The Problem
Every other layer can be reached
Follow an attacker who already holds domain administrator credentials, which is how 79 percent of ransomware attacks now begin. At each layer, ask one question: is there a path, and does a credential open it?
LAYER 2
Snapshots
A recovery point, not a separate copy. Usually on the same array that holds production.
REACHABLE
LAYER 3
Backup repository
Joined to the same directory, managed from the same console, on the same network.
Reachable
REACHABLE
LAYER 4
Software immutability
A retention policy on rewritable storage. Effective until someone privileged changes it.
REACHABLE
LAYER 5
Software immutability
No IP address. No authentication surface. No API endpoint. Nothing to send a command to.
NO PATH EXISTS
1
2
Software enforced immutability
A POLICY THAT CAN BE CHANGED
• Retention locks are administrative settings applied to rewritable media
• A sufficiently privileged credential can shorten or remove the lock
• Protection depends on the continued integrity of the platform enforcing it
• The enforcement layer sits on a network path an attacker can reach
• What would have to be true to turn it off: someone gets administrator access
3
Deep cloud archive tiers
12 hours
Standard retrieval, before a single byte downloads
Up to 48 hrs
Bulk retrieval, and the floor for very large restores
Per GB
Egress charges, so recovery cost scales with the disaster
Reachable
Retention and lock settings stay credential-configurable
The EchoLeaf SafeRoom™
On site
No retrieval queue, no provider throttling, no support ticket
Cache staged
Recent content returns from the archive quickly
No egress
A petabyte restore costs what a file restore costs
Unreachable
Physically disconnected, append only, no credential opens it
4
Detection stays yours
Your SIEM, EDR, or SOAR decides when something is wrong using the signals and thresholds your team already tuned.
Severance is ours
When your tooling raises an indicator, it calls the Dynamic Shield™ API and the platform’s two network connections close. No operator and no runbook required.
5
Lose the databases. Lose the appliance. Keep the cartridges.
Because uniqueness of path and filename is enforced on every cartridge at write time, each one carries a self-describing file system that is a working fragment of the whole. Read them back together and the full virtual drive, the media catalog, and the library database all reconstruct from the media alone. No surviving orchestration layer, no surviving database, no cloud service, and no vendor required. The media is the source of truth, which is what makes this suitable for retention measured in decades rather than quarters.
File-level redundancy
Each file can be written to two separate cartridges. If one fails, retrieval falls through to the second automatically, with no change to the restore request and no operator involvement.
Geo-duplication, not replication
A second SafeRoom™ at another site holds an independent archive. Nothing syncs between them, so corruption or compromise at one site has no path to propagate to the other. Two separate copies, not one copy in two places. Distance is not isolation. Independence is.
6
Nothing about your Monday changes
1
Backup writes
Your application writes to a standard NAS target.
2
3
Catalog indexes
Name, path, size, timestamp, cartridge, slot.
4
5
Media isolates
The cartridge moves beyond reach of any command.
Your files keep their names. Hundreds of cartridges appear as one contiguous drive, with the original folder structure intact for the life of the archive. Search by name, path, or date, then tag for restore. Nobody has to know which cartridge anything is on.
You cannot encrypt what you cannot reach
Detection is improving, and the industry is racing to identify threats faster than attackers can move. Physical isolation is the only defense that does not require winning that race, because it does not require detection at all. We do not need to find threats in data that was never exposed to them. True cyber resilience isn't winning the AI race. It's not needing to.
The Details
ENCRYPTION
AES-256 at the drive
A cartridge removed from the library is unreadable without the key. Keys held in HashiCorp Vault, retrievable for an offline restore.
MEDIA
LTO, an ISO standard
Append only by design. WORM cartridges additionally block format and low-level rewrite at the media level. Safe guarded slots supported.
AUDIT
Every action logged
User, timestamp, operation, file, cartridge, and drive. Exportable, and available to your SIEM through the API.
SCALE
Hundreds of TB to petabytes
Libraries configured by slot count, with expansion units that add capacity without replacing the platform.


