DATA SOVEREIGNTY

Digital Resilience
Platform

A sovereign ecosystem for data survival. We engineered an architecture that transcends traditional backup – StateWarden® autonomously protects your infrastructure with ML-KEM (FIPS 203) PQC encryption, detects ransomware in progress and automatically quarantines the affected backups, and restores machines to a login screen in 4-9 minutes (measured).

Audit Readiness Without Complex Deployments

Achieving legal compliance should not be difficult. StateWarden standardizes security with a deployment involving the installation of just one service, offloading IT departments.

Core System Modules

An architecture optimized for security, performance, and cost control.

RTO in Seconds. BMR in Minutes.

Instant iSCSI Mount puts data back online in 5-20 seconds on Linux and 5-120 seconds on Windows, independent of volume size - measured on volumes from 30 GB to 1 PB. Full bare-metal recovery to a login screen: 4-6 minutes (Linux) and 7-9 minutes (Windows), five runs each on 2 TB reference systems.

How we measure this
EngineBlock-Level CBT
ProtocoliSCSI / NBD

Continuous Vulnerability Intel

Low-footprint passive scanning. We utilize Sidecar Hashing to map CVEs against NVD/OSV databases without taxing production servers.

Intel SourceOSV / NVD / BAZAAR
StateActive Defense

Sovereign Infrastructure

Artemis, Vigil, and Driads operate as a managed sovereign perimeter. We distribute only the lightweight Rust agent, and encryption keys never leave your control plane (zero-knowledge architecture).

IdentitymTLS (X.509)
AlgorithmML-KEM + AES
EU CLOUD SOVEREIGNTY FRAMEWORK

SEAL-4 Sovereign Infrastructure (Self-Assessed)

StateWarden achieves a SEAL-4 rating in the public self-assessment against the EU Cloud Sovereignty Framework v1.2.1, with technical controls mapped to NIS2 Art. 21(2) and DORA requirements. Self-assessment, not an audited certification - the full per-objective scoring is published in the sovereignty whitepaper.

  • Zero-Knowledge Architecture (ML-KEM (FIPS 203) + ChaCha20 + AES)
  • EU Jurisdiction & Datacenters for All Backup Data
  • Single Self-Contained Binary (Rust) - no local database engines, no runtimes, no external services on the protected host
Read SEAL Assessment
SEALLevel 4(self-assessed)

Zero-Trust Data Flow

StateWarden is a sovereign ecosystem for data survival. Backup is just the transport layer - Vigil scans backup content against 200,000+ known vulnerabilities and malware signatures - before you restore, not after. Instant iSCSI Mount guarantees immediate data availability, and zero-knowledge key handling protects against leaks.

Your Server

Agent reads block device

PrimeKEM Engine

Cascaded Cryptography (ML-KEM (FIPS 203) + ChaCha20 + AES)

Secure Tunnel

mTLS Handshake

Immutable Vault

WORM Storage

Keys remain on the serverWe store only encrypted dataPost-quantum cryptography by name: ML-KEM-768 (FIPS 203), AES-256-GCM, ChaCha20-Poly1305, BLAKE3

Failure Risk Management

Architecture designed to maintain operational continuity in the event of ransomware infections, hardware failures, and configuration errors.

Ransomware Infection

Failure Scenario

Encryption of production databases and deletion of local VSS snapshots. Compromise of accounts with administrative privileges.

Recovery Mechanisms

The data vault operates in an immutable mode (WORM). Having local administrator privileges does not allow overwriting historical backups.

Hardware Failure

Failure Scenario

RAID controller failure or other physical defect requiring environment recreation (BMR) on new hardware.

Recovery Mechanisms

Booting the server from a Live ISO image and directly streaming the disk image without requiring OS re-provisioning.

Update Error

Failure Scenario

Faulty update or human error leading to corrupted system files or critical dependencies.

Recovery Mechanisms

Using the Instant Mount function to map the backup as a read-only block device (NBD/iSCSI) to restore a stable version of the system.

Privilege Model &
Deletion Control

Systems operating with high privileges are frequent attack targets. Our approach minimizes this risk.

!

Vulnerability Identification

Gaining access to administrator credentials can enable unauthorized data deletion commands in centralized consoles.

StateWarden Approach

StateWarden makes administrative compromise survivable: historical backups are immutable, and deletion requires MFA confirmation from a separate control plane - local admin rights are not enough.

Log AnalysisActive

$ ./scan_net.sh --target backups

> Detecting backup infrastructure...

> Verifying administrative accounts...

> ACCESS GRANTED.

$ statewarden-agent status

> Integrity: Backup chunks verified

> Tunneling: mTLS

> Repository: WORM (Append-Only)

> Access denied to modification commands.

Bare-Metal Execution Infrastructure

We operate on isolated servers located in the EU, reducing the overhead of virtualization environments. The architecture provides the performance consistency required for data recovery processes.

Agent Footprint &
Deployment

No dependencies on local database engines. The agent functions as a compiled binary file (Rust), minimizing the impact on the source system.

admin@server: ~
Root Access
#

curl -sSL https://get.statewarden.com | sudo bash

Installing StateWarden agent... [DONE]
#

sw init --code $PAIRING_CODE

Generating mTLS Node Identity... [READY]
mTLS Handshake with Artemis Control Plane... [ESTABLISHED]
Validating agent authenticity (mTLS identity + payload keys)... [VALID]
Receiving encryption policy... [READY]
Identity verified. Agent paired. First backup scheduled.
#

Privacy by Design

This website uses only first-party cookies strictly necessary for its operation. Zero third-party trackers, zero external analytics platforms.

Read our Privacy Policy for details.