Solutions

Controls you can evidence, not adjectives you can quote.

STORViX engineers AiRE for strict NIS2 requirements. What this page provides is the specific technical controls and where the data physically sits — the compliance conclusion is yours and your advisers' to draw.

  • Per-data-set encryption
  • Immutable snapshots
  • Named EU jurisdictions
  • 2FA on administrative access

The problem

The control exists. Proving it takes three weeks.

Most regulated organisations have the controls. What they lack is the ability to evidence them quickly, because the evidence is scattered across an array, a backup product and a cloud console, each with its own vocabulary for the same idea.

So a supervisor's question — is this data encrypted, where does it physically sit, who could alter the backup, when was recovery last proven — becomes a project rather than a query.

NIS2 has sharpened this. The obligations reach further up the management chain than previous regimes, which means the answers are wanted faster and by people who will not accept a vendor datasheet as evidence.

What is asked

Where the answer lives

  • Is this category encrypted?

    Encryption

    This data set only

  • Who can reach it?

    Access privileges

    This data set only

  • Could a record be altered?

    Immutable snapshots

    Per data set

  • Is it provably intact?

    Integrity verification

    Every block, on read

  • Where does the copy sit?

    Vault replication

    Named EU locations

Array-wide controls

One answer covers everything, so a question about one category needs caveating about the rest.

Per-data-set controls

The control is a property of the object being audited, so the answer is as specific as the question.

A technical control is not a certification, and this does not claim one. What it shows is where the evidence for each control physically lives — which is the part that usually takes three weeks to assemble.

What STORViX does about it

Make the control a property of the data set.

When encryption, retention and protection attach to the data set rather than to the appliance, the evidence is a property of the object being audited.

  • Encryption per data set

    Encryption is applied to each individual data set rather than array-wide, so a data set carrying regulated information can be treated differently from one that does not — and evidenced separately.

    • Granular rather than array-wide
    • Per-data-set configuration
    • Combined with per-data-set access privileges
  • Immutable snapshots as a control

    Copy-on-write snapshots cannot be altered once taken. For a control requiring that records be protected against modification, that is a technical property rather than a procedural promise.

    • Unalterable once taken
    • Point-in-time recovery
    • Survives compromised administrative credentials
  • Verifiable integrity

    Checksums extend through the data hierarchy to the root node and are verified on read, with automatic repair on mismatch. Silent data corruption is detected rather than returned as valid.

    • End-to-end checksums
    • Self-repair from redundant copies
    • RAID-Z and mirror topologies
  • Data residency you can name

    Vault replicas are held in STORViX-operated data centres in Sweden, Italy and other EU countries, under a zero-knowledge privacy policy and a data processing agreement that goes beyond the statutory minimum.

    • Named EU jurisdictions
    • AES 256 at rest
    • FIDO2 MFA on physical drives
  • Administrative access controls

    Two-factor authentication protects administrative access, following STORViX's 2020 partnership with Yubico. Access privileges can be defined per data set.

    • 2FA on administrative access
    • Per-data-set access privileges
    • Anomaly detection from telemetry
  • A ten-year platform for a ten-year obligation

    Retention obligations outlast refresh cycles. A seven-to-ten-year hardware lifecycle means the platform holding the records is not replaced three times during the retention period.

    • 7–10 year hardware lifecycle
    • Non-disruptive capacity expansion
    • Modular disk pack reconfiguration

What STORViX does not claim, and neither does this page

A technical control is not a certification. This page does not assert that deploying AiRE makes your organisation NIS2-compliant, GDPR-compliant, or compliant with any sectoral regime. Compliance is an assessment of your organisation's processes, governance and technology together, made by you and your advisers.

What STORViX states is that AiRE is engineered to exceed NIS2 standards, and that Vault operates from GDPR-compliant data centres. Those are the vendor's statements about the product, and they are reproduced here as such.

Where a specific control needs to be evidenced to a specific supervisor, that is a conversation with an architect who can describe exactly how the mechanism behaves — not a checkbox on a comparison sheet. Any figure or capability on this site that has not been verified against STORViX source material is marked as requiring validation, rather than presented as established.

Bring the control you need to evidence.

The productive conversation starts from a specific obligation and works back to the mechanism, rather than starting from a feature list and hoping it covers the obligation.