Your own copy of every database.
Lastro backs up the MySQL databases you look after — on the days and at the time you choose, compressed, verified and kept for as long as you say — while it waits in the Windows tray.
12:30, on the dot: one read-only snapshot, streamed straight into a compressed file.
It keeps the good backups
- A backup only exists once it is verified. It is written as .partial, read back — every byte hashed, decompressed and, if encrypted, decrypted — and only then given its name. A backup cut short never passes for one.
- Retention counts backups, never days. Keeping the last seven means seven good ones survive however long the failures last, and the first of each month can stay for a year as well.
- It only deletes what it wrote. Each folder keeps an index of the files Lastro put there. A dump of your own in the same folder is never touched.
It keeps the schedule
- A missed time is made up for. If the computer was off at 12:30, the backup runs two minutes after it is back — once, however many times were missed.
- A failure is a suspicion. It is tried again after 5, 15 and 45 minutes before anyone is told.
- The warning that matters is the absence. A database with no backup for two days is announced even when nothing failed — the computer was off, Lastro was paused — the one case no failure message catches.
- Stopping is not failing. A backup stopped by hand discards the file it was writing and keeps the databases it had finished. It is not retried, and nobody is told.
What it copies, and how
What it refuses to do
- No writes to your servers. It only reads, inside a transaction the server itself holds read-only. Restoring is your decision; Lastro makes it easy and stops there.
- Nothing installed but itself. No service, no agent on the servers, no mysqldump. It runs while you are logged in, and makes up for what it missed.
- No password in the clear. Database passwords are sealed by Windows for your user on this computer. SSH goes through your key; Lastro never stores an SSH password.
- No telemetry, no account, no cloud of its own. Your backups are files in a folder you chose.
Questions
How do I restore a backup?
Create an empty database and load the file into it. The file names no database, so it restores under any name — which is also how you try one out without touching the original:
gunzip -c portal_2026-10-06_1230.sql.gz | mysql -u root -p portal_test
A .zst file opens with zstd -dc instead, and an encrypted one with
age -d, on any system, with the passphrase and nothing of Lastro’s. For a tool that
cannot read compressed files, Extract .sql, beside each backup in the history, writes the
plain SQL next to it, for HeidiSQL, DBeaver or phpMyAdmin to open.
What does Lastro need on the server?
Only a user that can read. Create a read-only user for Lastro, where you add a database,
gives you the SQL for one that can read exactly what a backup reads —
SELECT, SHOW VIEW, TRIGGER, EVENT — so the master password never has to be on your
desktop.
Nothing is installed on the server. MySQL inside an EC2 instance that only listens to itself is reached through an SSH tunnel, with Windows’ own OpenSSH and your key.
Windows warns me about the download.
You will see a blue window headed Windows protected your PC. The button that continues is behind More info — click that, then Run anyway. Some browsers warn about the file before that, for the same reason.
That screen is Microsoft Defender SmartScreen, and it does not mean Windows found anything wrong with Lastro. It means Windows cannot tell who made it: a publisher proves that by signing its programs with a certificate it has bought, and Lastro does not have one yet. Every new unsigned program gets this screen, however harmless it is.
You can check the file instead of taking the message’s word for it: every release
publishes a fingerprint of each download beside it, in SHA256SUMS,
and Get-FileHash in PowerShell prints the same fingerprint for a file that
arrived intact.
Does Lastro send anything anywhere?
No telemetry, no analytics, no account. Lastro connects to the servers you added, and to their SSH hosts if you use tunnels. Besides that, it fetches a small file from this site five minutes after it starts and once a day after that, to see whether a newer Lastro exists. That check sends nothing about you, your machine or your databases, and Automatic updates in the preferences switches it off.
Can I take my list to another computer?
Everything lives in one readable JSON file, %APPDATA%\Lastro\config.json. Copy it
across and every database arrives with its schedule and folder — but not its password, which
Windows sealed for your user on the first computer. Type each one again and it is sealed anew.
An empty lastro.portable file beside the executable keeps the configuration in the
same folder instead.
Which servers, systems and languages?
MySQL 5.7, 8.0 and 8.4, and MariaDB 11.4: every change is tested by backing up an awkward database on each of them, restoring the file with the stock client and comparing the two row by row. Amazon RDS hosts are recognised and connected to over verified TLS. Windows 10 and 11, x64.
English, Português, Español, Deutsch, Français, Italiano, Polski, Русский, 中文, 日本語 and 한국어, following your Windows display language, with a choice in the preferences. Next: copies to S3-compatible storage, and after that PostgreSQL.
Lastro is free. If it has kept a copy of something you needed, a donation helps keep it that way.
Donate