Skip to content

Zero-Knowledge E2EE Cloud Backup

Pluvira Cloud Backup allows you to persist encrypted snapshots of your configuration files (config.yaml and rewrite rules) to the cloud with mathematically guaranteed Zero-Knowledge privacy.


1. Zero-Knowledge Cryptographic Architecture

[User Passphrase] + [16B Random Salt]
│
▼
[PBKDF2-HMAC-SHA256 (600,000 iterations)]
│
▼
[256-bit AES Key]
│
[config.yaml] + [12B Random IV] ──► [AES-256-GCM Encryption]
│
▼
[Opaque Encrypted Binary Blob]
│
HTTPS POST /api/v1/backup/upload
▼
[Pluvira Cloud Storage]
(Cannot Decrypt Blob)
  1. Client-Side Encryption: Snapshot encryption executes entirely inside your local browser or local daemon before network dispatch.
  2. Key Derivation (PBKDF2): Derives a 256-bit AES key using PBKDF2-HMAC-SHA256 with 600,000 iterations and a unique 16-byte random salt.
  3. Opaque Cloud Persistence: Pluvira Cloud stores only opaque binary blobs (BYTEA) and SHA-256 integrity checksums. Even in the event of a total server breach, stored snapshots cannot be decrypted.

2. Storage Quotas & Retention Policy

TierTypeMax SlotsMax SizeRetention Policy
Personal Free (Unregistered)None0—Local file export only
Personal Free (Registered)Manual1 Slot200 KBOverwrites previous snapshot
Pluvira Pro TierManual + Auto5 Slots500 KBAutomatic FIFO rotation (oldest pruned)
Pluvira Ultra TierManual + Auto10 Slots1 MBAutomatic FIFO rotation (oldest pruned)

3. Creating & Restoring Snapshots

Creating a Snapshot

  1. In the WebUI, navigate to Settings → Cloud Backup.
  2. Enter a strong personal encryption passphrase.
  3. Click Create Cloud Snapshot. The local engine verifies SHA-256 integrity and transmits the encrypted blob.

Restoring a Snapshot

  1. Navigate to Settings → Cloud Backup (or log in to the Customer Portal).
  2. Select your snapshot from the list and enter your decryption passphrase.
  3. Click Decrypt & Restore. The configuration is validated and atomically restored.