Duplicati

Encrypted backups to any cloud you choose

Files & Sync LGPL-2.1 beginner ★ 15,046 stars

What is Duplicati?

Duplicati stores encrypted, deduplicated, incremental backups on standard cloud storage or a local disk, and runs on a schedule without supervision. It works with any backend rclone also supports, so you keep control over where the encrypted data physically lives. Restores can pull a single file or the whole set back out of the archive.

Best for

Set-and-forget encrypted server backups to cheap object storage

Why choose Duplicati

Duplicati addresses the thing that stops most people from having real backups: the destination costs money and the client is tied to one provider. It backs up to whatever you already have — a cheap object store, a network share, another cloud drive, even a folder on an external disk — and it encrypts everything before it leaves your machine. Because it deduplicates and stores versions, a daily backup of a large photo library uses far less space than most people assume, and the destination never sees your files in readable form.

Replaces

  • Backblaze
  • Carbonite
  • Acronis

Key features

  • AES-256 encrypted backups before upload
  • Deduplication and incremental runs to keep storage small
  • Scheduled jobs with email or webhook reporting
  • Restore single files or full snapshots

What to watch out for

The single most important warning about Duplicati is not about the software, it is about the practice: an untested backup is not a backup. This tool can produce a perfectly healthy-looking backup that cannot be restored, and the only way to know is to actually restore something. Beyond that, very large backups — hundreds of gigabytes — become slow to verify and repair, the database that tracks file blocks can grow awkwardly, and the web interface's schedule handling becomes confusing once you have many jobs. Restore from a fresh machine is also more fiddly than it should be.

How to deploy

  • Docker
  • Windows
  • Linux packages

Getting started

Set a strong encryption passphrase and store it somewhere that is not the machine being backed up — lose it and the backup is noise. Configure the destination and immediately run a small test job on a folder you do not care about, then restore a file from it, so you have proven the loop works before trusting it. Enable the backup retention policy deliberately rather than keeping every version forever. Set up the email or webhook reporting, because a backup that stops running silently is the failure mode that hurts most, and schedule verification of the archives.

Typical setup

The typical deployment is a Docker container or a small service on the machine holding the data, backing up to cheap object storage or a network share, with email notifications for failures. Most people run one job for documents and one for photos, since retention needs differ. Serious users keep a second copy of the backup destination's data somewhere entirely different, on the principle that a backup stored in the same provider you are trying to escape is not really a backup.

Who should look elsewhere

Not suitable as your only backup for irreplaceable data unless you have actually completed and verified a restore, on different hardware, from the archive. Very large datasets are also a poor fit: verification and repair become slow, and the tracking database can grow into an awkward size. Anyone unwilling to test restores should use a simpler tool they will actually verify.

Project health

  • GitHub stars: 15,046
  • Last code push: 2026-09-30
  • Open issues: 617
  • Status: actively developed

Figures pulled from the GitHub API and refreshed periodically.

Duplicati as an alternative

More in Files & Sync