Hosting Backups: Who Backs Up What?

Understand the shared responsibility model for hosting backups: what providers back up, what you must export, and how to verify restores with an RPO/RTO checklist.

hosting automationreseller hostingbackupssecurity

You assume your hosting provider backs up everything. They assume you keep your own copies. When a file disappears, both sides point at the other. This guide explains the shared responsibility model for hosting backups, so you know exactly what to expect and how to verify restores.

What is the shared responsibility model for hosting backups?

The shared responsibility model means the provider secures the infrastructure and may offer backups as a service, but you remain responsible for your data's integrity and availability. In practice, most providers back up the server or account, but you must still export databases, emails, and application configurations. The split varies by host, so always read the terms.

What providers typically back up

Most shared and VPS providers perform regular backups of the entire server or account. These usually include:

  • Full account files (home directory, public_html, etc.)
  • Databases (MySQL, PostgreSQL) via snapshots or dumps
  • Email accounts and messages (if using provider's mail service)
  • DNS zones (if hosted with them)
  • Control panel configurations (cPanel, Plesk, etc.)

Retention periods vary: daily backups kept for 7 days, weekly for 30 days, or monthly for a year. Some providers charge for restores or limit the number of restores per month. Always check your provider's backup policy.

What customers must still export or replicate

Even with provider backups, you are responsible for:

  • Application-level data: Some apps store data outside the database (e.g., WordPress uploads are in files, but some plugins use external services).
  • Third-party integrations: API keys, webhook secrets, and external service configurations.
  • Email if using external mail: If you use Google Workspace or Microsoft 365, your provider does not back up those mailboxes.
  • DNS if hosted elsewhere: If your DNS is at a third-party registrar, your provider's backup won't include those records.
  • Compliance data: For GDPR, HIPAA, or other regulations, you may need to retain copies for audit purposes.

Additionally, provider backups are often for disaster recovery, not for individual file restores. If you accidentally delete a file, the provider may not restore just that file; they might restore the whole account to a previous point, overwriting newer data.

How to verify restores with an RPO/RTO checklist

RPO (Recovery Point Objective) is the maximum acceptable data loss measured in time. RTO (Recovery Time Objective) is the maximum acceptable downtime. You need to define these for your business and test them.

Step 1: Define your RPO and RTO

For a blog, an RPO of 24 hours and RTO of 4 hours might be fine. For an e-commerce site, you might need an RPO of 1 hour and RTO of 30 minutes. Write these down.

Step 2: Check your provider's backup schedule and retention

Ask: How often are backups taken? How long are they kept? How do I request a restore? What is the cost? Document the answers.

Step 3: Create your own backup routine

Use plugins or scripts to export databases and files regularly. Store them off-site (e.g., cloud storage, another server). Automate this with cron jobs or a backup service.

Step 4: Test a restore

Once a quarter, restore a backup to a staging environment. Verify that files, databases, and email work. Measure how long it takes. This is your actual RTO.

Step 5: Document and review

Keep a runbook with steps to restore. Update it when your stack changes. Review your RPO/RTO annually or when your business needs change.

Common pitfalls and how to avoid them

Many assume backups are immutable and complete. But backups can fail silently, be corrupted, or be incomplete. Avoid these pitfalls:

  • Not testing restores: A backup is only as good as its last successful restore.
  • Relying solely on provider backups: If the provider goes down, you need your own copy.
  • Ignoring retention limits: If you need a file from 60 days ago and backups are kept for 30, you're out of luck.
  • Forgetting about databases: Files are easy, but databases require consistent dumps.

If you use a billing or automation platform like Teculiar (a platform for hosting, domain, and VPS resellers to build and automate their storefront, billing, and provisioning), check whether it includes backup management features. For pricing and capabilities, see pricing.

What to do next

  • Read your provider's backup policy and note the schedule, retention, and restore process.
  • Set up your own automated backups to an off-site location.
  • Schedule a quarterly restore test and document the results.
  • Define your RPO and RTO, and adjust your backup strategy to meet them.

Start by checking your current backup coverage today.