The backup and export post I wrote a few weeks back covered how to get your content out of Cantrip. Somebody asked me the natural follow-up: fine, but if I ever actually need one of these backups, what happens when I restore it?
The honest answer: it's not a merge. It's not "add back whatever's missing." Restoring a backup into an existing website deletes every page, every page section, every post across every collection, and every menu item on that site, then rebuilds all of it from the ZIP you uploaded. If your current site has three pages the backup doesn't know about, those three pages are gone. The confirmation checkbox on the import screen says exactly that: importing will permanently replace all existing content and the action cannot be undone. That's not boilerplate legal language. That's a literal description of what the code does.
There's a real safety net underneath it, though. The wipe and the rebuild happen inside one database transaction. If the import fails partway through (a corrupted zip, a file the code expects but doesn't find) the whole thing rolls back, pages and all. You don't end up with a half-deleted site while support figures out what happened. Either the restore finishes clean or your site looks exactly like it did before you clicked the button.
One piece sits outside that safety net: media. S3 uploads aren't part of that transaction, so images get imported after the database side already committed. If a specific file fails partway through, everything else finishes and that one image just doesn't attach. Rare, worth knowing, and the reason it's still smart to download a fresh backup of your current site before you restore an old one over it, exactly like the warning banner tells you to.
Here's the part most people miss entirely: restoring into your existing site isn't the only thing that ZIP is good for. There's a second, completely separate import flow that creates a brand-new website from the same file and doesn't touch anything you already have. Different page, different button, no scary checkbox, because there's nothing to overwrite. Useful if you want to spin up a copy of an old site under a new name, or hand a client a snapshot without risking their live pages. Both paths work through the dashboard and through the Cantrip MCP tools too, so an AI agent managing your site can do either one the same way you would by clicking around.
Most tools that let you nuke your own content this thoroughly hide the button behind a support ticket, or bury the warning in fine print nobody reads. Cantrip just tells you what the button does in plain English and lets you press it. Handle the mechanics, sure, but don't pretend a destructive action isn't destructive.