Security & trust

Your customers trust you.
Here is why you can trust Argus.

Argus monitors the backups of your customers — that makes it part of your security story. This page describes, concretely, how we protect the data you route through us and how Argus helps you meet your own compliance obligations.

Architecture

An isolated instance per MSP

Every MSP runs their own Argus instance with its own database and own database credentials, hard-scoped at the PostgreSQL level. Your customers' data never shares a table, a queue or a cache with another MSP. Our fleet tooling sees health metrics and counters — never report contents.

EU hosting

Instances run on infrastructure in the European Union. GDPR-first

Dedicated mailbox principle

Argus reads a mailbox that only receives backup reports — by design, no general business mail enters the pipeline.

Data minimisation

Fleet management sees instance health and job counts. Report contents stay inside your instance.

Data protection

Encrypted at rest, in transit and in backup

Operational security

Access is earned, logged and revocable

Mandatory 2FA

Password sign-in requires TOTP two-factor — enforced before the first dashboard view, with recovery codes. SSO users inherit MFA from their identity provider.

Four roles

Owner, admin, user and reader — subscription management, configuration, daily operations and read-only access are separate privileges.

Fast revocation

Removing a user invalidates their session within a minute. Role changes propagate just as fast.

Audit log

Every administrative action — who, what, when — is recorded and exportable (CSV), with configurable retention.

Brute-force protection

Sign-in attempts are rate-limited; public endpoints validate strictly and authenticate with per-instance keys.

Spoofing resistance

Inbound report channels verify sender authenticity (SPF/DKIM); anything that fails verification is quarantined for human review — a forged "backup successful" can never silently paint a green tile.

Continuity

We rehearse losing everything

Backup monitoring that loses its own data would be an irony we refuse to risk.

NIS2 & compliance

Backup evidence for NIS2, ready to hand over

NIS2 asks essential and important entities — and the MSPs that serve them — to take backup management seriously and to prove it. Argus produces that proof as a by-product of doing its job:

Continuous verification

Every backup job is checked daily — including the silent failures: reports that simply stop coming are caught by schedule-based detection.

Evidence on paper

White-label PDF reports per customer, generated on schedule: per-job daily history and success rates over the period — auditor-friendly, in your branding.

Incident trail

Alerts with acknowledge/assign/notes plus the audit log give you a demonstrable response trail for every backup incident.

Agreements

A GDPR data processing agreement (DPA) and an SLA are available for every paid subscription.

Argus is a monitoring and evidence tool; it supports your NIS2 measures but does not by itself make an organisation compliant.

Disclosure

Found a vulnerability?

Tell us at hello@argusbackup.io — we respond fast, fix fast and credit researchers who report responsibly.