Backups attackers can't reach.
An encrypted backup pipeline that targets the multi-cloud RAID substrate. Scheduled or one-shot, chunk-level SHA-256-validated, retargetable from Veeam, AWS Backup, and Bacula. Every backup inherits the sovereignty topology of the live system.
A backup target with the same topology as production.
Encrypt-then-scatter
Every backup chunk encrypts on the client, frames, and Reed-Solomon RS(5,2)-encodes across seven providers. The backup target is not a single bucket — it is the topology itself.
Chunk-level SHA-256
Each chunk carries a SHA-256 fingerprint validated at write and at read. Silent corruption fails the restore loudly, not the data invisibly.
Scheduled or one-shot
Configure scheduled backups with retention windows, or trigger one-shot backups via API. Both surface in the audit log with the operator identity captured.
Veeam-retargetable
SkyeDATA exposes an S3-compatible target (via SkyeBucket). Add the endpoint as an Object Storage Repository in Veeam B&R and existing jobs continue with sovereign storage.
AWS Backup compatible
Cross-account archive targets work. Useful when AWS Backup remains the orchestration layer but the underlying durability and sovereignty come from SkyeConnex.
Bacula compatible
The legacy backup tool of choice for many regulated infrastructures. SkyeDATA appears as a standard storage target — minimal Bacula configuration change required.
Why your backup target is the new attack surface
Through 2024-2026 sophisticated ransomware crews adapted to the standard playbook of offline backups. They now attack backup infrastructure first — encrypt or delete the backup capability, then move to production. By the time the operator notices the production incident, the backup target is already unusable.
The architectural answer is to make the backup target plural. SkyeDATA writes backups into the multi-cloud RAID substrate — seven shards, five-of-seven needed to recover. Compromising one or two providers leaves the backup fully recoverable. Compromising five providers in different jurisdictions simultaneously is the attack-surface coordination problem that collapses the economics of ransomware.
What recovery looks like
Recovery is the read path in reverse. Fetch the shard manifest. Parallel-pull shards from any five of seven providers (up to two can be unreachable or compromised). Reed-Solomon decode on the recovery host. AES-GCM decrypt frame-by-frame using the customer's wrap key. Stream plaintext into restoration.
No provider needs to be uncompromised. The recovery succeeds as long as any five shards remain readable.
Retargeting Veeam in three steps
- Backup Infrastructure → Backup Repositories → Add Repository → Object storage → S3 Compatible.
- Service point: https://s3.skyeconnex.com. Region: your residency policy region. Credentials: SkyeConnex SigV4 key.
- Edit existing backup jobs to use the new repository as primary or copy target. No agent changes, no licence implications.
Provable clean restore points
Per-file integrity certificates dual-signed with HMAC-SHA-256 and ML-DSA-87 let you cryptographically prove which backup version was the last clean one before compromise. Restore decisions become auditable artefacts. "Did this version exist before the attack?" answers itself with a signed JSON receipt verifiable offline.
Make ransomware irrelevant.
Book a session. We'll walk through a retarget pattern and the recovery story for a representative incident.