AI DEFENCEBY ALTARI SYSTEMS
Menu

AI Defence / Remedy architecture

Plan the return to a known, usable state.

Security recovery restores required services and data while checking that the conditions behind an incident have been addressed. Remedy’s architecture connects recovery evidence to the decision about whether normal authority can be restored.

Planned architecture · This page explains the intended design. Current capabilities and release limits are documented in the product status guide.

Recovery is more than reconnecting a device

A device that can reach the network again may still contain the original weakness, altered configuration or unwanted software. A restored file may be outdated or inconsistent with related records. Successful connectivity and successful data copying answer only part of the recovery question.

The intended workflow records the incident condition, what was changed or rebuilt, which data was restored and which checks support return to service. Business health and security health both matter. A service that is secure but unusable has not met its operational recovery goal.

Protect the recovery path in advance

Backups need separation from the authority that could damage production. Depending on the environment, protected, immutable or off-domain copies can reduce the risk that a compromised account also destroys the recovery source. Administrative access to backup systems belongs behind its own controls.

A backup job reporting success does not establish that a restore will work. Teams need evidence of usable copies, required keys, documented dependencies, appropriate access and an exercised restoration procedure. Recovery objectives should be agreed from business needs and measured practice rather than invented on a marketing page.

Choose the appropriate restoration method

An endpoint rebuild establishes a fresh installation with reviewed configuration and trusted application sources. Authoritative storage restoration brings back the required data version. Database recovery also needs consistency, transaction handling and application-level validation. These are different operations with different permissions and risks.

A rollback description in a finding is not equivalent to an executable rollback, a reliable backup or a complete recovery service. The existing AI Defence development evidence includes rollback-related structures; a complete restore or decryption capability has not been established.

ActivityEvidence needed before return
Endpoint rebuildTrusted source, current posture, required applications and identity
Storage restorationUsable copy, intended version, permissions and application checks
Database recoveryConsistency, required records and workload-level verification
Network readmissionResolved restriction reason, current attestation and access policy

Approval belongs to the actual impact

Rebuilding a machine, replacing data, rotating credentials or changing a production policy may be irreversible or disruptive. The tenant’s policy should define the authorised scope and require an accountable approval where appropriate.

A bounded plan records the target, expected result, dependencies, preservation needs and what happens if verification fails. Recovery should retain relevant incident evidence before destructive work when operationally appropriate. The goal is a reviewable decision rather than a blanket instruction to repair everything.

Verify, then recertify the relevant state

After restoration, check the original security condition and the health of necessary services. A different observer or approved independent validation path can strengthen the evidence where available. Missing or contradictory observations must not disappear behind a closed status.

Continuous Integrity is intended to create a fresh certification for the resulting measured state. Network Trust can then use that evidence when deciding readmission. This is a scoped conclusion: the checked condition and time are known, while unexamined conditions remain outside the claim.

Current implementation and customer responsibilities

Protected recovery orchestration, rebuilding, restoration and integrated recertification remain planned architecture. Existing backup systems, recovery procedures and security operations should remain in place during evaluation.

Before any operational trial, confirm who operates backups, where copies and keys reside, which actions the candidate build supports and how restores are tested. Altari can discuss the intended workflow and available components; this page does not establish a production recovery service or fixed recovery commitments.

Questions answered

Is rollback the same as recovery?

No. Reversing a configuration change, restoring a service and recovering customer data from backup are separate capabilities. Each needs its own tested procedure.

What does recertification mean?

In the planned model, the restored device or object receives a new scoped trust decision based on its measured state, current policy and verification evidence.

Talk directly to Altari

Bring the environment.
Start with the right questions.

Discuss a demonstration, current capabilities and a bounded evaluation with Altari Systems.

Request a demonstration