Skip to content

Backup and recovery

This page is for the administrator responsible for protecting BioTrack’s attendance data. BioTrack keeps two kinds of backup: automatic daily backups that stay on the PC, and portable backups that you create and store elsewhere.

Only a BioTrack administrator can create or restore backups.

Settings, Backup and recovery: the Portable backup group with the database size and the Create backup and Restore from backup buttons. Settings, Backup and recovery: the Portable backup group with the database size and the Create backup and Restore from backup buttons.

The collector service makes one backup per business day without any action from you.

  • Each backup is stored under %ProgramData%\BioTrack\service\backups with a manifest (checksum, schema and size).
  • It stays encrypted with the same key as the live database, and BioTrack reopens and checks it before keeping it.
  • The latest 30 daily backups are kept.
  • They include terminal and cloud credentials, because they are same-machine recovery points.

A portable backup is an encrypted copy of attendance, employees and settings that you can store somewhere else and restore on this or another BioTrack installation.

  • It is protected by a recovery passphrase that you choose. BioTrack derives a 256-bit key from it with Argon2id.
  • It excludes terminal credentials, cloud credentials (including the cloud signing identity), setup-completion state and sign-in throttle state.
  • It is saved as two files: the encrypted .db and a .manifest.json beside it. The manifest records the encryption settings, checksum, size, schema and exclusions, and is authenticated with a key derived from the passphrase.
  1. Go to Settings → Backup & recovery and select Create backup….
  2. Enter a Recovery passphrase of at least 16 characters, and enter it again in Confirm recovery passphrase.
  3. Select Choose location and create and pick a folder.
  4. Wait for Backup created and verified. The saved path appears under Backup saved.

Then:

  • Keep the .db and .manifest.json files together and do not rename either one.
  • Store the passphrase separately from the files, through an approved channel such as your organisation’s password manager. BioTrack cannot recover a lost passphrase.
  • Take a portable backup before every update and on a regular schedule that suits your organisation.

A restore replaces all current BioTrack data with the backup.

  1. Go to Settings → Backup & recovery and select Restore from backup….
  2. Read the warning This replaces all current BioTrack data.
  3. Enter Your administrator password (the password of the BioTrack administrator you are signed in as).
  4. Enter the Backup recovery passphrase.
  5. Type RESTORE in the confirmation box.
  6. Select Choose backup and restore and pick the .db file. Its .manifest.json must be in the same folder.

BioTrack checks the manifest, file name, size, checksum, schema, exclusions and passphrase before it stops collection. If any check fails, nothing is changed and you see an error; current data is unchanged. If the checks pass, collection pauses, the backup is restored, and BioTrack restarts and signs everyone out.

  1. Sign in with a BioTrack administrator account from the restored backup.
  2. Enter the terminal password again in Settings → Terminal & connection and select Test connection. See Terminal and connection.
  3. If you use cloud reporting, reconnect it in Settings → Cloud reporting. See Connect and activate.
  4. Make a real scan on the terminal and check it appears on Today.

The database and daily backups are encrypted with a key stored at %ProgramData%\BioTrack\attendance.db.key, protected by Windows for this machine. If that file is lost or damaged, the database and the daily backups cannot be opened. BioTrack deliberately does not create a replacement key next to an existing encrypted database.

Your only route back is a portable backup and its recovery passphrase. If neither is usable, stop, do not delete anything, keep the files, and contact support.