Gallium inc. EN FR
NASLORD
NASLORD · Retention Lock module

Automate immutable PowerProtect DD copies from any backup application.

Your backup application writes its backups as usual. NASLORD creates the protected copies, applies the DD Retention Lock retention period and manages their lifecycle — without depending on the application’s own immutability capabilities.

The protection workflow

Five steps, fully automated

Retention Lock protection timeline Five-step timeline: the backup application writes its normal backup to PowerProtect DD; NASLORD initiates the protected copy; PowerProtect DD applies the retention period and the copy becomes immutable; on expiry, copies are managed automatically; at any time, authorized users can identify and select recoverable copies. 1 Normal backup The application writes to the DD MTree 2 Protected copy NASLORD initiates the copy (fastcopy) on the defined schedule 3 Retention applied DD locks the copy — immutable IMMUTABILITY WINDOW 4 Managed expiry Expired copies are purged automatically 5 Controlled restore Authorized users identify and select copies Backup-application independent — no application-side immutability feature required

Protection schedules

Define, per MTree, the frequency of protected copies and the retention period to apply. NASLORD executes, logs and notifies — every night, without intervention.

Real immutability

Retention is enforced by DD Retention Lock, at the platform level. Neither ransomware, nor a compromised administrator, nor the backup application itself can delete a locked copy before it expires.

Controlled restore

In an incident, authorized users browse the protected-copy inventory, identify the desired restore point and make it available to the backup application.

Technical precision

Governance, compliance and compatibility: what to distinguish

DD Retention Lock modes and how NASLORD handles them.
Aspect Governance mode Compliance mode
Purpose Operational protection against accidental or malicious deletion Strict regulatory requirements (legal archiving)
Revocability A DD security officer can intervene through an exceptional procedure No revocation possible before expiry, by anyone
NASLORD support Yes — primary operating mode Depends on the DD appliance configuration — validated during the evaluation

Backup application compatibility. NASLORD operates at the PowerProtect DD MTree level: it is independent of the software writing the backups. Validated combinations (application, write protocol, DD OS version) are documented in the compatibility matrix — we confirm your exact configuration during the discovery call rather than promising universal compatibility.

The interface

The protected-copy inventory, at a glance

Retention Lock Manager — Protected copies DD-MTL-01 · /data/col1/backup
Protected copies Primary data Appliances Authorized IPs Logs
Locked copies
1,284
3 protected MTrees
Retention applied
30 days
Governance mode
Expiring within 7 days
96
Automatic cleanup
Last run
02:15
Completed without errors
Protected-copy inventory with creation and expiry dates
Protected copySourceCreatedRetained untilSizeStatus
fc-backup-20260803-0215/data/col1/backup/full2026-08-03 02:152026-09-0214.2 TiBLocked
fc-backup-20260802-0215/data/col1/backup/incr2026-08-02 02:152026-09-011.8 TiBLocked
fc-backup-20260801-0215/data/col1/backup/incr2026-08-01 02:152026-08-312.1 TiBLocked
fc-backup-20260731-0215/data/col1/backup/incr2026-07-31 02:152026-08-301.6 TiBLocked
fc-backup-20260705-0215/data/col1/backup/full2026-07-05 02:152026-08-0413.8 TiBExpires tomorrow
fc-backup-20260628-0215/data/col1/backup/incr2026-06-28 02:152026-07-281.7 TiBExpired · purged
1Every copy carries its retention expiry date — verifiable at any time.
2Expired copies are purged automatically, without intervention.
3Restore is done by selection in this inventory, by authorized roles.
NASLORD inventory of immutable PowerProtect DD copies, with each copy’s source, retention expiry date and lifecycle state.
Controls

Designed for a sensitive backup perimeter

The Retention Lock module touches your last line of defence. Its access controls match.

  • Privileges per appliance and per MTreeEach user sees and operates only the scopes assigned to them.
  • Authorized IP addressesModule access can be restricted to a list of approved management addresses.
  • Two-factor authenticationTOTP available for all accounts, recommended for this module.
  • Complete loggingCreations, expiries and restores are recorded and exportable.

Why not rely on the backup application?

Some applications offer their own immutability — others don’t, or only in premium editions. And when ransomware compromises the backup server itself, application-driven protection falls with it.

NASLORD enforces retention at the DD platform level, outside the application’s path. The protected copy exists even if the backup server is encrypted, rebuilt or replaced — and the strategy stays the same if you ever change backup applications.

See NASLORD using your own Dell environment.

Connect a test DD appliance, protect an MTree and verify the immutability yourself — for 90 days, at no cost.

Book a Demo 90-Day Trial