Digital Resilience Platform
Boards and CFOs gain verifiable proof that the backup, recovery, cryptography, and access-control measures required by NIS2 Art. 21(2)(b), (c), (h), and (j) are in place and working. We automate the evidence, not the responsibility.
Meeting Legal Requirements
NIS2 Readiness
We help organizations meet the stringent requirements of the NIS2 directive by ensuring rapid data recovery.
- Transparent Audits: Automatic logging facilitates reporting and documenting actions for technical auditors.
- Threat Isolation: The network structure prevents the deletion of backups from an infected client server.
- Minimizing Downtime: The instant backup mount option reduces business downtime to a minimum.
GDPR / RODO Sovereignty
We provide organizations with full control over the data storage location and data confidentiality.
- Privacy Protection: The software provider has no access to company data due to the total isolation of encryption keys.
- Data Localization: The infrastructure allows information flow to be restricted exclusively within the borders of the European Union.
- Rights Management: The ability to permanently delete encrypted packages on demand (Right to be Forgotten).
DORA Operational Resilience
We build the digital resilience of the financial sector, securing infrastructure against extreme failure scenarios.
- Vault Immutability: The system protects the company's most valuable data - the vault copy cannot be encrypted or overwritten by ransomware running on the protected host.
- Resilience Verification: Tools for testing recovery procedures facilitate compliance with banking sector guidelines.
- Technological Independence: We provide the architecture to recover systems without relying on public cloud environments.
SEAL-4 Sovereign Infrastructure (Self-Assessed)
StateWarden achieves a SEAL-4 rating in the public self-assessment against the EU Cloud Sovereignty Framework v1.2.1, with technical controls mapped to NIS2 Art. 21(2) and DORA requirements. Self-assessment, not an audited certification - the full per-objective scoring is published in the sovereignty whitepaper.
- Zero-Knowledge Architecture (ML-KEM (FIPS 203) + ChaCha20 + AES)
- EU Jurisdiction & Datacenters for All Backup Data
- Single Self-Contained Binary (Rust) - no local database engines, no runtimes, no external services on the protected host
Own Hardware Infrastructure
Our servers are located in modern, European data centers. We do not rely on third-party cloud providers, simplifying legal verification and meeting GDPR recommendations.
Hardware Security & Certifications
The EU data centers we utilize operate under ISO/IEC 27001, SOC 2 Type II, SecNumCloud, and C5 certifications - held by the data-center operator. Data privacy is enforced by our proprietary Zero-Knowledge architecture.
Facilitating Audit Processes
Here is how StateWarden® streamlines security verification for boards and external auditors.
Scenario 1: Verification of Resistance to Malicious Deletion
EXPECTATION / CHALLENGE
Request to prove that an attacker taking over an administrator account does not result in the loss of backups.
STATEWARDEN REALITY
StateWarden verifies commands based on independent hardware keys (2FA). Compromising the local environment does not authorize the attacker to delete the secure archive.
Scenario 2: Data Processing Location Inspection
EXPECTATION / CHALLENGE
Requirement to prove that data does not leave the European Union, in accordance with GDPR regulations.
STATEWARDEN REALITY
The logging system unambiguously documents mTLS connections with European nodes, confirming territorial compliance of processing.
Scenario 3: RTO/RPO SLA Verification (DORA/NIS2)
EXPECTATION / CHALLENGE
Request to demonstrate the ability to restore a business-critical system within the declared recovery time objective.
STATEWARDEN REALITY
Instant iSCSI Mount puts data back online in 5-20 seconds on Linux and 5-120 seconds on Windows, independent of volume size - measured on volumes from 30 GB to 1 PB. Full bare-metal recovery to a login screen takes 4-6 minutes on Linux and 7-9 minutes on Windows, five runs each on 2 TB reference systems.
Audit Readiness Without Complex Deployments
Achieving legal compliance should not be difficult. StateWarden standardizes security with a deployment involving the installation of just one service, offloading IT departments.