions for the victim. Vault watches for file creation matching known ransom note patterns: README, DECRYPT, RECOVER, HOW_TO, ATTENTION, YOUR_FILES. Any match scores maximum points and triggers immediate block.
regex filename matchingRansomware encrypts files at machine speed — far faster than a human working. Vault tracks each endpoint's average file-change rate and alerts when velocity exceeds 10× the 7-day baseline. This catches novel ransomware strains that don't match any signature.
rolling 7-day baseline · 10× multiplier thresholdYour data flows through a pipeline designed so no single point of failure — not even a cloud provider going offline — can make your backups inaccessible.
Free plan — 1 device, 10 GB, AES-256-GCM encryption, real-time ransomware detection. No credit card required.