Open-Source Backup Ledger Methodology: How Every Score Is Built
How the Open-Source Backup Ledger scores 16 projects: fixed anchors, public evidence only, separate rankings for platforms, tools and database tools.
Part of the Open-Source Backup Ledger (edition 2026-10-02). The results are in the overview and the project reports. The Ledger uses the same method as the VM Platform Ledger; this page covers what is specific to open-source backup.
Who this is for
IT teams and system integrators who want to run, support or resell open-source backup in traditional enterprise environments: VMs, physical servers, databases, file servers and tape. Many of them are leaving VMware for Proxmox, XCP-ng or KVM and need backup that follows them. No project or vendor was briefed on, paid for or reviewed any score.
What is in scope
A project is included when its core is under an OSI-approved licence, it shipped a release in the last 12 months (dormant projects are kept and marked as such), it has a public repository and issue tracker, and it is built for servers or data centres. Kubernetes-native backup and personal or desktop backup are left for separate Ledgers.
Open-core projects are scored on their open-source edition only. Paid editions, such as Bacula Enterprise, are recorded as facts in the reports and belong to the commercial backup Ledger.
Three kinds of project
The 16 projects are not like-for-like, so every ranking is also shown per kind:
| Kind | What it is | Projects |
|---|---|---|
| Backup platform | Scheduler, catalogue and central management | Bacula Community, Bareos, Proxmox Backup Server, Amanda, UrBackup, Xen Orchestra, BackupPC, Burp |
| Backup tool | A backup engine driven by scripts or a thin UI | BorgBackup, restic, Kopia, Relax-and-Recover |
| Database backup tool | Built for one database family or a few | pgBackRest, Barman, WAL-G, Percona XtraBackup |
Tools and database tools score low in the domains outside their purpose (a PostgreSQL tool does not back up VMs). That is by design: the capability scale is shared with the commercial backup Ledger so that open-source and commercial products can be compared directly.
The scores
| Dimension | Scale | Direction | What it measures |
|---|---|---|---|
| Capability | 0 to 100 | Higher is better | Ten domains scored 0 to 5 against fixed anchors and weighted |
| Momentum | Points | Higher is better | Capability gained since the end of 2022 |
| Credibility | 0 to 25 | Higher is better | Cadence, roadmap transparency, say-do, velocity, lifecycle stability |
| Sustainability risk | 0 to 25 | Lower is better | Maintainer concentration, backer health, licence-change risk, abandonment signs, security response |
| Technical lock-in | 0 to 25 | Lower is better | Formats, export path, stack coupling, hardware or cloud coupling, skills |
| Support and ecosystem | 0 to 20 | Higher is better | Paid support, consultants and partners, documentation, community and Linux packaging |
| AI leverage | 0 to 20 | Higher is better | AI for protection, AI platform stack, AI-assisted operations, agent openness |
| Ledger Index | 0 to 100 | Higher is better | A weighted blend of all of the above |
Sustainability risk replaces the commercial risk used for commercial products: with open source the question is less what the next renewal costs and more whether the project will still be maintained. Support and ecosystem replaces integrator fit for the same reason.
Capability domains and anchors
| Domain (weight) | 3 = solid | 5 = reference |
|---|---|---|
| Virtual and physical servers (12) | Linux and Windows server backup; VM backup for at least one hypervisor with changed-block tracking | Agentless VM backup for VMware, Proxmox and KVM, application-aware, thousands of clients |
| Databases and applications (12) | One major database with point-in-time recovery | Several database families with log shipping, PITR, parallelism and verification |
| Recovery (14) | File-level and full restore; restore verification | Instant or live VM restore, bare-metal, cross-platform restore, automated restore tests |
| Cyber resilience (14) | Immutable or append-only repositories; encryption | Object lock, isolated or pull-based repositories, tamper detection, malware or anomaly checks |
| Storage efficiency and targets (10) | Dedupe or compression; disk and object storage | Global dedupe, many back ends incl. tape, lifecycle tiers |
| Long-term retention and tape (6) | Retention policies | Tape libraries with WORM, archive tiers |
| Replication and DR (10) | Copy or sync to a second site | Scheduled, verified replication with failover runbooks and bandwidth control |
| Security and compliance (8) | Client-side encryption, authenticated access | Roles, audit log, key management, signed releases, published audit |
| New-platform support for VMware leavers (8) | Agentless backup for Proxmox or KVM | Agentless changed-block backup for Proxmox, XCP-ng, oVirt, OpenStack and VMware |
| Management at scale and automation (6) | CLI and config files suitable for automation | Central web console, REST API, Ansible or Terraform, monitoring exporters |
Only released capability counts; betas and release candidates count half a step at most. History is scored at the end of 2016, 2019 and 2022 and today, always against these same anchors, so a project's line only rises when something ships.
Ledger Index weights
Capability 35, credibility 20, buyer safety 20 (sustainability risk and lock-in, inverted), AI leverage 10, support and ecosystem 10, momentum 5. The interactive Ledger offers other presets (risk-averse buyer, innovation-first, support-first). The index starts in 2023, because credibility, risk and support are scored from the 2023 to 2026 record; earlier years show capability and AI only.
Evidence
Every fact in the underlying research carries a source URL and a grade: A when the primary source (release notes, changelog, repository, official pricing) was opened, B for secondary sources, C for inferences. Release dates were checked automatically against GitHub and git tags; where a GitHub release page was created years after the real release, the tag or changelog date is used. Project-health figures (stars, issues, contributors) were read from the GitHub and GitLab APIs on 1 and 2 October 2026; some yearly commit figures are samples, so trends rely on contributor counts and release cadence.
The say-do record compares what each project said it would do (roadmap pages and their history, milestones, issues, beta notes) with what later shipped.
What the scores are not
They are not a measure of popularity, and they are not a recommendation for any one environment. Archetype labels such as "Dormant" or "One-maintainer project" are short readings of the scores, not separate scores. The Ledger will be refreshed twice a year, re-checking each project's stated plans as shipped, slipped or dropped.
Related reading
More from Open-Source Backup Ledger 2026
- Overview: all platforms side by side
- Amanda Community: Open-Source Backup Ledger 2026
- BackupPC: Open-Source Backup Ledger 2026
- Bacula Community: Open-Source Backup Ledger 2026
- Bareos: Open-Source Backup Ledger 2026
- Barman: Open-Source Backup Ledger 2026
- BorgBackup: Open-Source Backup Ledger 2026
- Burp: Open-Source Backup Ledger 2026
- Kopia: Open-Source Backup Ledger 2026
- Percona XtraBackup: Open-Source Backup Ledger 2026
- pgBackRest: Open-Source Backup Ledger 2026
- Proxmox Backup Server: Open-Source Backup Ledger 2026
- Relax-and-Recover: Open-Source Backup Ledger 2026
- restic: Open-Source Backup Ledger 2026
- UrBackup: Open-Source Backup Ledger 2026
- WAL-G: Open-Source Backup Ledger 2026
- Xen Orchestra: Open-Source Backup Ledger 2026