SECURITY & DATA PROTECTION
How Scality secures the data you store.
Protecting data that cannot be lost takes more than one safeguard. It comes down to three things working together: the architecture that stores the data, the engineering discipline that builds the software, and the standards the platform is held to. This page walks through all three, starting with the threats they exist to stop.
The architecture
CORE5
Five layers of defense, each holding when the one above it is bypassed.
THE SOFTWARE
How we build it
Inspectable, standards-based software, maintained for a decade-long support horizon.
THE STANDARDS
Standards & compliance
Built for the financial, data-protection, and sovereignty rules you operate under.
The threat model
What a storage platform has to survive.
Attackers rarely go after the disks directly. They compromise an identity, escalate their privileges, and turn the platform's own commands against it. A storage platform earns its place by holding data when the layers above it have already been breached.
Ransomware that reaches the backup
Modern ransomware finds the backup repository and encrypts or deletes it before triggering the primary attack, leaving nothing to recover from. It increasingly steals a copy first and extorts on exposure, not just on encryption.
96%
of ransomware attacks now involve data exfiltration. Blocking deletion is no longer enough; a stolen copy has to be unreadable.
89%
of organizations had their backup repositories targeted by an attacker in the past year. The backup is a primary target, not a safety net.
THE ARCHITETURE
The first answer is an architecture: CORE5.
API
Immutability at the interface
Data can be locked the moment it is written, with S3 Object Lock enforcing retention at the API so a request to modify or delete it is refused.
WHAT IT PROTECTS
Data
Identity, access, and encryption
Fine-grained IAM and MFA govern who can reach what, while TLS in transit and AES-256 at rest keep data unreadable to anyone without the keys.
WHAT IT PROTECTS
How we build it
Security also follows from how the software is built.
The architecture only holds if the software behind it is trustworthy. Two of Scality's operating principles carry the most weight here: engineering discipline, and full transparency about how the platform works. A storage platform runs for a decade, so it has to be built and maintained like it.
Inspectable, standards-based software
Open standards and inspectable software rather than opaque firmware, so operators and auditors can understand what the platform does with their data. In sovereign and regulated settings, a black box is itself a risk.
Vulnerabilities handled through the lifecycle
Security issues are tracked, prioritized, and patched across supported releases, so a platform that runs for years is maintained against the threats of today, not the ones it shipped with.
A clear path to report an issue
Researchers and customers need a direct route to report a suspected vulnerability and get a response. Coordinated disclosure keeps a found weakness on a path to a fix rather than an exploit.
These are the certifications and validations that security and procurement teams weigh when they choose a storage platform. Each is confirmed by independent audit and changes over time.
Information security management
Cryptographic module validation
Security & availability controls
Product security evaluation
Sovereign cloud qualification · ANSSI
what it protects
The promises we keep for the data you store.
Architecture, engineering, and standards are the means. Together they keep four things true for that data: it stays confidential, intact, available, and recoverable.
- Only the right people can read it
Access control decides who can reach data, and encryption keeps it unreadable to anyone else, in transit and at rest, including a copy that is stolen or leaves the system.
- It cannot be quietly changed
Immutability and erasure coding mean stored data cannot be altered or corrupted without detection, whether the cause is an attacker, a failing drive, or a mistake.
- It's there when you need it
Access control decides who can reach data, and encryption keeps it unreadable to anyone else, in transit and at rest, including a copy that is stolen or leaves the system.
- You can get a clean copy back
When an attack gets through everything else, an immutable, recoverable copy turns a breach into an inconvenience instead of a shutdown. This is what makes storage ransomware-resilient.


















