Skip to content

Tape Security and Storage

Security of tape copies within Cloud4You Tape as a Service is based on a combination of several mechanisms:

  • physical separation of media from active infrastructure,
  • controlled retention,
  • media inventory in Veeam,
  • the ability to encrypt data written to tape,
  • protection of selected tapes against overwrite,
  • periodic restore testing.

A typical model looks like this:

Cloud Repository
      │
      ▼
Backup to Tape
      │
      ▼
Write to physical media
      │
      ▼
Eject / Export
      │
      ▼
Tape offline
      │
      ▼
Storage for the agreed period

Important

Detailed rules for physical storage, media location, and retention period are agreed according to the selected Tape as a Service option.


Why is tape an additional security layer?

Data stored on active backup systems remains online and accessible to Veeam infrastructure.

After writing, a tape can be:

removed from the library

and stored as:

offline

media.

This means that after physical disconnection from the drive, it is no longer continuously accessible to production or backup systems.

Flow:

Production
   │
   ▼
Local backup
   │
   ▼
Cloud4You Cloud Repository
   │
   ▼
Tape
   │
   ▼
OFFLINE

This model provides an additional protection layer against events affecting active infrastructure.


Air gap — what does it mean in practice?

With physical tape, true separation of media from IT infrastructure can be achieved.

After data is written:

Tape Job
   ↓
Eject / Export
   ↓
medium outside the library
   ↓
no active connection to the system

Until the tape is loaded back into a library or drive, the Veeam infrastructure cannot write new data to it.

Note

Simply using tape does not automatically mean the medium is offline. A tape that remains in an active library is still available to the tape infrastructure. Therefore, media handling after job completion is an important part of the service.


Exporting tape after backup completion

Veeam allows automatic export of selected media sets after a job completes.

For GFS, this may include:

Weekly
Monthly
Quarterly
Yearly

Example policy:

Weekly
├── remains in active rotation
└── retention 4 weeks

Monthly
├── export after writing
└── retention 12 months

Quarterly
├── export after writing
└── retention 24 months

Yearly
├── export after writing
└── retention 5 years

This allows short-term tapes to remain in operational use while long-term copies are taken offline.


Media Vault

Veeam Backup & Replication provides:

Media Vault

A Vault is a logical container used to track tapes located outside the library.

Veeam stores information in the Vault about:

  • the medium,
  • its previous library,
  • Media Pool,
  • data stored on tape,
  • retention period.

Flow:

Library
    │
    ▼
Eject / Export
    │
    ▼
Tape Offline
    │
    ▼
Media Vault

Info

Media Vault is a logical mechanism in Veeam. It is not a physical storage facility. It allows the system to reflect the actual location where offline media is stored.


Media inventory

Each tape used by Veeam is identified and registered in the Tape Catalog.

This makes it possible to determine, among other things:

Barcode / Tape ID
Media Pool
Media Set
Status
Retention
Logical location
Contents

When data needs to be restored, this helps identify the correct medium or set of media.

Example:

ERP system
Restore point: 31.03.2026

        ↓

Tape Catalog

        ↓

LTO-000123
LTO-000124

Encrypting data on tape

Veeam Backup & Replication supports encryption of data written to tape.

Two levels are available:

Hardware Encryption

and:

Software Encryption

Veeam can use hardware encryption provided by the tape library or drive, or software encryption performed by Veeam.

Info

If hardware encryption is available and enabled, Veeam gives it priority over software encryption.


Hardware encryption

In this model, encryption is performed by the tape device.

Flow:

Veeam
   │
   │ encryption key
   ▼
Tape Library / Drive
   │
   ▼
encrypted tape

Encryption is handled by the library or drive according to the capabilities of the specific hardware.

Warning

A hardware-encrypted tape may require compatible equipment and the correct encryption mechanism for later reading. This should be considered in the long-term retention plan.


Software encryption

If hardware encryption is not used, Veeam can encrypt data in software.

In this case, the data is encrypted by a Veeam component before being written to the medium.

Flow:

Backup
   │
   ▼
Veeam Tape Server
   │
   ▼
Encryption
   │
   ▼
Tape

Encryption is configured at the:

Media Pool / GFS Media Pool

level using:

Use encryption

Password or KMS

In Veeam Backup & Replication 13, tape encryption can use:

Password

or:

KMS
Key Management Server

A password is used to derive keys that protect the data.

Alternatively, an external KMS can be used to manage encryption keys.

Loss of key

Losing the password or losing access to the required KMS keys may make it impossible to restore data from an encrypted tape.

Encryption-key management must be part of the Disaster Recovery plan, not only part of backup configuration.


Double encryption

A scenario is possible in which the:

source backup

is already encrypted and the:

Media Pool

also uses tape encryption.

In this case, Veeam may store:

double-encrypted data

Flow:

Encrypted Backup
       │
       ▼
Encrypted Tape Media Pool
       │
       ▼
double-encrypted data

Note

Double encryption increases requirements for correct password and key management. Restoring data later may require information for both the original backup encryption and the tape-encryption layer.


Protecting a tape from overwrite

In addition to standard retention, Veeam allows a selected tape to be marked as:

Protected

When enabled, Veeam applies:

Never overwrite

protection to the medium.

Tape protection overrides Media Pool retention settings.

Veeam does not allow a protected tape to be:

  • appended to,
  • erased,
  • marked as free,
  • removed from the catalog.

Info

Protection can be applied to both online and offline tapes if they contain data.


Retention vs Protected

These are two different mechanisms.

Retention

Example:

Monthly:
12 months

After 12 months, the medium may be reused.

Protected

Never overwrite

The tape remains protected regardless of Media Pool retention until an administrator deliberately removes protection.

Flow:

Media Pool:
12 months

Tape:
Protected

        ↓

effective:
Never overwrite

WORM

For environments requiring durable protection against rewriting, compatible:

WORM
Write Once Read Many

media can be used.

Once data is written, such media cannot be reused in the same way as standard rewritable tape.

Veeam supports:

WORM GFS Media Pools

Note

Availability of WORM in Cloud4You Tape as a Service depends on the infrastructure in use and the purchased service scope. A WORM requirement must be declared before archiving starts.


GFS retention

Standard tape-data protection can be implemented using a GFS policy.

Example:

Weekly      → 4 weeks
Monthly     → 12 months
Quarterly   → 24 months
Yearly      → 5 years

While retention is active, data is protected from reuse of the medium according to the policy of the specific Media Set.

More information:

GFS Retention


Offline storage

A medium intended for offline storage should, after the required operations are complete, be:

1. correctly finalized in Veeam
2. exported / removed from the library
3. registered as offline media
4. assigned to the correct location / Vault
5. stored for the required period

Example:

Quarterly Tape
      ↓
Export
      ↓
Offline
      ↓
Vault: ARCHIVE
      ↓
Retention 24 months

Physical media storage

Tapes are physical data media and require appropriate handling.

For long-term storage, take into account:

  • conditions recommended by the media manufacturer,
  • protection against mechanical damage,
  • protection against unauthorized access,
  • media traceability,
  • retention-period control,
  • the ability to locate a specific tape during restore.

Important

Exact physical storage conditions depend on the tape generation and manufacturer. Follow the media manufacturer's requirements instead of assuming one universal temperature or humidity value for all tapes.


Physical location vs Media Vault

For each tape placed into storage, it is worth maintaining consistency between:

physical location
        =
logical location in Veeam

Example:

Physical:
Storage A

Veeam:
Vault: STORAGE-A

This makes it possible to quickly determine where the required medium is located during restore.


Media transport

If tape is moved between locations, the process should ensure:

  • media identification,
  • controlled handover and receipt,
  • preservation of location information,
  • protection against damage,
  • access restricted to authorized personnel.

After a location change, update the logical media inventory in Veeam as well if it is used to represent the physical storage location.


Data removal after retention expires

After the agreed retention period ends, the medium may be:

reused

or handled according to individual arrangements.

For standard tape, Veeam may reuse the medium after the protection period expires.

If the data must not be rewritten or the medium requires durable protection, consider:

Protected

or:

WORM

according to service requirements.


Encryption-key security

For encrypted tapes, data security also depends on availability of the correct keys.

Good practices include:

  • storing the password outside the backup server,
  • controlling access to passwords and KMS,
  • having a key-recovery procedure,
  • documenting responsibility for key management,
  • testing restores from encrypted tapes.

Danger

Possessing the physical tape without being able to decrypt its contents does not constitute a usable backup copy.


Restore testing

Backup security does not end when the tape is written.

Periodically perform:

Tape
  ↓
Restore backup to repository
  ↓
read restore point
  ↓
data test

For important systems, extend the test to:

Tape
  ↓
Repository
  ↓
Entire VM Restore
  ↓
isolated environment
  ↓
application verification

More information:

Restoring Data from Tape


Example security policy

An example model can look like this:

Weekly
├── retention 4 weeks
└── active rotation

Monthly
├── retention 12 months
├── encryption
└── export after writing

Quarterly
├── retention 24 months
├── encryption
├── export after writing
└── offline storage

Yearly
├── retention 5 years
├── encryption
├── export after writing
├── offline storage
└── optionally Protected / WORM

Note

This is an example architecture, not the default configuration of every Cloud4You service. The required protection scope should be defined when ordering Tape as a Service.


Data-protection layers

Tape as a Service can be treated as another layer in a backup strategy:

LAYER 1
Production

     ↓

LAYER 2
Local backup

     ↓

LAYER 3
Cloud4You Cloud Repository

     ↓

LAYER 4
Tape

     ↓

LAYER 5
Tape offline / long-term retention

As a result, failure of one layer does not necessarily mean loss of all copies.


What should be agreed before ordering?

For security-related requirements, define:

[ ] whether tapes should be encrypted
[ ] whether WORM is required
[ ] which media sets should be exported
[ ] how long they should remain offline
[ ] whether Never overwrite protection is required
[ ] how often restore testing will be performed
[ ] the required RTO for tape data

RTO and offline storage

Offline tape provides stronger separation from active infrastructure, but it may also increase restore time.

The process may require:

locating the medium
        ↓
preparing the tape
        ↓
loading it into the library
        ↓
Inventory / Catalog
        ↓
reading the data
        ↓
restore to repository
        ↓
final restore

Therefore, service design should balance:

level of isolation

against:

required RTO

Summary

The most important Tape as a Service security mechanisms are:

Mechanism Purpose
Export / Eject physically disconnect the medium
Offline storage separation from active infrastructure
Media Vault inventory of tapes outside the library
GFS Retention protection against premature overwrite
Tape Encryption data confidentiality
Protected Never overwrite for a specific tape
WORM durable restriction of rewriting
Restore tests verification of actual recoverability

A well-designed policy can combine several mechanisms:

GFS
+
Encryption
+
Export
+
Offline
+
Restore Test

Related guides