Duplicati: Encrypted Incremental Backups to Cloud Storage, Reviewed
Store securely encrypted backups in the cloud!
At a glance
- What is it?
- Duplicati is an MIT-licensed C# backup client that encrypts, compresses and deduplicates data before sending it to S3, B2, SFTP, WebDAV and other remote targets. It is a good fit for scheduled client-side backup to cheap object storage, and a poor fit if you want a single Go binary with no server process.
- Who is it for?
- Adopt Duplicati if you need scheduled, client-side encrypted backups pushed to cheap object storage or a remote file server, and you are willing to run its server process and manage a passphrase you cannot lose. Do not adopt it if you want a single static binary with no web UI, or if you need to back up a whole machine image rather than files.
- Can I use it commercially?
- Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
- Is it still maintained?
- Yes. The repository last received commits 4 days ago.
- What is it written in?
- Mainly C#, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Duplicati is and the problem it targets
The README frames the project around three requirements: keep data safe, store it remotely, and back it up regularly. That combination is the actual problem. A local external drive protects against disk failure but not fire or theft. Plain rsync to a remote server protects against both but uploads everything readable, so a compromised or curious host sees your files. Duplicati sits between those: it encrypts and compresses each backup before it leaves the machine, then uploads to a destination that only ever sees opaque blocks.
The audience follows from that. It is for people who already pay for or want cheap object storage (Amazon S3, Backblaze B2, IDrive e2, Storj DCS, Tencent COS, Aliyun OSS, Google Cloud, Azure) or who have an FTP, WebDAV or SSH (SFTP) endpoint available. It is also for Windows users with locked files, since the README lists Volume Snapshot Service (VSS) support on Windows and Logical Volume Manager (LVM) on Linux. It is not aimed at image-level disaster recovery of a whole machine, and the README never claims that.
How the encryption and incremental backup chain works
The README states that Duplicati uses AES-256 encryption, or GNU Privacy Guard, to secure all data before uploading, and that only the initial backup carries full contents while additional backups are differential. Those two facts define the data flow. Your passphrase is used locally to encrypt and compress file data; the destination receives encrypted blocks plus whatever metadata the client needs to reconstruct the chain. The remote side never holds the key.
The practical consequence is that the passphrase is the entire recovery story. If you lose it, the destination holds ciphertext you cannot read, and no support channel can help, because the project never has your key. This is a deliberate design choice, not an accident, and it is the same trade-off every client-side encrypted backup tool makes.
The README also lists a built-in scheduler, an integrated updater that notifies you of new releases, and filters for folders, specific file types or custom rules. Those are the levers that keep a backup current without manual runs. Backup destinations are pluggable rather than hardcoded, which is why the same client can talk to object storage and to a plain SFTP server.
Installing Duplicati and running a first backup
The README does not give command-line install steps. It points to the download page at duplicati.com/download, states that the beta release notifies you of updates and can upgrade with a single click or a terminal command, and says releases are available for Windows, macOS and Linux. It also notes that all releases are GPG-signed with the public key 3DAC703D, and that the latest signature file and ASCII signature file are on the Duplicati download page.
So the first real step is fetching the package for your platform and verifying its signature against that key. The README gives the key identifier to look up, and the repository's own build tooling shows how the front-end assets are compiled:
npm run build:styleThat script, taken from the repository's package.json, runs stylelint, compiles dark.less and default.less into stylesheets, and post-processes them with autoprefixer. It is the build step for the web interface, not for the release package, and it is useful only if you are building from source rather than installing a published release.
After installation you get either the application or the command-line tool, both listed as available in the README.
The README says the beta release will automatically notify you of updates, and that you can choose another update channel in the UI or on the command line. That matters more than it looks. The project publishes canary builds alongside stable ones, and the release list shows a stable build dated 2026-09-03 with canary builds on 2026-09-04 and 2026-09-11. If you want fewer surprises, confirm which channel you are on before the first backup rather than after.
The first backup itself is a UI or CLI exercise: pick the source folders, pick a destination from the supported list, set a passphrase, and let the initial full backup run. Everything after that is differential by design.
Where Duplicati is the wrong tool
The clearest boundary is that Duplicati is a file backup client, not a disk imaging product. The README describes backing up folders, file types and filters. If your requirement is bare-metal restore of an operating system, this is not that, and the documentation does not present it as that.
The second boundary is operational. Duplicati is a C# application with a web-based interface and a server component, not a single static binary you drop on a machine and forget. The repository layout reflects that: there is a Duplicati.slnx solution file, a WebserverCore.Client.UsageExample directory, a Server webroot with its own less and CSS build pipeline, and a package.json whose scripts compile dark.less and default.less into stylesheets. That is a real application with a front end, and it carries the maintenance surface of one.
The third boundary is the passphrase model already described. Strong client-side encryption is a benefit right up to the moment the passphrase is lost, at which point it becomes the reason your data is unrecoverable. Any deployment that cannot guarantee the passphrase survives the person who set it should not use this design.
Duplicati compared with restic and Kopia
The two comparisons people search for most are restic and Kopia, and the difference is architectural rather than cosmetic. Both of those are written in Go and ship as a single command-line binary; the backup engine, the repository format and the CLI are the product. Duplicati is a C# application with a graphical interface, a server process and a scheduler, and it exposes both a UI and a command-line tool. If your environment is a headless server where you want one binary and a cron entry, the Go tools fit that shape more directly. If your environment is a desktop or a small office machine where someone needs a window with a schedule and a restore button, Duplicati's shape fits better.
Destination support is the second axis. The README lists a long roster: Amazon S3, IDrive e2, Backblaze B2, Box, Dropbox, FTP, Google Cloud and Drive, MEGA, Microsoft Azure and OneDrive, Rackspace Cloud Files, OpenStack Swift, Storj DCS, SSH (SFTP), WebDAV, Tencent COS and Aliyun OSS. That breadth, including consumer sync services like OneDrive and Google Drive, is unusual and is a genuine reason to pick it over a CLI-only tool that expects an S3-compatible endpoint.
Neither comparison changes the encryption story: all three encrypt client-side, and all three make the key your responsibility.
Licence, releases and what upgrades cost you
The README states Duplicati is licensed under the MIT license. The repository's licence field is recorded as NOASSERTION, which means the automated classifier did not match the file to a known licence text rather than that the project is unlicensed; the README and the LICENSE file in the repository root are the sources to read. MIT is permissive, so redistributing or embedding the client is not the constraint here. The practical constraint is that MIT gives you no warranty, and backup software is exactly the category where that matters. Nothing in the licence obliges anyone to recover your data.
Upgrade cost is mostly a channel decision. The README says the beta release notifies you of updates and can upgrade with a single click or a terminal command, and that you can pick another update channel in the UI or on the command line. The release history shows a stable build on 2026-09-03 followed by canary builds on 2026-09-04 and 2026-09-11, so canary is moving roughly weekly. Staying on stable is the lower-effort path; following canary means accepting that a build may change behaviour between runs. The repository's last push was on 2026-09-21, which is the same day as this review's reference point, so the project is not dormant.
Verification is the one recurring cost you should not skip. Because releases are GPG-signed, each upgrade is a chance to check the signature against key 3DAC703D rather than trusting the transport.
Editorial conclusion
Adopt Duplicati if you need scheduled, client-side encrypted backups pushed to cheap object storage or a remote file server, and you are willing to run its server process and manage a passphrase you cannot lose. Do not adopt it if you want a single static binary with no web UI, or if you need to back up a whole machine image rather than files. Before trusting it, verify the GPG signature on the release, confirm the version you install sits on the stable channel rather than a canary build, and run one restore of a small folder to a scratch directory.
Frequently asked questions
What is Duplicati used for?
It is a backup client that stores encrypted, incremental and compressed backups on cloud storage services and remote file servers. The README lists destinations such as Amazon S3, Backblaze B2, Google Drive, OneDrive, FTP, WebDAV and SSH (SFTP).
Is Duplicati free to use?
Yes. The README states that Duplicati is free and open source, and that it is licensed under the MIT license. There is no paid tier described in the README.
Is Duplicati open source?
The README describes it as a free, open-source backup client and states it is licensed under the MIT license. The repository also carries a LICENSE file at its root.
Is Duplicati safe to use?
The README states that Duplicati uses AES-256 encryption, or GNU Privacy Guard, to secure all data before uploading, so the destination only holds encrypted data. That also means your passphrase is the recovery path: without it the uploaded data cannot be read.
How do I install Duplicati on Linux?
The README does not give distribution-specific steps. It directs you to the download page at duplicati.com/download, where releases for Windows, macOS and Linux are published, and notes that all releases are GPG-signed with public key 3DAC703D.
How does Duplicati differ from restic?
Duplicati is a C# application with a graphical interface, a server process and a built-in scheduler, and it is available as an application or a command-line tool. Its README lists a wide set of destinations including consumer services such as OneDrive, Google Drive and Dropbox alongside S3, B2 and SFTP.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/duplicati-duplicati)