Grotabyte
Contact SalesBook a Demo

Who it’s for / CISO & Security

Grotabyte for CISOs and Security Teams

An archive is the single highest-value target your organisation will ever assemble: every sensitive conversation the company has had, decrypted, indexed and searchable, behind one login. You are the person whose name goes on the approval.

Rated 5 out of 5. “Ten-year holds, answered by self-service.” — College of DuPage

Also for: Security Engineer

What you are accountable for

You are accountable for the fact that this system concentrates everything sensitive in one place — and for being able to say precisely who can reach it, what they did with it, and what a single insider can do unilaterally.

What makes that hard

The archive is the crown jewels, by construction

Every control elsewhere in the estate exists to stop this material being aggregated. The archive aggregates it on purpose, which means its access model has to be stronger than the systems it collects from, not equivalent to them.

Tenancy answers that do not survive a follow-up question

'Logically separated' usually means a shared index filtered by a tenant identifier — one predicate away from a cross-customer disclosure. The distinction between a filter and an architecture is the thing your diligence has to establish.

The insider risk lives inside the tool

A compliance reviewer with broad reach is a legitimate user with an illegitimate opportunity. Ethical walls that screen documents but leak through result counts, facet totals or a hit number are not walls.

Destruction is the irreversible path

Purge, erasure and hold release cannot be undone. If any one of them is a single administrator's decision, the blast radius of one compromised account is the archive itself.

What Grotabyte gives you

Isolation that is architectural, not a filter

In the cloud product each customer gets their own compute and their own storage, with no catalog shared between customers. There is no shared index that a query is filtered against, because there is no shared index — so a scoping bug cannot become a cross-customer disclosure.

Encryption keyed down to the record

AES-256-GCM per-record encryption under a tenant to custodian to record key hierarchy. On an on-premise deployment those record keys never leave the machine, and any cross-tenant access by an operator is written to the customer's own ledger.

Least privilege that is enumerated, not asserted

Twenty-five permissions across ten roles. The auditor role verifies the chain of custody but cannot open a document — verification does not require handing anyone read access to your material.

Ethical walls enforced at one accessor

Screening is applied at a single engine accessor, so counts and facets stay screened along with the documents. A reviewer walled off from a matter cannot infer its existence from a result total, which is where wall implementations usually leak.

Dual control on everything irreversible

Purge, GDPR Article 17 erasure and legal hold release each require a second approver. Sign-in is passwordless with per-tenant OIDC routed by a DNS-verified domain, and no AI or LLM vendor processes customer content.

One checkable thing

The auditor role can verify chain of custody across the archive without being able to open a single document — proving integrity does not require granting read access.

Questions this role asks

Where does our data sit relative to other customers'?

In the cloud product, on its own compute and its own storage, with no catalog shared between customers. That is worth being precise about: multi-tenancy with logical separation is the ordinary way SaaS archiving is built and it is not a defect, but it means isolation depends on a filter being correct on every query path. Here there is no shared index to filter, so the guarantee is structural rather than behavioural. On-premise, the question does not arise — it is your hardware, your storage, and record keys that never leave the machine.

What can a single administrator do on their own?

Not the irreversible things. Purge, Article 17 erasure and legal hold release each require a second approver, so one compromised or malicious account cannot destroy records or lift a preservation obligation unilaterally. Everything else — views, queries, exports, and refusals — is written to a hash-chained, tamper-evident ledger, and the auditor role can verify that chain without being able to read the documents.

Does any third-party AI service see our content?

No AI or LLM vendor processes customer content. Where AI conversations are themselves archived, that is Claude Enterprise captured through Anthropic's Compliance API — the material is the record being preserved, not content being sent out for processing.

Chain of custody →Compliance & Governance →CJIS compliance →Platform features →
Book a demo Join a Wednesday session

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.