Documentation

What Is Off-Site Backup for Photographers, and Why Is It the One That Counts?

Two drives in one drawer are a single target. What qualifies a copy as off-site, and the realistic options for a photographer.

Preservation

What “off-site” precisely means

An off-site backup is a copy that shares no physical risk with your originals. The criterion isn’t distance in kilometres, it’s independence: does your copy survive the event that would destroy everything else?

A drive in the bottom drawer isn’t off-site. A drive in the garage isn’t off-site against a fire. A NAS in the next room isn’t off-site against a burglary or a flood. The test is simple, and unforgiving.

Why it’s the decisive copy

The other copies protect against hardware failure and human error, which are frequent but partial. The off-site copy protects against total loss, which is rare but final.

It’s also the only one that survives theft — a burglar takes the computer and the drives sitting next to it — and ransomware, provided it isn’t permanently mounted writable on the infected machine.

The realistic options

  • Remote object storage. Amazon S3, Backblaze B2, Cloudflare R2, and compatibles. Pay by volume, high availability, no hardware to maintain. The easiest to sustain over time because it requires no action from you.
  • A NAS at a trusted third party. At a relative’s, in another business premises. Controlled cost, but assumes synchronisation that actually works and access when you need to restore.
  • Rotating drives. Two drives alternated, one always elsewhere. Cheapest, but wholly dependent on human discipline — which is what makes it fail.
  • A bank vault. For a frozen, high-value archive on archival-grade media. Slow, safe, unsuited to a living collection.

The two traps

Confusing sync with backup. A continuously synced folder instantly propagates a deletion or a corruption. It is off-site without being a backup. You need dated retention, or at minimum versioning on the storage side.

Never testing the restore. An off-site copy never restored is a belief. The question isn’t “are the files there” but “can I get them back, how long will it take, and are they intact”.

In practice

  1. Apply the independence test: which event would destroy my originals and this copy?
  2. Prefer a mechanism that requires no recurring action.
  3. Insist on resumable uploads: without them, a large deposit never finishes.
  4. Verify integrity after upload, from the remote storage.
  5. Test a real restore once a year, on a sample.

Obscura Flow drives that off-site copy to S3, Backblaze B2, Cloudflare R2, a NAS, or a local folder, with resumable transfers and remote-side integrity verification after upload.