Back up your Cloudflare. We never hold the backups.

Maelstrom AI builds downpipes: enterprise backup for Cloudflare, covering eight source types including Workers KV, D1 and R2, backed up to storage you control and restorable offline. It runs inside your own Cloudflare account, under keys only you hold. Based in regional Victoria, Australia.

downpipes: no-custody backup and recovery

downpipes is no-custody backup and disaster recovery for the Cloudflare data layer. It deploys as a Worker inside your own Cloudflare account, seals every archive with post-quantum encryption under keys only you generate and hold, and writes to destinations you control. We never see your data.

Runs in your account

A Worker with no public route by default. Your console reaches it over a service binding in your account. It reads your sources on a schedule you set.

No-custody by design

You generate the encryption keys in a guided ceremony and hold them yourself. Maelstrom never receives your data, your keys, or your Cloudflare tokens.

Source-available

The engine and console are published under the Elastic License 2.0. The downpipe offline reader that restores your archives is MIT-licensed, so your recovery path is fully open.

Teams that run on Cloudflare and cannot hand a vendor the keys

Cloudflare's native backup story is thin, and the usual fix is to hand a third-party SaaS standing access to your account so it can copy your data onto its servers. Now your backup vendor is itself a breach target. downpipes exists for teams who want a real backup and recovery story without creating that new point of custody.

No-custody engineering for regulated environments

We design systems that hold as little of your data as possible, ideally none of it.

No-custody architecture

The data paths that would put your backups in our hands are architecturally absent. Not toggled off, not access-controlled. Missing by design.

Applied cryptography

Post-quantum hybrid encryption that seals every archive under keys only you hold. Our code is TypeScript and Go, both memory-safe languages.

Source-available

The code you run is published so you can check it. The offline reader is permissively licensed; the engine that runs in your account is source-available. Trust built on code, not promises.

Regulatory alignment

Built for the data-protection and breach-notification obligations of the Privacy Act (AU), GDPR (EU), and comparable regimes. Our security overview, privacy notices and legal terms are public; the detailed ISMS documents are available on request.

Regional Victoria. Global standards.

Based in St Arnaud, Victoria. We build under Australian privacy law and publish our security overview and legal terms. The code you run is public: the offline reader under the MIT licence, the engine and console under the Elastic License 2.0.