ARTESCA Glossary
Clear, concise definitions of the backup, object storage, and data-protection terms that matter when you evaluate ARTESCA. Browse the terms below.
A
Administrative Blast Radius — The amount of infrastructure and data a single administrative account can reach, alter or destroy if it is compromised — a measure of how concentrated privilege is.
B
Backup Target — The storage system where backup software writes and retains backup data — the destination in a backup architecture that keeps data available for restore.
Backup Storage Tiers — The classes of storage a backup copy can live on, each trading cost per terabyte against how quickly and cheaply the data can be read back.
Backup Tampering — The unauthorized alteration, encryption or deletion of backup data, catalogs or configuration, carried out to make recovery impossible.
C
Customer-Managed Keys (CMK) — Encryption keys that you generate, hold and control — rather than the provider — so the platform stores ciphertext it cannot read without a key you can withdraw.
Clean Room Recovery — The practice of restoring data into a separate, isolated environment where it can be validated and cleared of malware before it is allowed back into production.
D
Data Sovereignty — The principle that data is subject to the laws of the jurisdiction governing it — a question of which government can compel access, not simply where the data is stored.
Data Residency — The geographic location where your data is physically stored — a technical and contractual choice of region, distinct from which laws govern the data.
H
Hardware Security Module (HSM) — A dedicated, tamper-resistant hardware device that generates, stores and uses cryptographic keys so the key material never leaves it in plaintext.
I
Instant Recovery — The ability to run a workload directly from backup storage — booting a virtual machine or mounting a database off the repository — so it is usable in minutes rather than hours.
L
Logical Air Gap — A backup copy kept logically unreachable from production — isolated by network, identity and control plane rather than by physically disconnected media.
M
Multi-Tenancy — A storage architecture in which a single shared platform serves multiple isolated tenants, each with its own accounts, namespaces and credentials, so no tenant can see or affect another.
P
Point-in-Time Recovery — The ability to restore a system to exactly the state it was in at a chosen moment — a consistent snapshot as it existed before an attack or a corruption.
R
Restore Testing — The practice of periodically recovering data from backup and verifying that the result is complete, usable and free of malware — proof that a backup can actually come back.
Restore Throughput — The rate at which a backup system can return data and workloads to a usable state, usually measured in terabytes or virtual machines per hour.
Retention Policy Design — Deciding how long each backup copy is kept, on which storage and under what immutability rules — which determines the moments in time you can still return to.
S
S3 Object Lock — The S3 API mechanism that applies WORM retention to individual object versions, in either compliance or governance mode, so they cannot be overwritten or deleted.
Safe Copy Isolation — The practice of keeping a known-good backup copy separated from the production and identity environment that could compromise it, reachable only to the recovery process.
W
WORM (Write Once, Read Many) — A storage model in which data can be written once and read as often as needed, but never modified, overwritten, or deleted for the duration of a defined retention period.
3
3-2-1-1-0 Backup Rule — Three copies of data on two media types, with one offsite, one immutable or offline, and zero errors on restore verification — the ransomware-era update to the 3-2-1 rule.
