One secure platform for data that must stay available today and remain trustworthy for decades. Store it online, protect it on backup media, or preserve it as a long-term archive.
S3 applicationsDevices & systemsData Vault transfer app
Encrypted in transit
DV
ORGANIZATION VAULTPolicy-led storage
SHA-256
ONLINEImmediate access
BACKUPDisk + tape copy
ARCHIVEPreserved offline
Encryption at ingestOptional by policy
BUILT FOR LONG-TERM OWNERSHIP
Move data in with the tools you already use. Decide how it should live. Prove its integrity at every stage.
STORAGE, SHAPED AROUND VALUE
A lifecycle—not just a bucket.
Not every file needs the same treatment. Choose a policy when you create a bucket and Data Vault aligns online access, protected copies and long-term preservation with the value of that data.
01 / ONLINE
Ready when work is moving.
Keep one active copy on high-capacity disk for applications, teams and devices that need immediate S3 access.
Always available through S3 and web
Native files remain in their original format
Ideal for active production data
ACCESSImmediate
02 / BACKUP
Online, with a verified safety copy.
Keep the working copy available on disk while incremental jobs protect new and changed data on backup tape.
Online copy plus protected tape copy
Incremental capture avoids duplicate work
Restore with explicit overwrite or skip control
PROTECTIONDisk + tape
03 / ARCHIVE
Preserved beyond the disk lifecycle.
Write a verified archive copy to tape, then safely release the online source when the preservation contract is complete.
Offline status after verified source release
Tape, archive date and saveset traceability
Curated restore requests when needed
RETENTIONLong term
OPEN AT THE EDGE
Your data already knows how to get here.
Data Vault speaks the universal S3 protocol. Connect the applications, cameras, workstations, servers and automated systems your organization already operates—or use our purpose-built transfer application for guided movement.
01
Bring your own S3 workflowUse organization-scoped credentials with compatible software, appliances and services.
02
Move whole folder structuresUpload from the web, transfer recursively, or import directly from external S3 storage.
03
Choose encryption at ingestEncrypt when policy requires it, or retain interoperable source objects without data encryption.
Bring scattered object data into one governed vault.
Connect AWS S3, Wasabi and other S3-compatible services through one standard configuration. Browse the source, choose exactly what should move, or define a reusable policy that selects data automatically.
AWS S3WasabiPrivate S3Any compatible provider
01
Select what matters
Browse folders and objects, select individual files, whole folders or the complete source bucket.
02
Move data by policy
Match by age, last modified date, object size, key or storage class—with any or all conditions required.
03
Transfer without the browser
Data moves directly between services while progress, speed, failures and completed objects remain visible.
POLICY MIGRATION CONNECTION VERIFIED
EXTERNAL SOURCEProduction archives3-compatible
→
DESTINATIONData Vault bucketarchive policy
SELECTION POLICYALL CONDITIONS MUST MATCH
LAST MODIFIEDOlder than5 years
OBJECT SIZEAt least1 GiB
STORAGE CLASSEqualsSTANDARD
PREVIEW140 objects
DATA SELECTED35.8 GB
TRANSFER MODEServer-side
Immutable selection snapshotReady to transfer
Every completed object is catalogued and SHA-256 verified at ingest.
TRUST, MADE VISIBLE
Know what you have. Know it has not changed.
Security is carried through the full object lifecycle—from organization access and ingest to cataloguing, archive verification and restore.
SHA256
CONTENT INTEGRITY
A durable fingerprint for every object.
SHA-256 is calculated as data is written and retained in the organization catalog. Archive and restore workflows can compare against the same reference before status changes are accepted.
01
Tenant isolation
Users, buckets, credentials and file records stay within the organization boundary.
02
Encryption choice
Apply encryption at ingest where required while preserving unencrypted native objects where workflows depend on them.
03
Scoped S3 credentials
Issue and revoke bucket access independently without sharing web-account credentials.
04
Complete accountability
Administrative actions, storage activity and lifecycle events are retained in an auditable trail.
FROM INGEST TO RECOVERY
A clear chain of custody for every file.
Each stage produces a recorded, verifiable result before the file moves forward. You can see where data is, how it was protected and what is required to recover it.
01↓RECEIVE
Ingest
Receive native files without changing their original format.
S3 applications and devices
Web and recursive folder upload
External-storage migration
RESULTObject written to its organization bucket
02◇PROVE
Verify
Register the object and create the integrity evidence used throughout its life.
Calculate SHA-256 during ingest
Record size, path and timestamps
Write to the organization catalog
RESULTIdentity and integrity registered
03▣PROTECT
Apply policy
Route the verified object according to the bucket’s storage policy.
Online: retain active disk copy
Backup: disk plus verified tape copy
Archive: verified tape, then release disk
RESULTStatus, tape and saveset recorded
04↺RECOVER
Restore
Select files across buckets and recover them through one governed job.