Browse the manual
Self-hosting and backups
What self-hosting means for your invoicing data, what you are responsible for, and how to protect your records.
On this page
For: business owners and developers running Made with Pepper on their own server.
What self-hosting means
Self-hosting means Made with Pepper runs on your server. You own the files, the database, and every invoice record. Your hosting provider also controls the server infrastructure. Choose a provider whose access and backup policies meet your needs.
You are responsible for keeping it running. Made with Pepper does not monitor your server. If your hosting goes down, you cannot use Made with Pepper.
Your responsibilities
Keep backups. Your database contains your invoice records, customer data, payment history, and audit trail. If you lose the database, you lose that data. Back up the database and private and public media together.
Use Settings > Backups for an authenticated archive. Keep the original .env, APP_KEY and trusted application package separately.
Keep PHP updated. Made with Pepper requires PHP 8.4 or later. The PHP maintainers release security patches. Run a supported version.
Keep your server secure. Use HTTPS. Keep your operating system patched. Use strong passwords. Restrict SSH access.
Set up email. Made with Pepper sends invoices by email through your configured mail provider (SMTP or Resend API). If your mail server goes down, your credentials expire, or your API key is revoked, the mail server stops accepting invoice emails. Each document then shows Email queued, Email failed or Email result unknown on its Delivery tab. Made with Pepper retries temporary failures. Check the delivery state after you send, and keep the cron job running.
Backup strategy
A minimum backup strategy for a small business:
- Daily or weekly: authenticated database and media backup, using the server scheduler
- Separately: encrypted configuration and key copy, plus the matching trusted application package
- Off-site: store at least one copy somewhere other than your hosting server
Test each recovery procedure in a separate directory and empty database. Keep mail and scheduled work stopped during verification.
What Made with Pepper stores
| Data | Location |
|---|---|
| Invoice records, line items, payments | Database |
| Customer records and contacts | Database |
| Company settings and tax rates | Database |
| Audit log | Database |
| Company logo | storage/app/public/ directory |
| Issued PDF and XML originals | storage/app/private/documents/, with hashes in the database |
| Application key and connection settings | .env, excluded from backup archives |
Protect the database and media together. An issued original is stored evidence, not a disposable cache. You can reinstall the application code from the Made with Pepper package.
What Made with Pepper does not do
Made with Pepper can back up your database and uploaded files. You can create a backup on demand or enable a daily or weekly schedule; scheduled backups require the server scheduler. Backups stay on your server, so you need to keep an off-site copy. Made with Pepper does not replicate to a remote server or alert you if your disk fills up or your database becomes corrupted.
If you are not comfortable managing a server, consider managed hosting from a provider that handles backups and security patches for you. Recovery also needs shell access, a separate database and directory, stopped writers, and a document-root switch. Confirm these capabilities with your host.
Cutover and newer records
An online backup contains records only up to its snapshot. For a planned move, stop writers and take a final sealed backup.
For example, a snapshot may include a EUR 125.00 invoice but omit a later USD 240.00 payment. Reconcile that payment before activation.
After the replacement receives writes, do not return to the stale source. Follow Final snapshot and cutover.
Related pages
Need help with the product?
Contact support