Google Workspace. Any S3 bucket.

Backups You Can Prove

Automated backup for every mailbox in your Google Workspace org, restorable on demand, into storage you already own and control.

0-bitAES Encryption
0Storage Providers
0 yrMax Audit Retention
0hMax Session Length

Stop hoping your Google Workspace backups ran.
Start proving they did.

Automated backup for every mailbox in a Google Workspace org
Search the full archive by mailbox, sender, subject or date
Configurable retention, set per backup connection
Read/write OAuth connection to Gmail - nothing installed on end-user machines
One MSP console for every client org, white-labeled with your own domain
Idempotent, JWT-authenticated API for every mutating request
Point-in-time recovery for a single message or a whole inbox
Bring your own S3-compatible storage - AWS, Wasabi, Backblaze, MinIO
An append-only log of every restore, kept for up to seven years
Role-based team invites, TOTP two-factor, and lockout after failed attempts
AES-256-GCM encrypted secrets and credentials, held in a dedicated secrets store
Customer-held encryption keys, generated in your browser - optional

How it works

From first connection to a completed restore, here's what actually happens.

  1. 1

    Connect your Workspace

    Grant Bekap OAuth access to Gmail - read and write, so backups can run and restores can be written back to a mailbox. Nothing installs on end-user machines, and access can be revoked from your Google Admin console at any time.

  2. 2

    Point it at your own storage

    Bring your own S3-compatible bucket - AWS, Wasabi, Backblaze, or MinIO. Backups land there under credentials only you control. Encryption at rest is handled by your storage provider, outside Bekap's control - unless you turn on customer-held encryption keys, generated in your browser, for an extra layer we can't read even if we wanted to.

  3. 3

    Backups run automatically, multiple times a day

    No schedule to manage - every mailbox in the org gets backed up automatically, several times daily. Restores and connection changes are written to an append-only audit log, kept for up to seven years.

  4. 4

    Restore in minutes, not days

    Search the full archive by mailbox, sender, subject, or date, then restore a single message or a whole inbox to a specific point in time - without touching your Workspace admin console.

Questions, answered

The things people ask before talking to us.

Does Bekap back up Microsoft 365?
Not yet - today Bekap only connects to Google Workspace. If Microsoft 365 support matters to you, mention it when you talk to our team; it helps us prioritize.
How do I get started?
Leave your email or reach out directly, and someone from our team will contact you to walk through setup - connecting your Workspace, choosing your storage, and getting your organization ready. There's no self-serve signup.
How does billing work?
By invoice, based on the number of mailboxes under backup. We don't charge a card automatically, and invoices are payable within 30 days.
Can we cancel anytime?
Give 30 days' notice before your next billing period and it won't renew. Cancellation isn't self-service yet - it's a written request to our support address, and fees keep accruing until we've confirmed it.
What happens to our data if we leave?
Nothing - your backups live in storage you control, not ours, so they stay exactly where they are after cancellation. You keep direct access through your own storage provider.
Is our data encrypted?
Credentials and secrets always are, encrypted with AES-256-GCM in a dedicated secrets store. Backup content itself is optional per connection - turn on customer-held encryption and we can't read it even if we wanted to.

Tell us where to reach you.

Tell us a bit about you and someone from our team will follow up to walk through setup - no self-serve signup, just a conversation about your Workspace and what needs backing up.