FAQ
Frequently Asked QuestionsFrequently Asked Questions
Everything you need to know about VaultFuzion pricing, billing, and data handling.
A seat is one licensed Microsoft 365 user mailbox (USER_MAILBOX type). Shared mailboxes, room mailboxes, and equipment mailboxes are not counted. Active seats (protected, discovered, or paused) are billed at full rate. Archived seats, where backup data is retained but active protection is paused, are billed at 50% of the per-seat rate. Billing is based on the peak seat count during the billing period to prevent end-of-month adjustments.
Archived seats are mailboxes where the user has left the organisation or backup has been paused, but historical backup data is retained for compliance or legal hold purposes. Archived seats are billed at 50% of the active per-seat rate across all seat bands. They do not count toward per-seat add-on charges.
Moving up a band applies immediately. Moving down takes effect at the start of the next billing month, so the month you are in bills at the band you were on. Nothing about your feature set changes either way, the bands set your committed seat count, not what the software does.
Upon cancellation, your data is available for export for 30 days. After that, it's securely deleted with SHA-256 destruction certificates issued as proof of deletion. Retention and destruction commitments conform to the terms of your signed subscription agreement.
Fill out the Get Started form on our website. Our team will contact you within 24 hours to set up your account, configure your M365 connector, and onboard your first tenants.
International customers are invoiced in USD and can pay via credit card or international bank transfer. Applicable taxes (VAT, GST, sales tax) are added based on your billing jurisdiction.
Storage includes all backup snapshots across Exchange, OneDrive, SharePoint, and Teams. Content-addressable deduplication is applied before calculating usage, which typically reduces actual storage by 40-60%. Backups are written to storage you own under BYOS, so you pay your storage provider directly and VaultFuzion bills no per-GB overage.
Kapsul8 commitment discounts are 10% (1-year), 18% (3-year) and 25% (5-year), taking the Scale-band rate from $0.99 to $0.89, $0.81 and $0.74. VentraID carries its own ladder, 15%, 25% and 35% on the same terms.
Enterprise is custom-quoted per deal with a negotiated committed minimum. Below Enterprise the published bands apply: Starter 1-9 seats, Growth 10-99, Scale 100-999, Volume 1,000+. Your committed seat count is simply the floor of your band - 1 seat on Starter, 10 on Growth, 100 on Scale, 1,000 on Volume - so there is no seat minimum to get started. The commitment is a billing floor, not a feature gate: every band runs identical software.
Every backup is encrypted at rest with AES-256-GCM under a per-tenant key. All audit events are chained with SHA-256 for tamper evidence. The platform is engineered to support the retention, disposition, and evidence-grade requirements of common data-protection frameworks. We are not currently holding SOC 2 or ISO 27001 certification; specific regulatory commitments are addressed in your signed Master Services Agreement.
Yes, on the Enterprise tier and above. You can customise the Tenant Portal with your own logo, brand colours, and domain. Your clients will see your brand, not VaultFuzion.
Exchange Online (mail, calendar, contacts, and the in-place archive), OneDrive for Business (files, version history, and permissions), SharePoint Online (document libraries, custom lists, pages, and subsites), and Microsoft Teams (channel messages and files, plus 1:1, group and meeting chats). Microsoft 365 Groups conversations and Planner are included as well. Microsoft Entra ID (Azure AD) is protected separately through the VentraID add-on. Two honest caveats: Teams chats and Planner are captured, browsable and eDiscovery-exportable, not restored back into Teams — Microsoft’s Graph API can’t re-post historical chat history and Planner writes are Microsoft-restricted; and Teams chats hosted in another organisation’s tenant — external meeting threads — cannot be captured by a tenant-scoped connector, so we report those rather than skip them silently.
Microsoft 365 backs up three times a day by default, an eight-hour recovery point, and is configurable up to six times a day for a four-hour one. Endpoint backup and VentraID default to once a day and are configurable to the same six-times-a-day ceiling. Recovery Time Objective (RTO) for item-level restore is typically under 5 minutes for a single mailbox item; full-mailbox restores complete within hours depending on size. RPO/RTO targets are defined contractually in your subscription agreement.
Retention is configurable up to 7 years, with automated disposition when a window expires. Objects under a legal hold are exempt until the hold is released, a disposition run cannot remove them.
Not from inside your Microsoft 365 tenant. Your backups live on independent storage outside that tenant, so stolen Microsoft admin credentials give an attacker no path to them. Backups are written to write-once storage under S3 Object Lock in compliance mode: once a restore point is locked, it can’t be altered or deleted by anyone — not a rogue administrator, not VaultFuzion — until the retention period you set, from 30 days to 7 years, lawfully expires.
Yes, through the dedicated VentraID add-on. VentraID Backup captures users, groups, conditional access policies, named locations, service principals, directory roles, devices, and authentication-method policies on a snapshot cadence. Higher VentraID tiers add drift detection, multi-framework compliance scoring, conditional-access What-If, and identity threat detection.
Not in the sense most people mean. Microsoft operates a shared responsibility model: they guarantee the availability of the service and the infrastructure, and you remain responsible for your data within it. Microsoft 365 does have native recovery mechanisms and they are genuinely useful - items sit in a recycle bin, deleted mailboxes and sites are retained for a period, and retention policies can hold content in place. But those are time-boxed and designed to recover from ordinary mistakes, not to act as a long-horizon independent copy. Once a native retention window elapses the data is gone, and a retention policy is a hold on live data rather than a separate copy you control. The practical test: could you restore a specific mailbox to a specific point in time, six months after the fact, on your own timetable, into storage you control?
Sometimes not, and we would rather say so than oversell. Microsoft Entra Backup and Recovery is generally available, on by default, and takes a daily backup that not even a Global Administrator can delete - a genuinely strong guarantee. If you are protecting a single P1 or P2 workforce tenant against a change somebody notices within the week, it is likely sufficient. The limits Microsoft states itself are where an independent copy still earns its place: retention is up to seven days; backup data resides in the same geo-location as the tenant it protects, so it shares that tenant’s fate; hard-deleted objects are explicitly out of scope; External ID and Azure AD B2C tenants are not supported; and for objects mastered in on-premises Active Directory, Microsoft directs you to use an alternative solution. Microsoft’s own guidance is to treat it as part of a broader approach to recoverability, and we agree with that framing. Verified against Microsoft documentation on 15/08/2026 - they revise this product often, so check the current pages before deciding either way.
In storage you own. VaultFuzion is bring-your-own-storage: backups are written to an S3-compatible bucket you provide, in your own cloud account, and your storage provider bills you directly. That means there is no per-seat storage allowance to exhaust and no storage overage payable to us. It also means your backups do not become hostage to a billing dispute with a backup vendor, and that capacity planning and retention cost are yours to control.
Retention templates for HIPAA, SOX and GDPR windows ship with the platform, alongside per-tenant encryption, a SHA-256 audit chain, automated disposition and destruction certificates. To be direct about the difference between support and certification: we are not currently SOC 2 or ISO 27001 certified, and we do not claim GDPR or CCPA compliance. What we provide is the technical substrate and the evidence trail; the commitments that bind us are in your signed agreement. Specific requirements are addressed in your signed Master Services Agreement.
Veeam sells both self-managed backup software and a hosted service (Veeam Data Cloud). VaultFuzion is a cloud-native MSP-first platform with per-tenant encryption keys, hash-chained tamper-evident audit, content-addressable deduplication, and point-in-time restore across all four Microsoft 365 workloads. Identity protection (VentraID) and eDiscovery with legal holds (EvidenceVault) attach to the same subscription, backups land in storage you own, and the per-seat rate is published. Multi-tenant MSP isolation is native, not bolted on. Comparison reflects published capabilities as of 14/08/2026.
AvePoint is a long-established player. VaultFuzion differentiates on evidence-grade audit (SHA-256 hash chain), per-tenant encryption keys (another tenant’s at-rest data can never be read; cross-tenant restore is a supported, MSP-fenced operation that re-encrypts the data under the destination tenant’s own key), a retention engine with HIPAA, SOX and GDPR templates and destruction certificates, and bundled adjacent products (identity protection and eDiscovery). Our per-seat rate is published rather than quoted. Comparison reflects published capabilities as of 14/08/2026; compare current published capabilities directly.
Datto SaaS Protection covers Exchange, OneDrive, SharePoint and Teams (as of 14/08/2026, per Datto's published product page). VaultFuzion covers the same four workloads and adds identity-plane protection through VentraID plus a retention and legal-hold engine through EvidenceVault. Our per-seat rate is published and falls with volume, and backups are written to storage you own rather than to the vendor's. Compare current published capabilities and pricing directly — both products change often.
Every tenant's backup data is encrypted with AES-256-GCM. Each tenant has its own data encryption key, held encrypted under a platform master key, meaning a misrouted restore fails at the cryptographic layer, not at an application policy check. Master keys are stored in Azure Key Vault with purge protection. We never store raw card data, payment processing is delegated to Stripe.
Every sensitive operation (backup, restore, retention apply, purge, legal hold change, key rotation) is recorded as an audit block. Each block includes the SHA-256 hash of the previous block, forming a tamper-evident chain. Modifying any historical block invalidates every subsequent hash, making tampering mathematically detectable and providing forensic-grade evidence for regulator submissions.
VaultFuzion enforces MSP isolation at three layers: (1) MSPOwnershipGuard blocks cross-MSP requests at the controller level; (2) Tier-1 services (Restore, Backup, Evidence, M365) re-validate tenant.mspId at the service level for defence-in-depth; (3) cross-MSP tenant lookups return HTTP 404 (not 403) to prevent existence disclosure. VaultFuzion staff retain access for support and operations under documented break-glass procedures.
Yes. All 60 executables and libraries in the agent payload carry a valid Authenticode signature, and every signature is RFC 3161 timestamped so it stays verifiable over time. The backup engine is signed by the engine vendor under an Extended Validation (EV) code-signing certificate — that certificate belongs to the engine vendor, not to VaultFuzion — and the bundled Microsoft C++ runtime and Windows API-set components are signed by Microsoft. Because the payload is publisher-signed, MSPs running application control can allowlist by publisher in WDAC or AppLocker rather than by file hash, so the rule survives version upgrades instead of needing to be reissued after every update; we supply the exact publisher identity in the EDR pre-flight pack. The deployment script your RMM runs is an unsigned plain-text PowerShell file — you are welcome to read it in full before approving, and signing it is on our roadmap. We provide a full integrity manifest with SHA-256 hashes for every shipped file, plus a verification script that checks each signature against your own trusted root store, so your security team can confirm all of this independently rather than taking our word for it.
Ask us for the EDR pre-flight pack before you roll out. It lists the exact behaviours the installer performs and why, maps the detections you should expect to MITRE ATT&CK techniques with a recommended disposition for each, and supplies a ready-made Microsoft Defender exclusion script plus specific exclusion guidance for CrowdStrike Falcon and SentinelOne. It also documents steady-state behaviour once the agent is running, including how it uses Volume Shadow Copies: the agent never deletes pre-existing shadow copies or restore points, and nothing in the platform calls vssadmin delete shadows. A snapshot taken for a backup is released when that backup finishes, which is ordinary VSS behaviour. One caveat worth pre-staging with your SOC: Windows enforces a shadow-storage limit per volume, and if the diff area is near its maximum, VSS itself evicts the oldest shadow copies — System Restore points included — to make room for any new snapshot, whoever requested it. Check vssadmin list shadowstorage before attributing a missing restore point to the agent. An alert reporting deletion of pre-existing shadow copies or restore points is a genuine incident and not us. Deploy the installer as a file through your RMM rather than as a one-line remote script, pilot on three to five representative endpoints, and pre-stage the exclusions before a fleet-wide rollout.
No. The onboarding fee is charged ONCE, when your MSP first partners with us for Endpoint Backup. It is a one-time MSP onboarding fee, not a per-tenant, per-client or per-site charge. Adding your second, tenth or fiftieth client tenant carries no tenant onboarding fee. The only cost at tenant setup is a one-time server setup fee covering the servers that tenant brings into scope, because image-based capture is provisioned per server — it scales with server count, not tenant size, it is materially smaller than the MSP onboarding fee, and a tenant with no servers pays nothing at setup. Microsoft 365 backup (Kapsul8) and Entra ID protection (VentraID) carry no onboarding or setup fee at all; the server setup fee applies only to Endpoint Backup. Endpoint Backup tenants each receive their own isolated backup container and storage bucket; Microsoft 365 and Entra ID tenants are isolated by per-tenant encryption keys.
No. Kapsul8 Microsoft 365 backup and VentraID Entra ID protection have no onboarding fee, no setup fee and no activation charge — not for your MSP, and not for any tenant you bring on. A client tenant arriving purely for Microsoft 365 backup or Entra ID protection carries no one-time charges at all; ongoing cost is the published subscription rate, plus whatever your own storage provider charges you under BYOS. One-time charges exist only in Kapsul8 Endpoint Backup: an MSP onboarding fee charged once when you first partner with us, and a one-time server setup fee for any servers a tenant brings into scope.
A standard MSP onboarding from contract signature to first protected tenant typically completes within 1-2 business days. Initial M365 OAuth consent, Partner Portal access provisioning, and first tenant configuration happen within hours. The first full backup snapshot duration depends on tenant size and Microsoft Graph throttling, typically 24-72 hours for a 100-seat tenant.
Email support is included on every seat band. Growth and above receive priority support with 4-hour first-response targets during business hours. Scale and Volume include dedicated account management. Enterprise customers receive 24/7 support with named technical contact. Support languages: English. Support escalation procedures are documented in your subscription agreement.
Yes, VaultFuzion includes a guided migration flow for incumbent backup providers (AvePoint, Veeam Backup for M365, Datto, Spanning, Acronis Cyber Protect, Keepit). The flow exports historical data, validates integrity, and re-ingests into VaultFuzion with continuity of retention dates. Migration timing is driven by historical-data volume; typical 100-seat migrations complete in 1-2 weeks.
Still have questions?
Talk to Us →