Industries
Sovereignty is an engineering property, not a clause.
STORViX AB is a Swedish company. Vault replicas sit in STORViX-operated data centres in Sweden, Italy and other EU countries. Where the company is incorporated and where the data physically sits are both answerable.
- Swedish company
- Named EU facilities
- Zero-knowledge policy
- 7–10 year lifecycle
The problem
Public records outlast the procurement that bought their storage.
A public body committing to a storage platform is making a decision that will outlive the officials who make it, several budget cycles, and quite possibly the supplier's current ownership. That is a different risk calculation from a commercial one.
Sovereignty has moved from a preference to a requirement in much of European public procurement, and the question has become more precise: not merely where a data centre is, but under whose jurisdiction the operating company falls and who could be compelled to produce data.
Meanwhile continuity obligations are absolute. A public service does not have the option of being unavailable while a storage migration completes, and citizens' records do not have the option of being lost — which puts a premium on platforms whose service life matches the obligation.
What STORViX does about it
Answers to the questions a tender actually asks.
Each item below corresponds to a question that recurs in public sector storage tenders, answered with a specific fact rather than a reassurance.
Where is the supplier incorporated?
STORViX AB is registered in Sweden under number 559074-0865, headquartered at Ideon Science Park in Lund. The company was founded in 2016 and has been shipping AiRE since 2017.
- Swedish limited company
- Founded 2016, product shipping since 2017
- Serving customers across EMEA
Where does the data physically sit?
For an owned appliance, on your premises. For Vault replicas, in STORViX-operated data centres in Sweden, Italy and other EU countries — named jurisdictions, not a region setting.
- On-premises for owned units
- Named EU countries for Vault
- Zero-knowledge privacy policy and DPA
Who can reach the data?
Encryption is applied per data set with per-data-set access privileges, administrative access is protected by two-factor authentication, and Vault drives carry FIDO2 multi-factor authentication.
- Per-data-set encryption and access
- 2FA on administrative access
- FIDO2 MFA on Vault physical drives
- AES 256 at rest
How long will the platform last?
A seven-to-ten-year hardware lifecycle, achieved through reconfigurable disk packs and non-disruptive expansion. For a procurement horizon measured in years, that materially changes the whole-life cost.
- 7–10 years in service
- Capacity added without downtime
- Performance and capacity scale independently
What happens after an incident?
Immutable copy-on-write snapshots cannot be altered once taken, so recovery survives an attacker holding administrative credentials. Vault replication is one-way, so a compromised source cannot reach back into the archive.
- Immutable snapshots
- One-way replication into Vault
- Recovery over network or shipped drives
- DRaaS for orchestrated recovery
Can the records be proven intact?
Checksums extend to the root node and are verified on read, with automatic repair on mismatch. A record retrieved after fifteen years is verified rather than assumed.
- End-to-end integrity verification
- Self-repair from redundant copies
- Protection against silent decay
Outcomes
What changes for a public sector estate
Whole-life cost that survives scrutiny
A lifecycle two to three times longer than the conventional refresh assumption is the largest single lever in a whole-life cost comparison, and it is a defensible one.
Sovereignty answerable at two levels
Both corporate jurisdiction and physical data location can be stated precisely, which is what distinguishes a sovereignty answer from a sovereignty assurance.
Continuity without maintenance outages for growth
Non-disruptive expansion means capacity planning does not have to be negotiated against service availability.
Fewer migrations across the retention period
Every migration is a risk to records and a cost to the budget. Halving the number of them over a decade is a continuity argument as much as a financial one.
On NIS2 specifically
STORViX states that AiRE is engineered to exceed NIS2 standards. NIS2 raises obligations around risk management, incident handling, business continuity and supply chain security for essential and important entities, and places accountability on management bodies directly.
Storage sits inside several of those obligations: the integrity and availability of data, the ability to recover after an incident, and the security of the supply chain the entity depends on. The controls listed above map onto those areas, and an architect can walk through how each behaves in detail.
What this page will not do is assert that deploying AiRE makes an entity NIS2-compliant. Compliance is an assessment of governance, process and technology together, and it belongs to the entity and its advisers. Any statement on this site that has not been verified against STORViX source material is visibly marked as requiring validation.
Bring the tender questions.
If you are drafting or responding to a specification, the most useful conversation is the one that goes question by question — including the ones where the honest answer is that it depends on your environment.