Security begins at backup.

We deliver immunity by design.

Gardiel protects backup data before it enters the backup environment – through a hardware-based architecture, controlled data flow, and protection that does not depend on prior threat detection.

Download
Product Information

Problem
Backup does not automatically mean recovery.

Allianz Risk Barometer 2026
Top 5 Global Business Risks

A backup creates confidence – until the day it actually has to work.

Ransomware attacks cause far more than ransom demands. They lead to downtime, restart costs, operational disruption, and loss of trust. Sophos reported average ransomware recovery costs of USD 1.7 million in 2026, excluding ransom payments. At the same time, Cybersecurity Ventures projects global ransomware damages to reach approximately USD 275 billion per year by 2031.

The question is no longer simply whether data has been backed up. The real question is whether that data remains protected, inspectable, and ready for controlled recovery.

PRINCIPLE
Protection – even when the threat is unknown.

Conventional security approaches often begin once a threat can be detected, analyzed, or classified. Gardiel begins earlier – directly in the data path between the corporate network and the backup infrastructure.

Every incoming bitstream passes through the same device-specific, hardware-based protection process. Protection is not added after the content has been assessed. It is created by the way data enters the protected backup environment.

Backup therefore becomes more than a stored copy. It becomes a controlled protection process.

Gardiel does not protect because it knows the threat. It protects because the data path is built differently.

Gardiel does not need to recognize a threat before its protection architecture takes effect.

ARCHITECTURE
Five principles. One protection architecture.

An architecture designed for protected backup states and controlled recovery.

Gardiel does not protect backup data through a single feature. Its protection comes from the interaction of five technical principles. Together, they form a hardware-based architecture that controls the data path, transforms the backup state, and secures the route to recovery.

The five Architectural Principles

01 | Data Diode
During backup operation, data flows in one direction only: from the corporate network into the protected backup environment.

02 | Bit-Level-Obfuscation
The incoming bitstream is transformed at bit level while data is being transferred.

03 | Protected Backup State
After obfuscation, malicious code is no longer present in its original executable form within the protected backup state.

04 | Isolated Maintenance
The backup environment can be analyzed and maintained through a separate, protected administrative network.

05 | Controlled Recovery
For recovery, the data direction is authorized and switched in hardware, while the original bitstream is reconstructed within the Gardiel Gateway.

Integration
Protect your backup. Do not replace it.

Many organizations already rely on established backup systems, proven processes, and clearly defined responsibilities. Gardiel builds on that foundation. It is not intended to replace the existing infrastructure, but to add a dedicated protection architecture to the data path leading into the backup environment.

The Gateway is installed between the corporate network and the backup infrastructure. This allows Gardiel to control the path into the protected backup environment and obfuscate data in hardware as it is written – without requiring the organization to rebuild its entire backup strategy.

The result: existing systems remain in place, backup protection is strengthened at a critical point, and recovery rests on a more controlled foundation.

Gardiel is designed to add a hardware-based protection layer to existing backup environments.

Answers
But what if…?

No “but.”

Gardiel breaks the detection race.
Its primary protection does not depend on recognizing malware in time. Gardiel does not need to know its name or how it works.
Through hardware-based obfuscation, every data stream is transformed into a protected state. In simple terms, the data is technically altered so that it is not directly readable or executable in that state. The data remains available and can later be reconstructed through a controlled process – but malicious code cannot simply run inside the protected backup environment.
As long as the Gardiel hardware and the protected backup data remain physically available, the organization retains a protected foundation for recovery. Again and again.

No “but.”

Every digital attack needs a route in – and a route back out.
Gardiel is a one-way architecture. During backup operation, data can physically travel in one direction only: into the protected backup environment. There is no simultaneously open return path into the corporate network.
Access to the backup therefore does not automatically create a route back into the organization. The hardware architecture prevents software from simply moving out of the protected backup environment.
Without a return path, an attacker does not get far.

Yes.

Within the Gardiel-protected state, malicious code is no longer present in its original executable form. Put simply, only transformed, non-directly-executable components remain.
These components can be analyzed, identified, and selectively removed within an isolated environment – without creating a permanently open route back into the corporate network.

In theory, yes.

But only when you explicitly authorize it.
Critical changes require two physical hardware keys to be present in the Gardiel system at the same time. One person cannot authorize the process alone.
No accidental click.
No unilateral decision.
No unnoticed remote access.
A critical change becomes possible only when two authorized people approve it together.
You remain in control.

No “but.”

The protected copy still exists.
A recovery operation does not automatically delete or overwrite the protected backup state. You can return to a protected version and start again – this time with more information.
You know there is a problem.
You can examine the affected state.
You can narrow down the cause.
And you can remove the malicious component through the protected maintenance process.
You do not start from zero.

No “but.”

Gardiel is based on a one-time programmable hardware setup.
Once the system has been configured and activated, its core configuration cannot be changed later – not remotely, not unnoticed, and not by the manufacturer.
There is no password to steal.
Instead, access is controlled through physical hardware keys that remain under your control. A key can be stored in a highly secure location, or several keys can be distributed across different locations and responsible individuals.
One key. Five keys. Five locations.
You define the access model.
You retain control.

Pure protection. Zero compromise.

No “but.” No “what if.”

As long as the Gardiel hardware and the protected backup data remain physically available, the foundation for recovery remains protected.
No cybersecurity system can prevent a building from burning down, hardware from being physically destroyed, or an entire installation from being stolen.
Against digital attacks, Gardiel relies on an architecture that is powerful precisely because it is simple:
The data path is physically controlled.
Backup operation allows one direction only.
Software cannot execute directly within the protected state.
Critical changes require deliberate authorization.
The core hardware configuration cannot be altered later.
Recovery follows a controlled process.

Its strength lies in the clarity of its architecture.

Then we have bad news for you.

You may encrypt production systems.
You may create pressure.
You may demand a ransom.
But you cannot simply take, reprogram, or silently destroy the protected copy.
And without a compromised backup, you lose the one thing your business model depends on most:
Leverage.

You may need a new business model.

CONTACT
Let’s talk.

Interested in learning more about Gardiel or the current investment opportunity?
Let’s start the conversation.

We deliver
immunity by
design.

Valutis

Valutis Technologies GmbH
Industriestr. 29
82194 Gröbenzell
Germany
info@valutistech.com
www.valutistech.com

 

Legal Notice