Authenticated encryption
Calmbu uses AES-256-GCM authenticated encryption before data reaches the destination you choose, including external or cloud-synchronised storage.
Backup content and sensitive workspace metadata are protected together so readable workspace details are not exposed through the stored recovery point.
Recovery proof
Writing an encrypted backup is not enough. A recovery point must pass Calmbu's integrity and private recovery checks before it can become Protected.
The same recovery-proof standard applies whether a backup starts from Safety's selected daily time, Live Guard after supported changes settle, or a manual Back up now action.
Interrupted, incomplete, or unverifiable work cannot produce a green status. Recovery validation resumes or restarts safely after interruption.
Recovery code and key control
The machine-independent recovery code is shown to the user and is not escrowed by Calmbu Pty Ltd. Device unlock material uses current-user Windows protection where practical.
Loss of both the recovery code and every valid device unlock key is intentionally unrecoverable. Calmbu has no vendor back door to bypass encryption.
Backup integrity and safe boundaries
Calmbu checks recovery-point integrity and does not present incomplete, conflicting, or malformed backup data as recoverable.
Guarded recovery boundaries keep recovery activity within approved locations and stop safely when validation does not pass.
Credential exclusions
Standard protection excludes known credentials, private-key material, and unsafe or disposable runtime data. This reduces secret exposure and means a recovered machine may require signing in again.
Safe recovery
Standard recovery returns a separate verified copy for inspection and does not immediately change active agent state. New-PC migration and any deliberate live-state change include additional confirmations and recovery safeguards.
Privacy-safe diagnostics
Calmbu does not send agent content telemetry. Local operational logs use coarse events and privacy-safe error information rather than workspace content, recovery codes, credentials, or sensitive configuration values.
Operational boundaries
Software already running as your Windows account can read the original agent files and may invoke the unlocked app. Calmbu cannot protect original data from an account that is already compromised.
A continuously connected ordinary drive is not ransomware-proof. Disconnected storage or an appropriately locked immutable replica is needed when deletion resistance is a priority.
Release integrity and reporting
Public release readiness is separate from functional testing. Production releases require applicable signing, package-integrity, dependency, security, installer, hosting, and real-machine checks before public distribution.
If you believe you found a security issue, use the support address shown in the app or purchase receipt. Include enough detail to reproduce the issue without sending private agent data, recovery codes, credentials, or backup archives.