DECRU DATAFORT STORAGE ENCRYPTION
Home |  Agent Program |  Partners  



EQUIPMENT VENDORS



TELECOM VENDORS
 EMAIL    1 (866) 421-9522
TELECOM TECHNOLOGIES
ATM
VOIP
DSL
Conferencing
Consulting
Hosting
MPLS IP VPN
Long Distance
ISDN PRI
Private Line
International Private Line
T1
T3
OC-3 & OC-12
OC-48 & GigE

EQUIPMENT
Adtran Equipment
Allworx VOIP
Juniper Equipment
Cisco Equipment
Neoscale Tape Encryption
Decru Tape Encryption
Netezza Data Warehouse
StoneFly IP SAN
Wan Accelerator
Free Space Optics
Proxim Wireless
Storage Software
McData Storage Routers
CipherOptics Encryptors
Safenet
DECRU DataFort appliances combine secure access controls, authentication, storage encryption, and secure logging to provide unprecedented protection for sensitive stored data. Because DataFort protects data at rest and in flight with strong encryption, even organizations that outsource IT management can be sure their data assets are secure. In short, DataFort offers a powerful and cost-effective solution to address a broad range of external, internal, and physical threats to sensitive data.

DataFort is available in three models:
  • E-Series appliances for NAS
  • FC-Series appliances for SAN and tape backup
  • T-series appliances for tape backup

Decru DataFort™ E-Series storage security appliances integrate transparently into the existing NAS infrastructure, providing essential security without requiring changes to clients, servers or workflow.
Decru DataFort™ FC-Series appliances enable complete security for stored data through host authentication, access controls and strong data encryption for disk and/or tape from one powerful platform. DataFort is deployed transparently in Fibre Channel SAN environements, and is easily managed from a centralized, secure interface.

Decru DataFort™ T-Series storage security appliances enable complete security for data stored on tape, providing host authentication, strong data encryption, compression, and crypto-signed logging.




DECRU DATAFORT DETAILED INFORMATION

DataFort™ E-Series

Perimeter security technologies like firewalls and intrusion prevention systems are no longer enough to protect sensitive or regulated data. Decru DataFort™ E-Series storage security appliances integrate transparently into the existing NAS infrastructure, providing essential security without requiring changes to clients, servers or workflow. By locking down stored data with strong encryption, and routing all access through secure hardware, Decru DataFort radically simplifies the security model for data in networked storage.

MAXIMUM DATA SECURITY

Decru DataFort™ appliances combine secure access controls, authentication, storage encryption, and secure logging to provide unprecedented protection for sensitive stored data. Because DataFort protects data at rest and in flight with strong encryption, even organizations that outsource IT management can be sure their data assets are secure. In short, DataFort offers a powerful and cost-effective solution to address a broad range of external, internal, and physical threats to sensitive data. HARDENED ARCHITECTURE
DataFort hardware was designed from the ground up for maximum security. At the heart of the system is Decru's Storage Encryption Processor (SEP) — a robust hardware engine enabling full-duplex, wire-speed encryption and key management. Decru's SEP, clustering and key management have passed certification testing for FIPS 140-2 level 3. DataFort's AES-256, SHA-1 and SHA-256 encryption implementations have also been certified by the National Institute for Standards and Technology (NIST.)

ROBUST ENCRYPTION STANDARDS
Decru DataFort incorporates strong AES-256 encryption, optimized by Decru for protecting stored data. DataFort uses a True Random Number Generator (TRNG) to create keys, and cleartext keys never leave DataFort's secure hardware, offering the highest level of security against attacks.

COMPARTMENTALIZATION
Security administrators can compartmentalize aggregated data in shared storage using Cryptainer™ storage vaults. Cryptainer vaults cryptographically partition stored data, and provide an additional layer of threat containment. DataFort also supports the creation of cleartext Cryptainer vaults, which enable administrators to enforce access controls centrally, but leave less sensitive data unencrypted.

LIFETIME KEY MANAGEMENT™
Decru's Lifetime Key Management™ system (LKM) securely automates the archiving and recovery of encryption keys across the enterprise, ensuring data stored for decades can be decrypted. A software recovery tool ensures access to data in the event that DataFort hardware is rendered inoperable.

AUTHENTICATION AND ACCESS CONTROLS
DataFort provides a powerful, single point of secure access controls and authentication for heterogeneous client and storage environments. DataFort integrates transparently with directory servers such as LDAP, Active Directory and NIS, and adds a layer of hardware-based policy enforcement that prevents common attacks. DataFort also incorporates smart cards to ensure that only authorized DataFort administrators can configure and manage the DataFort. In SAN environments, DataFort can use Host Authentication to further lock down the fabric.

STORAGE VPN
In Ethernet environments, DataFort can secure data in flight from the desktop or server with integrated Storage VPN features. DataFort supports IPsec or SSL with hardware-based acceleration, and WebDAV support enables secure, drag-and-drop access to networked storage for remote users or partners over the Internet.

SECURE LOGGING
Each DataFort keeps a cryptographically signed log of activities. Reports are fully customizable to track relevant events, including failed authentication attempts, Cryptainer access, administrative actions, or intrusion.

CRYPTOSHRED™ KEY DELETION
CryptoShred simplifies the process of permanently deleting data. By deleting an encryption key, all copies of associated data are instantly destroyed, regardless of physical location. CryptoShred provides vital functionality for a range of applications, including regulatory compliance, hardware redeployment or disposal, and protection for data in harm's way.

EASY TO DEPLOY

DataFort fits seamlessly into the existing storage infrastructure, adding critical security without impacting network performance or user workflow. Security advantages are realized without installing software on clients, servers or hosts, and authorized users can read, write and modify files as they always have, without changing their workflow.

OPERATIONAL TRANSPARENCY
DataFort is implemented as a transparent storage proxy: to clients or hosts, DataFort looks like storage, and to storage, DataFort looks like clients or hosts. DataFort appliances natively support CIFS, NFS and Fibre Channel protocols for maximum transparency. Because only the payload is encrypted, existing applications - such as backups and restores - can function without modification.

EASY TO MANAGE
DataFort can be installed in less than 60 minutes, and ongoing administration is simple and straightforward via a Web-based management interface. Industry-standard tools like SNMP and syslog can be used for monitoring, and DataFort's robust CLI allows scripting for common management tasks.

ENTERPRISE-CLASS RELIABILITY
DataFort hardware is built for maximum availability with minimal moving parts and no internal disks. DataFort can be installed in clusters for automatic fail-over and load balancing.

DEPLOYMENT

Decru DataFort is highly flexible and can be placed in a variety of locations within a storage network.






Decru DataFort™ FC-Series

By locking down stored data with strong encryption, and transparently routing all access through secure hardware, Decru DataFort™ appliances radically simplify the security model for data in networked storage.

MAXIMUM DATA SECURITY

Decru DataFort™ FC-Series appliances enable complete security for stored data through host authentication, access controls and strong data encryption for disk and/or tape from one powerful platform. DataFort is deployed transparently in Fibre Channel SAN environements, and is easily managed from a centralized, secure interface. An automated key management system ensures data is both available and secure. Because DataFort supports encryption for both Fibre Channel SAN disk arrays, and tape media, DataFort can easily scale as enterprise security requirements grow.

APPLICATIONS

  • Compartmentalize data in shared storage
  • Secure backup and disaster recovery locations
  • Secure tape media for transit and offsite storage
  • Maintain compartmentalization for tape backups
  • Regulatory compliance
  • Secure outsourcing and offshoring
SECURITY HIGHLIGHTS



HARDENED ARCHITECTURE
DataFort hardware was designed from the ground up for maximum security. At the heart of the system is Decru's Storage Encryption Processor (SEP) — a robust hardware engine enabling full-duplex, wire-speed encryption and key management. Decru's SEP, clustering and key management have passed certification testing for FIPS 140-2 level 3. DataFort's AES-256, SHA-1 and SHA-256 encryption implementations have also been certified by the National Institute for Standards and Technology (NIST.)

ROBUST ENCRYPTION STANDARDS
Decru DataFort incorporates strong AES-256 encryption, optimized by Decru for protecting stored data. DataFort uses a True Random Number Generator (TRNG) to create keys, and cleartext keys never leave DataFort's secure hardware, offering the highest level of security against attacks.

COMPARTMENTALIZATION
Security administrators can compartmentalize aggregated data in shared storage using Cryptainer™ storage vaults. Cryptainer vaults cryptographically partition stored data at a LUN or host level, and provide an additional layer of threat containment.

LIFETIME KEY MANAGEMENT™
securely automates key backup, recovery and archiving across the enterprise, drastically simplifying key management. LKM provides unified key management across all DataFort appliances, and incorporates a software-based recovery tool to ensure access to data in disaster recovery scenarios. LKM requires a quorum of Decru Recovery Smart Cards for all sensitive recovery functions, eliminating vulnerability to attacks by any single malicious insider.

HOST AUTHENTICATION
DataFort provides a powerful, single point of authentication for heterogeneous storage environments. With Host Authentication, security administrators can lock down the fabric to ensure data access is granted only to authorized hosts.

SECURE LOGGING
Each DataFort keeps a cryptographically-signed, tamper-proof log of activities. Reports are fully customizable to track relevant events, including failed authentication attempts, Cryptainer access, administrative actions, or intrusion.

EASY TO DEPLOY

DataFort integrates transparently with existing infrastructures, and has been tested for compatibility with all major storage, switch, backup, and operating system vendors. Security advantages are realized without installing software on clients, servers or hosts.

SUPPORTS MULTIPLE TAPE DEVICES
Each DataFort can encrypt and decrypt at multi-gigibit speeds, making it possible to support multiple tape libraries with one DataFort or DataFort cluster.

EASY TO MANAGE

DataFort can be installed in less than 60 minutes, and ongoing administration is simple and straightforward using a secure Web-based management interface. Two-factor authentication for administrators further strengthens security for sensitive operations. Industry-standard tools like SNMP and syslog can be used for monitoring, and DataFort's robust CLI allows scripting of common management tasks.

ENTERPRISE-CLASS RELIABILITY
DataFort hardware is built for maximum availability with minimal moving parts and no internal disks. DataFort can be installed in clusters for automatic fail-over and load balancing.

DEPLOYMENT

DataFort supports 2Gb Fibre Channel SANs and tape libraries with flexible deployment options. A different encryption key can be used for each host, ensuring that data from different groups stays separate.






Decru DataFort™ T-Series

MAXIMUM DATA SECURITY

Decru DataFort™ T-Series storage security appliances enable complete security for data stored on tape, providing host authentication, strong data encryption, compression, and crypto-signed logging. DataFort is easily managed from a centralized, secure interface, and an automated key management system ensures data is both secure and always available. Because DataFort T-Series appliances can be upgraded to support encryption for both tape and Fibre Channel SAN disk arrays, DataFort can easily scale as enterprise security requirements grow.

APPLICATIONS

  • Secure data on tape for offsite storage
  • Maintain compartmentalization for tape backups
  • Secure data transfer
  • Regulatory compliance
  • Secure IT outsourcing
SECURITY HIGHLIGHTS



HARDENED ARCHITECTURE
DataFort hardware was designed from the ground up for maximum security. At the heart of the system is Decru's Storage Encryption Processor (SEP) — a robust hardware engine enabling full-duplex, wire-speed encryption and key management. Decru's SEP, clustering and key management have passed certification testing for FIPS 140-2 level 3. DataFort's AES-256, SHA-1 and SHA-256 encryption implementations have also been certified by the National Institute for Standards and Technology (NIST.)

ROBUST ENCRYPTION STANDARDS
Decru DataFort incorporates strong AES-256 encryption, optimized by Decru for protecting stored data. DataFort uses a True Random Number Generator (TRNG) to create keys, and cleartext keys never leave DataFort's secure hardware, offering the highest level of security against attacks.

COMPARTMENTALIZATION
Security administrators can compartmentalize data within a shared tape library using Cryptainer™ storage vaults. Cryptainer vaults cryptographically partition stored data per host, and provide an additional layer of threat containment.

LIFETIME KEY MANAGEMENT™ SYSTEM (LKM)
securely automates key backup, recovery and archiving across the enterprise, drastically simplifying key management. LKM provides unified key management across all DataFort appliances, and incorporates a software-based recovery tool to ensure access to data in disaster recovery scenarios. LKM requires a quorum of Decru Recovery Smart Cards for all sensitive recovery functions, eliminating vulnerability to attacks by any single malicious insider.

HOST AUTHENTICATION
DataFort provides a powerful, single point of authentication for heterogeneous storage environments. With Host Authentication, security administrators can lock down the fabric to ensure data access is granted only to authorized hosts.

SECURE LOGGING
Each DataFort keeps a cryptographically signed log of activities. Reports are fully customizable to track relevant events, including failed authentication attempts, Cryptainer access, admin-istrative actions, or intrusion.

EASY TO DEPLOY

DataFort integrates transparently with existing backup infrastructures, and has been tested for compatibility with all major storage, switch, backup, and operating system vendors. Security advantages are realized without installing software on clients, servers or hosts.

SUPPORTS MULTIPLE TAPE DEVICES
Each DataFort can encrypt and decrypt at multi-gigibit speeds, making it possible to support multiple tape libraries with one DataFort or DataFort cluster. DataFort also supports legacy cleartext tapes, ensuring a seamless transition to a secure environment.

EASY TO MANAGE
DataFort can be installed in less than 60 minutes, and ongoing administration is simple and straightforward using a secure Web-based management interface. Two-factor authentication for administrators further strengthens security for sensitive operations. Industry-standard tools like SNMP and syslog can be used for monitoring, and DataFort's robust CLI allows scripting of common management tasks.

ENTERPRISE-CLASS RELIABILITY
DataFort hardware is built for maximum availability with minimal moving parts and no internal disks. DataFort can be installed in clusters for automatic fail-over and load balancing.

DEPLOYMENT

DataFort supports 1 and 2 Gig Fibre Channel tape libraries with flexible deployment options.





SPECIFICATIONS

HARDWARE
  • Standard 19" EIA rack (1U and 2U options)
  • Hardware-accelerated compression
  • Front LCD display
  • Front LED for status and network activity
  • 2U model includes:
    • Redundant power supplies
    • Hot swappable fan assemblies
    • Touch panel LCD display for setting IP address and ongoing diagnostics
Get 24-hour Quote
Product
Name
Phone
Email
Company Name
Company Address
City     State      Zip  
Requirements