Mr.PlanB Logo
    Open-Source Backup Ledger 2026
    Ledger
    Open-Source Backup Ledger 2026

    Open-Source Backup Ledger Methodology: How Every Score Is Built

    How the Open-Source Backup Ledger scores 16 projects: fixed anchors, public evidence only, separate rankings for platforms, tools and database tools.

    Edition October 2, 20268 min read

    Part of the Open-Source Backup Ledger (edition 2026-10-02). The results are in the overview and the project reports. The Ledger uses the same method as the VM Platform Ledger; this page covers what is specific to open-source backup.

    Who this is for

    IT teams and system integrators who want to run, support or resell open-source backup in traditional enterprise environments: VMs, physical servers, databases, file servers and tape. Many of them are leaving VMware for Proxmox, XCP-ng or KVM and need backup that follows them. No project or vendor was briefed on, paid for or reviewed any score.

    What is in scope

    A project is included when its core is under an OSI-approved licence, it shipped a release in the last 12 months (dormant projects are kept and marked as such), it has a public repository and issue tracker, and it is built for servers or data centres. Kubernetes-native backup and personal or desktop backup are left for separate Ledgers.

    Open-core projects are scored on their open-source edition only. Paid editions, such as Bacula Enterprise, are recorded as facts in the reports and belong to the commercial backup Ledger.

    Three kinds of project

    The 16 projects are not like-for-like, so every ranking is also shown per kind:

    KindWhat it isProjects
    Backup platformScheduler, catalogue and central managementBacula Community, Bareos, Proxmox Backup Server, Amanda, UrBackup, Xen Orchestra, BackupPC, Burp
    Backup toolA backup engine driven by scripts or a thin UIBorgBackup, restic, Kopia, Relax-and-Recover
    Database backup toolBuilt for one database family or a fewpgBackRest, Barman, WAL-G, Percona XtraBackup

    Tools and database tools score low in the domains outside their purpose (a PostgreSQL tool does not back up VMs). That is by design: the capability scale is shared with the commercial backup Ledger so that open-source and commercial products can be compared directly.

    The scores

    DimensionScaleDirectionWhat it measures
    Capability0 to 100Higher is betterTen domains scored 0 to 5 against fixed anchors and weighted
    MomentumPointsHigher is betterCapability gained since the end of 2022
    Credibility0 to 25Higher is betterCadence, roadmap transparency, say-do, velocity, lifecycle stability
    Sustainability risk0 to 25Lower is betterMaintainer concentration, backer health, licence-change risk, abandonment signs, security response
    Technical lock-in0 to 25Lower is betterFormats, export path, stack coupling, hardware or cloud coupling, skills
    Support and ecosystem0 to 20Higher is betterPaid support, consultants and partners, documentation, community and Linux packaging
    AI leverage0 to 20Higher is betterAI for protection, AI platform stack, AI-assisted operations, agent openness
    Ledger Index0 to 100Higher is betterA weighted blend of all of the above

    Sustainability risk replaces the commercial risk used for commercial products: with open source the question is less what the next renewal costs and more whether the project will still be maintained. Support and ecosystem replaces integrator fit for the same reason.

    Capability domains and anchors

    Domain (weight)3 = solid5 = reference
    Virtual and physical servers (12)Linux and Windows server backup; VM backup for at least one hypervisor with changed-block trackingAgentless VM backup for VMware, Proxmox and KVM, application-aware, thousands of clients
    Databases and applications (12)One major database with point-in-time recoverySeveral database families with log shipping, PITR, parallelism and verification
    Recovery (14)File-level and full restore; restore verificationInstant or live VM restore, bare-metal, cross-platform restore, automated restore tests
    Cyber resilience (14)Immutable or append-only repositories; encryptionObject lock, isolated or pull-based repositories, tamper detection, malware or anomaly checks
    Storage efficiency and targets (10)Dedupe or compression; disk and object storageGlobal dedupe, many back ends incl. tape, lifecycle tiers
    Long-term retention and tape (6)Retention policiesTape libraries with WORM, archive tiers
    Replication and DR (10)Copy or sync to a second siteScheduled, verified replication with failover runbooks and bandwidth control
    Security and compliance (8)Client-side encryption, authenticated accessRoles, audit log, key management, signed releases, published audit
    New-platform support for VMware leavers (8)Agentless backup for Proxmox or KVMAgentless changed-block backup for Proxmox, XCP-ng, oVirt, OpenStack and VMware
    Management at scale and automation (6)CLI and config files suitable for automationCentral web console, REST API, Ansible or Terraform, monitoring exporters

    Only released capability counts; betas and release candidates count half a step at most. History is scored at the end of 2016, 2019 and 2022 and today, always against these same anchors, so a project's line only rises when something ships.

    Ledger Index weights

    Capability 35, credibility 20, buyer safety 20 (sustainability risk and lock-in, inverted), AI leverage 10, support and ecosystem 10, momentum 5. The interactive Ledger offers other presets (risk-averse buyer, innovation-first, support-first). The index starts in 2023, because credibility, risk and support are scored from the 2023 to 2026 record; earlier years show capability and AI only.

    Evidence

    Every fact in the underlying research carries a source URL and a grade: A when the primary source (release notes, changelog, repository, official pricing) was opened, B for secondary sources, C for inferences. Release dates were checked automatically against GitHub and git tags; where a GitHub release page was created years after the real release, the tag or changelog date is used. Project-health figures (stars, issues, contributors) were read from the GitHub and GitLab APIs on 1 and 2 October 2026; some yearly commit figures are samples, so trends rely on contributor counts and release cadence.

    The say-do record compares what each project said it would do (roadmap pages and their history, milestones, issues, beta notes) with what later shipped.

    What the scores are not

    They are not a measure of popularity, and they are not a recommendation for any one environment. Archetype labels such as "Dormant" or "One-maintainer project" are short readings of the scores, not separate scores. The Ledger will be refreshed twice a year, re-checking each project's stated plans as shipped, slipped or dropped.

    Related reading

    More from Open-Source Backup Ledger 2026