Industries

Data that cannot come ashore has to be safe where it is.

An installation generates seismic, drilling and condition-monitoring data faster than its link can move it, in a place where nobody's job title is storage administrator. AiRE is built to run unattended, replicate only what the link can carry, and be specified once across a whole fleet.

  • One configuration per fleet
  • No administrator on board
  • Snapshot-delta replication
  • 4U per installation

The problem

Three constraints a data centre never has to answer.

Topside space, power and cooling were allocated when the installation was built, and a storage decision offshore starts with what the structure will physically accept and what its area classification permits. Capacity is the second question, not the first — which is the reverse of how storage is normally specified, and the reason offshore designs so often end up as one-offs.

Then there is the link. Seismic acquisition, high-rate drilling telemetry and continuous condition monitoring generate more in a day than a satellite connection will carry in a week, so the ordinary default — send it to the data centre and deal with it there — is simply not available. What travels ashore has to be a decision, and everything else has to be safe where it was created.

And nobody is there. Crews rotate, and the person nearest the equipment is a technician with a long list, not a storage administrator. A system offshore has to survive being ignored for months, and when it does fail the cost is not an SLA credit — it is deferred production, priced by the hour.

Underneath all of it sits a retention obligation longer than any of these constraints. Well and subsurface records are consulted decades after acquisition, and in several jurisdictions the retention period is tied to the abandonment or decommissioning of the field — the exact trigger and duration vary by regulator and by record type — which means the archive will outlive several generations of the hardware holding it.

What STORViX does about it

Specify it once, then repeat it across the fleet.

A multi-installation rollout is won or lost on repeatability. Every mechanism below is chosen because it behaves identically on the fiftieth installation as on the first.

  • One configuration, repeated

    Every AiRE instance runs identical software and the same dataset policy model regardless of footprint, and configuration changes and updates are distributed to as many instances as needed at once. A fleet stays a fleet instead of becoming fifty near-misses commissioned in different years.

    • Identical software at every footprint
    • Fleet-wide updates
    • One console for many instances
  • Operation with nobody on board

    AutoPILOT performs optimisation and administration on its own and escalates only what it cannot resolve; CloudSight raises alerts from telemetry before anyone on the installation would notice. CoPILOT Connect gives support remote assistance without a helicopter.

    • Self-healing algorithms
    • Escalation to SmartCARE
    • No local administrator required
  • Replication sized for the link you actually have

    Snapshots replicate at block level, synchronising only the differences rather than re-sending data sets. That is what turns a regular copy ashore from a bandwidth negotiation into a policy setting.

    • Deltas only
    • Installation to shore, or into Vault
    • Schedule set by link, not by product
  • Serve the data where it was created

    Unified block and file in one 4U unit, presenting NFS and SMB alongside Fibre Channel and iSCSI, with a separate performance profile for latency-sensitive work and an optimisation profile for the archive. Interpretation and monitoring workloads run against local data rather than waiting on a round trip ashore.

    • True unified block and file
    • 32–501 TiB net in a 4U GEN 4 base unit
    • Per-workload profiles on one system
  • Records that outlive the field

    A seven-to-ten-year hardware lifecycle, end-to-end checksums with automatic repair, and one-way replication into STORViX-operated EU data centres. Which records must be kept, and for how long, is set by the regulator for each jurisdiction and record type; what the platform has to guarantee is that a well record retrieved thirty years after acquisition comes back intact, because silent corruption returning as valid data is the failure that matters most and is noticed least.

    • 7–10 year lifecycle
    • Self-repairing file system
    • EU-located Vault replicas
  • Recovery that survives a credentialled attacker

    As production networks and corporate IT converge, upstream operations have become a deliberate target, and an installation is a poor place to be negotiating. Immutable copy-on-write snapshots cannot be altered by an attacker holding administrative credentials, and revert is instant.

    • Immutable snapshots
    • Instant revert to a known-good point
    • One-way replication into Vault

Outcomes

What changes for a multi-installation programme

  • One design review instead of one per installation

    A single qualified configuration turns each subsequent deployment into a repeat of an approved design rather than its own engineering exercise — which is where the schedule on a large rollout is usually lost.

  • The link stops setting the capacity plan

    When data is retained and served locally and only deltas travel, bandwidth constrains what you can see from shore rather than what you are able to keep.

  • A replacement is a swap, not a project

    Standardising on one configuration across the fleet means spares are interchangeable and an offshore intervention is within a technician's scope during a normal rotation.

  • The estate is answerable from shore

    Which installations are behind on updates, near capacity, or have not replicated successfully this week should be one query rather than fifty phone calls.

Proof

The numbers behind the claim

  • 4U

    Base unit footprint per installation, single or dual controller

    STORViX published specification

  • 32–501 TiB

    Net capacity of a single 4U GEN 4 base unit, before any disk expansion unit

    STORViX FAQ, storvix.eu/frequently-asked-question

  • 7–10 years

    Hardware lifecycle, against a typical three-year refresh

    STORViX published specification

  • 7 years

    Continuous operation without a compromising software failure, reported by INS

    STORViX customer testimonial

Notes for a multi-installation rollout

Settle the environmental qualification before the capacity design, not after it. On a large programme it is the item with the longest lead time and the only one that can invalidate an otherwise finished architecture — see the section below on what STORViX does and does not publish.

Decide explicitly what has to travel ashore. Continuous condition monitoring, interpretation products and daily reports have very different volumes and very different urgencies, and a rollout that treats them as one replication policy will either saturate the link or under-protect the data that mattered.

Establish where the storage sits relative to the production network. Segregation between operational technology and corporate IT is an architectural decision that has to be made per operator, and it determines whether CloudSight telemetry and remote assistance are available in the form described above — for a restricted or air-gapped installation, that is a conversation with an architect rather than a datasheet extract.

Standardise the spares strategy alongside the configuration. The argument for one configuration across the fleet is only realised if the parts held onshore fit every unit in it.

What this page does not claim

AiRE holds no hazardous-area (ATEX or IECEx), marine, shock, vibration or extended-temperature qualification. STORViX has confirmed that directly, and this page states it rather than leaving it to be discovered at technical review. The published specifications describe a datacentre-style installation, and that is the environment the platform is specified for.

What follows from that is a design constraint rather than a dead end. Acceptance for any given location is a question for the operator against its own environmental specification, and where a location cannot take equipment of this class, the pattern that applies is onshore or near-shore processing with the installation holding only what it must. That is a different architecture from the one described above and is worth scoping as such from the outset rather than as a fallback discovered late.

It does not assert that deploying AiRE makes an operation compliant with IEC 62443, NIS2, any national offshore safety regime or any operator standard. Those assessments consider governance, process, personnel and technology together and belong to the operator and its assurance function.

Any statement on this site not backed by supplied STORViX source material is visibly marked as requiring validation rather than presented as established fact.

Questions

Frequently asked

Is AiRE certified for installation on an offshore platform?
No. AiRE holds no hazardous-area, marine or extended-environment certification, and STORViX has confirmed that rather than leaving it unstated. The published specifications assume a datacentre-style installation. If you are scoping an upstream rollout, that is worth knowing at the first conversation rather than at technical review: where a location cannot take equipment of this class, the design to scope is onshore or near-shore processing with the installation holding only what it must.
Question 1 of 4
How much bandwidth does replication from an installation need?
Snapshots replicate at block level and send only the differences between them, so the requirement is driven by your change rate rather than by your data set size. That is what makes a frequent copy over a satellite link realistic where a full transfer would not be. The actual figure has to be worked out against your change rate and your recovery objective, which is a sizing conversation rather than a published number.
Question 2 of 4
What happens when an installation loses its link entirely?
The system continues to serve data locally. AutoPILOT handles optimisation and routine administration without a connection, and replication resumes from the last completed snapshot when the link returns rather than restarting. What is lost during an outage is visibility from shore, not the availability of data on the installation.
Question 3 of 4
Can one platform hold both operational data and the long-term archive?
Yes — that is the point of per-data-set policy. Active operational data, retained records and anything being staged to travel ashore can carry different performance profiles, encryption settings, snapshot schedules and replication targets on the same unit, rather than each requiring its own box on an installation that has no room for three.
Question 4 of 4

Start with the two questions that gate the programme.

What the installation will physically and lawfully accept, and what genuinely has to travel ashore. Those two answers shape the design for every unit in the fleet, and they are worth settling before anyone sizes a disk pack.