A regulated organization retains contracts, financial records, transaction data, communications, audit records, reports, and other business information under different regulatory, legal, contractual, and internal retention requirements.
Some records remain active. Others may not be accessed for years but still must remain protected, retrievable, and verifiable.
Keeping all retained information indefinitely on high-performance SSD or continuously spinning HDD ties the cost of retention to infrastructure designed for active workloads. Savartus separates the two.
Retention follows policy
The organization's records-management, governance, or application systems remain authoritative for record classification, retention schedules, legal holds, access controls, and disposition authority. Savartus provides the storage and preservation layer beneath them.
Information can move between storage states as its access requirements change without changing its retention obligations. Active information can remain on high-performance storage. Retained information can move to online preservation. Long-term information can move to lower-activity preservation. Information requiring isolation can move to offline preservation. When retention is complete, it becomes eligible for authorized disposition.
The result is a retention architecture in which information does not have to remain on expensive active storage simply because it must continue to exist. A change in storage state is not a change in retention state: a record held for litigation stays held whether it resides on disk, online optical media, or offline media.
Immutability where it matters
For information requiring protection against modification, a write-once optical preservation copy creates an independent immutable version of the retained object. The operational copy can remain accessible and writable where appropriate. The preservation copy remains protected.
The copy being used does not have to be the copy being preserved.
Immutability is one control within the larger retention architecture. Compliance can also depend on classification, identity, metadata, access controls, audit history, legal holds, integrity verification, retrieval, and authorized disposition. A write-once copy that cannot be found, verified, or tied back to its record class does not satisfy a retention obligation by itself.
One retention model, multiple scales
Stand-alone systems: for departmental, branch, professional-office, laboratory, and smaller retention environments, an online optical library such as ELS100 provides a dedicated preservation tier for important long-lived information, paired with separate performance storage where active access is needed.
Integrated Active Archive systems: for environments requiring routine access alongside preservation, ELS150 and ELS300 combine an SSD/HDD cache for the operational tier with write-once optical storage that maintains an independent preservation copy in the same appliance.
Enterprise and offline systems: larger environments can scale preservation across networked optical libraries managed through oRain. Information requiring deeper protection can transition to drive-less offline libraries, such as ELS8000-OL and ELS10K-OL, for greater physical isolation while remaining governed by its retention policy and tracked by media location.
The retention model stays the same across these deployments. What changes is the scale of the archive, how frequently information is accessed, and how much physical isolation the organization's risk assessment requires.
Potential applicability: requirements depend on the organization and record class
SEC recordkeeping requirements: Rule 17a-4 includes electronic-recordkeeping requirements for covered broker-dealers. Current rules permit qualifying electronic recordkeeping through either a write-once, read-many (WORM) approach or an audit-trail alternative. Write-once storage should therefore be positioned as an available architectural control, not as automatic SEC compliance.
Federal records management: federal agencies must manage records under NARA-approved records schedules. Those schedules determine whether records are temporary or permanent, and when temporary records may be destroyed or permanent records transferred for preservation.
FDA-regulated electronic records: for covered FDA-regulated activities, the applicable predicate rules determine which records must be maintained and for how long. 21 CFR Part 11 electronic-record controls should be evaluated alongside the specific underlying regulatory requirement, not in isolation.
HIPAA-required documentation: the HIPAA Security Rule requires certain required documentation to be retained for six years from creation or when it was last in effect, whichever is later. That requirement should not be generalized into a six-year retention period for all healthcare or medical records.
Also assess state records laws, industry-specific requirements, contracts, litigation holds, privacy obligations, organizational retention schedules, and other applicable requirements. No storage appliance by itself makes an organization compliant.
Workflow design
Choose one record class and map its lifecycle: classify, assign policy, preserve, verify, retain, hold if required, reevaluate, authorize, and then dispose or preserve permanently.
For each retained object or record class, determine its owner, governing policy, retention trigger, retention period, required accessibility, immutability requirements, legal-hold status, integrity-verification process, preservation location, and disposition authority.
Then test the path end to end: confirm the preservation copy was written and verified, retrieve a record after it has moved to a lower-activity or offline state, confirm a legal hold prevents routine disposition, and document who authorized each disposition decision.
Keep the right information
The goal is not to keep everything forever. It is to keep the right information, for the right reason, for the right amount of time.
Retention is a policy decision. Storage should execute the policy.
