Skip to content
Osiris
BackupArchivePricingCompareRoadmapDocsGet notified
  • en
  • de
  • es
BackupArchivePricingCompareRoadmapDocsGet notified

← Back to the overview

Roadmap

By Lucas Flores, IT Systeme Flores UG. Last updated 2026-09-24

Available now: Microsoft 365 and IMAP backup/restore, recovery readiness checks, the audit log, multi-tenancy and the REST API. Everything else below is in development or planned, clearly labelled as such. See how Osiris is builtfor why that distinction is treated as non-negotiable.

Shipped: closed beta today

  • Microsoft 365 backup: Exchange Online mail, calendar and contacts, and OneDrive, incremental via Microsoft Graph delta queries.
  • IMAP backup for arbitrary mailboxes, password-authenticated (one login per source today).
  • Restore: single item, folder, file version, or a whole mailbox/OneDrive, into the original account or a different one, non-destructive by default (the current beta still has an explicit "Replace" exception; see below).
  • Weekly sampled recovery-readiness check, shown per mailbox and OneDrive.
  • Multi-tenancy: the Service Provider edition supports multiple tenants today.
  • Tamper-evident, hash-chained audit log for every read or restore.
  • REST API with OpenAPI docs, per-tenant API keys and scopes, for RMM/PSA integration.
  • Setup wizard, passkey-first admin login, full English/German UI.

In development: not available yet

Nothing in this section is available yet. It is being actively built against the current beta; see the product's own changelog for the version something actually ships in before relying on it.

  • Single sign-on (Entra ID, OIDC, LDAP), for Business and Service Provider.
  • Roles and permissions, including four-eyes approval for restore and deletion, for Business and Service Provider.
  • The archive layer built for German GoBD requirements (Business/Service Provider, planned as a separate, proprietary module unlocked by a licence key): Exchange Online journal receipt over SMTP, IMAP archive sync, a hash chain plus object-lock immutability where the storage target supports it, enforced retention and legal hold, an evidence report, and end users searching their own mailbox history.
  • A signed, independently verifiable restore report (PDF), for Business and Service Provider.
  • Delegated tenant administrators and tenant reporting, for Service Provider.
  • OAuth2 sign-in for IMAP sources hosted on Microsoft 365 or Google. Password authentication is what exists today.
  • Sign-in with Microsoft (Entra OIDC) for end users.The sign-in button exists, but the tenant/ownership binding behind it is not safe to enable yet. Today, ownership is tied to the email claim alone, with no verified Microsoft tenant/user binding, which is a real security gap, not a flag to flip. Self-service restore today uses a passkey or the emergency password with TOTP.
  • Full test restore into a separate target, and verifying every backed-up item rather than a weekly sample. The sampled check is the current, honestly-labelled interim state.
  • Removing the explicit "Replace" restore mode entirely, so overwriting an existing original becomes structurally impossible, not just discouraged.
  • Per-mailbox IMAP credentials (today: one login per IMAP source).
  • White-labelling for the Service Provider edition.

Planned: on the roadmap, not started

  • A Linux and Windows server/client backup agent.A separate "Infrastructure" track alongside Microsoft 365 and IMAP, reusing the same encrypted, deduplicated chunk store, deliberately file-level only (no block imaging, no bare-metal restore; tools like UrBackup, Veeam Agent or ReaR already do that well). One console and one restore discipline for mail, files and server files is the actual point, not competing on imaging.
  • Proxmox VE support, via Proxmox Backup Server (PBS).
  • An SFTP storage target, alongside local disk, S3-compatible object storage, NFS and SMB.
  • arm64 container images, alongside the current amd64 image.

Deliberately out of scope for now

SharePoint, Microsoft Teams (beyond what Graph already exports), Google Workspace, Exchange Public Folders, PST import, eDiscovery case management, and a mobile app are not planned for the current phase. Osiris is backup and archive for Microsoft 365 and IMAP, plus the planned file-level infrastructure track above, not a general SaaS-backup or eDiscovery platform, and not a monitoring/RMM/PSA tool in its own right (the REST API exists so your actual RMM/PSA can integrate, not to replace one).

For what's shipped today in detail, seefeatures; for the archive layer built for German GoBD requirements specifically, seeGoBD and email archiving, explained.

Get notified when any of this ships →

PricingRoadmapFeaturesCompare with other vendorsTopicsHow Osiris is builtYour data is your dataOpen source

The Osiris core (backup, restore, audit log) is open source under the AGPL-3.0. The Business/Service Provider archive and multi-tenant modules are planned as proprietary. This website's text and design are licensed CC BY 4.0.

ImprintPrivacyLicence termsDocumentationSource codeLicenceSecurity contact