RestoreGuard app icon

RestoreGuard v1.7.3 · Built for Jamf Pro

Zero-gap backup.For every managed Mac.

Backup and restore built for Jamf-managed Macs. RestoreGuard protects each user’s data and settings in storage your organization owns — and puts them back without breaking enrollment.

★ Founding customers get 35% off any plan, price-locked for two years.

The menu bar app

Protection you can see.

Users see exactly what’s protected — and can back up before a trip or bring back a folder they deleted yesterday, without opening a ticket.

  • 86 sTypical incremental backup with the native scan engine
  • <2 sFrom backup complete to the console showing the result
  • 5–15 sBackup integrity verification time per device
  • 30 minFleet-wide deployment through a standard Jamf policy

The problem

Traditional backup breaks
a managed Mac.

Time Machine, Migration Assistant, disk cloners and consumer backup agents were built for personal Macs. They copy the whole machine — including the parts that belong to the device, not the user.

01

The restore brings back the old machine.

A whole-Mac restore carries the previous install’s MDM enrollment records, device certificates, Platform SSO and Company Portal registration, keychains and Apple Account identity onto the new install. None of it matches the Mac it now runs on.

02

Jamf loses the Mac. The user loses the day.

Profiles stop applying, the MDM channel and single sign-on break, the login keychain won’t unlock, AirDrop and Continuity go dark. The standard fix is the one nobody wants: erase the Mac, re-enroll it, and set it up again by hand.

03

RestoreGuard restores the user, not the machine.

It backs up documents, desktop, application data and settings — everything the user keeps at the top of their home folder — and knows what is bound to the device, so it never restores it. The Mac keeps its Jamf enrollment, and every restore comes from a backup verified within the last 24 hours.

Recovery, the managed way

Built for the erase‑and‑re‑enroll workflow.

The same flow works for a repaired Mac or a brand-new replacement — it comes back managed, compliant and familiar.

  1. Erase

    Wipe the Mac — or unbox its replacement.

  2. Re-enroll

    Automated Device Enrollment brings it back into Jamf.

  3. Install

    Your normal policy installs the RestoreGuard agent.

  4. Restore

    Pick a restore point in the console — or let the user do it from the menu bar.

  5. Back to work

    Enrollment intact. No wipe, no rebuild by hand.

Features

Designed for admins
who move fast.

Every feature is built around real Jamf workflows — silent deployment, PPPC profiles, webhooks, and zero user interaction required.

Jamf-native PKG deployment

Drop the signed, notarized package in a Jamf policy and every enrolled Mac gets the agent, daemon and menu bar app — silently, at enrollment. No custom scripting required.

Real-time fleet status

After every backup the agent checks in immediately. No 30-minute polling lag.

<2 s

Daily verification

Each Mac checks the backup it actually uses — proof for auditors that it’s readable, not just present.

Selective restore and merge

Choose exactly what comes back. Merge mode adds files alongside existing ones — nothing is deleted. Existing Time Machine backups can be restored from too.

Your cloud, your data

Back up to your own Amazon S3 bucket or any S3-compatible storage. Every file is encrypted on the Mac before upload, with per-device keys escrowed to your admin console.

Full audit trail

Every admin action logged with timestamp and operator. One-click CSV export.

Jamf inventory sync

Names, users, models and enrollment status — and new Macs register themselves via the ComputerEnrolled webhook.

User-initiated backups

Before a software update, before a trip, or anytime something important changes — users back up on demand from the menu bar, and every run shows up in the console’s audit trail.

Inside the product

One console. One menu bar.
Total control.

Admins run the fleet from the web console. Users see exactly what’s protected — and can help themselves — from the menu bar app on every Mac.

Admin console

Everything an admin needs to prove the fleet is recoverable — live, not last-sync.

  • Live dashboard — fleet compliance at a glance, backup freshness, real-time check-ins
  • Device inventory — synced from Jamf, enriched with backup health, storage and OS version
  • Backup and restore history — per-folder detail and the macOS version on every snapshot
  • Groups and policies — per-group schedules, include and exclude rules, retention windows
  • Encryption key escrow — per-device cloud keys, encrypted at rest, every retrieval audit-logged
  • Alerts and access control — Slack and Teams routing, MFA, admin / technician / read-only roles

Menu bar app

A native macOS app on every managed Mac — informative enough to build trust, safe enough to hand to users.

  • Live status — backup progress, next scheduled run, connected-drive detection
  • On-demand backup — one click before an OS update or a trip, fully audit-logged
  • Restore picker — whole snapshot or hand-picked folders, with a merge mode that never deletes
  • Time Machine import — restores the user’s home folder from existing Time Machine backups
  • Cloud restore — pull the encrypted cloud backup back, whole or per folder
  • Safety rails — warns before restoring from a newer macOS, and never breaks Jamf enrollment

Security and privacy

Your data never
touches our servers.

Backups go straight from each Mac to storage you own. RestoreGuard’s servers hold metadata only — device health, backup history and snapshot indexes.

Where RestoreGuard data goes Encrypted backup data travels directly from each Mac to storage you own. Only metadata goes to the RestoreGuard console, and the console has no path to your backup data. ENCRYPTED BACKUP DATA METADATA ONLY No data relay Your MacEncrypts before upload Your storageS3 · S3-compatible · drives RestoreGuard consoleHealth · history · indexes Where RestoreGuard data goes Encrypted backup data travels directly from each Mac to storage you own. Only metadata goes to the RestoreGuard console, and the console has no path to your backup data. ENCRYPTEDDATA METADATAONLY Your MacEncrypts before upload Your storageS3 · drives ConsoleMetadata only No data relay between them

Encrypted on the Mac

Cloud backups are encrypted client-side before a single byte leaves the device, with a unique key per device.

Recoverable keys

Per-device keys are escrowed to your admin console, encrypted at rest with AES-256-GCM, so a wiped Mac can always be recovered.

Encrypted drives

External drive backups use APFS encryption with a key controlled by the device owner.

Secure transport

Agent-to-server traffic uses HTTPS with TLS 1.2+. API keys are scoped per organization and can be rotated at any time.

Two-factor and roles

TOTP two-factor sign-in, invite-based onboarding, and admin, technician and read-only roles.

Every action on record

Each admin action is logged with a timestamp and operator, with one-click CSV export for compliance reviews.

Backup destinations

Your cloud. Your drives.
Your rules.

RestoreGuard orchestrates — you own. Connect your cloud credentials once and every Mac backs up directly to your infrastructure.

Amazon S3

Back up directly to a bucket in your own AWS account with scoped IAM credentials. Each Mac uploads straight to the bucket.

Your bucketScoped IAM keysDirect upload

S3-compatible storage

Bring Backblaze B2, Wasabi, MinIO or a custom endpoint. Same encrypted-mirror workflow, often at a fraction of the storage cost.

Backblaze B2WasabiMinIOCustom endpoint

External drives

Encrypted APFS or HFS+ drives attached to each Mac, with Time Machine-style hard-link snapshots. No cloud account required.

APFS encryptedHard-link snapshotsWorks offline

Hybrid mode runs cloud and external drive backups side by side.

How it works

Up and running
in 30 minutes.

A standard Jamf workflow: two configuration profiles and one package, all downloaded from your admin console. No build scripts, no custom scripting, no re-enrollment.

  1. 1

    Sign in and set your policy

    Your admin console is ready the moment you sign up. Pick the schedule and the destination — an encrypted external drive, your own S3 bucket, or both.

  2. 2

    Download two profiles and the agent

    A settings profile with your server address and enrollment token, a Full Disk Access (PPPC) profile, and the signed, notarized agent package.

  3. 3

    Upload to Jamf and scope

    Upload both profiles under Configuration Profiles, add the package to a policy that runs at enrollment, and scope it to a Smart Group. Profiles first, package second.

  4. 4

    Macs enroll themselves

    On first launch each Mac swaps the shared enrollment token for its own key and checks in. Inventory sync and the ComputerEnrolled webhook keep the device list current.

  5. 5

    Back up, verify, restore

    Backups run on schedule or on demand, every backup is verified within 24 hours, and a restore is a few clicks in the console or the menu bar.

Admin console › Settings › Agent deployment
# Downloads — ready the moment you sign in✓ RestoreGuard-Agent-Enrollment.mobileconfig✓ RestoreGuard-FullDiskAccess-PPPC.mobileconfig✓ RestoreGuard-1.7.3.pkg  signed · notarized # Jamf Pro → Configuration Profiles → Upload (both profiles)# Jamf Pro → Policies → install at enrollment → scope: All Managed › MBP-0042 enrolled · checked in 2 s after install› Policy applied · first backup scheduled tonight 22:00

Jamf Pro 10.45+ · Smart Groups · Extension Attributes · Webhooks · PPPC profiles

Integrations

Works with the tools
you already use.

Jamf Pro

PKG deployment, webhooks, inventory sync and Smart Groups.

Slack

Failure alerts, compliance digests and restore notifications.

Microsoft Teams

Backup alerts and reports with per-severity routing.

Email (SMTP)

Your own SMTP server for reports, alerts and invites.

Single sign-on Soon

OIDC for Entra ID, Google Workspace, Okta and more.

Pricing

Priced per device.
Simply.

Start with monitoring and local backup, add cloud orchestration when you’re ready, and upgrade to enterprise continuity for compliance-critical fleets.

Tier 1

Monitoring and Local Backup

$3/device/mo · billed yearly

Founding: $1.95 /device/mo, locked for 2 years

Protect a Jamf-managed fleet with local external drive backup and full compliance visibility.

  • Incremental backups to encrypted external drives
  • Full restores from the console or the menu bar
  • Daily backup verification
  • Backup health and compliance dashboard
  • Jamf inventory sync and group policies
  • Time Machine import
  • Audit log with notes
Apply for founding access

Tier 3

Enterprise Continuity Platform

$8/device/mo · billed yearly

Founding: $5.20 /device/mo, locked for 2 years

For large enterprises and MSPs that need a dedicated instance and compliance reporting.

Everything in Tier 2, plus:

  • Dedicated single-tenant instance
  • Scheduled compliance reports and export
  • Anomaly detection with per-device baselines
  • Device changes and cross-device migration
  • Custom retention (7–90 days)
  • Dedicated onboarding engineer
Apply for founding access

Founding customers get 35% off any plan, price-locked for two years — limited spots while the founding group is open. Full plan details at restoreguard.io

What’s new

Shipping, constantly.

v1.7.3 Latest

Whole home folder · Time Machine from another Mac · Drive backups on schedule only

Backups now include everything at the top of each user’s home folder, with project folders backed up whole. Drive restores bring back Finder tags, custom icons, extended attributes, ACLs, permissions, hard links and folder dates.

v1.7.1

Daily verification · Cloud restore points · Restores that keep the Mac managed

Every Mac verifies the backup it actually uses once a day. Cloud backups record a restore point on every run, and restores leave device-bound state alone — Apple Account and AirDrop identity, keychains, Platform SSO and Company Portal registration.

v1.7.0

Encrypted cloud backup · Time Machine restore · Native-engine speed

Encrypted cloud backup to your own S3 or S3-compatible bucket, with per-device keys escrowed to the console. The native scan engine cut typical incremental backups from over 30 minutes to under 90 seconds.

v1.6.5

Portal security · MFA · Roles · Alerting

Two-factor authentication, invite-based onboarding, admin / technician / read-only roles, and Slack and Microsoft Teams alerting with per-severity routing.

Full changelog on restoreguard.io

Requirements

macOS Sequoia 15 or laterOn Mac computers with Apple silicon.
Jamf Pro 10.45 or laterDeploys as a standard PKG plus PPPC profile.
Your own bucket — optionalS3 or S3-compatible for cloud backup; drive backup works on its own.

FAQ

Common questions.

Will a restore break Jamf enrollment or single sign-on?

No. RestoreGuard backs up the user — documents, desktop, application data and settings, and everything else they keep at the top of their home folder — and deliberately leaves out everything bound to the device: MDM enrollment and profiles, device certificates, Platform SSO and Company Portal registration, keychains, Apple Account and AirDrop identity. After a restore the Mac stays enrolled and compliant; users sign back into apps that keep their credentials in the login keychain.

What does recovering an erased or replacement Mac look like?

The workflow you already use: erase the Mac (or unbox the new one), let Automated Device Enrollment bring it into Jamf, and let your normal policy install the agent. Then pick the device and a restore point in the admin console — or let the user do it from the menu bar app. RestoreGuard closes open apps before it touches settings, and recommends a restart when it finishes.

Where is backup data stored?

Entirely in your infrastructure — encrypted APFS or HFS+ drives attached to each Mac, your own Amazon S3 bucket, or S3-compatible storage such as Backblaze B2, Wasabi or MinIO. Cloud backups are encrypted on the device before upload, and every destination uses your credentials and your account. The RestoreGuard server stores metadata only: device health, backup history and snapshot indexes.

Do I need Jamf Pro?

RestoreGuard is designed around Jamf Pro but the core backup and restore works without it. Jamf unlocks inventory sync, Smart Group targeting, webhook-based enrollment and enrollment verification before restores, and backup health can be surfaced in Jamf inventory with the Extension Attribute script in the Jamf Integration guide.

Which Macs are supported?

The agent requires macOS Sequoia 15 or later on Apple silicon. Intel Macs and earlier macOS versions aren’t supported. The management server is cloud-hosted and maintained by CodeFuzion — there’s nothing to run on your end.

Is RestoreGuard self-hosted or cloud-hosted?

The management server is cloud-hosted and fully managed; self-hosted options are on the roadmap. This refers only to the management server — your backup data always lives in your own infrastructure and never passes through our servers.

Your fleet deserves
better.

Deploy in 30 minutes. Full-featured from day one.

Already a customer? Sign in to the customer portal