Home / Sentryx / Sentryx Specification
Sentryx
Data protection, simplified.
Sentryx is a modular, open-source cloud backup and data protection system designed to provide secure, resilient, privacy-focused data protection for individuals, organizations, distributed storage environments, and enterprise infrastructure.
The specification defines Sentryx as a collection of independent core modules and optional plugin modules. Each module is designed to provide a distinct capability while communicating through defined interfaces and services. Modules should remain replaceable, independently scalable, and independently maintainable wherever practical.
Specification Goals
Sentryx is designed around the following goals:
- Provide secure and reliable backup and recovery.
- Encrypt user data before transmission whenever client-side encryption is enabled.
- Minimize dependency on any single storage provider or infrastructure vendor.
- Support personal, organizational, distributed, and enterprise deployments.
- Provide strong authentication, authorization, auditing, and security controls.
- Support local-first operation where practical.
- Allow storage infrastructure to scale independently from application services.
- Provide optional intelligent automation without requiring cloud-based AI services.
- Maintain clear separation between backup, storage, identity, security, monitoring, and intelligence functions.
- Support extensibility through independently developed plugins.
- Provide transparent and auditable data protection operations.
Core Architecture
Sentryx shall use a modular architecture in which major system capabilities are implemented as independent modules.
Core modules provide the fundamental functionality required to operate Sentryx as a backup and data protection system.
Optional plugin modules extend functionality without requiring changes to the fundamental backup architecture.
Modules should communicate through defined interfaces rather than relying on tightly coupled internal implementations.
A deployment may enable or disable optional capabilities according to its requirements.
Core Backup Engine Module
The Core Backup Engine Module provides the fundamental backup and restore data model.
It shall support:
- Incremental backups.
- Full system snapshots.
- Deduplication.
- Compression.
- Versioned backup chains.
- Restore points.
- Scheduled backups.
- Manual backups.
- File system change tracking.
- Include and exclude rule management.
- Backup integrity verification.
- Cross-platform backup operations.
- Backup metadata management.
- Backup state tracking.
- Backup failure detection.
- Backup retry handling.
The module shall maintain a consistent relationship between source data, backup versions, metadata, and restore points.
Backup operations should be designed so that storage backends can be replaced without requiring changes to the core backup logic.
Encryption and Key Management Module
The Encryption and Key Management Module provides cryptographic protection for backup data and associated metadata.
It shall support:
- End-to-end client-side encryption.
- Zero-knowledge storage architecture.
- Modern strong encryption standards.
- Unique encryption keys for backups or snapshots.
- Manual key rotation.
- Automated key rotation.
- Secure key derivation from user-controlled passphrases.
- Optional hardware-backed key storage.
- Encrypted backup metadata.
- Optional file-name encryption.
- Secure key lifecycle management.
- Key recovery mechanisms.
- Optional key escrow mechanisms.
- Protection against unauthorized server-side decryption.
When configured for zero-knowledge operation, the storage service shall not require access to the keys necessary to decrypt user backup contents.
Storage Backend Module
The Storage Backend Module abstracts physical and logical backup storage from the rest of the system.
It shall support:
- S3-compatible object storage.
- Self-hosted object storage.
- Distributed storage.
- Multi-node storage.
- Erasure coding.
- Replication.
- Cross-region replication.
- Hot storage.
- Warm storage.
- Cold storage.
- Immutable storage.
- WORM storage modes.
- Storage quotas.
- Storage lifecycle policies.
- Snapshot retention policies.
- Storage health monitoring.
- Storage capacity monitoring.
The module shall permit storage providers and storage architectures to be changed without requiring changes to backup clients or authentication services.
Client Agent Module
The Client Agent Module provides the local interface between user devices and Sentryx services.
It shall support:
- Lightweight background operation.
- Command-line operation.
- Graphical user interfaces where available.
- Local encryption before upload.
- Offline backup queueing.
- Bandwidth throttling.
- Battery-aware scheduling.
- Backup status reporting.
- Restore workflows.
- Device registration.
- Multi-device account association.
- Local backup state management.
- Connection recovery.
- Interrupted transfer recovery.
The client agent should continue managing queued operations when network connectivity is unavailable and resume operations when connectivity is restored.
Authentication and Identity Module
The Authentication and Identity Module manages users, organizations, devices, sessions, and permissions.
It shall support:
- OAuth 2.0.
- OpenID Connect.
- Role-based access control.
- Multi-tenant organizations.
- Two-factor authentication.
- TOTP authentication.
- Device authorization.
- Session tracking.
- Session revocation.
- Fine-grained permission scopes.
- Organization-level access controls.
- User-level access controls.
- Authentication event logging.
- Integration points for login anomaly detection.
Authentication and identity services shall remain separate from storage services so that storage systems do not inherently require access to user credentials.
API Gateway Module
The API Gateway Module provides controlled access to Sentryx services.
It shall support:
- REST APIs.
- Optional GraphQL APIs.
- API versioning.
- API key management.
- Rate limiting.
- Abuse protection.
- Request validation.
- Request logging.
- Audit event generation.
- Webhooks.
- Backup event notifications.
- Restore event notifications.
- API access controls.
The API Gateway shall provide a consistent interface for external applications, administrative interfaces, client agents, and plugins.
Web Dashboard Module
The Web Dashboard Module provides an administrative and user-facing interface for Sentryx.
It shall support:
- Backup status overview.
- Restore point browsing.
- Backup history.
- One-click restore workflows.
- Storage usage visualization.
- Storage analytics.
- Device management.
- User management.
- Security settings.
- Two-factor authentication management.
- Key management interfaces.
- Session management.
- Audit log viewing.
- Role and permission management.
- Organization management.
- Multi-organization workspaces.
The dashboard shall consume system capabilities through defined services and APIs rather than directly depending on storage implementation details.
Monitoring and Observability Module
The Monitoring and Observability Module provides visibility into system health and backup operations.
It shall support:
- Backup success tracking.
- Backup failure tracking.
- Restore operation tracking.
- System health metrics.
- Storage performance monitoring.
- Storage health monitoring.
- Resource utilization monitoring.
- Alert generation.
- Email notifications.
- Webhook notifications.
- Metrics export.
- Structured logging.
- Centralized logging integrations.
- Anomaly detection interfaces.
Monitoring data should provide sufficient information to identify failed backups, degraded infrastructure, storage problems, authentication events, and operational anomalies.
Scheduling and Automation Module
The Scheduling and Automation Module manages automated backup and maintenance operations.
It shall support:
- Cron-style schedules.
- Event-driven backup triggers.
- Automatic backup retries.
- Automatic pruning.
- Retention policies.
- Scheduled maintenance.
- Load-aware scheduling.
- Device-aware scheduling.
- Multi-device coordination.
- Storage lifecycle automation.
- Automated integrity verification.
Scheduling logic should remain independent from the underlying storage system and backup data model.
Disaster Recovery Module
The Disaster Recovery Module provides recovery capabilities for catastrophic data loss, infrastructure failure, corruption, and other recovery scenarios.
It shall support:
- Full system restoration.
- Partial restoration.
- Granular file recovery.
- Cross-device restoration.
- Cross-system restoration.
- Integrity verification.
- Checksum verification.
- Corruption detection.
- Corruption recovery.
- Multi-node failover.
- Offline restoration.
- Snapshot rollback.
- Secure key recovery.
- Optional key escrow recovery.
- Disaster recovery orchestration.
Recovery workflows shall preserve backup integrity and provide clear verification of recovered data where practical.
Security and Hardening Module
The Security and Hardening Module provides system-wide security controls.
It shall support:
- Zero-trust architectural principles.
- Immutable backups.
- Ransomware-resistant backup configurations.
- Intrusion detection integration points.
- IP allowlists.
- IP denylists.
- Optional geographic restrictions.
- API abuse detection.
- Tamper-resistant audit logging.
- Suspicious activity detection.
- Automatic session invalidation.
- Security event reporting.
- Administrative security policies.
Security controls should be independently configurable and should not require changes to the underlying backup storage model.
Deployment and Infrastructure Module
The Deployment and Infrastructure Module defines the mechanisms required to deploy, operate, scale, and maintain Sentryx.
It shall support:
- Containerized deployment.
- Self-hosted deployment.
- Hybrid cloud deployment.
- Distributed deployment.
- Horizontal service scaling.
- Horizontal storage scaling.
- Load balancing.
- Automated deployment workflows.
- Environment-based configuration.
- Infrastructure automation.
- Configuration validation.
- Service health checks.
- Deployment health monitoring.
Infrastructure configuration shall remain separate from application logic wherever practical.
Storage Optimization and Efficiency Module
The Storage Optimization and Efficiency Module reduces storage consumption, transfer requirements, and operational overhead.
It shall support:
- Adaptive deduplication.
- Context-aware deduplication.
- Delta-based storage.
- Efficient storage of large files.
- Efficient storage of databases.
- Efficient storage of virtual machine images.
- Bandwidth-aware synchronization.
- Intelligent backup pruning.
- Automatic cold-storage migration.
- Predictive compression selection.
- File-type-aware compression.
- Storage footprint analytics.
- Backup efficiency analysis.
Optimization mechanisms shall preserve the integrity and recoverability of backup data.
High-Assurance Enterprise Module
The High-Assurance Enterprise Module provides capabilities for environments requiring enhanced resilience, governance, auditing, and operational guarantees.
It shall support:
- Multi-region failover.
- High-availability clusters.
- Configurable service objectives.
- Backup service objectives.
- Compliance-oriented operating modes.
- Privacy controls.
- Immutable forensic logging.
- Hardware security module integration.
- Air-gapped master key architectures.
- Enterprise role-based access control.
- Enterprise policy management.
- Disaster recovery orchestration.
- Audit exports.
- Compliance reporting.
- Administrative policy enforcement.
Enterprise capabilities should remain modular so that smaller deployments are not required to operate unnecessary enterprise services.
AI-Assisted Backup Intelligence Module
The AI-Assisted Backup Intelligence Module provides optional intelligence for backup prioritization, scheduling, anomaly detection, and recovery workflows.
It shall support:
- Smart backup prioritization.
- File importance detection.
- Identification of documents, source code, media, configuration files, and other potentially important data.
- Critical data prioritization under bandwidth constraints.
- Behavioral scheduling.
- Activity pattern analysis.
- Ransomware detection assistance.
- Suspicious file activity detection.
- Predictive backup optimization.
- Natural-language restore queries.
- Intelligent backup recommendations.
AI processing should be local-first whenever practical.
AI functionality shall remain optional and Sentryx shall remain functional without a cloud-based AI dependency.
AI-generated recommendations shall not automatically override user-defined backup, security, retention, or deletion policies unless explicitly configured to do so.
Optional Plugin Modules
Sentryx shall provide a plugin architecture allowing additional functionality to be developed independently from the core modules.
Plugins should use documented interfaces and should not require modification of unrelated core modules.
Optional plugins may include the following capabilities.
External Storage Plugin
Provides additional storage provider integrations.
Potential capabilities include:
- Additional object storage providers.
- Network storage systems.
- Specialized archival storage.
- Distributed storage networks.
- Removable storage.
- Custom storage backends.
Encryption Plugin
Provides optional cryptographic integrations beyond the default encryption module.
Potential capabilities include:
- Alternative encryption implementations.
- Specialized key management.
- Hardware security integrations.
- External key management services.
- Organization-specific cryptographic policies.
Authentication Plugin
Provides additional authentication and identity integrations.
Potential capabilities include:
- Alternative identity providers.
- Enterprise authentication systems.
- Hardware authentication.
- Custom identity providers.
- Organization-specific authentication policies.
Notification Plugin
Provides additional notification mechanisms.
Potential capabilities include:
- Email.
- Messaging services.
- Mobile notifications.
- Administrative alerts.
- Incident notifications.
- Custom webhook destinations.
Dashboard Extension Plugin
Extends the Sentryx user interface.
Potential capabilities include:
- Custom dashboard panels.
- Additional analytics.
- Administrative widgets.
- Custom reporting interfaces.
- Organization-specific views.
- UI themes.
Backup Source Plugin
Provides additional data sources for backup operations.
Potential capabilities include:
- Databases.
- Virtual machines.
- Containers.
- Network services.
- Application-specific data.
- Cloud application data.
- Custom data sources.
Restore Target Plugin
Provides additional restoration destinations.
Potential capabilities include:
- Alternate devices.
- Network locations.
- Cloud destinations.
- Virtual machines.
- Application environments.
- Custom restoration targets.
Compliance Plugin
Provides additional governance and compliance functionality.
Potential capabilities include:
- Compliance reports.
- Retention enforcement.
- Legal hold workflows.
- Audit exports.
- Policy verification.
- Regulatory reporting.
Threat Detection Plugin
Provides additional security analysis.
Potential capabilities include:
- Malware detection integrations.
- Ransomware detection.
- Behavioral analysis.
- File anomaly detection.
- Threat intelligence integrations.
- Security event correlation.
Analytics Plugin
Provides extended operational and storage analytics.
Potential capabilities include:
- Capacity forecasting.
- Cost analysis.
- Backup performance analysis.
- Storage efficiency reporting.
- Usage reporting.
- Organization-level analytics.
Automation Plugin
Provides custom event-driven workflows.
Potential capabilities include:
- Pre-backup actions.
- Post-backup actions.
- Pre-restore actions.
- Post-restore actions.
- Custom scheduled tasks.
- Administrative workflows.
- External service triggers.
Plugin Requirements
Plugins shall:
- Use documented plugin interfaces.
- Declare their capabilities.
- Declare required permissions.
- Operate within defined security boundaries.
- Avoid unnecessary access to user data.
- Respect encryption and authorization controls.
- Provide clear configuration requirements.
- Provide failure reporting.
- Avoid modifying unrelated core functionality.
- Be independently installable where practical.
- Be independently removable where practical.
Plugins that process user data shall clearly identify what data they access and why that access is required.
Data Protection Principles
Sentryx shall follow these architectural principles:
Encryption Before Transmission
Where client-side encryption is enabled, sensitive backup contents shall be encrypted before leaving the originating device.
User-Controlled Keys
Users and organizations should retain meaningful control over the keys required to decrypt their data.
Separation of Duties
Authentication, storage, encryption, backup processing, monitoring, and administration should remain logically separated.
Storage Independence
The backup system should not depend on a single storage provider.
Recovery First
Backup operations shall be designed around successful and verifiable recovery rather than merely successful data upload.
Integrity Verification
Backup data should be verifiable through checksums, hashes, manifests, or equivalent integrity mechanisms.
Least Privilege
Users, services, plugins, and administrators should receive only the permissions required for their assigned functions.
Auditability
Security-sensitive and data-management operations should generate auditable events.
Modularity
Core functionality should remain replaceable and independently maintainable.
Extensibility
New capabilities should be added through modules and plugins wherever practical instead of expanding tightly coupled core services.
Local-First Intelligence
Optional intelligent functionality should favor local processing and should not require transmission of user data to third-party AI services by default.
Backup Integrity and Verification
Sentryx shall provide mechanisms for determining whether backup data remains complete and usable.
Verification should include:
- Backup manifest validation.
- Checksum validation.
- Metadata validation.
- Snapshot consistency checks.
- Storage object verification.
- Restore-point verification.
- Optional scheduled verification.
- Corruption reporting.
Verification failures shall be recorded and exposed through monitoring and administrative interfaces.
Retention and Lifecycle Management
Sentryx shall support configurable retention policies.
Retention policies may define:
- Number of restore points.
- Time-based retention.
- Backup frequency.
- Storage tier transitions.
- Automatic pruning.
- Immutable retention periods.
- Organization-specific policies.
- Dataset-specific policies.
Retention policies shall not remove protected or legally retained data when an applicable protection policy prevents deletion.
Security Events and Auditing
Sentryx shall maintain auditable records for security-sensitive operations.
Auditable events should include:
- Authentication attempts.
- Authentication failures.
- Two-factor authentication events.
- Session creation.
- Session revocation.
- Permission changes.
- Backup creation.
- Backup failures.
- Restore operations.
- Key-management operations.
- Configuration changes.
- Administrative actions.
- Plugin installation.
- Plugin removal.
- Security alerts.
Audit records should support tamper-resistant storage and controlled export.
Specification Branding License (SBL)
Standard
- Fully AGPL-3.0+ compliant system
- Copyleft enforced for network deployments
- Required attribution:
- Roxanne Ardary
- https://www.roxanneardary.com/
Optional
- Specification Branding License (SBL)
- Attribution-free commercial deployment
- Pricing based on scale, usage, and deployment scope
- https://roxanneardary.com/sentryx/
License & Notice Requirements
Sentryx is released under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
By contributing to this project, you agree that your contributions will also be released under this license.
Please note the following:
- All contributions must comply with the AGPL-3.0+ terms.
- Under Section 7 of the license, all redistributions, forks, and derivative works must preserve attribution to:
Roxanne Ardary and roxanneardary.com. - Sentryx specifications are free to use with attribution. A Specification Branding License can be negotiated upon request.
- The project’s notice.md file tracks attribution requirements and contributor acknowledgments. Any update that adds new contributors or modifies attribution should also update
notice.md. - When submitting a pull request, ensure that any new files maintain the attribution headers where applicable.
- Network-deployed versions of this software must also remain fully AGPL-3.0+ compliant, including exposure of source code modifications when applicable under the license.
For full legal details, please refer to the AGPL-3.0+ license and the project’s notice.md file.
Notice – Sentryx
Attribution Requirement: Under Section 7 of the AGPL 3.0+ license, all redistributions, forks, and derivative works, including network-deployed versions of this project, must provide attribution to Roxanne Ardary and roxanneardary.com.
Contributors
This file tracks contributors and their specific contributions to the project.
- Roxanne Ardary, roxanneardary.com – May 11, 2026
Created the Sentryx repository and established the initial architecture for a modular, open-source cloud backup and data protection system. - [Add other contributors here] – [Date]
[Describe contribution in one sentence]
License – Sentryx
This repository is licensed under the GNU Affero General Public License v3.0 or later (AGPL-3.0+).
Key Points
- You are free to use, modify, and distribute the code.
- All redistributions, forks, and derivative works or network-deployed versions must also be licensed under AGPL-3.0+ and provide attribution to Roxanne Ardary and roxanneardary.com as required under Section 7 of the license.
- The software is provided “as is,” without warranty of any kind.
For the full license text, see GNU AGPL-3.0 License.
