Who it’s for / CISO & Security
Grotabyte for CISOs and Security Teams
An archive is the single highest-value target your organisation will ever assemble: every sensitive conversation the company has had, decrypted, indexed and searchable, behind one login. You are the person whose name goes on the approval.
Rated 5 out of 5. “Ten-year holds, answered by self-service.” — College of DuPage
Also for: Security Engineer
What you are accountable for
You are accountable for the fact that this system concentrates everything sensitive in one place — and for being able to say precisely who can reach it, what they did with it, and what a single insider can do unilaterally.
What makes that hard
The archive is the crown jewels, by construction
Every control elsewhere in the estate exists to stop this material being aggregated. The archive aggregates it on purpose, which means its access model has to be stronger than the systems it collects from, not equivalent to them.
Tenancy answers that do not survive a follow-up question
'Logically separated' usually means a shared index filtered by a tenant identifier — one predicate away from a cross-customer disclosure. The distinction between a filter and an architecture is the thing your diligence has to establish.
The insider risk lives inside the tool
A compliance reviewer with broad reach is a legitimate user with an illegitimate opportunity. Ethical walls that screen documents but leak through result counts, facet totals or a hit number are not walls.
Destruction is the irreversible path
Purge, erasure and hold release cannot be undone. If any one of them is a single administrator's decision, the blast radius of one compromised account is the archive itself.
What Grotabyte gives you
Isolation that is architectural, not a filter
In the cloud product each customer gets their own compute and their own storage, with no catalog shared between customers. There is no shared index that a query is filtered against, because there is no shared index — so a scoping bug cannot become a cross-customer disclosure.
Encryption keyed down to the record
AES-256-GCM per-record encryption under a tenant to custodian to record key hierarchy. On an on-premise deployment those record keys never leave the machine, and any cross-tenant access by an operator is written to the customer's own ledger.
Least privilege that is enumerated, not asserted
Twenty-five permissions across ten roles. The auditor role verifies the chain of custody but cannot open a document — verification does not require handing anyone read access to your material.
Ethical walls enforced at one accessor
Screening is applied at a single engine accessor, so counts and facets stay screened along with the documents. A reviewer walled off from a matter cannot infer its existence from a result total, which is where wall implementations usually leak.
Dual control on everything irreversible
Purge, GDPR Article 17 erasure and legal hold release each require a second approver. Sign-in is passwordless with per-tenant OIDC routed by a DNS-verified domain, and no AI or LLM vendor processes customer content.
One checkable thing
The auditor role can verify chain of custody across the archive without being able to open a single document — proving integrity does not require granting read access.
Questions this role asks
Where does our data sit relative to other customers'?
In the cloud product, on its own compute and its own storage, with no catalog shared between customers. That is worth being precise about: multi-tenancy with logical separation is the ordinary way SaaS archiving is built and it is not a defect, but it means isolation depends on a filter being correct on every query path. Here there is no shared index to filter, so the guarantee is structural rather than behavioural. On-premise, the question does not arise — it is your hardware, your storage, and record keys that never leave the machine.
What can a single administrator do on their own?
Not the irreversible things. Purge, Article 17 erasure and legal hold release each require a second approver, so one compromised or malicious account cannot destroy records or lift a preservation obligation unilaterally. Everything else — views, queries, exports, and refusals — is written to a hash-chained, tamper-evident ledger, and the auditor role can verify that chain without being able to read the documents.
Does any third-party AI service see our content?
No AI or LLM vendor processes customer content. Where AI conversations are themselves archived, that is Claude Enterprise captured through Anthropic's Compliance API — the material is the record being preserved, not content being sent out for processing.