Back up your Cloudflare. We never hold the backups.
downpipes is enterprise backup for Cloudflare: eight source types including Workers KV, D1 and R2, backed up to storage you control and restorable offline. It runs inside your own Cloudflare account, seals every archive with post-quantum encryption under keys only you hold. We never see your data.
The problem
Your Workers KV, D1, R2, Secrets Store, and account configuration are the backbone of your product. Cloudflare's native backup story is thin, and the usual fix is to hand a third-party SaaS standing access to your account so it can copy your data onto its servers.
Now your disaster-recovery vendor is itself a breach target, holding a copy of everything and a key into your account. The thing meant to protect you becomes the thing most worth attacking.
Our approach
downpipes never takes custody. The backup engine is a routeless Cloudflare Worker you deploy into your own tenant. It reads your data, seals it with post-quantum hybrid encryption under keys you generate and hold, and writes the archives to destinations you control.
Maelstrom never sees your data, never holds your keys, and keeps no standing path into your account. None of your backup data or keys are on our side for anyone to breach or subpoena.
Runs in your account. Sealed under your keys.
1. Deploy in your account
The engine is a routeless Cloudflare Worker that runs inside your own tenant. No public route, and no inbound path from us. It reads your sources on a schedule you set.
2. Sealed under your keys
Every archive is sealed with post-quantum hybrid encryption. You generate the keys in a guided in-browser ceremony and store the break-glass key offline. We never receive them.
3. 3-2-1 fan-out
Each source can be written to two or more independent destinations you control. Workers KV, D1, R2, Secrets Store, and 313 zone and account configuration surfaces.
4. Proven recovery
Hourly canary integrity flights test the backup and restore path to your destination with a known test corpus. With the opt-in operational key, scheduled in-account restore drills prove that your backups restore. Signed reports give you the evidence.
Who holds what
No party other than you holds the keys that open your backups.
| Party | Holds | Never holds |
|---|---|---|
| You (the customer) | Your data, your encryption keys, your backup destinations | N/A |
| Maelstrom AI (vendor) | The software, a signed update channel, the licence and customer record of a paid plan, and beacon data if you turn the beacon on | Your keys, your backup data, your Cloudflare tokens |
| Cloudflare | The edge compute and storage your engine runs on | Your backups in plaintext (every archive is sealed before it lands) |
Even Maelstrom disappearing cannot lock you out. The MIT-licensed downpipe offline reader restores from archive bytes plus your key and your pinned signer, with no vendor and no network, built from a frozen public format specification. Your last-resort recovery path is fully open and forkable.
What ships
| Component | Role |
|---|---|
| engine | In-tenant backup Worker. Reads, seals, fans out. Runs in your account. |
| console | Operator console for configuration, restore approvals, posture, and reports. |
| control-plane | Vendor-side licence tokens and a content-free advisory beacon. Holds none of your keys or backup data. |
| downpipe | MIT offline reader. Restores from archive bytes plus your key and pinned signer, with no vendor and no network. |
| update channel | Static, signature-pinned R2 bucket. The engine verifies and pulls; it is never pushed to. |
Updates are pull-only and signature-pinned. When you apply an update from the console, the engine verifies it against a pinned public key and settles it behind a canary integrity flight. If the canary fails while the console page is open, the engine rolls the update back automatically. The engine sends no telemetry unless you turn on the advisory beacon, which is off by default. On each cron tick, the engine checks the signed update channel at update.downpipes.io with a GET for two static files. Cloudflare adds a CF-Worker header to that request, and the header names the engine's zone. To stop the check, unset UPDATE_CHANNEL_URL.
The licence is fail-open by design. A missing, expired, or forged licence degrades to the free tier; it never gates backup or restore. The control-plane holds no customer keys, backup data or Cloudflare tokens, so its compromise cannot read a single archive.
Observability by consent, never a back door
downpipes runs dark: no telemetry by default and no standing vendor access. The no-inbound property is part of every edition, including the free one.
When you want help, you mint a time-boxed, scoped, immediately-revocable read-only credential and send a redaction-safe, signed support bundle. We can diagnose an issue without a permanent path into your account and without your data ever leaving it.
- Scored security posture with regression alerts
- Hourly canary integrity flights
- Notification rules that page your operator on failure
- Owner-minted, revocable, read-only diagnostic access
- We dogfood it: Maelstrom's entire Cloudflare estate is backed up by our own production instance of downpipes
Source-available, and free to run yourself
downpipes is source-available under the Elastic License v2. You are free to read it, run it yourself in your own Cloudflare account, and rely on it, for free. The licence on its own does not allow you to provide downpipes to others as a hosted or managed service. It also does not allow you to remove its licence notices or bypass its licence key checks.
A managed-service provider can run downpipes for its clients under the MSP / MSSP rider. It deploys the engine and console in each client's own Cloudflare account and holds operational access to them. The provider and each client agree who holds that client's keys. Maelstrom still holds no keys and no backup data. The downpipe offline reader is MIT-licensed, so your recovery path is fully open.
- Engine and console: source-available (Elastic License v2); the control plane is operated by Maelstrom and not published
- Offline reader: open source (MIT)
- Free to self-host, no licence required to back up or restore
- Managed-service providers: an MSP / MSSP rider grants the right to run downpipes for clients
- Paid enterprise support available
Available now
downpipes is available now. It is source-available today and free to self-host. Paid plans add support, and a Custom plan adds help to deploy it in your Cloudflare estate.