RestorSignal Documentation

An independent testing third party

Why verification is performed by a system separate from the one that produces and interprets the backup.

A system that produces a backup, chooses what should be tested, runs the restore itself, and then interprets its own result combines four distinct roles with no outside observation at all. This is not an accusation leveled at backup tools specifically — it is a structural observation that holds for any system whatsoever. An actor that is both judge and party over its own result cannot, by construction, offer the same guarantee as a check carried out by a separate system.

Separating production, selection, control, and qualification

RestorSignal rests on the explicit separation of four functions:

  1. Producing the backup remains entirely the responsibility of the client's own backup tool — Veeam, PBS, Hyper Backup, or whatever other mechanism is already in place.
  2. Selecting the object to test remains the client's decision, never RestorSignal's (see Division of responsibilities).
  3. Controlling the restore — the technical execution of the test — is carried out by RestorSignal, on a system separate from the one that produced the archive.
  4. Qualifying the result — PASS, FAIL, or ERROR, and building the evidence package — is also produced by RestorSignal, from facts observed during execution, never from simply reading back the status already reported by the backup tool.

None of these four functions is carried out by the same system as the other three. That separation, not a claim of competence, is what gives the result its value.

Independent execution, not provenance certification

This independence covers the execution of the control and the qualification of its result — never the origin of the artifact being tested. These are two different claims, never to be confused or substituted for one another:

  • RestorSignal never says: "this backup genuinely comes from production." In Local mode especially, nothing technically prevents whoever controls the host from supplying an artifact that isn't the real production backup — that is a structural limit of the model, not a gap in the control's rigor.
  • RestorSignal asserts: from the artifact explicitly submitted for testing, an identified, versioned protocol was applied, the results actually observed were recorded, and a verifiable evidence package — never reinterpreted after the fact — was produced from them.

It is this second, precise and verifiable claim that gives the service its value — never a guarantee about the provenance of what was submitted for testing.

Complementary, not adversarial

RestorSignal never positions itself against backup software vendors. A backup tool's native controls and an independent verification serve complementary purposes: the former monitors whether the backup job ran, the latter verifies what can actually be restored from it. The backup software produces. RestorSignal verifies.

Audit the method, don't just take our word for it

RestorSignal's credibility does not rest on a declaration of trust but on the client's ability to audit the method itself: control rules are documented, test scenarios are versioned, every conclusion must be traceable back to the observations that produced it, and the limits of what was actually verified are stated explicitly rather than left unsaid. RestorSignal never presents itself as a certification body: it produces independent verification and an evidence package, not an official certification in the regulatory sense of the term.

Documentation version : 1.1Last reviewed : 2026-08-15