Cyber vaults

Keep the attack out of your cyber vault. Prove each copy clean before it is locked.

A cyber vault holds the isolated, immutable copy you restore the business from. It keeps whatever it receives, including the persistence an attacker planted and files ransomware already encrypted. Elastio proves each copy clean before the vault locks it, and flags the ones that are not.

Your vault keeps the copy. Elastio proves what is inside it.
What makes a cyber vault work?

A vault needs three properties. Storage provides two of them.

Isolation and immutability come from your vault platform. Integrity, proof that a copy was clean when it went in, has to be established before the lock. Once a copy is locked, whatever it carries stays for the full retention period.

  1. 01Isolation

    The vault sits in its own account or tenancy, behind its own identity boundary. Credentials stolen from production do not reach it.

  2. 02Immutability

    A retention lock keeps each copy from being altered or deleted until its retention period ends. It protects the copy exactly as it was written.

  3. 03Integrity

    Each copy is proven free of the attack before it is locked. This is the property Elastio provides: Pursuit analyzes the system copy for an active attack, and Hunt hunts the data for ransomware.

Isolation and immutability decide whether the copy survives an attack. Integrity decides whether restoring it ends the attack or starts it again.

What can an attack leave in a vaulted copy?

What the vault keeps when the attack got there first.

Attackers get in and move undetected before they strike, and your backup plan keeps copying through that window. Every copy made in it enters the vault with the attack inside, and a restore from any of them brings the attack back with the data.

Elastio Pursuit

The attacker’s way back in

A system copy made after the intrusion carries the persistence the attacker planted: a scheduled task, a service, a WMI subscription, a Run key. Restore it and the attacker returns with the host. Pursuit analyzes the system copy off-host and names the persistence, with the evidence behind it.

Elastio Hunt

Data already encrypted

Ransomware can encrypt slowly, or a few blocks per file, so each new copy looks like ordinary change. Hunt opens the files with Deep File Inspection, finds ransomware with or without a signature, and names the last recovery point proven clean.

  1. 01PersistenceRun keys, scheduled tasks, WMI subscriptions, and services that start the attack again on boot.Elastio Pursuit
  2. 02Endpoint agent tamperingThe point where your endpoint control stopped reporting.Elastio Pursuit
  3. 03Ransomware encryptionFast, slow, and partial encryption, named by family where the family is known.Elastio Hunt
  4. 04File corruptionCorrupted files and file-system damage that leave a copy unusable for recovery.Elastio Hunt
  5. 05Malware and your own indicatorsKnown malware, plus the rules your team writes in SQL, YARA, or Regex.Elastio Hunt
What does vaulting guidance say about integrity?

Integrity is checked before the lock, not after.

The UK financial sector’s guidance for cloud-hosted vaults sets immutability and network isolation as foundation principles, and places the integrity check ahead of the lock.

“Integrity checks must be done prior to securing the data, doing it post will not ensure recovery of the original data or the service that the data supported.”

CMORGCloud-Hosted Data Vaulting Good Practice Guidance, Foundation Principle 11, January 2025
NYDFS 500.16

A financial services firm moved immutable, encrypted backups into a bunker account, but could not prove the copies were clean before they went in. With Hunt, every backup is hunted before it is copied to the bunker account, and the CIO reports vault integrity with evidence.

Read the case study →
How does it fit our vault workflow?

Every recovery point passes a gate before the vault.

Elastio sits upstream of the vault. Your backup platform keeps creating and retaining copies as it does today, and each recovery point is proven clean before it is copied in.

Each recovery point

  1. 01

    Created

    Your backup plan writes the recovery point to its default vault.

  2. 02

    Hunted

    Hunt hunts it for ransomware encryption, corruption, and malware.

  3. 03

    Promoted

    A clean recovery point is copied to the cyber vault and joins the set you restore from.

  4. 04

    Quarantined

    A flagged recovery point goes to a separate quarantine vault, outside the restore and replication path, where your IR team can work it.

  5. 05

    Reported

    Every decision reaches your SIEM with its finding and evidence.

The automated quarantine workflow runs on AWS Backup and AWS Logically Air-Gapped Vaults.

Does it work with the vault we have?

Elastio proves the copies your vault already holds.

  • AWS

    AWS Backup vaults and Logically Air-Gapped Vaults.

  • Azure

    Azure Backup and Recovery Services Vaults.

  • Backup vendors

    Veeam, Commvault, Rubrik, and Cohesity.

Elastio is not a vault and does not replace yours. It hunts the recovery points your existing tools create and store, with no change to your retention or recovery tooling.

When a new indicator emerges, Hunt re-hunts every copy you already vaulted and tells you whether any of them carry it.

Where does Elastio run?

Before the vault, after it, or both.

Before the vault

  • Runs in the workload account, where recovery points are created.
  • Each recovery point is proven clean before it is copied to the vault.
  • Flagged recovery points never reach the vault.

Inside the recovery account

  • The vault is shared with a separate recovery account through AWS Resource Access Manager.
  • Elastio hunts vaulted copies and runs restore tests there, without opening the vault to production.
  • Findings on vaulted copies name the last recovery point proven clean.

Integrity, from both engines.

Pursuit finds the attack in the system copy. Hunt proves the data in it is clean. Together they give the vault the one property it cannot provide for itself.

Find out what your vault is holding.

30 minutes. Your environment, no slides.

Request a demo