Skip to main content
Th1nkDev
All Projects
LiveclientClient projects2025 Groupe ISIS

Hathor DS - Management of disconnected storage appliances

A supervision and management application for cyclically disconnected backup appliances, designed to protect against ransomware.

Project Overview

A ransomware can't encrypt a drive that isn't plugged in.

Every backup strategy eventually collides with the same contradiction: for a backup to be usable, it must be reachable — and anything reachable from the network is reachable by whatever compromises the network. Modern ransomware understands this perfectly. It doesn't attack production first; it attacks the backups, quietly, sometimes for weeks, and only triggers once the last clean restore point is gone. Organizations then discover that they had backups, that those backups ran green every night, and that every one of them is now encrypted.

The countermeasure has been known for decades and is called an air gap: physically disconnect the copy. In practice, almost nobody does it, because doing it properly means someone plugging in and unplugging a disk on a schedule, in a server room, forever — and human discipline is not a security control.

Hathor makes the air gap operational. The platform pilots a fleet of storage appliances installed at customer sites — machines that stay disconnected by design and only come online for the window in which they receive their data, then withdraw. Connection is not a background state; it is a piloted event, ordered from a supervision console, traced, and closed. What used to depend on someone remembering becomes an operation the system executes.

Everything is driven from a single console. Each appliance is identified by its serial number and remote device, attached to a company, reachable through its broker — the relay that carries commands to a machine deliberately kept off the open network. Each appliance carries its own agents, the installers distributed to protected endpoints, each one fingerprinted with a SHA-256 hash so that what gets deployed is provably what was published. The backup layer is supervised through Acronis integration, with per-company credentials held encrypted, so operators watch job health and alerts where they already watch everything else.

The platform was designed for managed service providers as much as for their clients. It is multi-tenant to the core: every appliance, every broker, every credential is scoped to its company, and no operator ever sees a fleet that isn't theirs. Access is governed by granular, resource-level permissions on top of two-factor authentication, and every sensitive action is logged — who connected what, when, and on whose order. Real-time alerting propagates status changes to the console as they happen rather than at the next refresh.

Because a disconnected backup that no one can prove is worth as much as no backup at all, Hathor treats evidence as part of the product: the state of the fleet, the history of connections, the integrity of what was deployed.

The result: the strongest protection in the field — physical isolation — finally usable at fleet scale, without asking anyone to be perfectly disciplined at 2 a.m.

Project Details
Year2025
Categoryclient
Project typeClient projects
Client Groupe ISIS
StatusLive
Stack14 technologies
Project Narrative
01

The Problem

01 / 03

Backups have become the primary target rather than the last resort.

Ransomware now spends weeks locating and neutralizing recovery points before triggering, so an organization discovers the failure at the exact moment it needs the recovery.

The one defense that categorically works — physically disconnecting the copy — is almost never applied, because it depends on a person performing a manual gesture, on schedule, indefinitely. Under that constraint, the air gap remains a best practice everyone cites and nobody operates.

02

Our Solution

02 / 03

Hathor turns physical isolation into a piloted operation.

A fleet of storage appliances stays disconnected by design and connects only for its data window, on command from a central console, through a broker that reaches machines deliberately kept off the open network.

Around that core, the platform delivers what makes such a fleet actually operable: multi-tenant isolation per company, granular permissions over two-factor authentication, agents distributed with SHA-256 integrity fingerprints, backup supervision through Acronis with encrypted per-company credentials, real-time status propagation, and an action log covering every sensitive operation.

03

Impact

03 / 03

What the platform changes, in the field:

· The air gap stops depending on a person. Disconnection becomes a system state, not a nightly discipline.

· One console for an entire fleet. A provider supervises every client's appliances, brokers and agents from one place, with strict per-company partitioning.

· What was deployed can be proven. Every agent carries a SHA-256 fingerprint; every sensitive action carries an author, a timestamp and a trace.

· Incidents surface as they happen, propagated in real time rather than discovered at the next check.

Tech Stack

Technologies we used

14 technologies carefully chosen for this project.

Vue 3 TypeScript Node.js API REST Supervision Webhooks Cybersécurité laravel php Docker Acronis Appliance Stockage Deconnecte Securite

Our Process

How we built it,
step by step.

Every project at Th1nkDev follows the same structured methodology — from discovery to launch and beyond, with full transparency at every step.

Explore our services
01

Discover

Deep-dive into your context, goals and constraints.

02

Design

Architecture, UX flows, prototypes — before code.

03

Build

Clean, tested, documented production code.

04

Launch

Zero-surprise go-live and ongoing support.

Ready to get started?

Your next digital product
Start here.

Let's talk about your project. No commitment required — just an honest conversation about what's possible.