Digital Resilience Platform

Boards and CFOs gain verifiable proof that the backup, recovery, cryptography, and access-control measures required by NIS2 Art. 21(2)(b), (c), (h), and (j) are in place and working. We automate the evidence, not the responsibility.

Meeting Legal Requirements

NIS2 Readiness

We help organizations meet the stringent requirements of the NIS2 directive by ensuring rapid data recovery.

  • Transparent Audits: Automatic logging facilitates reporting and documenting actions for technical auditors.
  • Threat Isolation: The network structure prevents the deletion of backups from an infected client server.
  • Minimizing Downtime: The instant backup mount option reduces business downtime to a minimum.

GDPR / RODO Sovereignty

We provide organizations with full control over the data storage location and data confidentiality.

  • Privacy Protection: The software provider has no access to company data due to the total isolation of encryption keys.
  • Data Localization: The infrastructure allows information flow to be restricted exclusively within the borders of the European Union.
  • Rights Management: The ability to permanently delete encrypted packages on demand (Right to be Forgotten).

DORA Operational Resilience

We build the digital resilience of the financial sector, securing infrastructure against extreme failure scenarios.

  • Vault Immutability: The system protects the company's most valuable data - the vault copy cannot be encrypted or overwritten by ransomware running on the protected host.
  • Resilience Verification: Tools for testing recovery procedures facilitate compliance with banking sector guidelines.
  • Technological Independence: We provide the architecture to recover systems without relying on public cloud environments.
EU CLOUD SOVEREIGNTY FRAMEWORK

SEAL-4 Sovereign Infrastructure (Self-Assessed)

StateWarden achieves a SEAL-4 rating in the public self-assessment against the EU Cloud Sovereignty Framework v1.2.1, with technical controls mapped to NIS2 Art. 21(2) and DORA requirements. Self-assessment, not an audited certification - the full per-objective scoring is published in the sovereignty whitepaper.

  • Zero-Knowledge Architecture (ML-KEM (FIPS 203) + ChaCha20 + AES)
  • EU Jurisdiction & Datacenters for All Backup Data
  • Single Self-Contained Binary (Rust) - no local database engines, no runtimes, no external services on the protected host
SEALLevel 4

Own Hardware Infrastructure

Our servers are located in modern, European data centers. We do not rely on third-party cloud providers, simplifying legal verification and meeting GDPR recommendations.

Hardware Security & Certifications

The EU data centers we utilize operate under ISO/IEC 27001, SOC 2 Type II, SecNumCloud, and C5 certifications - held by the data-center operator. Data privacy is enforced by our proprietary Zero-Knowledge architecture.

Facilitating Audit Processes

Here is how StateWarden® streamlines security verification for boards and external auditors.

Scenario 1: Verification of Resistance to Malicious Deletion

EXPECTATION / CHALLENGE

Request to prove that an attacker taking over an administrator account does not result in the loss of backups.

STATEWARDEN REALITY

StateWarden verifies commands based on independent hardware keys (2FA). Compromising the local environment does not authorize the attacker to delete the secure archive.

Scenario 2: Data Processing Location Inspection

EXPECTATION / CHALLENGE

Requirement to prove that data does not leave the European Union, in accordance with GDPR regulations.

STATEWARDEN REALITY

The logging system unambiguously documents mTLS connections with European nodes, confirming territorial compliance of processing.

Scenario 3: RTO/RPO SLA Verification (DORA/NIS2)

EXPECTATION / CHALLENGE

Request to demonstrate the ability to restore a business-critical system within the declared recovery time objective.

STATEWARDEN REALITY

Instant iSCSI Mount puts data back online in 5-20 seconds on Linux and 5-120 seconds on Windows, independent of volume size - measured on volumes from 30 GB to 1 PB. Full bare-metal recovery to a login screen takes 4-6 minutes on Linux and 7-9 minutes on Windows, five runs each on 2 TB reference systems.

Audit Readiness Without Complex Deployments

Achieving legal compliance should not be difficult. StateWarden standardizes security with a deployment involving the installation of just one service, offloading IT departments.

Privacy by Design

This website uses only first-party cookies strictly necessary for its operation. Zero third-party trackers, zero external analytics platforms.

Read our Privacy Policy for details.