Data Convoy
Data Convoy turns S3 archiving into a visible, permissioned workflow. Teams select real objects, preview the work, send it to customer-operated workers, and keep a durable record of the result.
Explore Data ConvoyGlacier Backups builds governed tooling for moving S3 data into cold storage and safely back again. Our first product, Data Convoy, gives research, data, and engineering teams a governed path from active S3 data to cold storage—and back—without handing out standing AWS credentials.
Glacier Backups is a company, not a single feature. Here’s what we ship today, and what’s next.
Data Convoy turns S3 archiving into a visible, permissioned workflow. Teams select real objects, preview the work, send it to customer-operated workers, and keep a durable record of the result.
Explore Data ConvoyEnterprise-grade network-attached storage with built-in backup to AWS S3 and Glacier. Automated scheduling, advanced encryption, and multi-cloud support for organizations needing robust backup infrastructure.
Explore GNASNot another lifecycle-rule dashboard. A control plane for the human decisions around archive and restore.
Every strong claim should have something concrete behind it. These are the mechanisms Data Convoy actually ships.
Encrypted metadata, wrapped team keys, and the key-encryption key live across separate trust domains.
Four team roles and a DB-backed permission matrix separate visibility, safe copies, deletion, retrieval, and bucket control.
Workers compare checksums—or size when needed—before an authorized archive can delete its production source.
Glacier and Deep Archive become managed workflows with dry runs, queues, logs, audit history, cancellation, and retry.
Workers assume your IAM role and perform server-side S3 operations. Data Convoy coordinates selection, authorization, progress, and protected job metadata.
Explore the worker architecture →s3://lab-prod/runs/1842/s3://lab-archive/2026/lab-prodlab-archiveBrowse a production bucket and select keys or prefixes in the language your team already uses.
Dry run to see object counts, bytes, and exclusions without copying, deleting, or rehydrating.
The server maps the exact operation to safe-copy or destructive permissions before it enters the queue.
Inspect progress, checks, failures, audit events, and worker logs stored in your own S3 bucket.
Built by engineers who know that “it’s in Glacier” is not the same thing as “we can get it back.”
No fake customer wall. No borrowed trust. Just the product philosophy behind the work.