Trust & evidence

Checkable by your client

The security model in plain language: what is immutable, where data lives, and how destruction is proven.

Your client's questions land on you

An insurer asks how recovery is proven. A regulator asks where the data sits. A prospect's questionnaire runs to forty questions. Your vendor's assurance is not an answer you can forward, so the answering falls to you, on a Friday, in your own words.

Assurance is not evidence

A vendor promising that backups are safe gives you nothing to put in front of an auditor.

Compromise reaches the backups

An attacker with administrator access goes after the recovery points first, because that is what forces the payment.

Deletion has to be provable

When a client offboards, saying the data is gone is not the same as showing it.

Compromised console Refused

How the Evidence Works

Immutability

Immutability by default

Recovery points carry rolling locks that renew daily. Suspension for non-payment leaves existing immutability intact, so a commercial dispute stays a commercial dispute.

Residency

Residency as a boundary

Each organization chooses its storage location from your allowed set; a residency preflight confirms the region before the first capture.

Destruction

Certified destruction

When retention ends and destruction runs, a signed certificate is issued. It outlives the data it certifies.

Identity

Read-only by design

Backups run under a consented read-only identity; writes exist only during restores, just-in-time, and revoke themselves.

Questions your client will ask you

Who at EnterProtect can read my clients’ data?

Backups run under a consented read-only identity, and write access exists only during a restore, just in time, and revokes itself. Operating the platform does not carry the right to read what it protects.

What happens if an attacker gets our console credentials?

They cannot shorten or remove an immutability lock. Retention holds for its term regardless of what any administrator, ours or yours, asks for. That is the whole point of the lock being outside the console.

Where does the data physically live?

In the region each organization selects from the set you allow. A residency preflight confirms the region before the first capture, so residency is settled before data moves rather than discovered afterwards.

What do we hand a client who is offboarding?

A signed destruction certificate, issued when destruction runs. It outlives the data it certifies, which is what an auditor asking about a client from three years ago actually needs.

What if we stop paying?

Service suspends and existing immutability stays intact for its term. A commercial dispute does not become a data-loss event, and we will not hold a client’s recoverability as leverage.

Can we see the evidence before we commit?

Yes. Ask for a demo and restore something in the console yourself; the manifest it produces is the artifact your client would receive.

Answer the questionnaire with documents

The next security review is coming. Walk through the console and leave with the artifacts your clients keep asking for. The questionnaire becomes an hour's work.

What we commit to

  • An immutability lock cannot be shortened from the console, by you or by us.
  • Residency is confirmed before the first capture, in the region you select.
  • Every destruction closes with a signed certificate that outlives the data.