- Backup
- weekly-2026-08-24.dump
- Freshness
- 02h 14m
- Restore
- ✓ 48.2 s
- ✓ orders have owners
- ✓ ledger balances
- ✓ migration 2026082201
Backup success is not recovery proof
Sentinel restores your newest PostgreSQL backup in an isolated target, tests the facts your application depends on, and signs the evidence.
One command. Three pieces of evidence.
Selects the newest eligible dump, rejects stale backups and production-looking targets, then invokes PostgreSQL’s own restore tools.
Runs your SQL invariants and migration checks in read-only transactions. Expected values stay in config; returned values stay out of receipts.
Writes JSON for automation and Markdown for humans, both tied to the backup SHA-256 and an HMAC signature you can verify later.
Start locally
You bring a disposable PostgreSQL target. Sentinel brings the guardrails and proof format.
$ cargo install --git https://github.com/B-Divyesh/sf-recovery-drift-sentinel
$ recovery-drift-sentinel init
Wrote sentinel.toml
$ recovery-drift-sentinel run --config sentinel.toml
Recovery proof: Passed
Compact by design
Receipts say what passed, how long it took, and which backup was tested. Query output and credentials never enter the artifact.
Intentionally narrow
Discover, restore, check, sign, and report.
Transport backups, host databases, repair production, or collect telemetry.
Free core, useful forever
Every restore, check, signed receipt, and export remains free. The optional Team rollout pack adds a browser-local policy generator for multi-database schedules and 90-day drill evidence.
$39 once
Paste your license to unlock this browser. Verification never blocks the free CLI or docs.
✓ Team pack unlocked
By purchasing, you agree to the terms. See how license data is handled in our privacy note.
Your next backup deserves a trial run