Encryption and key management

In short

Magnus Box encrypts your clients' backup data with AES-256, both while it travels and while it's stored. The encryption keys are created and managed automatically. You and your clients never see or handle them, so there's nothing to set up, store or lose.

What's encrypted, and how

  • In transit: backup data is AES-256 encrypted while it moves between your clients' devices and storage.
  • At rest: backup data stays AES-256 encrypted while it's stored.

This happens on every backup by default. There's no setting to turn on and no extra step for you or your techs.

Who manages the keys

Encryption keys are generated automatically. Partners and end users never see or access them, and nobody on your team has to create, copy or keep track of a key.

What this means for you

  • Nothing to set up. New clients, devices and Storage Vaults are encrypted from the first backup without any key setup.
  • Nothing to store or lose. There's no key file, recovery phrase or key password to put in your password manager or hand over to the client.
  • Restores just work. Restore from the Web Portal or the backup app as usual. You don't need to find or enter a key first.
  • No key recovery. Because you never hold the keys, there's no key recovery process to plan for or go through.

FAQ

Do I need to back up an encryption key somewhere safe?

No. Keys are created and managed automatically, and you never need to see or store them.

Can I choose my own encryption key?

No. Keys are always generated automatically, so there's nothing to choose or configure.

Does encryption change how I restore?

No. Restores work the same way from the Web Portal or the backup app. See Restore options explained.

A client sent us a security questionnaire. Who can help?

Email support@magnusbox.com for help with security questionnaires, vendor assessments or compliance paperwork.

Related articles

Did this answer your question? Thanks for the feedback There was a problem submitting your feedback. Please try again later.

Still need help? Contact Us Contact Us