Defense-in-Depth Network

Recovery systems sit in an isolated network, separated from the internet and from each other.

Recovered data never touches a general-purpose network. Our lab is segmented into layers, each with its own controls, so a failure in one layer doesn't expose the next.

Six layers between your data and the outside world

Defense-in-depth layersSix nested layers protect client data: facility perimeter, personnel controls, segmented network, isolated recovery workstations, encryption, and the client data at the center. 1 · Facility perimeter — badge + biometric access, 24/7 CCTV 2 · Personnel — background checks, NDAs, two-person rule 3 · Segmented network — no internet on recovery VLANs 4 · Isolated workstations — write-blocked, logged 5 · AES-256 encryption at rest & in transit Your data
Defense-in-depth diagram

What each layer does

  • Facility: badge and biometric entry, visitor escort, 24/7 recorded CCTV
  • People: background checks, annual security training, NDAs, two-person rules for sensitive cases
  • Network: recovery VLANs have no internet route; management traffic is isolated and logged
  • Workstations: hardened builds, write-blockers, USB control and session logging
  • Encryption: AES-256 for data at rest and TLS 1.2+ for anything in transit

Certifications

SOC 2 Type IIIndependently audited controls
HIPAABusiness Associate Agreements
ISO Class 5 cleanroomParticle-controlled lab
Chain of custodyEvery device, every step

More on security

Every hour matters. Contact us now.

Stop using the device, then talk to an engineer. Evaluation is free and your quote is fixed before we start.