Secure data storage

Protected exchange storage

Secure cloud data storage, for the files currently in motion

Protect sensitive information while it is being exchanged, with encryption, named access and configurable availability. MX complements long-term repositories by concentrating on the controlled handoff.

Anonymise · shard · restoreASR
Identifiers separated
Fragments distributed, original restored on demand

How ASR works

Secure cloud data storage during a live exchange

ASR is an additional protection method instead of another name for encryption. Identifying information is separated from the data, what remains is divided into independent protected fragments, those fragments are distributed, and the verified original is reconstructed for an authorised recipient.

  • Anonymise. Identifying information is separated from the protected data.
  • Shard. The remaining data is split into independent protected fragments.
  • Distribute. Shards are held across separate secure destinations.
  • Restore. The verified original file is reassembled for the authorised recipient.

Layers, not a single control

Six things that together decide whether stored data is actually safe.

Storage security is usually discussed as an encryption question. Encryption is necessary and it is also the part most vendors have equally covered. The differences appear elsewhere.

Cryptography

Encryption at rest and in transit

AES-256 applied to data as it moves and as it sits. This is the baseline, and a supplier who cannot describe it plainly is worth further questions.

Structure

Fragmentation through ASR

Distributing protected shards across separate destinations means that access to a single location does not yield a usable file. It is a structural protection instead of a cryptographic one.

Identity

Who can reach it

Named accounts, role-based permissions and MFA where the material warrants it. Most storage incidents are access incidents instead of cryptographic failures.

Location

Where it is held

Choices over data location, in suitable configurations, so the arrangement can match your own residency and contractual requirements.

Lifecycle

How long it stays

Retention and expiry controls, so that data which no longer serves a purpose stops being an exposure you are still carrying.

Evidence

What was done to it

Activity records covering access and movement, so a question about a stored file has an answer that does not rely on memory.

Storage and movement

Most of the risk to stored data happens when it stops being stored.

A repository can be protected carefully and still be the origin of an uncontrolled copy, because the security model usually ends at the point of export. Keeping storage and exchange connected closes that gap.

Export is the weak point

The moment a file is downloaded and re-sent, it leaves every control that was applied to it in storage.

The copy outlives the purpose

Exported material rarely inherits the retention rule that governed the original.

The trail breaks

Storage logs show the export. They cannot show what happened to the file afterwards.

The lifecycle view

Four stages where stored data is either governed or quietly is not.

Protection is usually assessed at rest. Most of the practical exposure sits at the transitions, where data enters, moves, leaves and should end.

Step 01

Arrival

How material enters, who submitted it and whether that is recorded.

Step 02

At rest

Encryption, fragmentation through ASR and the access model around it.

Step 03

Departure

The controls that follow a file out instead of stopping at export.

Step 04

End of life

Retention that is applied instead of intended, including to external copies.

Supplier questions

Five questions worth asking any storage provider.

These come up in most security reviews and the answers vary more than the marketing pages suggest. Ask them early, because they are difficult to renegotiate after a deployment.

01

Where is the data held, and can we choose?

Ask about the specific configuration available to you instead of the regions the provider operates in generally. Residency commitments belong in the contract, not in a support article.

02

Who at the provider can access it?

Understand administrative access, the circumstances in which it is used and how it is logged. This is often more consequential than the encryption specification.

03

What happens when we leave?

Ask how content and activity records are exported and how long anything is retained afterwards. The answer indicates how the provider thinks about your ownership of the data.

04

How is protection applied to large or unusual material?

Confirm that the same controls apply to complete folders, archives and very large files, instead of degrading quietly at scale.

05

What does the evidence actually show?

Ask to see a real record instead of a description of one. Whether it answers an ordinary operational question is the useful test.

A note on quantum

Fragmenting and distributing protected data is a structural safeguard, not a claim about future cryptography.

ASR is described as a quantum-secure methodology because it does not rely solely on the difficulty of a single cryptographic problem. Treat it as an additional layer alongside AES-256, and assess it on that basis.

AES-256Applied in transit and at rest
PatentedThe ASR anonymise, shard and restore method
ConfigurableLocation choices in suitable deployments
– INSERT TESTIMONIALS –
– INSERT ESSENTIAL READS –
– INSERT FAQs –

Storage with a controlled boundary

See how protection and exchange work as one model.

Start a seven-day trial for up to five users, or ask for a technical walkthrough of ASR, data location and access controls.

View in