Solutions
Controls you can evidence, not adjectives you can quote.
STORViX engineers AiRE for strict NIS2 requirements. What this page provides is the specific technical controls and where the data physically sits — the compliance conclusion is yours and your advisers' to draw.
- Per-data-set encryption
- Immutable snapshots
- Named EU jurisdictions
- 2FA on administrative access
The problem
The control exists. Proving it takes three weeks.
Most regulated organisations have the controls. What they lack is the ability to evidence them quickly, because the evidence is scattered across an array, a backup product and a cloud console, each with its own vocabulary for the same idea.
So a supervisor's question — is this data encrypted, where does it physically sit, who could alter the backup, when was recovery last proven — becomes a project rather than a query.
NIS2 has sharpened this. The obligations reach further up the management chain than previous regimes, which means the answers are wanted faster and by people who will not accept a vendor datasheet as evidence.
What is asked
Where the answer lives
Scope
“Is this category encrypted?”
Encryption
This data set only
“Who can reach it?”
Access privileges
This data set only
“Could a record be altered?”
Immutable snapshots
Per data set
“Is it provably intact?”
Integrity verification
Every block, on read
“Where does the copy sit?”
Vault replication
Named EU locations
Array-wide controls
One answer covers everything, so a question about one category needs caveating about the rest.
Per-data-set controls
The control is a property of the object being audited, so the answer is as specific as the question.
What STORViX does about it
Make the control a property of the data set.
When encryption, retention and protection attach to the data set rather than to the appliance, the evidence is a property of the object being audited.
Encryption per data set
Encryption is applied to each individual data set rather than array-wide, so a data set carrying regulated information can be treated differently from one that does not — and evidenced separately.
- Granular rather than array-wide
- Per-data-set configuration
- Combined with per-data-set access privileges
Immutable snapshots as a control
Copy-on-write snapshots cannot be altered once taken. For a control requiring that records be protected against modification, that is a technical property rather than a procedural promise.
- Unalterable once taken
- Point-in-time recovery
- Survives compromised administrative credentials
Verifiable integrity
Checksums extend through the data hierarchy to the root node and are verified on read, with automatic repair on mismatch. Silent data corruption is detected rather than returned as valid.
- End-to-end checksums
- Self-repair from redundant copies
- RAID-Z and mirror topologies
Data residency you can name
Vault replicas are held in STORViX-operated data centres in Sweden, Italy and other EU countries, under a zero-knowledge privacy policy and a data processing agreement that goes beyond the statutory minimum.
- Named EU jurisdictions
- AES 256 at rest
- FIDO2 MFA on physical drives
Administrative access controls
Two-factor authentication protects administrative access, following STORViX's 2020 partnership with Yubico. Access privileges can be defined per data set.
- 2FA on administrative access
- Per-data-set access privileges
- Anomaly detection from telemetry
A ten-year platform for a ten-year obligation
Retention obligations outlast refresh cycles. A seven-to-ten-year hardware lifecycle means the platform holding the records is not replaced three times during the retention period.
- 7–10 year hardware lifecycle
- Non-disruptive capacity expansion
- Modular disk pack reconfiguration
What STORViX does not claim, and neither does this page
A technical control is not a certification. This page does not assert that deploying AiRE makes your organisation NIS2-compliant, GDPR-compliant, or compliant with any sectoral regime. Compliance is an assessment of your organisation's processes, governance and technology together, made by you and your advisers.
What STORViX states is that AiRE is engineered to exceed NIS2 standards, and that Vault operates from GDPR-compliant data centres. Those are the vendor's statements about the product, and they are reproduced here as such.
Where a specific control needs to be evidenced to a specific supervisor, that is a conversation with an architect who can describe exactly how the mechanism behaves — not a checkbox on a comparison sheet. Any figure or capability on this site that has not been verified against STORViX source material is marked as requiring validation, rather than presented as established.
Bring the control you need to evidence.
The productive conversation starts from a specific obligation and works back to the mechanism, rather than starting from a feature list and hoping it covers the obligation.