The Danish company Keepit is making great strides as a European backup platform. With its own object store and data centers, and by staying away from U.S. hyperscalers, CTO Jakob Østergaard says that, as a business, you have exactly what you need at the core of your backup strategy. How is the architecture structured? And what can Keepit do to support data sovereignty and protection against ransomware?
Østergaard explains that Keepit’s European position didn’t just happen overnight. The idea for the backup platform actually began to take shape around 2010, when many companies chose AWS without giving it much thought. After that, Microsoft Azure and Google Cloud also came into the picture more and more frequently. As a Danish company, Keepit saw an opportunity to build its own infrastructure, incorporating elements such as the storage layer and data centers. According to Østergaard, that was a logical choice for what a backup should actually be.
Østergaard notes that during the transition from Exchange Server to Exchange Online, many companies actually ran into the problem that their backups didn’t transfer over. There was a widespread assumption that the cloud provider would take care of it. According to Østergaard, Microsoft has always been transparent about this in its terms of service: if you lose data in the online services, the backup is your responsibility. However, this wasn’t a top priority in marketing campaigns.
Why no hyperscaler?

This led to the key question of where to store that backup. A backup is an immutable copy that is completely isolated from production data. The ideal solution is an offline tape in a safe, without power and without any IT infrastructure surrounding it. While this isn’t literally possible in the cloud, Keepit wanted to get as close to that as feasible.
And that’s where the problem lies with hyperscalers. Microsoft 365 runs on Azure, a large portion of Salesforce runs on AWS, and Google Workspace runs on Google Cloud. The average organization uses dozens to hundreds of cloud services. There isn’t a single hyperscaler that doesn’t host at least some of those services. Storing backup data with one of them therefore inherently means that the separation between primary and secondary data breaks down somewhere.
Keepit assumed that the majority of global data would move to the cloud and that a significant percentage of it would need to be protected. Some customers pay for 100 years of retention. That requires a system that is virtually infinitely scalable, with guaranteed backward compatibility and a service agreement covering the same timeframe. Keepit’s answer to this is its own object store, specifically designed for backup workloads.
Merkle tree architecture
This object store is based on a Merkle tree architecture. This is a tree structure in which higher-level elements (hashes) refer to multiple underlying data elements. Thanks to these cryptographic properties, it is possible to verify at a glance whether the data has remained unchanged. This structure is a perfect fit for backup sets, according to Østergaard. Keepit can cryptographically prove that data coming out of the system is identical to what was originally entered, even if that happened, so to speak, fifty years ago. This applies down to every individual email and chat message.
Keepit manages the Merkle tree itself. The customer trusts that the company knows what the backup set was yesterday. However, according to Østergaard, the structure makes it easy for customers to verify things themselves.
Filling almost the entire disk
The proprietary file system has a second effect, which is purely economic. Conventional file systems do not fill a hard drive completely, because filling it further would sacrifice too much performance. Keepit manages this more efficiently, filling the drive to nearly its full capacity. The system can do this because it is fully tailored to backup. Østergaard sees this as giving Keepit an edge over other platforms. The result is a cost structure that, in his view, is more favorable than what a hyperscaler can offer, certainly more favorable than that of competitors running on AWS themselves.
Keepit charges per seat, not per gigabyte. There are no calculations based on the number of documents or required IOPS. If you have a thousand employees and add two hundred more, you know exactly what that will cost. Keepit is thus consciously taking a risk on data volume, but also benefits if the volume turns out to be lower than expected.
From three workloads to nearly twenty
Workload support began with Microsoft 365. Salesforce and Google Workspace followed shortly thereafter. In 2015, the main debate was whether cloud backup was even necessary. Even large enterprises still assumed that Microsoft would step in if things went wrong.
That perception has shifted, making expansion a priority. However, each new workload required a significant amount of work. Adding Entra ID was a major project. A few years ago, Keepit concluded that workloads are more similar at a high level than we realize; an HR system and an identity management system, for example, have a lot in common. The company therefore built its own programming language to abstract those similarities.
That technology has now been in use for two and a half to three years. Keepit currently supports 18 workloads. It now also protects Jira, Zendesk, Dynamics 365, Azure DevOps, and Power Platform, among others.
Anomaly detection on backup data
If a ransomware attack does occur at a company, the focus quickly shifts to recovery. Keepit offers standard integrations with SIEM systems and performs anomaly detection on the backup data itself. This allows the affected company to see, for example, whether an unusually large number of files have been modified. Given the volume and richness of the dataset, Østergaard believes more is possible than what is currently being done in practice, and he expects further developments in this area.
What’s also interesting is what happens after detection. Should you roll back everything or just the affected objects? Keepit operates entirely at the granular object level. This makes it possible to restore only the compromised files (such as individual documents and/or emails).
Most restores are very small
That granular model aligns with what Keepit observed in its annual data report. For the first time, the company examined the actual usage of the platform by its customer base, anonymized and at an aggregated level. The conclusion is that the vast majority of all restores consist of small, isolated file recoveries. This points, for example, to a minor mishap, such as an employee losing a document.
For Østergaard, these are two positive signs. First, it turns out that most incidents result in only minor damage. Second, this means that backup isn’t like fire insurance, something you hope you’ll never have to use, but rather something that delivers value on a daily basis. Backup is often dismissed as a “Plan B” for when everything is lost. But how often is everything actually lost? Fortunately, in practice, that happens less frequently. The figures show that organizations have simply integrated the service into their daily operations.
Sovereignty as an unexpected differentiator
The discussion about infrastructure and jurisdiction inevitably extends to sovereignty. Østergaard has observed a stronger focus on this over the past year to a year and a half than ever before. Can a European company operate without non-European products? Theoretically, yes. In practice, you wouldn’t want to.
What he believes has really sunk in is the scenario in which a non-European service is shut down. No matter how good the relationship between customer and supplier may be, if the supplier falls under a non-European jurisdiction and is ordered to stop the service, then the service actually stops. The question then is what your plan is. Losing access to your data and shutting down operations is a worse outcome than restoring from a backup, even if that’s not ideal.
According to Østergaard, Keepit is seeing a lot of interest in European alternatives to primary cloud services as well as in migrations to those alternatives. The company itself remains focused on the backup side. The fact that the company is pretty much the only European player in this segment is a nice bonus. It’s now truly a differentiator in the current geopolitical climate.
Own equipment in colocation
Growth in this area continues unabated, even in a market where organizations are trying to cut costs across the board. According to Østergaard, the increased focus on European providers offsets that drive to cut costs.
Although Keepit’s infrastructure is rock-solid, the data centers are colocation facilities. The equipment in the data centers belongs to Keepit: servers, networking, its own IP blocks, its own internet routing, and its own peering with major providers. The company once owned its own data center, a holdover from its hosting days. The conclusion was simple: if it’s not necessary, it’s better not to own one. Moreover, the storage density is high enough that it isn’t necessary at this time.
Customers choose their own region, and each region consists of two physically separate locations. In Frankfurt, these are two colocation facilities. If you choose Copenhagen, your data is stored in two centers within that region. This ensures that an entire site can go offline without data loss or service interruption. Keepit serves customers in Switzerland, Germany, Denmark, the Netherlands, and the United Kingdom in this way. Data remains within the selected region. The regions are isolated from one another. According to Østergaard, for an EU company, it makes no technical difference whether the location is Copenhagen or Frankfurt. Both are good locations.
Ultimately, Keepit has built a platform that ensures independence and control, which is an attractive option for companies that want to maintain control over their backups.