Grotabyte
Contact SalesBook a Demo
WORM Compliance

WORM Compliance and What SEC 17a-4 Actually Requires

WORM is one of two ways to satisfy the SEC's electronic records rule, and since 2022 it is no longer the only one. Knowing which route your vendor takes matters more than the acronym.

Book a Demo Contact Sales

Sealed, hash-verified records · Built for SEC 17a-4, FINRA, HIPAA & CJIS programmes · Email, Teams chats, Drive, AI assistants & more

What is WORM compliance?

WORM stands for write once, read many: storage that accepts a record once and then physically prevents it being rewritten or erased for a set period. In recordkeeping, WORM compliance is shorthand for meeting SEC Rule 17a-4(f) by keeping records in non-rewriteable, non-erasable form. In October 2022 the SEC amended the rule, and since then a firm may instead meet it with an audit-trail alternative: a system that maintains a complete record of every change, so an original record can be recreated and any alteration is evident. Both routes are valid; they make different promises, and they fail in different ways.

Key capabilities

The two routes, plainly
The WORM route makes the storage layer refuse writes. The audit-trail route makes every change visible and reconstructible. A regulator accepts either, provided the system does what the firm says it does.
Which route Grotabyte takes
Grotabyte implements the audit-trail alternative. Records are sealed and hash-verified onto a tamper-evident, hash-chained ledger, and every view, query, export, and refusal is recorded against it. Grotabyte does not describe its storage as WORM, immutable, or non-rewriteable.
What the hash chain proves
Each entry carries the hash of the one before it, so an edited or removed record breaks the chain at that point. Verification runs across the archive and reports whether the chain is intact and whether there are gaps or excisions.
Retention locking, on request
Storage-level retention locking is available if your programme calls for it, and it can be applied to an archive that already holds records — each customer's material sits in storage dedicated to them, so there is no migration and no re-upload.
What the lock was measured to do
Under test, a locked object could not be overwritten or deleted — both refused — while an unlocked object in the same bucket deleted normally as a control. It stops deletion and overwriting for the term set, including by mistake and by lifecycle rule.
What the lock does not do
The rule can be lifted by whoever holds the storage account, and the object then deletes. That makes it a retention control rather than non-rewriteability, and it is why Grotabyte does not claim the stronger term.

Choosing between the two routes

  • Ask any vendor which route they take, and ask them to show it — a claim of WORM is a claim about storage, not a feature flag
  • The audit-trail route answers a broader question: not only was this record preserved, but who looked at it, when, and what they did next
  • If your written procedures specify storage-level locking, it can be enabled for your archive without a migration
  • An auditor role can verify the chain of custody without being able to read a document, so verification does not require handing over access

Frequently asked questions

Does SEC 17a-4 still require WORM storage?

Not exclusively. Since the amendments adopted in October 2022, Rule 17a-4(f) permits an electronic recordkeeping system to meet the requirement either by preserving records in a non-rewriteable, non-erasable format or by maintaining an audit trail that allows the original record to be recreated if it is altered or deleted. Firms should confirm which route their system takes and reflect it in their written procedures.

Is Grotabyte WORM storage?

No, and it does not describe itself that way. Grotabyte takes the audit-trail route: sealed, hash-verified records on a tamper-evident, hash-chained ledger, with every access and export recorded. Storage-level retention locking is available on request as an additional control.

What is the difference between a retention lock and WORM?

A retention lock prevents deletion and overwriting for a defined term, including by accident and by automated lifecycle rules — which was confirmed by measurement. It differs from non-rewriteability because whoever holds the storage account can lift the rule, after which the object can be deleted. That distinction is why the two terms should not be used interchangeably.

How do I know a record has not been altered?

Every record is sealed with a SHA-256 hash that is chained to the previous entry. Altering or removing a record breaks the chain at that point, and chain verification reports it. The verification can be run by an auditor who has no ability to read the documents themselves.

Related

SEC 17a-4 & FINRA compliance →Compliance archiving →Financial services compliance →Information Archiving solution →

See worm compliance in action

Book a personalized demo and see how Grotabyte fits your data sources and compliance requirements.

Book a demoRead the buyer's guide

Stay in the loop

Subscribe to receive the latest product releases, compliance insights, and event invites from Grotabyte.

Grotabyte

Next-generation enterprise archiving and eDiscovery platform trusted by leading organizations worldwide.

Secure • Scalable • Reliable

Platform

  • Solutions
  • Features
  • Workflows
  • Data Sources
  • Email Archiving
  • Data Archiving
  • Records Management
  • Compliance

Industries

  • Financial Services
  • Education
  • Government
  • Healthcare
  • Public Safety

Resources

  • Complete Guide
  • Glossary
  • Compare
  • Case Studies
  • Whitepapers
  • Blog

Company

  • About
  • Contact

Trust & Legal

  • EULA
  • Support Terms
  • Privacy Policy

© 2026 Grotabyte. All rights reserved. Built with enterprise security and compliance in mind.