How Do You Keep Off-Site Backups Safe? A Community Guide
Flashback to the Home Server Show days.
Kevin Schoonover dropped a great comment in our Discord that sent me back to a topic we talked about years ago on the Digital Media Zone: off-site backup.
Back then, one of the options we discussed was rotating USB hard drives off-site — perhaps keeping one in a safe deposit box at the bank and swapping it periodically. Another idea that often comes up is putting backup drives in a fireproof safe at home.
Kevin made an important point: a safe that is designed to keep paper from burning is not necessarily designed to protect hard drives, SSDs, USB flash drives, optical discs or other digital media.
A fireproof safe is not automatically a data safe
Fire-resistant containers are rated around what happens inside the safe during a fire, not simply whether flames reach the contents. UL Solutions explains that fire-endurance testing monitors internal temperature and humidity and that the class on the label indicates the maximum internal temperature reached during the test. UL identifies Class 350 for paper products, while lower-temperature classifications are used for more heat-sensitive media. A Class 125 container is designed around a much lower maximum internal temperature than a typical paper-oriented Class 350 container.
That distinction matters. A safe can do its job protecting paper and still expose electronic or magnetic media to conditions those devices were never meant to survive.
Source: UL Solutions — Turning Up the Heat: A Sneak Peek into UL’s Fire Testing of Safes.
The bigger question: how do you keep an off-site backup safe?
This gets us back to the real issue. A backup sitting next to the computer it protects is useful for hardware failure, accidental deletion and plenty of everyday disasters. But it does not necessarily protect you from a house fire, theft, flood or another event that takes out everything at that location.
So I want to turn this into a broader community discussion about what makes an off-site backup genuinely safe. The location matters, but so do the risks at that location, the condition of the media, how often the copy is refreshed, whether it is encrypted, and whether you have actually tested a restore.
Different ways to protect an off-site copy
There is no single right answer. Depending on the data, budget and how much maintenance you are willing to do, an off-site copy might live in several very different places:
- Rotated external drives stored at a trusted second location.
- A bank safe deposit box with drives swapped on a schedule.
- A second NAS at a friend’s house, office or another property.
- Cloud backup such as Backblaze or another provider that keeps a copy outside your home.
- Object storage for more technical or archive-focused workflows.
- A purpose-built data or media safe when the copy needs to remain on-site but requires better heat protection than a paper safe offers.
- A hybrid approach that combines local fast restores with one or more geographically separate copies.
The interesting part is not just where the backup lives. It is how each option handles fire, theft, flood, hardware failure, accidental deletion, account loss, ransomware, stale media and the possibility that nobody remembers to rotate or test the backup for months.
Five questions every off-site backup strategy should answer
No matter which method you use, I think every off-site backup plan should be able to answer the same five questions.
1. How far away is the copy?
Off-site should mean far enough away that one event is unlikely to take out both the primary data and the backup. A drive in a detached garage is better than a drive sitting next to the NAS, but it may still share the same fire, storm, flood, theft or power-event risk. Geographic separation matters.
2. Is the backup encrypted?
Once a drive leaves your house, physical control changes. A disk in a safe deposit box, a NAS at someone else’s house or data stored with a cloud provider all introduce different access risks. Encryption helps make sure that losing control of the media does not also mean losing control of the data.
3. How current is the copy?
A perfectly protected backup that is nine months old may not be very useful. Manual drive rotation works only if the rotation actually happens. Remote replication works only if jobs are completing. Cloud backup works only if important folders are included and the backup client is still healthy. Freshness needs to be something you can verify, not something you assume.
4. What can still destroy or compromise it?
Every option has a failure mode. External drives can fail in storage. Safe deposit boxes can be inconvenient to update. Remote NAS systems can be exposed to ransomware if replication is not designed carefully. Cloud accounts can be lost, misconfigured or become expensive at restore time. A data safe can protect media from heat but still does not create geographic separation. Knowing what your chosen method does not protect against is just as important as knowing what it does.
5. Have you tested a real restore?
This may be the most important question. A backup is only useful if you can restore from it. That means knowing the encryption password, having the right software, understanding the recovery process and periodically proving that the data is readable. The first time you test your recovery plan should not be after the original data is gone.
Think in layers, not in one perfect backup
For many people, the strongest answer will not be one storage location. It will be layers: a fast local backup for everyday recovery, an off-site copy for location-wide disasters, and perhaps a cloud or archival copy for another level of separation.
That is the spirit of the familiar 3-2-1 backup idea: multiple copies, more than one type of storage, and at least one copy somewhere else. The exact tools can change over time. The goal does not.
If your house disappeared tomorrow, would at least one complete copy of your important data still exist somewhere else?
What are you doing for true off-site backup in 2026?
- Rotating hard drives to another location?
- Using a bank safe deposit box?
- Keeping another NAS at a friend’s, family member’s or second location?
- Using Backblaze or another cloud backup service?
- Using object storage?
- Using a fire-rated data/media safe?
- Combining several of these approaches?
Community setup: Bustout’s Synology + CrashPlan approach
Discord member Bustout shared a strong example of a layered off-site strategy:
“I have a Synology NAS. I keep an off site backup at a relatives house. They let me add a large drive to their Synology device to use for my backups. I also use Crashplan to do a separate cloud backup of the same data.”
This is useful because it avoids relying on a single off-site destination. The copy stored on a relative’s Synology provides geographic separation and keeps the data on hardware Bustout can account for directly. CrashPlan adds a second, independent cloud copy of the same data.
I’ve had too many customers lose their data because someone at Microsoft/Amazon/etc flip a bit and the data disappeared never to be seen again.
That experience helps explain why Bustout does not treat any cloud provider as the one and only copy. The cloud can be a valuable layer, but his approach assumes that provider-side mistakes, account problems or unexpected data loss are still possible. The practical lesson is simple: even if you trust a cloud platform, an independent copy under a different failure domain gives you another path back to your data.
Using the five-question framework above, this setup has some clear strengths: the data is physically separated from the primary location, the remote Synology can be updated without manually transporting drives, and the cloud layer adds another failure domain if something happens to either physical NAS. The remaining questions are the same ones every strategy should answer: how the remote copy is encrypted, how quickly changes propagate, what retention/versioning is enabled, and how often a restore is tested.
That is exactly the kind of real-world setup I want to add to this guide as the discussion grows.
More community backup setups
Brian F: local copies plus cloud backup
While my backups are in the cloud, and at home (Time Machine as well as whole-hard drive duplicates), I am looking forward to reading about the wisdom of the community and incorporating some of the ideas brought up into my routines.
Brian’s setup is a good reminder that backup routines evolve. He already has multiple local copies through Time Machine and whole-drive duplicates, plus a cloud copy. What he is looking for now is not necessarily another product, but ideas for improving the overall routine. That is one of the reasons this community approach is useful: sometimes the next improvement is better geographic separation, a more deliberate restore-testing schedule, or simply tightening the process around copies that already exist.
Dan L.: a dedicated Backblaze backup machine
I work off my Synology NAS and then have one mini pc that has about a dozen external drives and it’s only purpose is to back up to Backblaze.
Dan has created a dedicated backup path between his working Synology environment and Backblaze. The interesting part here is the separation of roles: the NAS is where he works, while the mini PC and its external drives exist specifically to stage and push backup data to the cloud. That gives him a distinct backup workflow rather than asking the primary system to do everything.
Bustout: extending the same idea into Proxmox
As I’ve been working more in Proxmox, I’ve also spun up a couple of Proxmox Backup servers (PBS) and I have all my VMs and LXC containers backed up to the primary PBS and all of that gets replicated to the secondary PBS. I haven’t done it yet (because I’m lazy sometimes) but I plan on pushing that to Crashplan too.
Bustout’s newer Proxmox setup adds another layer to the same strategy he already described for his Synology data. His VMs and LXC containers are backed up to a primary Proxmox Backup Server, then replicated to a second PBS. His planned next step is to add CrashPlan as another independent cloud copy.
That progression is worth calling out because it shows how backup systems often grow in layers rather than appearing all at once. First comes a reliable local backup. Then a replicated copy. Then, when time and motivation allow, an independent off-site or cloud layer. The important thing is knowing which layer protects against which failure.
Pest: Carbonite today, planning the next off-site layer
I missed my renewal cancellation window this past year for Carbonite. Carbonite was great when I was running Windows + StableBit DrivePool. It was an easy turnkey solution that was around best pricing at the time with no recovery fees. I did trial recovery runs that were as simple as could be. Backups are encrypted on their side and you can download them to any computer via website. My main server has since migrated to Unraid, so I’m very curious about Unraid 8 with offsite backup integration so I can decommission the old Windows server, which was stripped down to photo and document backup at this point. I’ve got until March for my next cancellation window so I’ll look into Unraid 8, Duplicati, or another off-site option early next year. So at the moment I have dual parity on Unraid, a redundant copy on Windows, and off-site backup to Carbonite.
Pest’s setup is a useful example of a backup strategy in transition. Carbonite worked well in the old Windows + DrivePool environment, and the fact that he has already done trial restores is a big positive. The migration to Unraid changes the shape of the problem: the old Windows box is now serving mostly as a legacy backup layer while he evaluates a cleaner off-site path for the new platform.
It also highlights an important distinction: parity is valuable for keeping a storage array available through drive failures, but it is not a substitute for an independent backup. Pest still has a separate redundant copy plus Carbonite off-site, which gives the system more than one failure domain while he works through the migration.
Orso: Cloud-first, with local and remote copies where they make sense
Orso takes a cloud-first approach for much of his data, but adds local and remote protection based on the type of data involved.
FWIW, I use a Synology DS124 NAS that backs up my two OneDrive accounts. That’s 30Gb of data. Then I have a 550Gb Apple photos library that I back up to an external drive connected to my mac.
I think the main takeway from this is: I trust the cloud as a solid source for my data. And then I have an offsite backup in case I delete something that I shouldn’t have deleted.
Additionally, i have a small movie collection (1TB) and a Calendar running on the Synology DS124 that backs up to a remote DS124 located rent-free at a customer. Movie collections doesnt work very well with cloud services…
What stands out in Orso’s setup is that he is not treating every type of data the same. OneDrive is a trusted primary source for documents and other cloud-friendly data, with the Synology providing another copy. His large Apple Photos library is protected locally on an external drive, while the movie collection and Synology-hosted calendar are replicated to a second DS124 at another physical location.
That illustrates an important point for this guide: the best off-site strategy may depend on the workload. Cloud services can be an excellent fit for documents and smaller personal datasets, while large media collections may be more practical to protect with another NAS or physical storage at a remote site. Orso also frames the off-site copy as protection against accidental deletion, which is a different failure mode than fire or hardware loss but just as important.
Jim S.: Tiered backups based on how important the data is
Jim S. shared one of the clearest examples yet of matching backup frequency and location to the value of the data. His setup combines scheduled local copies, manual local copies, automated cloud backups and a physically isolated full backup in a safe deposit box.
Local, scheduled
Syncthing runs hourly to update a backup of everything from the “gold copy” on my QNAP to my Unraid server.
Local, manual
I have added multi-terabyte drives to a couple of machines and they hold synced copies of some folders that I update a couple times a year.
Offsite, scheduled
The most important files (family videos and photos) backup to Back Blaze daily at 1am. This cost less than $15 a month.
The next most important files backup to OneDrive daily at the completion of the Back Blaze process.
Note: I have 1TB of OneDrive space as part of having a 365 subscription.
Offsite, manual
I have several large (16TB+) USB drives. Each of them can hold a backup of everything, including DVD rips, etc. At least one of these is kept in a safe deposit box at my credit union. I update the backup and swap them out a couple times a year or after a significant event (e.g. photos from a big vacation are added). I have other items and documents that benefit from having a safe deposit box anyway. For only $45 a year I get climate controlled, fire protected, theft protected storage. Can’t beat the price.
About once a quarter I copy all my photos to a folder on OneDrive.
What makes Jim’s approach stand out is the prioritization. He is not trying to give every file the same recovery objective. The most important family photos and videos get daily cloud protection, while the full data set is captured less frequently to large removable drives stored off-site. That keeps cost and maintenance reasonable without treating a ripped movie collection and irreplaceable family media as though they have the same value.
It also shows why manual backups still have a place. A disconnected 16TB drive sitting in a credit-union safe deposit box is inconvenient compared with an always-online backup, but that inconvenience can also be a strength: it is physically separated, offline most of the time, and outside the normal chain of events that could affect the live systems.
This is a community-built post
I’m starting this article before we have all the answers because I want the community to help build it.
If you’re in the Home Gadget Geeks Discord, jump into the discussion and tell us what your current backup strategy looks like. What works? What is inconvenient? What have you changed over the years? Have you ever had to restore from the off-site copy?
If you’re comfortable having your setup, experience or recommendation included in this article, say so in your Discord reply and I’ll credit you. I’ll update this post with useful examples and lessons from the community as the discussion develops.
Thanks to Kevin Schoonover for kicking this one off.
Backup technology has changed quite a bit since the Home Server Show days. The underlying problem really hasn’t.

