0.1.0 betaFirst public release on 6 October 2026: source code and release notes go public on GitHub.What works today
restowbackup

Backup you can prove is restorable.

Open-source, self-hosted backup for Microsoft 365 and IMAP. Every backup is read back through the restore path and compared byte for byte before Restow calls it restorable.

restore check: weekly, per mailbox and OneDrive
sample: ≈20 mails, 20 files, calendar, contacts
method: read back, compared byte for byte
shown as: recovery readiness on the dashboard

Back up, verify, restore. In that order, every week.

Back up

Exchange Online mail, calendar, contacts and OneDrive through the Graph API, IMAP mailboxes over IMAP, Linux and macOS servers and clients with an agent, and imported mail files. Incremental, deduplicated, encrypted, on your storage.

Verify

A weekly job reads a sample from each latest snapshot back through the restore path and compares hashes. A backup that was never checked is never shown as proven. For servers and clients, the sample the agent recorded is read back from the repository after each new backup.

Restore

A single message, a folder, an older file version or a whole mailbox, into the original account or another one. The same path an emergency restore uses.

How the weekly restore check works
  1. Back up

    Mail, calendar, contacts and OneDrive, incremental and encrypted, on your storage.

  2. Pick a sample

    Every week, per mailbox and OneDrive: about 20 mails, 20 files, calendar and contacts.

  3. Read it back

    From the latest backup, through the same path a real restore uses.

  4. Compare

    Byte for byte against the recorded checksums. Only a match counts.

Shown per mailbox as recovery readiness

  • ReadyLatest check passed
  • AttentionWarnings in the check
  • Not restorableCheck failed
  • Not provenNot read back yet

Restore is non-destructive: recovered items go next to what is already there, never over it.

What it protects, and what is still being built

available in 0.1.0

Backup and archive

  • Exchange Online: mail, calendar, contacts
  • OneDrive
  • IMAP mailboxes
  • Non-destructive restore, weekly sampled restore checks
  • Servers and clients with an agent: Linux and macOS, from Community
  • Mail file import and export: EML, MSG, MBOX, MailStore
  • Failure explanations: what happened, why and what to do
  • Update check (off until you turn it on) and an optional updater
  • Signed images for amd64 and arm64, with SBOM
  • Archive in every edition: Microsoft 365 and IMAP sync, SHA-256 hash chain, full-text search
  • GoBD layer from Business: Exchange Online journaling, enforced retention, legal hold
  • Several administrators with roles (from Business)
in development

Organisation and more sources

  • Audit log viewer with search and chain verification, exportable as CSV and PDF (Business and above); recording runs in every edition
  • Single sign-on and four-eyes approval
  • Signed restore report
  • Google Workspace backup
planned, not started

Windows, more formats, more targets

  • Windows agent
  • Agent mTLS and filesystem snapshots
  • PST and OST import, PST and MSG export
  • Proxmox VE via Proxmox Backup Server
  • SFTP storage target

Stated limits: Teams messages are not part of v1. An IMAP source currently uses one login for all mailboxes under it. The first backup of a large tenant can take days, because Microsoft throttles the Graph API; Restow shows that wait instead of hiding it. The endpoint agent backs up files, not disk images, and has no Windows version, no mTLS and no filesystem snapshots yet.

Editions

Everything you need to back up is free. Everything your organisation needs to sign off on is Business.

Early access Restow is in beta, and Business and Service Provider are on pre-sale until general release. Business: Pre-sale price €476 net until general release. List price from release: €595 net. Service Provider: Pre-sale price €1,560 net until general release. List price from release: €1,950 net. You get the license for good and every feature the edition adds, as it ships. Business unlocks today: scheduled reports (daily, weekly or monthly summary by e-mail); several administrators with roles (owner, administrator, technician, read only); GoBD layer for the archive (Exchange Online journaling, enforced retention, legal hold). Service Provider unlocks today: multiple tenants and the cross-tenant REST API. No dates are promised. Not to be used as your only backup.

Community

Free 

One organisation. Every backup source, every restore function, no mailbox limit, no license key.

  • Microsoft 365 and IMAP backup
  • Non-destructive restore
  • Weekly restore checks
  • Server and client backup (Linux, macOS)
  • Mail file import and export
  • Archive with hash chain and full-text search
  • Failure explanations, job history, REST API

For homelabs, small teams and anyone who wants to see the code.

Business

Pre-sale price€476List price from release: €595 −20% beta pre-saleonce, net, plus VAT

Pre-sale price €476 net until general release. List price from release: €595 net.

Everything in Community, plus what an organisation needs to prove.

  • Audit log viewer (search, details, hash-chain verification, export as CSV and PDF) (In development)
  • Scheduled reports (daily, weekly or monthly summary by e-mail)
  • Single sign-on (Entra ID, OIDC, LDAP) (In development)
  • Several administrators with roles (owner, administrator, technician, read only)
  • Four-eyes approval for restores and deletions (In development)
  • GoBD layer for the archive (Exchange Online journaling, enforced retention, legal hold)
  • Signed, independently verifiable restore report (with checksum) (In development)

For one company. Business customers only (§ 14 BGB).

Buy Business · €476Early access license for software in beta

Service Provider

Pre-sale price€1,560List price from release: €1,950 −20% beta pre-saleonce, net, plus VAT

Pre-sale price €1,560 net until general release. List price from release: €1,950 net.

Everything in Business, plus running Restow for many clients.

  • Multiple tenants and the cross-tenant REST API
  • Delegated tenant administrators and tenant reporting (Planned)
  • White label (Planned)

For IT service providers. Business customers only (§ 14 BGB).

Buy Service Provider · €1,560Early access license for software in beta

IncludedCommunityBusinessService Provider
Available now
Microsoft 365 backup and restore (mail, calendar, contacts, OneDrive)YesYesYes
IMAP backup and restoreYesYesYes
Non-destructive restore (never overwrites the original)YesYesYes
Weekly recovery readiness checks (sampled restore verification)YesYesYes
Basic operations log (job history, error messages)YesYesYes
REST APIYesYesYes
Alerts by e-mail, in-app and webhook (failed backups, failed restore checks, storage damage)YesYesYes
Mailbox limitNoneNoneNone
Scheduled reports (daily, weekly or monthly summary by e-mail)NoYesYes
Several administrators with roles (owner, administrator, technician, read only)One administratorYesYes
Archive with Microsoft 365 and IMAP sync, SHA-256 hash chain and full-text searchYesYesYes
GoBD layer for the archive (Exchange Online journaling, enforced retention, legal hold)NoYesYes
Multiple tenants and the cross-tenant REST APIOne tenantOne tenantYes
Server and client backup with an agent (Linux and macOS, file-level, append-only)YesYesYes
Mail file import (EML, MSG, MBOX, MailStore export) and export (EML ZIP, MBOX)YesYesYes
Failure explanations: what happened, why, and what to doYesYesYes
Update check (off until you turn it on) and an optional updater with automatic rollbackYesYesYes
Signed release images for amd64 and arm64, with SBOMYesYesYes
In development
Audit log viewer (search, details, hash-chain verification, export as CSV and PDF)Recorded, no viewerIn developmentIn development
Single sign-on (Entra ID, OIDC, LDAP)NoIn developmentIn development
Four-eyes approval for restores and deletionsNoIn developmentIn development
Signed, independently verifiable restore report (with checksum)NoIn developmentIn development
Planned
Delegated tenant administrators and tenant reportingNoNoPlanned
White labelNoNoPlanned
Windows agent (with VSS snapshots)PlannedPlannedPlanned
Agent mTLS and LVM, ZFS and btrfs snapshotsPlannedPlannedPlanned
PST and OST import, PST and MSG exportPlannedPlannedPlanned
Proxmox VE support (via PBS)PlannedPlannedPlanned
SFTP storage targetPlannedPlannedPlanned

Buy once, own it forever. A signed key, verified offline. No phone-home, nothing that can switch the software off, no subscription that lapses.

All updates included. For as long as Restow lives and receives updates. If we ever stop, we announce it twelve months in advance and publish the Business and Service Provider modules under the AGPL. Your installation keeps running without a key.

Software only. Licenses include the software and all updates. No support is included.

Honour rule. Mailbox and tenant counts are not enforced technically. We trust you to buy the edition that matches how you use Restow.

Your data is your data

Encrypted before it leaves the server

AES-256-GCM per chunk, a separate key per organisation.

Storage you choose

Local disk, S3-compatible object storage, NFS or SMB. More than one target per organisation.

An open, documented format

A small standalone tool restores from it even without a running Restow server. Losing Restow does not mean losing your backups.

No phone-home

No telemetry, no license server, no connection to us. Restow only talks to what you set up; the update check is off until you turn it on.

Source code on GitHub · How Restow is built, loop by loop

Who runs it

Run it yourself

A Docker Compose stack on a server you control. How Community and Business are normally used.

Have your IT service provider run it

Your provider installs and operates Restow for you, on their infrastructure or yours, under the Service Provider edition. Restow itself does not offer a hosted service.

About the project

Restow is built by Lucas Flores, an IT systems engineer and owner of a small managed service provider near Cologne, not a professional software developer. The code is written with AI assistance, with his own understanding of Exchange, Graph and storage, and a testing discipline that is not negotiable for a backup tool. If you consider that a risk, you are right to; that is why the tests, the restore evidence and the storage format stay open.

Lucas Flores, IT Systeme Flores UG · last updated 2026-09-30

Get Restow Community Edition

Community is free and open source, licensed under the AGPL-3.0. Version 0.1.0, beta.

Download 0.1.0 beta

Container image, source archive and full release notes for the first public release.

Available on 6 October 2026

Source code

The AGPL-3.0 source code is public on GitHub. Every release is published there.

Get started

Install with Docker Compose using the published images, ghcr.io/restow-backup/restow:0.1.0 and ghcr.io/restow-backup/restow-web:0.1.0 (amd64 and arm64, signed with cosign). Restow 0.1.0 is a beta: test it before you rely on it, and keep an independent backup alongside it.

Get started

Business and Service Provider editions unlock in the same installation with a license key: no separate download, no separate signup.

Questions, or one email when your edition ships

No account to create, and signing up here buys nothing (licenses are on pre-sale under Editions). We email you once, when your edition or the live demo is ready.

Your details are processed on our own server, only to contact you about Restow, and never sold or shared.

Questions

What happens if Restow development ever stops?

We announce it at least twelve months in advance and publish the Business and Service Provider modules under the AGPL. Your installation keeps running without a license key, and the AGPL core already released cannot be withdrawn.

Where is my data stored?

Wherever you point Restow: local storage, S3-compatible object storage, NFS or SMB. If your IT service provider runs Restow for you, they tell you where. Restow itself never stores your data on our infrastructure.

What Microsoft 365 permissions does Restow need?

An Entra ID app registration that your tenant administrator consents to once, with Graph application permissions scoped to backup and restore. Restow only uses Graph, never EWS and never legacy authentication. The exact list is in the documentation.

Is the archive available?

Yes, from 0.1.0. Every edition, Community included, archives Microsoft 365 and IMAP mail into an append-only store with a SHA-256 hash chain, chain verification and full-text search. Business and Service Provider add the layer built for German GoBD requirements: Exchange Online journaling over SMTP, enforced retention and legal hold. It is built for German GoBD requirements, not certified. Self-service archive search for end users is still in development.

Can Restow back up servers and laptops?

Yes, on Linux and macOS, in every edition including Community. You paste one command with a one-time token into the machine; the agent connects outbound over HTTPS only and can add backups but never delete them. Restores go into a new folder or a ZIP download, and a restore test compares hashes. Windows, filesystem snapshots and disk images (bare-metal restore) are not part of 0.1.0: the agent backs up files.

Can I import old mail from PST, MailStore or Thunderbird?

EML, MSG, MBOX (Thunderbird, Apple Mail) and MailStore exports in EML or MSG form can be imported as a legacy mailbox that you can browse, restore into Microsoft 365 or IMAP, download and optionally archive. PST and OST files are recognised and refused with an explanation; PST and OST import is planned. MailStore's internal archive format cannot be read, so export from MailStore first.

Does Restow update itself?

Not unless you switch it on. The update check is off until an administrator turns it on, and then only reads the release list of the source you chose (the public GitHub releases by default). An optional updater, a separate Compose profile, can apply an update with a database backup first and an automatic rollback. It needs the Docker socket, which is root on the host, so read the trade-off in the documentation before you enable it.

How do I know a release is genuine?

Every release image is built for amd64 and arm64, signed with cosign and ships an SBOM; the documentation shows the command that verifies a signature. Before a release is published, a smoke run has to pass: fresh install, restores with hash comparison, endpoint backup, mail import. The Microsoft 365 check runs against a test tenant only when credentials are configured.

Is Restow open source?

Yes. Everything outside the ee/ folder is AGPL-3.0 with the Restow Module Exception and is published on GitHub with the first public release. The Business and Service Provider features live in ee/ of the same repository under a source-available license: you can read and run the code, and using an edition feature in production needs a license key. Contributions need a CLA and a DCO sign-off.

Can I try a live demo?

Yes, at demo.restowbackup.com: two fictional tenants with synthetic mail and 30 days of history. Browsing, statistics, backups, restore checks and restoring as a download work; restoring into a mailbox and changing sources, settings or users are locked. Everything resets every night at 03:00, and no visitor IP address is stored.