Everything an AI Server needs, apart from re-downloadable models, lives in its data folder: %USERPROFILE%\AISuite\v2 on Windows (or the folder chosen in Settings), /data in the container images.
What is in the data folder
| Item | Path in the data folder | Back up? |
|---|---|---|
| API keys (hashes) | credentials/server-keys.json | Yes — clients stop working without it |
| Licence lease | licensing/ | Yes — lets a restored server start before it can reach the licence service |
| Gateway pool | gateway.json | Yes on a gateway — it holds worker keys; keep it secret |
| Server settings | server-settings.json | Yes |
| Governance policies | governance/*.json | Yes |
| Audit signing key | governance/audit-signing-key.json | Yes — and protect it: it signs audit exports |
| Audit log | audit/ | As your retention policy requires |
| HTTPS certificate | server/tls/ | Optional; a self-signed one is regenerated |
| Logs | logs/ | No |
| Models and engines | models/, engines/ (or the cache folder) | No — download again |
On Windows the same folder also holds every AI Suite app's documents and your registration. Back up the whole folder; never delete it to "reset" the server.
Full backup
- Stop the server (the service, or the container) so files are not being written.
- Copy the data folder, leaving out
models,enginesandlogsif you want it small. - Start the server again.
For containers, snapshot the /data volume or copy it with a throwaway container:
docker run --rm -v aisuite-data:/data -v "$PWD:/backup" alpine \
tar czf /backup/aiserver-$(date +%F).tgz --exclude=./models --exclude=./engines -C /data .
On Kubernetes, use your volume snapshot tooling on each worker's PVC; the gateway's state is in its Secrets.
Restore
Stop the server, copy the folder back (keep file owners: UID 1654 in containers), start it. Clients keep working because their keys are in server-keys.json. If the licence lease has expired in the meantime, the server activates again at start-up.
Settings export (Windows app)
Settings → Backup & restore exports a portable copy of the configuration — governance, quotas, moderation, catalogue and gateway settings — for copying a setup to another server or keeping it in version control.
- Secrets are replaced by placeholders; importing a bundle with placeholders keeps the secrets the target server already has.
- Network settings (access, port, HTTPS, start mode) are not in the bundle and never change on import.
- API keys, the licence and the audit log are not in the bundle. Use a full backup for those.
Copy AI prompt on the same page produces a description of the settings format plus your current (redacted) settings, so an AI assistant can draft a change for you to review and import.
Questions
Can I move a server to new hardware? +
Yes: restore a full backup on the new machine and start it. The licence seat moves with it once the old server is stopped.
Are API keys in the backup usable by someone who steals it? +
No. The file holds salted hashes only. The audit signing key and gateway.json are sensitive, though; store backups encrypted.