> ## Documentation Index
> Fetch the complete documentation index at: https://3to1go.docs.thesteau.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Storage and the 3-2-1 rule

> Which copies 3to1go covers, and where Central can keep your snapshots.

The [3-2-1 rule](https://en.wikipedia.org/wiki/Backup#Storage) says to keep **3** copies of your data, on **2** different media, with **1** of them offsite. 3to1go gives you **two** copies: your live files and Central's snapshots. The third copy is always up to you.

| Copy | What | Covered by |
| - | - | - |
| 1: live data | The original files on your machine | Edge |
| 2: second copy, different media | Encrypted snapshots on a separate machine | **3to1go: Edge → Central** |
| 3: third copy | An independent copy of Central's snapshots | Your choice (see below) |

## Getting the third copy

Copy Central's backup folder somewhere independent of Central. Where Central runs decides which copy is your offsite one:

<CardGroup cols={2}>
  <Card title="Central is local" icon="house">
    Central runs on a home NAS or server for fast access. Sync its backup folder to offsite storage. That synced copy is both your **third** copy and your **offsite** one.
  </Card>

  <Card title="Central is offsite" icon="globe">
    Central runs on a VPS, at a family member's place, or on another host physically separate from your Edge machines. Its snapshots are your **offsite** copy, but you still have only two copies. Add a third, such as a sync of Central's backup folder to another disk or provider.
  </Card>
</CardGroup>

<Warning>
  Running Central offsite does **not** give you three copies on its own. If Central's disk fails at the same time as a machine, there's nothing else to restore from.
</Warning>

Because Central only holds encrypted archives, you can run it on hardware you don't fully control, and push its data to any storage without exposing your files.

## Where Central can store snapshots

Central writes encrypted archive files into its backup folder (`/backups` inside the container, set by `BACKUP_DIR` in Compose). Storage is accessed through ordinary filesystem operations:

* **Local disk.** The default. Fast and simple.
* **Mounted NAS.** Mount it on the Docker host and give Central write access. Central handles moves across filesystems when the backup folder is on a different device from its staging directory.
* **Removable hard drive.** Mount it and point `BACKUP_DIR` at it.
* **Dropbox, Google Drive, or OneDrive.** Point `BACKUP_DIR` at the local sync folder. The desktop client replicates it to the cloud, and the provider only ever sees encrypted archives.
* **Object storage.** Central has no native object-storage backend. Use an external tool to copy the local backup folder to your provider. If using a filesystem mount over object storage, verify that it supports Central's file writes, listing, renames, and deletion before relying on it.

<Note>
  Central is not a sync engine. It just writes files, so any tool that can replicate a directory can handle the rest.
</Note>

Keep Edge's encryption keys independently of these copies. To recover the Central service as well as the archives, also preserve its signing key and PostgreSQL database as described in [Install Central](/central/install#what-gets-created). A mirror can propagate retention deletions, so its history depends on the replication tool and destination's retention settings.
