Automate immutable PowerProtect DD copies from any backup application.
Your backup application writes its backups as usual. NASLORD creates the protected copies, applies the DD Retention Lock retention period and manages their lifecycle — without depending on the application’s own immutability capabilities.
Five steps, fully automated
Protection schedules
Define, per MTree, the frequency of protected copies and the retention period to apply. NASLORD executes, logs and notifies — every night, without intervention.
Real immutability
Retention is enforced by DD Retention Lock, at the platform level. Neither ransomware, nor a compromised administrator, nor the backup application itself can delete a locked copy before it expires.
Controlled restore
In an incident, authorized users browse the protected-copy inventory, identify the desired restore point and make it available to the backup application.
Governance, compliance and compatibility: what to distinguish
| Aspect | Governance mode | Compliance mode |
|---|---|---|
| Purpose | Operational protection against accidental or malicious deletion | Strict regulatory requirements (legal archiving) |
| Revocability | A DD security officer can intervene through an exceptional procedure | No revocation possible before expiry, by anyone |
| NASLORD support | Yes — primary operating mode | Depends on the DD appliance configuration — validated during the evaluation |
Backup application compatibility. NASLORD operates at the PowerProtect DD MTree level: it is independent of the software writing the backups. Validated combinations (application, write protocol, DD OS version) are documented in the compatibility matrix — we confirm your exact configuration during the discovery call rather than promising universal compatibility.
The protected-copy inventory, at a glance
| Protected copy | Source | Created | Retained until | Size | Status |
|---|---|---|---|---|---|
| fc-backup-20260803-0215 | /data/col1/backup/full | 2026-08-03 02:15 | 2026-09-02 | 14.2 TiB | Locked |
| fc-backup-20260802-0215 | /data/col1/backup/incr | 2026-08-02 02:15 | 2026-09-01 | 1.8 TiB | Locked |
| fc-backup-20260801-0215 | /data/col1/backup/incr | 2026-08-01 02:15 | 2026-08-31 | 2.1 TiB | Locked |
| fc-backup-20260731-0215 | /data/col1/backup/incr | 2026-07-31 02:15 | 2026-08-30 | 1.6 TiB | Locked |
| fc-backup-20260705-0215 | /data/col1/backup/full | 2026-07-05 02:15 | 2026-08-04 | 13.8 TiB | Expires tomorrow |
| fc-backup-20260628-0215 | /data/col1/backup/incr | 2026-06-28 02:15 | 2026-07-28 | 1.7 TiB | Expired · purged |
Designed for a sensitive backup perimeter
The Retention Lock module touches your last line of defence. Its access controls match.
-
Privileges per appliance and per MTreeEach user sees and operates only the scopes assigned to them.
-
Authorized IP addressesModule access can be restricted to a list of approved management addresses.
-
Two-factor authenticationTOTP available for all accounts, recommended for this module.
-
Complete loggingCreations, expiries and restores are recorded and exportable.
Why not rely on the backup application?
Some applications offer their own immutability — others don’t, or only in premium editions. And when ransomware compromises the backup server itself, application-driven protection falls with it.
NASLORD enforces retention at the DD platform level, outside the application’s path. The protected copy exists even if the backup server is encrypted, rebuilt or replaced — and the strategy stays the same if you ever change backup applications.
See NASLORD using your own Dell environment.
Connect a test DD appliance, protect an MTree and verify the immutability yourself — for 90 days, at no cost.