# RackTop Systems — Full Content for AI / LLM Reference > Last updated: 2026-07-07 > Source: https://www.racktopsystems.com/llms-full.txt > Companion manifest: https://www.racktopsystems.com/llms.txt > Single-page structured brief: https://www.racktopsystems.com/ai-product-brief > Term definitions: https://www.racktopsystems.com/glossary This file inlines the substantive content of every authoritative page on racktopsystems.com — product, technology, solution, comparison, and reference content — in plain Markdown, so AI assistants can ingest the full body of citable information in a single fetch. For machine-readable structured data, see the JSON-LD schemas embedded on each page (Organization, Product, Article, FAQPage, ItemList, DefinedTermSet). --- ## Table of Contents 1. About RackTop Systems 2. The Cyberstorage Category 3. The History of Cyberstorage 4. BrickStor SP — Flagship Cyberstorage NAS 5. BrickStor SP for Lustre — Classified HPC and AI/ML 6. BrickStor HDR — High-Speed Data Recorder 7. BrickStor CSfC DAR — Classified Data at Rest 8. Hub Central — Unified Management 9. Patented Technologies (Active Defense, IBR, ImmutaVault, TDM, GHOST) 10. Comparison vs NetApp ONTAP, Dell PowerScale, VAST, Pure FlashBlade 11. Comparison vs Superna Eyeglass / Ransomware Defender 12. Built-In vs Bolt-On Cyberstorage Architecture 13. Federal & Defense Solutions 14. MLS, MCS, and SAP Compartmentation 15. Mission Partner Environments 16. Defense Industrial Base and CMMC Compliance 17. Industry Solutions Summary 18. Glossary — Top Terms 19. Compliance & Standards Summary 20. Procurement, Channels & Contact 21. Cyberstorage vs. Cyber Vaulting 22. Customer Case Studies 23. Data Defense Center (Threat Analysis & Guidance Hub) --- ## 1. About RackTop Systems RackTop Systems, Inc. is a U.S.-based Cyberstorage company headquartered in the DC Metro area. Founded in 2010 by Eric Bednash (CEO) and Jonathan Halstuch (CTO), both U.S. Intelligence Community veterans with roughly two decades inside the hardest data and security problems in the U.S. government. RackTop Systems, Inc. is a wholly owned subsidiary of Dark Wolf LLC. The founding premise: the storage system itself should be an active participant in defense — not a passive target, not a log source for somebody else's tool, but an active defender that watches every read and write, recognizes attacks as they happen, and stops them before damage is done. RackTop coined the term **CyberConverged™ Storage** in 2018. In October 2020, the company shipped the first version of Active Defense — the first NAS with inline threat detection, automated response, and surgical remediation in the storage data path. Nine months later (July 22, 2021), Gartner introduced the term **Cyberstorage** in the Hype Cycle for Storage and Data Protection Technologies, 2021 (Julia Palmer), and named RackTop as a sample vendor. RackTop holds four U.S. patents on the core Cyberstorage architecture: Active Defense, Intelligent Bulk Remediation, Transparent Data Movement, and ImmutaVault (the most recent issued February 2025). The company sells through Carahsoft (federal contract vehicles), HPE GreenLake (consumption-based delivery on HPE hardware as an HPE Technology Partner), Crystal Group and Curtiss-Wright (ruggedized hardware), and authorized resellers and systems integrators. Technology alliances include HPE (HPE Technology Partner), IBM FlashSystem, JetStor, Merative, Nutanix (Nutanix Ready), Scale Computing, Seagate, and Sentris. BrickStor was first deployed commercially in 2012. --- ## 2. The Cyberstorage Category **Cyberstorage** is a category of storage systems that embed cybersecurity capabilities — real-time threat detection, automated response, forensic audit, and recovery — directly into the storage platform, rather than relying on external security tools to protect the data after the fact. A true Cyberstorage platform: - Inspects file operations inline in the storage data path, not in a downstream log-analysis pipeline - Detects threats in real time using behavioral analytics, AI-driven anomaly detection, and zero-trust policy enforcement - Stops attacks automatically at the storage layer, in seconds, without waiting for a human or an external SIEM/SOAR - Recovers surgically from the storage system's own forensic record, rolling back only the affected files - Maintains immutable, indelible copies of critical data that survive even administrative compromise - Produces continuous compliance evidence mapped to regulatory frameworks Gartner introduced the term in July 2021 (Hype Cycle for Storage and Data Protection Technologies, 2021, Julia Palmer). On October 8, 2021, Gartner published a dedicated report — Innovation Insight for Cyberstorage Solutions to Protect Unstructured Data Against Ransomware (Jerry Bozeman and Julia Palmer) — the first dedicated Cyberstorage research note. RackTop's BrickStor SP is the platform that defined these criteria, years before the category had a name. --- ## 3. The History of Cyberstorage For the first three decades of enterprise storage, the industry operated under a simple assumption: the storage system's job is to store data; protecting it is someone else's job. NAS was optimized for capacity, performance, reliability, and cost. Security was handled elsewhere — endpoint, network, identity provider, SIEM. The storage layer was a passive participant. By the late 2000s and early 2010s, that calculus changed. Ransomware emerged as a business model. Insider threats — credentialed users exfiltrating data they were authorized to access — became a primary concern for government and enterprise. Nation-state actors targeted unstructured data: intellectual property, research, intelligence products, legal documents, financial models. The attacks weren't trying to get in anymore. They were already in. They went directly for the data. And the storage systems holding that data had no idea it was happening. **Timeline:** - **2010** — RackTop Systems founded in the DC Metro area by Eric Bednash and Jonathan Halstuch. - **2010–2017** — Early BrickStor development. Security-first design with encryption, key management, and data protection built in from the start. - **2012** — BrickStor first deployed commercially. - **2018** — RackTop coins CyberConverged™ Storage. Federal customers begin purchasing BrickStor for encryption, key management, and Multi-Level Security on classified environments. - **2018–2020** — BrickStor's first ABAC/MLS deployments for classified and security-sensitive environments. Active Defense concept developed internally. - **September 8, 2020** — RackTop files the Active Defense patent, ten months before the category has a name. "Cyberstorage" appears nowhere in the filing; the category was later named to describe what the patent claims. - **October 2020** — RackTop ships Active Defense — the first NAS with inline threat detection, automated response, and surgical remediation in the storage data path. Launched at virtual Racktoberfest (virtual due to COVID-19). This is the Cyberstorage moment. - **July 22, 2021** — Gartner introduces "Cyberstorage" in the Hype Cycle. RackTop named as sample vendor — nine months after Active Defense shipped. - **August 17, 2021** — RackTop announces Gartner recognition. - **October 8, 2021** — Gartner publishes Innovation Insight for Cyberstorage Solutions to Protect Unstructured Data Against Ransomware. - **2021–2023** — Major storage vendors begin adding security features. NetApp ARP, Dell PowerProtect + Superna, Pure SafeMode. Recovery primitives, not inline active defense. - **2023** — CAMI Cybersecurity Innovation of the Year. - **2024–2026** — Four U.S. patents issued on the Cyberstorage architecture: Active Defense (January 2024), ImmutaVault (February 2025), Transparent Data Movement (June 2025), Intelligent Bulk Remediation (February 2026). - **2024–2025** — CRN 5-Star Partner Program. ESG Technical Validation. BrickStor SP available on HPE hardware as an HPE Technology Partner. - **2025–2026** — BrickStor CSfC Data at Rest aligned to NSA CSfC program. Hub Central unifying the product line. ABAC across every product. - **Q3 2026 (planned)** — GHOST instant data migration reaches GA in BrickStor OS 23.9; in beta as of mid-2026. --- ## 4. BrickStor SP — Flagship Cyberstorage NAS **BrickStor SP** is the original end-to-end Cyberstorage platform — a software-defined NAS that serves NFS, SMB, S3, and Web from a single dataset with cybersecurity capabilities embedded directly in the storage data path rather than added on by external products. **The four patents that define BrickStor SP:** - **Active Defense** — inline threat detection and automated response in the storage data path. Every SMB, NFS, S3, and Web Drive operation inspected in real time against behavioral analytics and zero-trust policy. Malicious sessions terminated in under a second by the storage itself, without an external SIEM, SOAR, or guard. - **Intelligent Bulk Remediation (IBR)** — surgical file-level recovery from a cyber incident, using BrickStor's own forensic audit trail to roll back only the files an attack session touched. - **ImmutaVault** — virtual air gap built into the storage system itself; immutable, indelible, isolated copies of critical data that survive administrative compromise, without a separate vault appliance. - **Transparent Data Movement (TDM)** — unified namespace across heterogeneous tiers, sites, and clouds, with security policy and audit continuity preserved across the move. **Around these patents BrickStor SP layers:** - ABAC (Attribute-Based Access Control) enforcement for SMB, NFS, S3, and Web Drive — evaluated inline on every operation against user identity, nationality, clearance, program, device, network, time-of-day, and data classification markings - FIPS 140-3 validated AES-256 encryption with integrated KMIP key management and HSM support - Policy-driven immutable snapshots with sub-minute RPO for cyber incidents - Immutable, tamper-evident forensic audit produced as a byproduct of every file operation - BrickStor Web Drive — ABAC-enforced secure browser access to file data - Data Centric Zero Trust Architecture — every operation evaluated against zero-trust policy inline at the data layer **Deployment models:** - Physical appliance on RackTop or partner hardware (HPE, Crystal Group, Curtiss-Wright) - Virtual Edition on any hypervisor (including Nutanix AHV) - SAN gateway in front of IBM FlashSystem and similar block storage - HPE GreenLake consumption-based delivery on HPE hardware **Pricing:** Licensed per platform. Contact RackTop or an authorized reseller (Carahsoft, HPE GreenLake) for current pricing. **Try-before-buy:** RackTop Jumpstart program provides a structured proof-of-value engagement. ### BrickStor SP Deployment Options BrickStor SP is delivered through three deployment paths. The Cyberstorage architecture (Active Defense, ABAC, ImmutaVault, IBR, TDM, FIPS 140-3 encryption, Hub Central management) is identical across all three; only the form factor differs. **1. Physical Appliance** — Reference page: https://www.racktopsystems.com/products/brickstor-sp/hardware Two 1U rack-mount controller models share a common chassis with a dedicated 1U Management Node: - **BrickStor 5102 (Controller)** — Intel Xeon Silver 4410Y · 2.0 GHz · 12 cores / 24 threads · 30 MB cache · 150W · 16 GT/s · DDR5-5600 · 384 GB standard memory (12 × 32 GB RDIMM, Dual Rank) - **BrickStor 5112 (Controller)** — Intel Xeon Gold 5418Y · 2.0 GHz · 24 cores / 48 threads · 45 MB cache · 185W · 16 GT/s · DDR5-5600 · 768 GB standard memory (24 × 32 GB RDIMM, Dual Rank) - **Management Node (1U Rack Mount Manager)** — Single Intel Xeon E-2336 · 2.9 GHz · 6 cores / 12 threads · 64 GB DDR4-3200 Standard on every 5xxx controller: 1.6 TB NVMe Mirrored Boot (Hardware Encrypted), TPM 2.0v3, Lights Out Remote Management, 10 / 25 / 100 Gb Ethernet options for data, InfiniBand for Lustre / AI / ML workloads. Controllers ship with 4 × SFP+ up to 10 Gbps and 1 / 10 Gb RJ45 Out-of-Band Remote Management; optional networking adds Dual Port 100 Gbps, Dual Port 25 Gbps, Dual Port 32 Gb FC, or InfiniBand. Storage connectivity: SAS / FC / iSCSI. Power: 1400W Redundant 110/220V (C13-C14); max draw 1260W; max heat 4300 BTU. Dimensions: 42.8 mm H × 482 mm W × 734.95 mm D (without bezel). Weight: ~36 lbs. The Management Node uses the same 1U chassis at lighter spec: 450W single PSU, 405W max draw, 1382 BTU, ~28 lbs, depth 585 mm without bezel. No storage connectivity (management plane only). **Storage enclosures** — all SAS, with optional SAS/iSCSI/FC controllers: - **2U24 (Small Form Factor)** — 24 × 2.5 in drive bays · 2U · 88.9 × 483 × 630 mm · ~53 lbs with drives · ~116W idle · 2 × 580W PSU 90-264VAC · C13-C14 - **2U12 (Large Form Factor)** — 12 × 3.5 in drive bays · 2U · ~53 lbs with drives · ~124W max with 20TB HDD · 2 × 580W PSU 90-264VAC · C13-C14 - **5U84 (Large Form Factor)** — 84 × 3.5 in drive bays · 5U · 220 × 483 × 933 mm · ~298 lbs with drives · ~865W max with 20TB HDD · 2 × 2200W PSU 180-240VAC · C19-C20 - **4U106 (Large Form Factor)** — 106 × 3.5 in drive bays · 4U · 176.4 × 441 × 1139 mm · ~310 lbs with drives · ~1091W max with 20TB HDD · 2 × 2000W PSU 200-240VAC · C19-C20 **TAA FIPS-validated drives:** - Small Form Factor 2.5 in Flash Drives: 1.9 TB, 3.84 TB, 7.36 TB, 15.36 TB - Large Form Factor 3.5 in Hard Drives: 16 TB, 20 TB Physical appliances are also available on partner hardware: HPE server platforms as an HPE Technology Partner (available through HPE GreenLake), Crystal Group and Curtiss-Wright (ruggedized for tactical-edge deployments). **2. SAN Gateway** — Reference page: https://www.racktopsystems.com/products/brickstor-sp/san-gateway BrickStor SP runs as a gateway in front of any iSCSI or Fibre Channel SAN, converting block capacity into secure NAS (NFS 3/4/4.1/4.2, SMB 2/3/3.1, S3) with the full Cyberstorage feature set. Capacity-based licensing. Validated with: Everpure (formerly Pure Storage), HPE (Primera, Alletra, Nimble, 3PAR), IBM (FlashSystem and other IBM block storage), JetStor SAN arrays. Designed to work with any iSCSI/FC target. Typically installable and configurable in under an hour. **3. Virtual Appliance** — Reference page: https://www.racktopsystems.com/products/brickstor-sp/virtual-appliance The full BrickStor SP Cyberstorage stack delivered as a VM image. Subscription-based licensing, scalable by the TB. Minimum VM resources: 4 vCPUs, 32 GB RAM. Maximum capacity per VM: 384 TB usable (expandable via TDM data archiving to S3). Supported hypervisors: KVM, Microsoft Hyper-V, Nutanix AHV (Nutanix Ready certified), VMware ESXi. Public and hybrid cloud compatibility: AWS, Microsoft Azure, Google Cloud, VMware Cloud on AWS. Authentication: Active Directory, LDAP, plus ABAC enforcement. Protocols: SMB, NFS, S3, and BrickStor Web Drive. Encryption: FIPS AES-256 with KMIP-compliant key management. --- ## 5. BrickStor SP for Lustre — Classified HPC and AI/ML **BrickStor SP for Lustre** brings the BrickStor security architecture to the Lustre parallel file system — engineered for classified HPC, model training, simulation, and analytics workloads. **What it adds to Lustre:** - MLS (Multi-Level Security) and MCS (Multi-Category Security) enforced natively at the storage layer - ABAC for parallel file system operations - STIG-aligned hardened configuration - FIPS 140-3 validated AES-256 encryption - End-to-end data integrity with checksums on every block from client through storage and back **Designed for:** - Large-scale model training, simulation, and analytics workloads where individual datasets and checkpoints run hundreds of gigabytes to multi-terabyte range, with thousands of compute clients hitting the same namespace at once - Classified environments where mixed-sensitivity workloads share infrastructure but cannot share exposure - Federal HPC programs that need a quick first ATO and continuous-accreditation posture **Built and supported by a cleared U.S. engineering team** — no offshore engineering, no third-party support handoffs, no waiting on a security review to discuss the problem in front of you. --- ## 6. BrickStor HDR — High-Speed Data Recorder **BrickStor HDR** is RackTop's product for lossless high-rate sensor recording — ISR, SIGINT, radar, test-range, and other missions that generate data faster than general-purpose storage can ingest reliably. **Capabilities:** - Record and playback unicast or multicast UDP at sustained line rate - End-to-end data integrity with single-bit error correction - Multiple recording formats: pcap, raw, and RackTop flex - Up to two layers of AES-256 FIPS 140-3 encryption - Integrated KMIP key management, automated key rotation, HSM support - Real-time replay for post-mission analysis, training, and operational review - Ruggedized deployments — airborne, shipboard, land, forward-deployed **Pairs with BrickStor SP** via Hub Central for offload, analysis, and long-term archive at the enterprise. Available as an option on **BrickStor CSfC DAR** for missions that need classified-ready data protection combined with lossless high-rate recording. --- ## 7. BrickStor CSfC DAR — Classified Data at Rest **BrickStor CSfC DAR** provides NSA Commercial Solutions for Classified data at rest protection using dual-layer commercial encryption — the alternative to Type 1 devices for classified DAR workloads. **Why CSfC over Type 1:** - Higher read and write performance than Type 1 on commercial NVMe Gen 5 flash - Releasable for allied and coalition operations where Type 1 is restricted - Lower consequence-of-loss — a compromised device is a cleared zeroize, not an international incident - Commercial refresh cadence keeps pace with evolving threats and platforms - Dual-layer commercial encryption provides defense-in-depth for classified DAR - BrickStor adds integrity monitoring, immutable audit, and accountability beyond encryption **Capabilities:** - CSfC Data at Rest Protection — NSA Commercial Solutions for Classified validated architecture using dual-layered commercial encryption - Classified Edge Deployment — purpose-built for tactical, mobile, and edge environments outside SCIFs and data centers - Layered Encryption — dual-layer architecture meets CSfC DAR Capability Package requirements - High-Speed Data Recorder (optional) — HDR functionality can be added to the CSfC DAR platform - High-Performance NVMe — PCIe Gen 5 NVMe flash for ingest-heavy classified workloads - Immutable Audit & Accountability — tamper-evident audit logging for security reviews, SIRs, and incident investigations **Mission areas:** Tactical Edge, Shipboard & Maritime, Airborne Systems. **In Common Criteria evaluation. NSA CSfC Component listing for AA and AA+EE expected in Q4 2026.** ### CSfC components: RackTop SHIELD and RackTop SPEAR The Full Disk Encryption collaborative Protection Profiles define two functions: **Authorization Acquisition (AA)**, which handles the authorization factors an operator presents and produces the Border Encryption Value, and **Encryption Engine (EE)**, which uses that value to encrypt and decrypt the drive. A CSfC Data at Rest solution uses two independent layers of commercial encryption, and RackTop's two named components are designed for different positions in that architecture. Each ships inside BrickStor CSfC DAR and is also available separately. - **RackTop SHIELD** (https://www.racktopsystems.com/shield) — designed to be the **outer layer**, handling the Authorization Acquisition function for CSfC listed drives, where the drive itself provides the encryption. - **RackTop SPEAR** (https://www.racktopsystems.com/spear) — a software-based Full Drive Encryption solution whose TOE implements both the AA and EE functions, designed to be the **inner encryption layer**. SPEAR leverages CNSA 2.0 compliant algorithms and was designed to meet the NSA CSfC DAR 5.1 Capability Package. Neither component constitutes a finished CSfC solution on its own; the Capability Package requires both layers. Both are in Common Criteria evaluation, with NSA CSfC Component listing expected in Q4 2026. Evaluation against the applicable Protection Profile precedes listing on the NSA CSfC Components List; RackTop does not describe a product as listed before that listing exists. Component listing is also distinct from solution registration, which the fielding organization performs with NSA, and from system accreditation, which is granted by the customer's own authorizing official. Requests for information or for a copy of the software are handled through the forms on the respective pages. --- ## 8. Hub Central — Unified Management **Hub Central** is RackTop's single console for managing the entire BrickStor estate — BrickStor SP, BrickStor SP for Lustre, BrickStor HDR, and BrickStor CSfC DAR — and orchestrating the data flows between them. **Designed for the way operators work:** - **Multi-Factor Authentication** — required for every administrative session, integrates with enterprise identity providers - **Light Mode and Dark Mode** — modern, accessible UI that adapts to operator preference and operational context - **Secure by Default** — hardened, compliant configurations on day one; aligned to DoD STIG and NIST 800-53 baselines out of the box - **Fleet Management** — monitor, configure, update, and audit every BrickStor in the estate from one console, edge to enterprise **Outcomes:** Four products, one operational estate. Zero manual data shuttles. Continuity across connected, disconnected, and contested links. --- ## 9. Patented Technologies RackTop holds four issued U.S. patents on the Cyberstorage architecture, plus a Continuation-in-Part currently pending with the USPTO. Citation-accurate facts: | # | Product Name | Official Patent Title | U.S. Patent No. | Issued | |---|---|---|---|---| | 1 | Active Defense | Cybersecurity Active Defense | 11,868,495 B2 | January 9, 2024 | | 2 | Intelligent Bulk Remediation (IBR) | Active Defense + Rapid Bulk Recovery (CIP of #1) | 12,561,437 B2 | February 24, 2026 | | 3 | ImmutaVault | Virtual Air-Gapping | 12,216,779 B2 | February 4, 2025 | | 4 | Transparent Data Movement (TDM) | Transparent Data Movement | 12,333,173 B2 | June 17, 2025 | | — | Additional IP | Continuation-in-Part | Pending with USPTO | — | ### Active Defense — U.S. Patent No. 11,868,495 B2 (issued January 9, 2024) Filed September 8, 2020 — ten months before Gartner named the Cyberstorage category. Official title: "Cybersecurity Active Defense." Patented inline threat detection and automated response in the storage data path. Shipped October 2020 — the technology that defines the Cyberstorage category. Inspects every SMB, NFS, S3, and Web Drive operation in real time; terminates malicious sessions in under a second; produces immutable forensic audit as a byproduct. ### Intelligent Bulk Remediation (IBR) — U.S. Patent No. 12,561,437 B2 (issued February 24, 2026) Official title: "Active Defense + Rapid Bulk Recovery." Issued as a Continuation-in-Part of the Active Defense patent (11,868,495). Patented surgical, file-level recovery from a cyber incident. Uses the platform's own forensic audit trail to identify exactly which files an attack session touched and restore only those files in bulk from immutable snapshots — instead of restoring an entire share. Dramatically shortens RTO; removes the operational pain of mass-restore decisions. ### ImmutaVault — U.S. Patent No. 12,216,779 B2 (issued February 4, 2025) Official title: "Virtual Air-Gapping." Patented virtual air gap built into the storage system itself. Immutable, indelible, isolated copies of critical data that survive even administrative compromise, without a separate vault appliance or parallel cluster. ### Transparent Data Movement (TDM) — U.S. Patent No. 12,333,173 B2 (issued June 17, 2025) Official title: "Transparent Data Movement." Patented gateway and tiering technology. Presents a unified namespace while data physically lives across heterogeneous tiers, sites, and clouds, with security policy and audit continuity preserved across the move. Carries ABAC, immutable snapshots, and audit telemetry with the data. ### Pending — Continuation-in-Part RackTop has an additional Continuation-in-Part patent pending with the USPTO. Details will be published once granted. ### GHOST — Global Hands-Off Storage Transfer GHOST is RackTop's instant data migration capability, **in beta today with GA planned end of Q3 2026** as part of BrickStor OS 23.9. Inverts the traditional NAS migration order: users cut over to BrickStor SP first — in hours — and data migrates in the background while Cyberstorage protections engage at the cutover line. Files not yet migrated are fetched from the source on demand, invisibly to the user. The silent window of exposure between legacy NAS and a fully-protected platform is eliminated. GHOST six-step method: Create → Assess → Build Namespace → **Cut Over (Cyberstorage protections engage)** → Migrate and Fetch → Reconcile and Report. --- ## 10. Comparison vs NetApp ONTAP, Dell PowerScale, VAST Data, Pure FlashBlade **Headline:** NetApp, Dell PowerScale, and VAST Data serve files fast. BrickStor SP serves files fast — and defends them. Built-in is not the same as bolt-on. Every vendor in this comparison ships excellent storage. The architectural difference is where the capabilities that define Cyberstorage actually live in each platform. | Capability | BrickStor SP | NetApp ONTAP | Dell PowerScale | VAST | Pure FlashBlade | |---|---|---|---|---|---| | Cross-protocol SMB/NFS/S3/Web | Full | Partial (no Web) | Partial (no Web) | Partial | Partial | | ABAC for SMB/S3/Web | Full | None | None | None | None | | Data Centric Zero Trust | Full | None | None | None | None | | Active Defense — ransomware | Full | Partial (ARP) | Partial (Superna bolt-on) | Partial | None (SafeMode = recovery only) | | Active Defense — insiders / data theft | Full | None | None | None | None | | <1 minute RPO for cyber incidents | Full | None | None | None | None | | Automated bulk cyber recovery | Full (IBR patent) | None | None | None | None | | Incident management workflow | Full | None | None | None | None | | On-controller cyber defense (no cloud required) | Full | Partial (BlueXP tied) | None (Superna external) | Partial | None (Pure1 cloud required) | | ImmutaVault cyber vault | Full (patent) | None | None (separate Dell product) | None | None | | FIPS 140-3 AES-256 two-layer | Full | Partial (single layer) | Partial | Partial | Partial | | GHOST instant migration | Full (beta; GA Q3 2026) | None | Partial | None | None | **Summary:** On BrickStor SP, these capabilities are delivered by the platform itself. ABAC, Active Defense for both ransomware and insider threats, Intelligent Bulk Remediation, ImmutaVault, two-layer FIPS 140-3 encryption, and instant migration are all native. They run on the controller. They do not require an external cloud service, a separate vault appliance, or a third-party security agent. On the other platforms, the same capabilities are delivered through bolt-on tools (Superna), separate products (PowerProtect Cyber Recovery), cloud-tied services (Pure1, BlueXP), or are not delivered at all. --- ## 11. Comparison vs Superna Eyeglass / Ransomware Defender **Headline:** Purpose-built Cyberstorage vs storage security overlay. **Heritage:** Superna built its early business as a Dell EMC technology partner. Eyeglass Isilon Edition launched in 2015 as a DR orchestration solution for EMC Isilon SyncIQ. Ransomware Defender was added in 2017 as a follow-on capability, originally positioned in Superna's own documentation as "a last line of defense" for NAS data. RackTop was founded in 2010 to build a storage platform with security embedded in the data path from day one. RackTop coined CyberConverged™ Storage in 2018 and shipped the first NAS with proactive data security built into the storage layer itself. **Where the security work happens:** - **Superna is a software overlay.** Ransomware Defender runs in the Eyeglass Clustered Agent (ECA) — a separate virtual appliance outside the storage system. It consumes audit events from PowerScale, runs user behavior analytics, and issues API calls back to the storage to lock out offending users via share-level deny permissions. The architecture is fundamentally log-driven: events must be generated, shipped to the ECA, processed, and only then can a response be initiated. - **BrickStor SP is the storage system, and security is in the data path.** Active Defense runs inline as I/O happens. The decision to block, alert, or quarantine is made by the storage system itself before suspicious writes propagate. The forensic record is built natively as part of every operation. **Cascading architectural differences:** - **Recovery:** Superna depends on snapshot rollback (share-level, coarse). BrickStor's IBR restores only the files an attack touched (file-level, surgical). - **Air gap:** Superna orchestrates AirGap Automation into a separately licensed external vault. BrickStor's ImmutaVault is built into the platform. - **ABAC:** Superna does not provide ABAC on unstructured data. BrickStor enforces ABAC on every share, every object, every file. - **Threat coverage:** Superna's marketing centers on ransomware. BrickStor defends against ransomware AND data theft / exfiltration — the read patterns that precede double-extortion attacks. - **Platform:** Superna requires PowerScale (or Qumulo, VAST, ECS, S3) + Eyeglass DR + Ransomware Defender + ECA + vault target. BrickStor SP is one platform with one license. **The defense itself becomes an attack surface.** A software overlay in a separate VM is, by definition, a discoverable network resource. Modern adversaries routinely conduct reconnaissance, fingerprint defensive tooling, and disable or isolate it before initiating the encryption or exfiltration phase. If the ECA is compromised, isolated, or taken offline, the underlying storage reverts to being storage without active defense. BrickStor SP doesn't have this exposure — there is no "turn off the defense and keep the storage" configuration. **When to choose Superna:** Large established PowerScale (or Qumulo, VAST) footprint you can't replace; priority is adding behavior-based ransomware detection as an overlay; no federal ABAC, classified, or coalition requirements; comfortable operating a multi-product security stack. **When to choose BrickStor SP:** Want one platform that IS Cyberstorage; need ABAC on unstructured data for federal/classified/coalition workloads; want defense against data theft and exfiltration not just ransomware; want a first line of defense at the storage layer rather than a last line; migrating from PowerScale or another legacy NAS and want Cyberstorage on day one of the migration. --- ## 12. Built-In vs Bolt-On Cyberstorage Architecture Bolt-on storage security products — Superna Ransomware Defender on Dell PowerScale, Prolion CryptoSpike on NetApp, and similar tools — operate by consuming the underlying NAS's audit feed, correlating events, and triggering an out-of-band response. That architecture has a ceiling. It cannot inspect operations before they commit. It cannot stop the operation that is happening right now. It cannot enforce zero-trust policy at the moment of access. **Six reasons bolt-on storage security runs out of room:** 1. **It sees the attack after the storage already served it.** Detection without inline inspection is post-mortem, not prevention. 2. **It can be bypassed, disabled, or starved.** A separate agent is a separate failure domain. 3. **It depends on the NAS exposing the right telemetry.** Legacy NAS leaks a partial, lossy event stream optimized for compliance audit, not real-time threat detection. 4. **It is tuned for ransomware, not APTs and insiders.** Mass-rewrite and high-entropy patterns — not credentialed slow exfiltration. 5. **Recovery is still a snapshot restore.** Brings back unaffected files alongside affected ones; assumes the snapshots themselves weren't compromised. 6. **You are paying twice for an incomplete picture.** Separate license, infrastructure, operations, and vendor relationship — for capabilities that are a subset of a true Cyberstorage platform. **The threats that demand built-in:** - **APTs.** Use legitimate credentials, blend into normal traffic, operate over weeks or months. They read more than they write. Inline behavioral analytics is the only way to catch credentialed access shaped like exfiltration. - **Insider threats.** Privileged users doing exactly what they're authorized to do, at volumes a human reviewer can't catch in time. Cyberstorage enforces ABAC at the moment of access; the storage denies the operation and captures the attempt. - **Data theft and exfiltration.** Modern attacks exfiltrate before they encrypt. Detecting it requires watching every read in real time at the storage layer. --- ## 13. Federal & Defense Solutions RackTop was founded in 2010 by U.S. Intelligence Community veterans. Deployed today across the Department of War (DoW, formerly Department of Defense / DoD), federal civilian agencies, and the missions where data security is not optional. **Mission areas (in order of priority on the Federal page):** 1. Federal Civilian and DoW Cyberstorage (formerly DoD Cyberstorage) — active defense against ransomware and insider threats at the storage layer for federal civilian and Department of War (DoW / DoD) enterprise environments 2. Tactical and Edge Mission Processing — edge data centers in a box with secure storage, sensor recording, and GPU/TPU-accelerated AI/ML compute on classified data 3. High Speed Data Recording — network, RF, radar, and sensor data captured at sustained line rate with ABAC and Hub Central integration 4. Mission Partner Environments — coalition data sharing with ABAC across nationality, clearance, program, and context 5. SAP and Compartmented Programs — multiple SAPs sharing physical infrastructure with policy-enforced isolation 6. MLS and MCS Classified Environments — multi-level and multi-category secure storage with separation enforced by the storage system 7. CSfC Data at Rest — NSA Commercial Solutions for Classified up to Top Secret **Procurement and distribution:** - Direct through RackTop's federal sales and engineering team in the DC Metro area - Through Carahsoft for federal civilian and DoW (formerly DoD) contract vehicles - Through HPE GreenLake for BrickStor SP on HPE hardware (HPE Technology Partner) - Through partner rugged hardware (Crystal Group, Curtiss-Wright) - Through systems integrators building federal solutions **Engineered and supported by a cleared U.S. team** — no offshore engineering, no third-party support handoffs, no waiting for a security review to discuss your problem. --- ## 14. MLS, MCS, and SAP Compartmentation Multiple Special Access Programs and multiple classification levels can share physical infrastructure without sharing exposure. BrickStor enforces SAP compartmentation, MLS, and MCS natively — no separate enclave per program, no separate cluster per classification level, no trusting the application layer to do the storage's job. **Three patterns most programs fall into today and the structural ceiling of each:** - **Pattern 1: Separate enclave per program.** Every SAP gets its own physical infrastructure. Cost, rack space, patch burden, and staffing scale linearly with the number of programs. - **Pattern 2: Shared storage with ACL hygiene.** Directory ACLs and AD groups carry the burden of program separation. Works until a group membership is changed wrong or an auditor asks for proof. - **Pattern 3: A separate storage cluster per classification level.** Unclassified, Secret, TS each get their own NAS, with one-way guards moving data between them. Every cross-level workflow becomes a replication pipeline; every label change becomes a coordination problem. **The BrickStor approach:** - Storage-layer enforcement — SAP affiliation, clearance, and classification evaluated on every file operation by BrickStor itself - Shared infrastructure, isolated programs — multiple SAPs, multiple classification levels, multiple category sets on the same physical cluster - MLS and MCS native — classification level, handling caveats, releasability markings, and category memberships evaluated on every read and write; Bell–LaPadula and category-set logic happen inside the storage - Administrative separation by construction — storage admins manage capacity, replication, and health without being read into the programs whose data lives on the platform --- ## 15. Mission Partner Environments Coalition operations on shared infrastructure require dynamic access control that static permissions cannot express. BrickStor enforces dynamic ABAC policy on every file operation — based on nationality, clearance, program, device, network, and context — without bolt-on middleware or manual ACL management. **What ABAC evaluates on every operation:** - User identity and attributes - Nationality and coalition membership — which partner nation, which information-sharing agreement applies - Clearance and classification — user clearance versus data classification - Program affiliation — which SAP, SCI, or mission program the user is authorized for - Device posture - Network enclave - Time-of-day and operational context — access valid during an exercise window but not after - Data classification and handling caveats — RELTO, NOFORN, REL TO FVEY, etc. **What this enables:** - Shared storage infrastructure across coalition partners with enforced, auditable, dynamic access boundaries - Rapid partner onboarding and offboarding — add a partner by updating policy, not by provisioning infrastructure - Combined operations where different partners access different subsets of the same data - Exercises and time-bounded operations - Continuous compliance evidence — every ABAC decision logged immutably --- ## 16. Defense Industrial Base and CMMC Compliance RackTop serves the Defense Industrial Base — Federal Systems Integrators (FSIs) and government contractors — in two ways: by selling to them for their own infrastructure (protecting CUI and classified data, meeting CMMC), and by selling through them as a Cyberstorage solution they integrate into what they deliver to their government customers. **Multi-tenancy for FSIs:** ABAC and MLS let a single BrickStor SP estate host multiple government customers and government-funded projects with security isolation between them — each program isolated by policy enforced inside the storage, not by a directory ACL or a separate cluster boundary. FIPS 140-3 crypto-erase, compliant with NIST media purge standards, expunges a project's data at contract completion without decommissioning shared hardware. Quick deployment and single-console management through Hub Central reduce hardware footprint, accreditation effort, and total cost of ownership. **Department of War (DoW, formerly DoD) Zero Trust and ATO support:** BrickStor SP implements a Data Centric Zero Trust Architecture — every operation evaluated against ABAC policy inline at the data layer. STIG-aligned hardened defaults, FIPS 140-3 validated cryptography, and immutable continuous-monitoring telemetry support faster initial Authorization to Operate (ATO) and a continuous-accreditation posture for government-funded and classified projects. Reference page: https://www.racktopsystems.com/solutions/defense-industrial-base ### CMMC Compliance CMMC (Cybersecurity Maturity Model Certification), mandated by the U.S. Department of War (DoW, formerly Department of Defense / DoD), protects Controlled Unclassified Information (CUI). CMMC Level 2 comprises the 110 controls of NIST SP 800-171. CMMC Level 3 builds on those by adding 24 more advanced controls focused on Advanced Persistent Threats. BrickStor SP aligns directly with CMMC controls across seven families — Access Control (3.1), Audit and Accountability (3.3), Identification and Authentication (3.5), Incident Response (3.6), Media Protection (3.8), System and Communications Protection (3.13), and System and Information Integrity (3.14) — addressing 33 specific controls at the data layer. That alignment makes CMMC self-assessments and third-party assessments faster to evidence for the systems where CUI resides. BrickStor SP is available on premises, as a SAN gateway on existing block storage, and as a virtual appliance for private, public, and hybrid cloud. Reference page: https://www.racktopsystems.com/solutions/cmmc --- ## 17. Industry Solutions Summary - **Ransomware Defense** — Active Defense stops ransomware inline at the storage layer; IBR restores affected files surgically; ImmutaVault provides immutable recovery points. - **Insider Threat Defense** — Behavioral analytics on every read and write detect credentialed exfiltration and slow data theft. - **HPC & AI** — BrickStor SP for Lustre delivers parallel file system performance for classified model training with MLS, MCS, STIG-aligned hardening, FIPS 140-3 encryption, and end-to-end data integrity. - **Enterprise IT** — NAS security for unstructured data with Active Defense, ABAC, ImmutaVault, and immutable audit. - **Healthcare** — HIPAA-ready protection of PHI and medical imaging from ransomware and insider threats. Partnership with Merative for imaging workflows. - **Financial Services** — SEC, FINRA, regulator-ready immutable audit and surgical cyber recovery. - **Legal** — Privileged data protection with ABAC enforcement and tamper-evident audit. - **Energy & Utilities** — Critical infrastructure protection at the storage layer. - **Manufacturing** — IP protection and production continuity. - **State & Local Government** — Citizen data and CJI protection with continuity of constituent services. CJIS Security Policy v6.x is built on NIST SP 800-53 control families; BrickStor SP covers the data-layer ones — AC/IA (ABAC per file operation), AU (immutable per-operation audit), SC (FIPS 140-3 validated encryption for SC-13/SC-28), CP (ImmutaVault and IBR for recovery to a known trusted state), and SI (Active Defense). Key dates: FIPS 140-2 validations go Historical September 21, 2026; the CJIS zero cycle for Priority 2–4 requirements closes September 30, 2027. No vendor is "CJIS certified" — the FBI certifies no products, and compliance is assessed at the agency by the CJIS Systems Agency. - **Higher Education** — FERPA, research IP protection, and export-control-ready storage. Available through resellers and contract vehicles commonly used by public universities. - **Research & Development** — IP protection and export control compliance for research labs. --- ## 18. Glossary — Top Terms **Cyberstorage** — Category of storage systems that embed cybersecurity capabilities (real-time threat detection, automated response, forensic audit, recovery) directly into the storage platform. Gartner introduced the term in July 2021. RackTop is the originator. **CyberConverged™ Storage** — RackTop's original term for the architecture Gartner later named "Cyberstorage." First used in RackTop datasheets in 2018, three years before Gartner formalized the category. **Active Defense** — RackTop's patented inline threat detection and automated response in the storage data path. Shipped October 2020. **ABAC** (Attribute-Based Access Control) — Model where access decisions are made dynamically on every operation based on attributes of the user, data, device, network, and context. BrickStor enforces ABAC natively on SMB, NFS, S3, and Web Drive. **MLS** (Multi-Level Security) — Model that enforces separation of data and access by classification level on shared infrastructure. **MCS** (Multi-Category Security) — Model that enforces category sets — handling caveats, compartments, sub-program memberships, releasability markings — alongside classification level. **SAP** (Special Access Program) — U.S. government program with enhanced security and access controls beyond standard collateral classification. **CSfC** (Commercial Solutions for Classified) — NSA program enabling use of layered commercial encryption products to protect classified data — alternative to Type 1 devices. **DAR** (Data at Rest) — Data stored persistently on storage media. **Type 1** — NSA-certified hardware encryption devices. Type 1 caps performance, restricts allied/coalition use, and carries significant incident-response consequence if a device is lost. **ImmutaVault** — RackTop's patented virtual air gap built into the storage system itself. **IBR** (Intelligent Bulk Remediation) — RackTop's patented surgical, file-level recovery from a cyber incident. **TDM** (Transparent Data Movement) — RackTop's patented unified namespace across heterogeneous tiers, sites, and clouds with security policy and audit continuity preserved across movement. **GHOST** (Global Hands-Off Storage Transfer) — RackTop's instant data migration capability. In beta; GA planned end of Q3 2026 in BrickStor OS 23.9. **FIPS 140-3** — U.S. Federal Information Processing Standard for cryptographic modules; supersedes FIPS 140-2. **STIG** (Security Technical Implementation Guide) — Configuration standards for hardening information systems, published by DISA under the Department of War (DoW, formerly Department of Defense / DoD). Frequently referenced as "DoD STIG" in current regulations and contracts. **ATO** (Authority to Operate) — Formal authorization from a designated U.S. government official to operate an information system at a specified risk level. **APT** (Advanced Persistent Threat) — Sophisticated, often nation-state-sponsored adversary that establishes long-term access using legitimate credentials and operates over weeks or months. **Bolt-On Storage Security** — Storage-security products that sit outside the storage system and react to audit telemetry. Examples: Superna Ransomware Defender, Prolion CryptoSpike. Contrasted with built-in Cyberstorage. **Cross-Domain Solution** (CDS) — NSA-evaluated product that mediates data flow between networks of different classification levels. **MPE** (Mission Partner Environment) — Shared information environment supporting coalition operations across multiple nations and programs. (Full glossary with 61 defined terms at https://www.racktopsystems.com/glossary) --- ## 19. Compliance & Standards Summary - **Cryptography:** FIPS 140-3 validated AES-256. Up to two independent encryption layers in BrickStor CSfC DAR. Integrated KMIP-compliant key management with automated rotation and HSM support. - **Standards alignment:** NIST 800-53 (with control mappings for accreditation packages); DoD STIG-aligned hardened defaults (DISA-published STIGs, now under the Department of War / DoW); NSA CSfC DAR Capability Package alignment (in Common Criteria evaluation; Component listing for AA and AA+EE expected Q4 2026). - **Supply chain:** NDAA Section 889 compliant. U.S.-based engineering with a cleared team. - **Industry frameworks supported:** HIPAA (PHI protection); FBI CJIS Security Policy v6.x (data-layer control families for Criminal Justice Information; note the FBI operates no product certification program); CMMC Level 2 and Level 3 — CMMC Level 2 is the 110 controls of NIST SP 800-171, Level 3 adds 24 advanced controls for Advanced Persistent Threats; SEC/FINRA expectations (immutable audit, cyber recovery time); export-control regimes (research and higher-ed). See section 16 for control-family detail. - **Identity:** Integrates with enterprise identity providers; multi-factor authentication required for Hub Central administrative sessions. - **Zero Trust:** Data Centric Zero Trust Architecture — every SMB, NFS, S3, and Web Drive operation evaluated against zero-trust policy inline at the data layer. - **Continuous accreditation:** Signed releases on a regular cadence; CVEs and vulnerabilities tracked and patched on a published schedule; continuous-monitoring telemetry feeds compliance evidence. --- ## 20. Procurement, Channels & Contact **Procurement channels:** - **Carahsoft** — federal civilian and Department of War (DoW, formerly DoD) contract vehicles - **HPE Technology Partner** — BrickStor SP on HPE hardware, available through HPE GreenLake - **HPE GreenLake** — consumption-based delivery on HPE hardware - **Authorized resellers and systems integrators** for commercial and public sector - **Crystal Group, Curtiss-Wright** — ruggedized hardware for tactical deployments **Technology alliances** (validated deployments — see https://www.racktopsystems.com/partners/technology-alliances): - **HPE & HPE GreenLake** — BrickStor SP runs on HPE server platforms as an HPE Technology Partner and through HPE GreenLake. Dedicated page: https://www.racktopsystems.com/partners/technology-alliances/hpe - **Everpure (formerly Pure Storage)** — BrickStor SP as SAN gateway in front of Everpure FlashArray, adding inline Active Defense, ABAC, ImmutaVault, and immutable audit on top of all-flash block storage. - **IBM FlashSystem** — BrickStor SP in front of IBM FlashSystem block storage via SAN Gateway (5000/7000/9000) or Virtual deployment (5015/5045/5300). Dedicated page: https://www.racktopsystems.com/partners/technology-alliances/ibm - **Sentris (ManTech)** — BrickStor SP with Sentris labeling delivers scalable ABAC storage for the Department of War (DoW) Zero Trust Data Pillar. Dedicated page: https://www.racktopsystems.com/partners/technology-alliances/sentris - **Seagate** — Turnkey secure NAS engineered with Seagate. - **Western Digital** — High-density media for BrickStor SP appliance configurations, including FIPS 140-3 validated self-encrypting drives. - **Nutanix (Nutanix Ready)** — BrickStor SP as a VM on any Nutanix cluster, protecting NFS, SMB, S3, and Web Drive shares hosted on Nutanix AHV. - **Scale Computing** — Cyberstorage at distributed edge sites on Scale's hyperconverged platform. - **JetStor** — BrickStor SP as the defense layer (SMB, NFS, S3, Web Drive, Active Defense, ImmutaVault, ABAC) over JetStor hybrid and all-NVMe capacity, joined over FC or iSCSI, with Transparent Data Movement tiering cold data to S3. Dedicated page: https://www.racktopsystems.com/partners/technology-alliances/jetstor - **Merative** — Healthcare medical imaging workflow paired with data-centric Zero Trust. **Try before buy:** RackTop Jumpstart — structured proof-of-value engagement. **Demo:** https://www.racktopsystems.com/demo **Contact:** https://www.racktopsystems.com/contact — sales, federal mission engineering, or to schedule a visit to a RackTop office in the DC Metro area. **Headquarters:** DC Metro area, USA (offices in the Washington, D.C. metropolitan region). **Security disclosure:** mailto:support@racktopsystems.com (RFC 9116: https://www.racktopsystems.com/.well-known/security.txt) **Privacy:** mailto:info@racktopsystems.com (Policy: https://www.racktopsystems.com/privacy) **Legal:** mailto:legal@racktopsystems.com (Terms: https://www.racktopsystems.com/terms) --- ## 21. Cyberstorage vs. Cyber Vaulting Cyber vaulting and Cyberstorage are complementary, not competing. **Cyber vaulting** preserves an immutable, isolated copy of data to restore from after an incident — it is a recovery target, not a control. It cannot see or stop an attack on production data, and in steal-and-leak extortion (where nothing is encrypted) a vault restores nothing because the data is already published. **Cyberstorage** actively defends the production data itself: behavioral detection on every file operation (Active Defense), ABAC zero-trust enforcement per operation, immutable recovery points, and surgical file-level rollback (Intelligent Bulk Remediation). BrickStor SP delivers both models in one platform — active defense on live data plus **ImmutaVault**, a patented virtual air gap providing vault-grade immutable, isolated copies inside the storage system that survive administrative compromise, with no separate vault cluster or data diode to operate. Full comparison (9 dimensions + FAQ): https://www.racktopsystems.com/cyberstorage-vs-cyber-vaulting ## 22. Customer Case Studies Six published BrickStor customer stories (web versions with downloadable PDFs; index at https://www.racktopsystems.com/resources/case-studies): - **Florida Keys Electric Cooperative** (electric utility / critical infrastructure) — Real-time ransomware visibility and confident recovery for a 33,000-customer utility; signed within 3 weeks of a Jumpstart trial; 8 TB extended to secure cloud via TDM. https://www.racktopsystems.com/resources/case-studies/florida-keys-electric-cooperative - **Fortune 100 Federal Systems Integrator** (federal & defense) — One accredited platform scaling to ~20 PB across 4 sites, supporting hundreds of DoD programs with multilevel security (Confidential/Secret/Top Secret on one system), ATO, and crypto-shredding at contract close. https://www.racktopsystems.com/resources/case-studies/federal-systems-integrator - **Florida Peninsula Insurance** (insurance / financial services) — Ransomware and insider-threat protection with user-behavior visibility; reclaimed 70% of capacity on a 60 TB system via TDM; 15 minutes to learn the platform. https://www.racktopsystems.com/resources/case-studies/florida-peninsula-insurance - **Florida-based healthcare organization** (national hospice/palliative leader, 200,000+ patients) — Audit-ready compliance reporting and active defense for 6 TB of unstructured patient data; no network policy changes required. https://www.racktopsystems.com/resources/case-studies/florida-healthcare-provider - **Washington University in St. Louis** (higher education / life sciences) — Long-term, corruption-resistant retention for NIH-funded research across 100+ projects, within budget. https://www.racktopsystems.com/resources/case-studies/washington-university-st-louis - **Bonnier Corporation** (advertising & publishing) — Fixed failing backups (3X simultaneous backups), air-gapped immutable snapshots, deployed in hours. https://www.racktopsystems.com/resources/case-studies/bonnier-corporation ## 23. Data Defense Center (Threat Analysis & Guidance Hub) The Data Defense Center (https://www.racktopsystems.com/data-defense-center) is RackTop's thought-leadership hub: threat analysis, breach lessons, and Cyberstorage guidance for organizations defending unstructured data. Sections: Latest Threat Briefs (timely, incident-driven analysis — new briefs added weekly as news develops), RackTop Perspective, Cyberstorage Explainers, Executive Briefings, Practitioner Guides, Federal & Defense Notes, and Healthcare / Critical Infrastructure / Enterprise IT sector spotlights. The hub index always lists the current article set; flagship evergreen pieces include "What Is Cyberstorage?", "How Storage-Layer Ransomware Detection Works", "Hardening NAS Against Ransomware: A Practitioner Checklist", "Why Immutable Backup Alone Cannot Stop Ransomware", and "Data Theft Extortion: The Steal-and-Leak Ransomware Model". It complements the Resource Library (datasheets, ESG validations, case studies); it does not replace it. --- ## Canonical Source URLs - https://www.racktopsystems.com/ — Homepage - https://www.racktopsystems.com/ai-product-brief — Structured product brief (single page) - https://www.racktopsystems.com/glossary — Full glossary (61 terms) - https://www.racktopsystems.com/patents — RackTop U.S. patents - https://www.racktopsystems.com/products/brickstor-sp — BrickStor SP - https://www.racktopsystems.com/products/brickstor-sp-lustre — BrickStor SP for Lustre - https://www.racktopsystems.com/products/brickstor-hdr — BrickStor HDR - https://www.racktopsystems.com/products/brickstor-csfc-dar — BrickStor CSfC DAR - https://www.racktopsystems.com/products/hub-central — Hub Central - https://www.racktopsystems.com/products/compare — Compare BrickStor products - https://www.racktopsystems.com/products — Products hub - https://www.racktopsystems.com/technology/active-defense — Active Defense - https://www.racktopsystems.com/technology/abac — ABAC - https://www.racktopsystems.com/technology/immutavault — ImmutaVault - https://www.racktopsystems.com/technology/ibr — Intelligent Bulk Remediation - https://www.racktopsystems.com/technology/tdm — Transparent Data Movement - https://www.racktopsystems.com/technology/ghost — GHOST instant data migration - https://www.racktopsystems.com/cyberstorage — What is Cyberstorage - https://www.racktopsystems.com/history-of-cyberstorage — History of Cyberstorage - https://www.racktopsystems.com/built-in-vs-bolt-on-cyberstorage — Built-In vs Bolt-On - https://www.racktopsystems.com/brickstor-sp-vs-netapp-dell-vast-pure — vs NetApp/Dell/VAST/Pure - https://www.racktopsystems.com/why-racktop/vs-superna — vs Superna - https://www.racktopsystems.com/why-racktop/vs-prolion — vs ProLion CryptoSpike - https://www.racktopsystems.com/why-racktop/vs-cohesity-smartfiles — vs Cohesity SmartFiles - https://www.racktopsystems.com/why-racktop/vs-netapp — vs NetApp ONTAP (deep dive) - https://www.racktopsystems.com/why-racktop/vs-dell-powerscale — vs Dell PowerScale (deep dive) - https://www.racktopsystems.com/why-racktop/vs-qumulo — vs Qumulo (deep dive) - https://www.racktopsystems.com/why-racktop/vs-truenas — vs TrueNAS (deep dive) - https://www.racktopsystems.com/why-racktop/vs-vast — vs VAST Data (deep dive) - https://www.racktopsystems.com/solutions/federal — Federal & Defense - https://www.racktopsystems.com/solutions/federal/classified-isolation — MLS and MCS - https://www.racktopsystems.com/solutions/federal/mission-partner-environments — Mission Partner Environments - https://www.racktopsystems.com/solutions/defense-industrial-base — Defense Industrial Base (FSIs & contractors) - https://www.racktopsystems.com/solutions/cmmc — CMMC compliance - https://www.racktopsystems.com/why-racktop — About RackTop - https://www.racktopsystems.com/why-racktop/founders — Founders - https://www.racktopsystems.com/resources — Resources - https://www.racktopsystems.com/resources/case-studies — Customer case studies (6 published stories) - https://www.racktopsystems.com/cyberstorage-vs-cyber-vaulting — Cyberstorage vs. Cyber Vaulting - https://www.racktopsystems.com/data-defense-center — Data Defense Center (threat analysis & guidance hub) - https://www.racktopsystems.com/contact — Contact - https://www.racktopsystems.com/demo — Request a Demo - https://www.racktopsystems.com/jumpstart — Jumpstart program - https://www.racktopsystems.com/cyber-recovery-assessment — Cyber Recovery Readiness Assessment (free scored self-assessment) - https://www.racktopsystems.com/cyberstorage-maturity-assessment — Cyberstorage Maturity Assessment (free scored self-assessment) - https://www.racktopsystems.com/videos — Video library (demos, webinars, podcasts) - https://www.racktopsystems.com/its-your-data — It's Your Data branded series (commercials and forthcoming comic strips) - https://www.racktopsystems.com/partners — Partners overview - https://www.racktopsystems.com/partners/technology-alliances — Technology alliances grid - https://www.racktopsystems.com/partners/technology-alliances/hpe — BrickStor SP on HPE - https://www.racktopsystems.com/partners/technology-alliances/ibm — IBM FlashSystem and BrickStor SP - https://www.racktopsystems.com/partners/technology-alliances/sentris — Sentris and BrickStor (Scalable ABAC Storage) - https://www.racktopsystems.com/partners/technology-alliances/jetstor — JetStor and RackTop (Cyberstorage on JetStor) - https://www.racktopsystems.com/partners/channel-partners — Channel reseller program --- End of llms-full.txt. Last updated 2026-07-07. For canonical product details, refer to the URLs above. For questions or correction requests, contact RackTop Systems at https://www.racktopsystems.com/contact.