Client Backup and Restore
Download a complete, self-contained backup of one client, with every record, the full document history and every file, and restore it as a new client.
A client backup is one ZIP that holds everything Bedrock GRC keeps about one client. Use it to hand a program over, to keep an off-system record at the end of an engagement, to move a client to another Bedrock GRC deployment, or as a per-client safety copy.
Download a backup
Open the client's Import / export page and choose Download a full backup (.zip). It needs edit access to the client (admins, and consultants whose access there is Edits), and works on archived clients too. People who only read the client, and assessors, cannot take one, because a backup is every file at once. Each backup is written to the client's audit trail.
The ZIP contains:
| File | Contents |
|---|---|
README.txt | What the backup is and how to restore it. |
backup.json | Every record: profile, contacts, team, goals, appetite, risks, adopted frameworks and answers (objective answers included), which partner firm holds which framework, issued assessments, snapshots, roadmap (with links to issued assessments), calendar events, engagement log, vendors and their reviews, assets, documents with every version and their full history, and the client's audit trail as a record (without IP addresses, which only admins see in the app). |
workbook.xlsx | The same data as a readable Excel workbook. |
files/ | Every uploaded document and evidence file, decrypted. |
A backup holds the client's documents in the clear
Files are decrypted into the backup so that it can be read without Bedrock GRC's encryption key. That also means anyone holding the ZIP can read the client's policies, diagrams and evidence. Keep backups somewhere encrypted, and delete them when you no longer need them.
Restore a client
Only an admin can restore a backup, because a backup carries who is on the client, which partner firm holds which framework and its issued assessments. Open Clients → New client and use Restore a client from a backup. Upload the ZIP exactly as it was downloaded. The page shows the size limit (2,048 MB by default).
- A restore always creates a new client, in one transaction. It never changes an existing client. If the name is taken, the new client's name says it was restored.
- Reference numbers, dates, statuses and history are kept.
R-012is stillR-012, and a document's approvals and reviews are as they were. - Every file is checked against its recorded SHA-256 and encrypted again with this deployment's key.
- People: you become the restored client's lead. Other staff come back, with their access, when an active account with the same email exists. Assessors are never added back: the restore lists who was left out, so an admin can assign them again on purpose.
- Partner firms: a framework held by a firm stays held only if a firm with the same name exists; otherwise it comes back with Foxx Cyber staff, and the restore says so. Issued assessments come back as they were, and each says it was restored from a backup and not issued on this deployment, so an edited backup cannot pass as the firm's word.
- Framework answers travel by framework and control reference, so they land on the same controls on any deployment.
- Portal links are never part of a backup. Create new ones after a restore.
What a client backup leaves out
A client backup covers one client. It does not include team accounts, branding, other clients, the practice-wide audit log, anyone's two-step sign-in, calendar feeds or portal links.