Backup for AI Workloads
AI runs on more than GPUs. Training data spans Cinder, Ceph, and Swift; checkpoints and model artifacts live across the stack; inference moves to containers. Storware protects the whole thing — GPU Nova instances, training datasets, and the OpenShift layer — under one policy-driven, EU-based platform.
Key Highlights
Protect the whole AI data estate
GPU Nova instances, training datasets across Cinder, Ceph RBD, and Swift, checkpoints, and model artifacts — not just the VM disk.
One platform across training and inference
OpenStack VMs for training and OpenShift/Kubernetes persistent volumes for inference, protected together — no coverage gap at the boundary between them.
Immutable, auditable, compliance-ready
WORM immutability (Object Lock, Retention Lock), audit logging, and configurable retention support EU AI Act and DORA evidence requirements.
EU-based, sovereign by design
Warsaw headquarters and EU control plane — protect private-AI infrastructure without the US-jurisdiction exposure that comes with most public cloud.
What powers AI-workload protection
Agentless protection for GPU Nova instances
Protect GPU-attached OpenStack instances through the infrastructure APIs — no in-guest agents to deploy or maintain across training nodes.
Coverage across Cinder, Ceph RBD, and Swift
Storage-agnostic protection reaches the block and object storage where training data actually lives. Native Ceph RBD integration with CBT and Snap Diff transfers only changed blocks.
Block-level incremental backups with CBT
Change block tracking keeps large, fast-growing datasets protected without re-reading terabytes each cycle. Multithreaded reads raise throughput for OpenStack and OpenShift Virtualization workloads.
Checkpoint and model-artifact protection
Short-cycle backup of checkpoint storage for long-running training jobs, plus object-storage mirroring for final model artifacts and WORM-immutable copies of production model versions.
Container and persistent-volume protection
Protect the OpenShift/Kubernetes inference layer — including the persistent volumes stateful AI services depend on — with the same platform that protects the training VMs.
WORM immutability and audit logging
Object Lock and Retention Lock make backup copies tamper-evident; audit logging and configurable retention turn backups into defensible compliance evidence, not just recovery points.
Ransomware-resistant backup layer
IsoLayer air-gap, AES encryption, and Keycloak MFA protect the backups themselves — the target attackers reach for when the training data is the crown jewel.
Flexible destinations, including EU cloud
Local storage, S3-compatible object storage, Swift, tape, and Storware Cloud tiers (N-able, Vawlt, Seagate Lyve Cloud) — with policy-driven placement across at rest, in transit, and at scale.
Technology partners
Frequently Asked Questions
What does "backup for AI workloads" actually protect?
The infrastructure and data your AI runs on: GPU-attached OpenStack (Nova) instances, training datasets spread across Cinder, Ceph RBD, and Swift, training checkpoints, model artifacts, and the persistent volumes behind containerized inference. It’s enterprise data protection applied correctly to the AI stack — not a separate ML-specific tool.
Why isn't standard VM backup enough for AI?
Because the value isn’t on the VM disk. Training data spans block and object storage at once, GPU instances need handling snapshot-only methods miss, long jobs depend on checkpoints, and regulators increasingly expect immutable, auditable records. A VM-disk-only backup leaves most of that unprotected.
Do you protect GPU instances and long-running training jobs?
Yes. GPU-attached Nova instances are protected agentlessly through the OpenStack APIs, with block-level incremental backups. For long jobs, the architecture pattern is short-cycle backup of checkpoint storage plus object-storage mirroring of model artifacts, so a failure doesn’t cost days of compute.
Can you protect both the OpenStack training layer and the OpenShift/Kubernetes inference layer?
Yes — one platform covers both. Training VMs on OpenStack and the persistent volumes behind OpenShift/Kubernetes inference are protected under the same policies, with no coverage gap at the boundary. (Note: OpenShift Containers and OpenShift Virtualization are handled as distinct scopes.)
How does this help with EU AI Act and DORA compliance?
Backup becomes a compliance artifact: WORM immutability, audit logging, and configurable retention give you tamper-evident, auditable records of what data trained a model and when. The EU AI Act’s transparency, GPAI, and penalty provisions apply from August 2, 2026, while the high-risk (Annex III) obligations were deferred to December 2, 2027 under the Digital Omnibus — so the requirement direction is set even though the heaviest deadline moved
Is Storware agentless for AI workloads?
For OpenStack VMs and GPU Nova instances, protection is agentless through the infrastructure APIs. Some file- and object-level paths use the OS Agent where that’s the correct mechanism — the platform applies agentless protection by default and agent-based handling only where the architecture requires it.
Where is backup data stored, and is it EU-sovereign?
You choose the destination — local, S3-compatible object storage, Swift, tape, or Storware Cloud tiers. For EU and regulated organizations, Storware’s EU-based control plane and EU cloud options keep private-AI data protection outside US extraterritorial jurisdiction.
Do I need a separate product for AI versus the rest of my estate?
No. The same universal license and platform that protects your AI infrastructure also protects VMware, OpenStack, Proxmox, Nutanix, Hyper-V, containers, and databases — 15+ platforms, one tool, one license.
WHY AI WORKLOADS BREAK STANDARD BACKUP
Data is scattered, not on the VM disk.
A training environment's value spans Cinder block volumes, Ceph RBD, and Swift object storage at once. Back up only the instance disk and you miss most of the dataset.
GPU instances aren't ordinary VMs.
GPU-attached Nova instances need handling that snapshot-only approaches don't cover correctly. The compute is expensive; the protection has to match it.
Long training jobs need checkpoint protection.
A job that runs for days can't restart from zero. Checkpoints need short-cycle backup, final model artifacts need object-storage mirroring, and production models need WORM-immutable copies.
AI data is now a compliance artifact.
Under the EU AI Act and DORA, you may need immutable, auditable records of what data trained a model and when — tamper-evident, not merely recoverable. Backup architecture becomes an audit requirement.
Modern intrastructure makes data protection more complex
Enterprise AI has a common shape: training on OpenStack GPU instances, inference in containers, and an artifact repository at the boundary. Standard backup covers one layer and leaves gaps at the seams. Storware covers all three.
– Training layer — OpenStack
– Inference layer — OpenShift / Kubernetes
– The boundary — artifact repository