Skip to main content
Each job builds up a picture of what its backups normally look like. When a new backup looks very different, such as a folder that suddenly emptied or files that ransomware encrypted, Scout holds it instead of uploading it. Your good snapshots on Station stay safe from retention until you decide. Detection only uses file paths, sizes, file types, and how well the archive compresses. It never reads your files’ contents.

What Scout checks

Each job keeps its last 20 uploaded backups as its “normal”. Photo and video folders that never compress well aren’t flagged by the compression check, and adding lots of new files only trips the count check, not the changed-files check.

Machine learning

Detection is unsupervised anomaly detection. Scout doesn’t use a trained model. It learns each job’s own baseline from that job’s past backups and flags a backup that falls far outside it. There’s nothing to download or train, nothing leaves the Scout, and a check takes milliseconds. The median and MAD ignore a few odd backups in the history, where an average would be pulled off by them. The log scale treats growing from 1 GB to 2 GB the same as 10 GB to 20 GB. The baseline keeps learning. Every uploaded backup joins the history, including one you approve with Upload anyway. A held backup doesn’t join it until you approve it, so a bad backup can’t teach Scout that bad is normal.

When a backup is held

The job shows held for review with the reasons, for example:
The archive barely compresses (100% of the original size, usually 41%), which is typical of encrypted files. Files ending in .locked went from 0% to 100% of the folder.
Scout also sends a high-priority ntfy alert if notifications are set up. Then either:
  • The change is expected, such as a reorganized folder: click Upload anyway. The backup uploads and becomes part of the job’s normal, so the same pattern won’t be flagged again.
  • Something is wrong: click Clear staged backup to discard it, then fix the folder, for example by restoring the last good snapshot.
A held job stays held on later cycles while its files stay the same. If the files return to their last uploaded state, the hold clears by itself.

Settings

Choose Unusual backups in Edit Scout Settings, or set ANOMALY_MODE in .env: Force Upload always uploads without checking, since it’s an explicit request. Station runs its own, simpler check on archive sizes as a second line of defense. See Unusual sizes.