---
title: Compliant Archiving
date: 2026-05-19T16:11:00+02:00
author: Hannes Heckel
canonical_url: "https://www.fast-lta.de//en/solutions/compliant-archiving"
section: Topic Pages
---
Silent Cubes • Long-term archiving • Secondary Storage • Made in Europe

# Compliant archiving that regulators can verify, not just trust.

Silent Cubes write data once. Hardware WORM makes it immutable: no administrator, no attacker, no software update can alter or delete archived records. That is a physical property of the system, not a policy you hope nobody resets.

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/worm)

 

[Book an appointment ](https://www.fast-lta.de//en/fast/contact/archiving "Book an appointment")

![A bright isometric archive hall 202605261023 | FAST LTA](https://fast-lta.transforms.svdcdn.com/production/images/A_bright_isometric_archive_hall_202605261023.jpeg?w=960&q=80&auto=format%2Cavif&fit=crop&dm=1779796691&s=2520fdf6454410170426739f169bfca4)

---

Made in EuropeZero Loss by DesignThousands of installationsKPMG-certified complianceGDPR-compliant

satisfied customers

25 yearsRetention for clinical trial master files under EU Regulation 536/2014

17+ yearsSilent Cubes for secure archiving

---

The Problem

## Why archives fail when regulators look closely 

What compliance and IT teams across Europe actually face:

 

**Software WORM is a setting, not a guarantee.** Object Lock, retention policies and immutability flags are configuration. An administrator with sufficient rights can reset them. When a regulator or court asks whether records \*could\* have been altered, "our policy forbids it" is a weak answer. "The hardware makes it impossible" is a strong one.

### Immutable Storage

Immutable storage refers to storage technologies that protect stored data from subsequent alteration or deletion — where the decisive difference lies in whether this protection is enforced at the hardware level (cannot be circumvented) or at the software level (can be circumvented by administrators with sufficient rights).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/immutable-storage)

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/worm)

  

**The burden of proof sits with you.** MiFID II requires records kept so that they cannot be altered or deleted. French, Italian and Swiss archiving rules all demand integrity that can be demonstrated, not asserted. An archive without tamper-proof storage and a complete audit trail leaves you arguing instead of proving.

### Immutable Storage

Immutable storage refers to storage technologies that protect stored data from subsequent alteration or deletion — where the decisive difference lies in whether this protection is enforced at the hardware level (cannot be circumvented) or at the software level (can be circumvented by administrators with sufficient rights).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/immutable-storage)

  

**Cloud archives create decade-long dependencies.** A compliant archive must outlive price changes, service discontinuations and shifting jurisdictions. For retention periods of 10, 25 or 30 years, US CLOUD Act and FISA 702 exposure is not a theoretical concern for European data. What you archive today must still be yours, intact and readable, in 2050.

### US CLOUD Act

The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) authorizes US authorities to require US companies to hand over data — regardless of where that data is physically stored, including servers located in the EU.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/us-cloud-act)

### US CLOUD Act

The US CLOUD Act (Clarifying Lawful Overseas Use of Data Act, 2018) authorizes US authorities to require US companies to hand over data — regardless of where that data is physically stored, including servers located in the EU.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/us-cloud-act)

  

**File servers (or backups) are not archives.** A file share with access controls is not compliant archiving: administrators can change files, integrity is not verified, and nothing stops silent corruption over the years. Immutability has to be enforced below the operating system.

### Immutable Storage

Immutable storage refers to storage technologies that protect stored data from subsequent alteration or deletion — where the decisive difference lies in whether this protection is enforced at the hardware level (cannot be circumvented) or at the software level (can be circumvented by administrators with sufficient rights).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/immutable-storage)

  

The solution

## Silent Cubes: Hardware WORM as a ready-to-use appliance 

Silent Cubes are a WORM archiving system that makes data immutable at the hardware level. Immutability is a physical property of the storage, not a configuration that can be disabled. The system has been in production for over 17 years, with every installation still able to read its first byte.

### Immutable Storage

Immutable storage refers to storage technologies that protect stored data from subsequent alteration or deletion — where the decisive difference lies in whether this protection is enforced at the hardware level (cannot be circumvented) or at the software level (can be circumvented by administrators with sufficient rights).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/immutable-storage)

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/worm)

 

[Find out more ](https://www.fast-lta.de//en/products/silent-cubes "Find out more")

#### **Hardware WORM at firmware level**

No root access, no stolen credentials, no software update can modify or delete archived data. The write operation seals the data. There is nothing to switch off.

  

#### **Self-healing data integrity**

Automatic integrity checks run continuously in the background. Damaged blocks are repaired from redundant copies without manual intervention. You can prove integrity at any point, for any year.

  

#### **Complete appliance**

No integration project, no separate hardware underneath, no second vendor in the support chain. Connect via NFS or SMB and start archiving.

  

#### Energy-efficient for decades

Sleep mode keeps long-term operating costs low. Designed for retention periods of 10, 25, 30 years without media migration or data loss.

  

#### Retention management built in

Define retention per archive. After expiry, data can be selectively released and deleted. Legal retention and GDPR erasure obligations work in one system instead of against each other.

### GDPR

The GDPR (General Data Protection Regulation, EU 2016/679) is the European regulation for the protection of personal data — particularly relevant for IT infrastructure in Art. 5 (principles), Art. 17 (right to erasure), Art. 28 (processors) and Art. 32 (security of processing).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/gdpr)

  

#### **Certified under Europe's strictest regime**

Silent Cubes are KPMG-certified for audit-proof archiving under German law (GoBD), widely regarded as the most demanding compliance archiving standard in Europe. Wherever you operate, that certification is evidence of how seriously the system takes immutability.

### Audit-Proof Archiving

Audit-proof archiving describes the legally required property of an archiving system that preserves documents completely, immutably, traceably and accessibly at all times — and that this can be demonstrated without gaps to tax authorities, auditors and data protection supervisory bodies.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/audit-proof-archiving)

### GoBD

The GoBD (Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form as well as Data Access) is a German Federal Ministry of Finance letter that specifies how tax-relevant documents must be archived electronically in Germany — particularly regarding immutability, completeness and auditability.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/gobd)

  

How it works

### Compliant archiving in four steps 

From capture to regulator access. Fully on-premises, no cloud in the operating path.

 

### Capture and indexing

Your DMS, ECM or business application indexes, classifies and converts documents (for example to PDF/A). Metadata stays with the record. 

### WORM sealing

Records are written to Silent Cubes and sealed by hardware WORM in the same operation. Every write is atomic. There is no window in which data is modifiable. 

### Long-term operation

Silent Cubes switch to energy-efficient sleep mode. Integrity checks run automatically; damaged blocks are repaired from redundant copies. No media migration, no tape handling, no operator routine. 

### Audit and regulator access

Every access and export is logged in a tamper-proof audit trail. When a regulator, auditor or court requests records, you deliver them with proof that they have not changed since the day they were written. 

Regulations

## Compliance: What Silent Cubes covers across Europe

There is no single EU archiving law. There is a dense net of EU regulations and national standards that all demand the same thing: records that demonstrably cannot be changed.\*

 

 0"&gt;RegulationRequirementsSilent CubesMiFID II (Art. 16(7)) + Del. Reg. (EU) 2017/565Trading and communication records kept so they cannot be altered or deleted; 5 years, up to 7 on request✓ Hardware-WORMGDPR Art. 5(1)(f), Art. 32Integrity; technical measures against unauthorised modification✓ Hardware WORMGDPR Art. 17Erasure once retention ends✓ Retention-based release and deletioneIDAS 2 (Reg. (EU) 2024/1183)Electronic archiving preserved against loss and alteration, with presumption of integrity✓ Immutable storage layer for archiving servicesDORA (Reg. (EU) 2022/2554)Backup and restoration with data integrity, for financial entities✓ Immutable secondary storageNIS2 (Art. 21)Business continuity incl. backup management for essential and important entities✓EU Clinical Trials Reg. 536/2014 (Art. 58)Trial master file complete and legible for 25 years✓ Designed for decadesNational standards: NF Z42-013 / ISO 14641 (FR), AgID Guidelines / CAD Art. 44 (IT), GeBüV (CH)Integrity, immutability or verifiable tamper-evidence of archived records✓ Hardware WORM exceeds tamper-evidence requirements

Silent Cubes provides the storage layer: immutability, integrity verification and audit trails. Full compliance with each framework also involves processes and documentation on your side; under eIDAS 2, "qualified electronic archiving" is a designation for trust service providers, for whom Silent Cubes serves as the immutable storage foundation. Our compliance overview maps each requirement to the system capability. FAST LTA engineers support the assessment.

Use Cases

## Who archives on Silent Cubes? 

Wherever immutability is required by law, or has to be proven in court.

 

[Healthcare

Medical imaging and patient records carry retention periods of 10 to 30 years across Europe, set by national law. PACS, RIS and hospital information systems connect directly via DICOM and NFS/SMB.

[Find out more ](https://www.fast-lta.de//en/verticals/healthcare "Find out more")](https://www.fast-lta.de//en/verticals/healthcare "Find out more")

[Finance

MiFID II requires trading and communication records on storage that prevents alteration or deletion, for 5 to 7 years. DORA adds integrity-protected backup obligations. Both without a US provider in the operating path.

[Find out more ](https://www.fast-lta.de//en/verticals/financial-services "Find out more")](https://www.fast-lta.de//en/verticals/financial-services "Find out more")

[Public sector

National records laws, NIS2 obligations and decades of administrative files. On-premises archiving keeps sensitive records under your jurisdiction, with no foreign provider in the chain.

[Find out more ](https://www.fast-lta.de//en/verticals/public-sector "Find out more")](https://www.fast-lta.de//en/verticals/public-sector "Find out more")

[Life sciences and research

Clinical trial master files must remain complete and legible for 25 years under EU Regulation 536/2014. Silent Cubes archives them on storage designed for exactly these timescales.

[Find out more ](https://www.fast-lta.de//en/verticals/research-education "Find out more")](https://www.fast-lta.de//en/verticals/research-education "Find out more")

[DMS/ECM integration

Compatible with d.velop, ELO, DocuWare, OpenText and all NFS/SMB-enabled systems. In most cases, no proprietary plug-in is required.

[Technology partners ](https://dev.fast-lta.de/en/partner?t=technology&a=compliant#partner-grid "Technology partners")](https://dev.fast-lta.de/en/partner?t=technology&a=compliant#partner-grid "Technology partners")

[Key technical specifications

**WORM:** Hardware, firmware level  
**Protocols:** NFS, SMB  
**Capacity:** TB to PB, scalable without downtime  
**Integrity:** Self-healing, continuous verification  
**Maintenance:** Support contracts up to 10 years  
**Origin:** Munich, Germany

[Find out more about Silent Cubes ](https://www.fast-lta.de//en/products/silent-cubes "Find out more about Silent Cubes")](https://www.fast-lta.de//en/products/silent-cubes "Find out more about Silent Cubes")

## Frquently asked questions

#### Is hardware WORM really impossible to bypass?

Yes. Hardware WORM at firmware level is not a configurable setting; it is a physical property of the storage. No root access, no stolen credentials, no software update can modify written data. In front of a regulator, that is a categorically different argument from software WORM: the system *cannot* alter data, not merely "is not permitted to".

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/worm)

### WORM

WORM (Write Once, Read Many) refers to a storage principle in which data is written once and can technically no longer be altered or deleted — in hardware WORM, this immutability is a physical property of the storage controller, independent of software, operating system or user privileges.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/worm)

 

#### Can I delete data to comply with GDPR despite WORM?

Yes. Silent Cubes supports retention-based management: once the defined retention period expires, data can be selectively released and deleted. Legal retention duties and the GDPR right to erasure are handled in one system.

### GDPR

The GDPR (General Data Protection Regulation, EU 2016/679) is the European regulation for the protection of personal data — particularly relevant for IT infrastructure in Art. 5 (principles), Art. 17 (right to erasure), Art. 28 (processors) and Art. 32 (security of processing).

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/gdpr)

 

#### We are not in Germany. Why does a German GoBD certification matter to us?

GoBD is among the strictest archiving compliance regimes in Europe, and Silent Cubes is KPMG-certified against it. The certification does not replace your local requirements, but a system proven under the hardest rules gives you a strong starting position under MiFID II, NF Z42-013, AgID guidelines or GeBüV, which all demand the same core property: demonstrable immutability.

### GoBD

The GoBD (Principles for the Proper Management and Storage of Books, Records and Documents in Electronic Form as well as Data Access) is a German Federal Ministry of Finance letter that specifies how tax-relevant documents must be archived electronically in Germany — particularly regarding immutability, completeness and auditability.

[Mehr erfahren →](https://www.fast-lta.de//en/glossary/gobd)

  

[Zur Themenseite ](https://www.fast-lta.de//de/blog/revisionssicherheit "Zur Themenseite")

#### Does Silent Cubes make us eIDAS-compliant?

eIDAS 2 defines "qualified electronic archiving" as a trust service provided by qualified providers. No storage product alone makes you compliant. Silent Cubes delivers what those services and any serious archiving setup require underneath: storage that preserves data against loss and alteration, with verifiable integrity.

 

#### Which DMS and ECM systems are compatible?

Every system that writes to a standard NFS or SMB share: d.velop, ELO, DocuWare, SER Doxis, windream, OpenText and others. No proprietary plugin required in most cases.

 

#### How does migration from an existing archive work?

Without interrupting operations. The existing archive keeps running while new records go to Silent Cubes; legacy data is migrated in stages. FAST LTA supports the migration planning.

 

Next step

## Compliant archiving is not an IT project you finish. t is an obligation you carry for decades.

To regulators, to auditors, and in court. Silent Cubes gives you the storage layer that holds: immutable by hardware, verified continuously, independent of any cloud provider. Talk to our engineers about your retention requirements.

 

[Request a demo ](https://www.fast-lta.de//en/fast/contact/archiving "Request a demo")

»It is becoming increasingly important whether a manufacturer is based in Europe. These days, anything coming from the US needs to be viewed with a critical eye, whether because of the costs or data protection concerns.«

![Michael Guenther Werra Meissner FAST LTA | FAST LTA](https://fast-lta.transforms.svdcdn.com/production/images/customer/Michael-Guenther-Werra-Meissner-FAST-LTA_2026-05-13-052953_vmut.JPG?w=960&q=80&auto=format%2Cavif&fit=crop&dm=1778650194&s=552bc1994b5e4b22d8b99e3f83d14b43)Michael Günther  
Head of IT at GHWM
