Backups before updates
What is backed up automatically before an update runs, and where the system's regular, ongoing backups live.
Automatic, before every update
An update never changes anything without a safety copy first. Before switching over, it saves a copy of the currently running version — application and configuration — on the server. If the new release also changes the database, the database itself is backed up too, before any change to it runs. This is exactly what the System update page itself says:
"New versions come from the update server. Before switching over, this server saves a copy of the current version — and, if the update changes the database, a backup of the database as well. If the new version does not start, the previous one is put back automatically."
That last part matters in practice: if the new version fails its own health check right after switching over, the previous version is put back automatically, using exactly that saved copy — see Updating from the web interface for the full sequence.
The regular Backup Manager
Separately from updates, the database is also backed up on its own hourly schedule, all the time — not just around updates.
See Administration & API's Backups, health & integrity check for that page, its schedule, and where the files are stored.
Before you click update, anyway
The update already makes its own copies, so nothing extra is required. If you want extra peace of mind before a particularly important update, the Backup Manager page above shows whether recent scheduled backups are present. Free disk space is also checked automatically by the update itself — it refuses to start if there isn't enough room, without changing anything.
Check
After an update, the newly installed version's release notes on the System update page show it marked "installed"; the automatic copy of the version before it stays on the server until the next update replaces it — so the previous version is never more than one step away.