icon-double-hexCORE5, THE CYBER RESILIENCE BY DESIGN

Five layers between attackers and your data.

CORE5 is Scality's five-layer cyber resilience architecture, built into every Scality deployment. It defends data from API to architecture, so a stolen credential, a privilege escalation, or a physical breach is never enough to lose data.

icon-double-hexWHY A SINGLE LAYER FAILS

Your storage may be immutable. Is it unbreakable?

Immutability has become a cornerstone of cybersecurity. In the era of AI- powered ransomware, it is no longer enough. The vast majority of organizations rely on immutable storage, and the number of victims paying ransoms has doubled.

96%

of ransomware attacks now involve data exfiltration. Immutability cannot stop theft.

Veeam 2025 Ransomware Trends

89%

of organizations had their backup repositories targeted by a threat actor in the past year.

Veeam 2025 Ransomware Trends

94%

of IT leaders use or plan to use immutable storage - and ransomware payments still rise.

VANSON BOURNE, 2023 DATA IMMUTABILITY SURVEY

icon-double-hexINSIDE CORE5

Each layer defends against what gets past the one above.

01

Object Lock at the API

Ransomware mimics legitimate application commands to encrypt, modify, or delete stored data. The fastest place to stop that attack is at the interface itself, before the request reaches the storage layer. Backups become immutable the moment they are written.

S3 Object Lock
Configurable retention
Compliance mode
02

Identity, encryption, and zero-trust

Modern ransomware exfiltrates more often than it encrypts. The data layer blocks unauthorized read and unauthorized movement, and renders any data that does leave the system unreadable without the keys.

AWS-style IAM
Zero-trust enforcement
TLS in transit
AES-256 at rest
03

Erasure coding and hardened metadata

If higher layers are bypassed, an attacker may try to read directly from disks. Distributed erasure coding fragments every object across many drives, and the metadata that reassembles them is protected on a separate, hardened path.

Distributed erasure coding
Hardened metadata
Redundant encoding
04

Multi-site and stretched-cluster replication

A single site is one fire, one flood, or one ransomware sweep away from total compromise. Multi-site replication spreads data across sites and clouds. Site- specific IAM keeps an attacker who reaches one site from pivoting freely to the others.

Multi-site replication
Stretched cluster
Site-specific IAM domains
05

Inherently immutable write path

The strongest attacks compromise a privileged account and operate as the system itself. Most "immutable" platforms collapse here, because immutability is enforced at the API and the architecture still allows overwrites. The fifth layer removes that path entirely: data is preserved in its original form once stored, even if an attacker attains the privileges needed to bypass API-level immutability.

Inherently immutable writes
Logical delete markers
MFA-controlled admin
Mandatory access control

icon-double-hexCORE5 ACROSS THE PORTFOLIO

CORE5 runs under every Scality product.

The same five-layer architecture sits underneath each product. What changes is which workloads it's tuned for and which layers carry the most weight.

CORE5 ACROSS THE DATA PLANE

One security architecture spanning training data, model weights, retrieval indexes, and agent logs. CORE5's five layers protect every workload class the platform serves.

Icon-Scality-RING-02

Scality RING

Explore Scality RING
On the roadmap

On the roadmap

RING is the second product on the Guardian roadmap. Preventive maintenance and security posture monitoring are expected first, given RING's installed-base scale.

icon-scality-artesca-noborder

SCALITY ARTESCA

On the roadmap

The Guardian framework is being extended to ARTESCA on the roadmap. Today ARTESCA participates in audit evidence via CORE5 attestations; Guardian agent coverage follows.

Continue through the Scality technology stack.