AES-256 backup encryption
Backup archives are encrypted before storage to help protect sensitive business information.
Security built on practical engineering and real-world recovery experience.
MindShield Backup Platform uses layered controls to protect business-critical backup data throughout its lifecycle. Encryption, authenticated communication, role-based authorization, tenant isolation and infrastructure boundaries work together to reduce operational risk while supporting reliable recovery.
MindShield was created by the engineers behind Mind Merge Data Recovery Services. For more than two decades, our work has involved helping organizations recover after storage failures, ransomware attacks, damaged databases, RAID incidents and unsuccessful recovery attempts.
A backup is valuable only when it remains secure, accessible and recoverable.
Our security philosophy
Protecting critical data requires multiple independent controls. MindShield follows a defense-in-depth approach where identity, authentication, authorization, encryption, infrastructure security and recoverability reinforce one another.
“A backup is only valuable when it remains secure, accessible and recoverable.”
Security by design
No single feature is treated as the entire security boundary. Protection is distributed across data, identity, transport, authorization and infrastructure layers.
Backup archives are encrypted before storage to help protect sensitive business information.
Communication between the Windows Agent, Cloud API and Dashboard is protected through HTTPS.
Each deployed Agent authenticates with the platform before configuration or operational requests are accepted.
Administrative access is governed through role and organization-aware permissions for multi-organization environments.
Hierarchical authorization is reinforced at the database layer to help isolate tenant-scoped records.
Public services operate on Linux infrastructure behind Nginx with HTTPS enforced across external endpoints.
The current Private Beta focuses on controlled Microsoft SQL Server backup workflows using compression, AES-256 encryption and administrator-configured local storage.
Roadmap boundary: cloud replication and immutable storage are in active development and are not yet available.
Multi-tenant security
MindShield was designed for multi-organization environments. Access decisions combine organization hierarchy, role-based permissions and database-level enforcement to help ensure users can reach only authorized organizations and resources.
Requests are evaluated using user identity, membership, role and effective organization scope.
Tenant-scoped records are protected through database policies as a defense-in-depth boundary.
The application uses a non-superuser database identity without PostgreSQL BYPASSRLS privileges.
Platform security
Each platform layer has a defined role and is separated from the public marketing website.
Security principles
Users and services receive only the permissions required for their defined responsibilities.
Sensitive backup data is encrypted before storage and protected while transmitted between platform components.
Organizations remain logically separated through layered application authorization and database controls.
Security decisions should strengthen the ability to recover critical business data—not obstruct it.
Implemented capabilities are documented accurately and clearly separated from planned enhancements.
Controls evolve through implementation, review, operational experience, customer feedback and ongoing improvement. The same discipline is applied repeatedly as the platform matures.
In active development
These capabilities are planned for future releases and are not presented as currently available functionality.
We welcome good-faith vulnerability reports that help protect customers, partners and the platform. Reports are reviewed confidentially and investigated promptly.
Email security@mindshieldpk.comDo not send passwords, encryption keys, customer data or backup archives by email.
Frequently asked questions
Yes. Backup archives are encrypted using AES-256 before they are written to configured storage.
The platform uses hierarchical organization-aware authorization reinforced by PostgreSQL Row-Level Security for tenant-scoped records.
No. The Agent is designed for controlled backup-related operations and does not expose a general-purpose remote execution capability.
Not in the current Private Beta. The present release uses administrator-configured local storage. Cloud replication is in active development.
Not yet. Multi-Factor Authentication is listed as an active security roadmap item and is not represented as an implemented feature.
Not yet. Independent assessment is planned, and certifications or audit claims will only be published after completion and evidence review.
Engineering commitment
As MindShield evolves, this page will be updated to reflect implemented security controls and clearly distinguish them from future enhancements.
Built by people who have spent more than two decades recovering data after failures. That experience continues to shape every engineering decision behind MindShield.