FAQ
Frequently Asked QuestionsFrequently Asked Questions
Everything you need to know about VaultFuzion pricing, billing, and data handling.
A seat is one licensed Microsoft 365 user mailbox (USER_MAILBOX type). Shared mailboxes, room mailboxes, and equipment mailboxes are not counted. Active seats (protected, discovered, or paused) are billed at full rate. Archived seats, where backup data is retained but active protection is paused, are billed at 50% of the per-seat rate. Billing is based on the peak seat count during the billing period to prevent end-of-month adjustments.
Archived seats are mailboxes where the user has left the organisation or backup has been paused, but historical backup data is retained for compliance or legal hold purposes. Archived seats are billed at 50% of the active per-seat rate across all subscription tiers. They do not count toward per-seat add-on charges.
Band upgrades take effect immediately and are pro-rated for the remaining days in your billing period. Downgrades are processed by your VaultFuzion account manager at the end of the billing cycle. Your feature set is unchanged either way, the band sets your committed seat count and per-seat rate, not what the software does.
Upon cancellation, your data is available for export for 30 days. After that, it's securely deleted with SHA-256 destruction certificates issued as proof of deletion, in compliance with POPIA requirements.
Fill out the Get Started form on our website. Our team will contact you within 24 hours to set up your account, configure your M365 connector, and onboard your first tenants.
We process payments through Peach Payments, supporting credit/debit cards, EFT/bank transfer, and debit orders. South African customers are billed in ZAR with 15% VAT applied.
Storage includes all backup snapshots across Exchange, OneDrive, SharePoint, and Teams. Content-addressable deduplication is applied before calculating usage, which typically reduces actual storage by 40-60%. Overage is billed at R1/GB/month.
Kapsul8 commitment discounts are 10% (1-year), 18% (3-year), and 25% (5-year). Entra ID add-ons (VentraID) carry a steeper ladder, 15% (1-year), 25% (3-year), and 35% (5-year) commitment discounts.
Enterprise is custom-quoted in ZAR with a negotiated committed seat minimum. Below Enterprise the published bands apply: Starter 1-9 seats, Growth 10-99, Scale 100-999, Volume 1,000+. Your committed seat count is simply the floor of your band - 1 seat on Starter, 10 on Growth, 100 on Scale, 1,000 on Volume - so there is no separate seat minimum to get started. The commitment is a billing floor, not a feature gate: every band runs identical software. Contact our sales team for an Enterprise quote.
Yes, the platform is engineered to support your POPIA programme. Per-tenant encryption keys, configurable retention periods up to 7 years, automated disposition workflows, destruction certificates, and a tamper-evident SHA-256 audit chain are all included by default. POPIA compliance remains your responsibility as the responsible party; we provide the tooling and evidence trail to make that ongoing work auditable.
Yes, on the Enterprise tier and above. You can customise the Tenant Portal with your own logo, brand colours, and domain. Your clients will see your brand, not VaultFuzion.
Exchange Online (mail, calendar, contacts, and the in-place archive), OneDrive for Business (files, version history, and permissions), SharePoint Online (document libraries, custom lists, pages, and subsites), and Microsoft Teams (channel messages and files, plus 1:1, group and meeting chats). Microsoft 365 Groups conversations and Planner are included as well. Microsoft Entra ID (Azure AD) is protected separately through the VentraID add-on. Two honest caveats: Teams chats and Planner are captured, browsable and eDiscovery-exportable, not restored back into Teams — Microsoft’s Graph API can’t re-post historical chat history and Planner writes are Microsoft-restricted; and Teams chats hosted in another organisation’s tenant — external meeting threads — cannot be captured by a tenant-scoped connector, so we report those rather than skip them silently.
Microsoft 365 backs up three times a day by default, an eight-hour recovery point, and is configurable up to six times a day for a four-hour one. Endpoint backup and VentraID default to once a day and are configurable to the same six-times-a-day ceiling. Recovery Time Objective (RTO) for item-level restore is typically under 5 minutes for a single mailbox item; full-mailbox restores complete within hours depending on size. RPO/RTO targets are defined contractually in your subscription agreement.
Retention is configurable up to 7 years across every band, with automated disposition when a window expires. Legal-hold-attached objects are exempt from disposition until the hold is released.
Not from inside your Microsoft 365 tenant. Your backups live on independent storage outside that tenant, so stolen Microsoft admin credentials give an attacker no path to them. Backups are written to write-once storage under S3 Object Lock in compliance mode: once a restore point is locked, it can’t be altered or deleted by anyone — not a rogue administrator, not VaultFuzion — until the retention period you set, from 30 days to 7 years, lawfully expires. Destruction happens only after that lawful expiry, with SHA-256 destruction certificates issued as proof, in line with POPIA.
Yes, through the dedicated VentraID add-on. VentraID Backup captures users, groups, conditional access policies, named locations, service principals, directory roles, devices, and authentication-method policies on a snapshot cadence. Higher VentraID tiers add drift detection, multi-framework compliance scoring, conditional-access What-If, and identity threat detection.
Not in the sense most people mean. Microsoft operates a shared responsibility model: they guarantee the availability of the service and the infrastructure, and you remain responsible for your data within it. Microsoft 365 does have native recovery mechanisms and they are genuinely useful - items sit in a recycle bin, deleted mailboxes and sites are retained for a period, and retention policies can hold content in place. But those are time-boxed and designed to recover from ordinary mistakes, not to act as a long-horizon independent copy. Once a native retention window elapses the data is gone, and a retention policy is a hold on live data rather than a separate copy you control. The practical test: could you restore a specific mailbox to a specific point in time, six months after the fact, on your own timetable, into storage you control?
Sometimes not, and we would rather say so than oversell. Microsoft Entra Backup and Recovery is generally available, on by default, and takes a daily backup that not even a Global Administrator can delete - a genuinely strong guarantee. If you are protecting a single P1 or P2 workforce tenant against a change somebody notices within the week, it is likely sufficient. The limits Microsoft states itself are where an independent copy still earns its place: retention is up to seven days; backup data resides in the same geo-location as the tenant it protects, so it shares that tenant’s fate; hard-deleted objects are explicitly out of scope; External ID and Azure AD B2C tenants are not supported; and for objects mastered in on-premises Active Directory, Microsoft directs you to use an alternative solution. Microsoft’s own guidance is to treat it as part of a broader approach to recoverability, and we agree with that framing. Verified against Microsoft documentation on 15/08/2026 - they revise this product often, so check the current pages before deciding either way.
Section 19 of POPIA requires the responsible party to secure the integrity and confidentiality of personal information through appropriate, reasonable technical and organisational measures. VaultFuzion supports Section 19 compliance through per-tenant AES-256-GCM encryption, hash-chained audit trails, content-addressable storage, and restricted operator access through MSP isolation. Section 19 compliance remains your responsibility as responsible party, we provide the technical substrate.
Section 22 requires the responsible party to notify the Information Regulator and affected data subjects of a security compromise. VaultFuzion's tamper-evident audit chain provides forensic-grade evidence of what data was accessed, when, and by whom, the foundation for any Section 22 notification. We also surface incident timelines and integrity-verification reports through the Partner Portal so notifications can be drafted and substantiated rapidly.
Section 109 governs personal-information destruction following the lawful retention period. VaultFuzion issues SHA-256 destruction certificates whenever data is purged, with the certificate hash chained into the audit trail. The certificate documents object identifiers, encryption-key destruction status, and the destruction timestamp, providing the responsible party with cryptographic proof of destruction for regulator submissions.
South African customer data is stored in South African Microsoft Azure regions and Z1Storage facilities in Johannesburg by default. SA data residency is contractually committed in your subscription agreement. International customers may opt for alternate residency through their signed Master Services Agreement.
You as the responsible party must register an Information Officer with the Information Regulator under POPIA, VaultFuzion does not register one on your behalf. Synchplus Consulting (Pty) Ltd has its own Information Officer registered for VaultFuzion-platform processing. Our Privacy Policy lists the Information Officer contact for VaultFuzion-internal data-subject requests.
The A-F compliance grade is VaultFuzion's internal scoring across 13 platform-level POPIA checks (Sections 19, 22, 109, retention, audit-chain integrity, encryption posture, etc.). It is operational scoring, not a regulatory verdict from the Information Regulator. The grade surfaces as a card on every tenant dashboard, with portfolio-distribution views for MSPs and platform-wide histograms for VaultFuzion staff.
Veeam sells both self-managed backup software and a hosted service (Veeam Data Cloud). VaultFuzion is a cloud-native MSP-first platform with per-tenant encryption keys, hash-chained tamper-evident audit, content-addressable deduplication, point-in-time restore across all four M365 workloads, and an integrated POPIA compliance engine. We also bundle identity protection (VentraID) and eDiscovery with legal holds (EvidenceVault) in one subscription. Multi-tenant MSP isolation is native, not bolted on. Comparison reflects published capabilities as of 14/08/2026.
AvePoint is a long-established player. VaultFuzion differentiates on evidence-grade audit (SHA-256 hash chain), per-tenant encryption keys (another tenant’s at-rest data can never be read; cross-tenant restore is a supported, MSP-fenced operation that re-encrypts the data under the destination tenant’s own key), POPIA-aligned retention engine with destruction certificates, and bundled adjacent products (identity protection and eDiscovery). For South African MSPs, ZAR-native billing through PayI and SA data residency are core to how we are built. Compare current published capabilities directly (checked 14/08/2026).
Datto SaaS Protection covers Exchange, OneDrive, SharePoint and Teams (as of 14/08/2026, per Datto's published product page). VaultFuzion covers the same four workloads and adds identity-plane protection through VentraID and a POPIA-aligned retention engine with destruction certificates, on one subscription. Compare current published capabilities and pricing directly — both products change often.
Every tenant's backup data is encrypted with AES-256-GCM. Each tenant has its own data encryption key, held encrypted under a platform master key, meaning a misrouted restore fails at the cryptographic layer, not at an application policy check. Master keys are stored in Azure Key Vault with purge protection. We never store raw card data, payment processing is delegated to Peach Payments.
Every sensitive operation (backup, restore, retention apply, purge, legal hold change, key rotation) is recorded as an audit block. Each block includes the SHA-256 hash of the previous block, forming a tamper-evident chain. Modifying any historical block invalidates every subsequent hash, making tampering mathematically detectable and providing forensic-grade evidence for regulator submissions.
VaultFuzion enforces MSP isolation at three layers: (1) MSPOwnershipGuard blocks cross-MSP requests at the controller level; (2) Tier-1 services (Restore, Backup, Evidence, M365) re-validate tenant.mspId at the service level for defence-in-depth; (3) cross-MSP tenant lookups return HTTP 404 (not 403) to prevent existence disclosure. VaultFuzion staff retain access for support and operations under documented break-glass procedures.
Yes. All 60 executables and libraries in the agent payload carry a valid Authenticode signature, and every signature is RFC 3161 timestamped so it stays verifiable over time. The backup engine is signed by the engine vendor under an Extended Validation (EV) code-signing certificate — that certificate belongs to the engine vendor, not to VaultFuzion — and the bundled Microsoft C++ runtime and Windows API-set components are signed by Microsoft. Because the payload is publisher-signed, MSPs running application control can allowlist by publisher in WDAC or AppLocker rather than by file hash, so the rule survives version upgrades instead of needing to be reissued after every update; we supply the exact publisher identity in the EDR pre-flight pack. The deployment script your RMM runs is an unsigned plain-text PowerShell file — you are welcome to read it in full before approving, and signing it is on our roadmap. We provide a full integrity manifest with SHA-256 hashes for every shipped file, plus a verification script that checks each signature against your own trusted root store, so your security team can confirm all of this independently rather than taking our word for it.
Ask us for the EDR pre-flight pack before you roll out. It lists the exact behaviours the installer performs and why, maps the detections you should expect to MITRE ATT&CK techniques with a recommended disposition for each, and supplies a ready-made Microsoft Defender exclusion script plus specific exclusion guidance for CrowdStrike Falcon and SentinelOne. It also documents steady-state behaviour once the agent is running, including how it uses Volume Shadow Copies: the agent never deletes pre-existing shadow copies or restore points, and nothing in the platform calls vssadmin delete shadows. A snapshot taken for a backup is released when that backup finishes, which is ordinary VSS behaviour. One caveat worth pre-staging with your SOC: Windows enforces a shadow-storage limit per volume, and if the diff area is near its maximum, VSS itself evicts the oldest shadow copies — System Restore points included — to make room for any new snapshot, whoever requested it. Check vssadmin list shadowstorage before attributing a missing restore point to the agent. An alert reporting deletion of pre-existing shadow copies or restore points is a genuine incident and not us. Deploy the installer as a file through your RMM rather than as a one-line remote script, pilot on three to five representative endpoints, and pre-stage the exclusions before a fleet-wide rollout.
No. The onboarding fee is charged ONCE, when your MSP first partners with us for Endpoint Backup. It is a one-time MSP onboarding fee, not a per-tenant, per-client or per-site charge. Adding your second, tenth or fiftieth client tenant carries no tenant onboarding fee. The only cost at tenant setup is a one-time server setup fee covering the servers that tenant brings into scope, because image-based capture is provisioned per server — it scales with server count, not tenant size, it is materially smaller than the MSP onboarding fee, and a tenant with no servers pays nothing at setup. Microsoft 365 backup (Kapsul8) and Entra ID protection (VentraID) carry no onboarding or setup fee at all; the server setup fee applies only to Endpoint Backup. Endpoint Backup tenants each receive their own isolated backup container and storage bucket; Microsoft 365 and Entra ID tenants are isolated by per-tenant encryption keys.
No. Kapsul8 Microsoft 365 backup and VentraID Entra ID protection have no onboarding fee, no setup fee and no activation charge — not for your MSP, and not for any tenant you bring on. A client tenant arriving purely for Microsoft 365 backup or Entra ID protection carries no one-time charges at all; ongoing cost is the published subscription rate plus any storage overage under the Fair Usage Policy. One-time charges exist only in Kapsul8 Endpoint Backup: an MSP onboarding fee charged once when you first partner with us, and a one-time server setup fee for any servers a tenant brings into scope.
A standard MSP onboarding from contract signature to first protected tenant typically completes within 1-2 business days. Initial M365 OAuth consent, Partner Portal access provisioning, and first tenant configuration happen within hours. The first full backup snapshot duration depends on tenant size and Microsoft Graph throttling, typically 24-72 hours for a 100-seat tenant.
Email support is included on every seat band. Growth and above receive priority support with 4-hour first-response targets during business hours. Scale and Volume include dedicated account management. Enterprise customers receive 24/7 support with named technical contact. Support languages: English. Support escalation procedures are documented in your subscription agreement.
Yes, VaultFuzion includes a guided migration flow for incumbent backup providers (AvePoint, Veeam Backup for M365, Datto, Spanning, Acronis Cyber Protect, Keepit). The flow exports historical data, validates integrity, and re-ingests into VaultFuzion with continuity of retention dates. Migration timing is driven by historical-data volume; typical 100-seat migrations complete in 1-2 weeks.
Still have questions?
Talk to Us →