Docs Developers Sign in ← Site
Docs / Guardian (CCTV backup)

Guardian: off-site CCTV backup from your DVR

Your recorder already knows how to upload to an FTP server. Point it at CloudBox and every clip it sends is sealed on arrival and kept off-site in the UK — so the footage survives the break-in, the fire, or the recorder walking out of the door.

How it works

  1. You create a site in the Cameras tab. Your browser generates a key pair: the public half goes to CloudBox, the private half becomes a 24-word recovery kit that never leaves your browser.
  2. The DVR uploads to ingest.cloudbox.biz using the login card we give you — its own “Upload to FTP” feature, nothing to install, no hardware on your network.
  3. We seal each file as it streams in. Every file is sealed the moment it arrives: encrypted in memory with a key made from your site's public key, then written to UK storage. Only the 24-word recovery kit shown when you created the site can open it — CloudBox holds no key that can, and neither would anyone who broke in.
  4. You see it in the dashboard: sites, cameras detected, last clip, storage used, and a Decrypt & save button that opens any clip in your browser with the 24 words.
Heads upThis is not end-to-end encryption: a stock DVR cannot encrypt for us, so the hop from your DVR to CloudBox is plain FTP (or FTPS where the DVR supports it), and the plaintext exists briefly in our ingest process while it streams. Anyone claiming end-to-end from a stock DVR is describing something the DVR cannot do.

Set it up

  1. Open your dashboardCamerasStart free.
  2. Add a site, name the place, generate keys, and write down the 24 words. Tick the box to confirm, then Create site.
  3. Copy the login card into your recorder's FTP settings: Hikvision · Dahua · Reolink. Other brands: any “upload to FTP” screen takes the same values.
  4. Trigger some motion, then press Test connection on the site card and watch it go from “waiting for login” to “connected — 4 cameras detected”.
Field on the DVRWhat to enter
Server / Host / Server Addressingest.cloudbox.biz
Port21
User namethe site's site_… login from your Cameras tab
Passwordthe password shown once when you created the site (issue a new one from the site card if you lost it)
Directory / Remote path/ — any directory structure the DVR wants to create is fine
ModePassive (PASV), if asked. No inbound ports are opened on your network.
EncryptionFTPS / explicit TLS if your model offers it; otherwise plain FTP
TipAny directory structure the recorder wants to create is accepted. Guardian works out the camera from the folder or file name (ch01, D4, camera names, Hikvision and Reolink naming) and files everything by camera and day.

What arrives, and how it is named

Recorders upload event snapshots (JPEG), short video clips (MP4, or Dahua's .dav), or both, depending on the brand and the options you enable. Every file is sealed the same way and indexed with its size, arrival time and a SHA-256 of the original — the integrity record for evidential use. Guardian keeps the recorder's own file name and files it under site / camera / day.

Plans, retention and downloads

  • Free: 10 GB, one site, unlimited cameras, 7-day retention. Never expanded or charged.
  • Paid (not open for purchase yet): £9.99 / 250 GB, £19.99 / 1 TB, £39.99 / 3 TB per site per month, 31-day retention, extra storage £8.99/TB.
  • When a plan is full the recorder's uploads are refused until retention frees space. Nothing already stored is deleted, and you get one email when it happens and one when uploads resume.
  • A camera that goes quiet for 3 hours after having uploaded gets an offline alert email — most owners only discover a dead camera when they need it.
NoteA browser viewer with a timeline is the next phase. Until then, Decrypt & save in the Cameras tab downloads and decrypts any clip in your browser; the key never leaves the page.

Questions

Is my footage end-to-end encrypted?

No, and we say so plainly. A stock DVR cannot encrypt for us, so footage travels to CloudBox over FTP (or FTPS where the DVR supports it) and is encrypted the moment it arrives, with a key made from your site's public key. Once stored, only your 24-word recovery kit can open it; CloudBox holds no key that can.

What if I lose the 24 words?

The footage sealed with that key is unrecoverable — by you, by us, by anyone. That is the point of the design. Print the recovery kit and keep it somewhere safe. If it is lost, create a new site (a new key) and point the DVR at it; old clips stay sealed.

Which recorders work?

Any DVR, NVR or camera with an “upload to FTP” setting: Hikvision (and Hilook, Annke and other Hikvision OEMs), Dahua (and Lorex, Amcrest and other Dahua OEMs), Reolink PoE and Wi-Fi cameras and NVRs, Uniview, Swann and most others. We have written step-by-step guides for Hikvision, Dahua and Reolink.

How much storage does a camera need?

A camera on motion-clip upload (the FTP default) sends roughly 13.5 GB a month; full motion recording about 97 GB; continuous 24/7 recording about 648 GB. The free tier's 10 GB with 7-day retention comfortably covers a 2–3 camera shop on motion clips.

How long is footage kept?

7 days on the free tier and 31 days on paid plans (aligned with ICO guidance for CCTV), after which the oldest clips are purged automatically. Storage is counted exactly as it is used.

Can CloudBox staff view my footage?

No. Stored footage is ciphertext we cannot open; the only key exists in your recovery kit. We can see when clips arrive, their sizes and which camera they came from — which is what powers offline alerts.