The backup question nobody asks: has it ever been restored?

“Daily backups” is on every hosting page ever written. It is also the easiest promise in the industry to keep badly, because the failure is completely silent: a backup job that produces an empty file exits successfully, runs again tomorrow, and reports green for months.

We know because it happened to us. For two days our nightly backup produced snapshots containing every file and no databases at all. Every run reported success. Nothing anywhere would have said otherwise, and we only found it by going to restore one.

A backup nobody has restored is a hypothesis

Until a snapshot has been restored and the result inspected, all you know is that a file exists and has a plausible size. You do not know that the database dumped cleanly, that the dump is inside the archive, that the encryption key still works, or that the restore procedure itself does what it says.

So the question to ask a host is not “do you take backups”. It is: when did you last restore one, and how do you know it worked?

What we do about it

  • Every backup asserts its own contents. The run counts the databases it dumped, then counts them again inside the finished snapshot, and fails loudly if the two numbers disagree.
  • A drill runs weekly. It restores the most recent snapshot into a scratch area and checks that each database is really valid SQL containing real WordPress tables โ€” not that a file exists, but that its contents are what a restore would need.
  • Silence counts as failure. A backup that stops running does not leave yesterday’s green tick on the screen. If we have not heard from it, the panel says so.
  • Restore refuses rather than half-applies. If a snapshot turns out to be incomplete, the restore stops before touching your site, and your site stays exactly as it was.

Where the copies live

Encrypted on the server before they leave it, then stored at an EU-owned provider in a different datacentre from the site itself. Sixty daily, eight weekly and six monthly copies. The encryption key is ours, not the storage provider’s, which means the storage provider holds ciphertext and nothing else.

None of that is exotic. It is what “daily backups” was always supposed to mean.