ARTESCA Glossary

Clear, concise definitions of the backup, object storage, and data-protection terms that matter when you evaluate ARTESCA. Browse the terms below.

A

Administrative Blast RadiusThe amount of infrastructure and data a single administrative account can reach, alter or destroy if it is compromised — a measure of how concentrated privilege is.

B

Backup TargetThe storage system where backup software writes and retains backup data — the destination in a backup architecture that keeps data available for restore.

Backup Storage TiersThe classes of storage a backup copy can live on, each trading cost per terabyte against how quickly and cheaply the data can be read back.

Backup TamperingThe unauthorized alteration, encryption or deletion of backup data, catalogs or configuration, carried out to make recovery impossible.

C

Customer-Managed Keys (CMK)Encryption keys that you generate, hold and control — rather than the provider — so the platform stores ciphertext it cannot read without a key you can withdraw.

Clean Room RecoveryThe practice of restoring data into a separate, isolated environment where it can be validated and cleared of malware before it is allowed back into production.

D

Data SovereigntyThe principle that data is subject to the laws of the jurisdiction governing it — a question of which government can compel access, not simply where the data is stored.

Data ResidencyThe geographic location where your data is physically stored — a technical and contractual choice of region, distinct from which laws govern the data.

H

Hardware Security Module (HSM)A dedicated, tamper-resistant hardware device that generates, stores and uses cryptographic keys so the key material never leaves it in plaintext.

I

Instant RecoveryThe ability to run a workload directly from backup storage — booting a virtual machine or mounting a database off the repository — so it is usable in minutes rather than hours.

L

Logical Air GapA backup copy kept logically unreachable from production — isolated by network, identity and control plane rather than by physically disconnected media.

M

Multi-TenancyA storage architecture in which a single shared platform serves multiple isolated tenants, each with its own accounts, namespaces and credentials, so no tenant can see or affect another.

P

Point-in-Time RecoveryThe ability to restore a system to exactly the state it was in at a chosen moment — a consistent snapshot as it existed before an attack or a corruption.

R

Restore TestingThe practice of periodically recovering data from backup and verifying that the result is complete, usable and free of malware — proof that a backup can actually come back.

Restore ThroughputThe rate at which a backup system can return data and workloads to a usable state, usually measured in terabytes or virtual machines per hour.

Retention Policy DesignDeciding how long each backup copy is kept, on which storage and under what immutability rules — which determines the moments in time you can still return to.

S

S3 Object LockThe S3 API mechanism that applies WORM retention to individual object versions, in either compliance or governance mode, so they cannot be overwritten or deleted.

Safe Copy IsolationThe practice of keeping a known-good backup copy separated from the production and identity environment that could compromise it, reachable only to the recovery process.

W

WORM (Write Once, Read Many)A storage model in which data can be written once and read as often as needed, but never modified, overwritten, or deleted for the duration of a defined retention period.

3

3-2-1-1-0 Backup RuleThree copies of data on two media types, with one offsite, one immutable or offline, and zero errors on restore verification — the ransomware-era update to the 3-2-1 rule.