You are here:
Verify Data Integrity with Blockchain Verify for Salesforce
Blockchain Verify ensures data integrity and authenticity within electronic storage, preventing fraud through verification against falsifying changes. Blockchain technology provides irrefutable evidence that backups remain unaltered, supporting regulatory compliance such as SEC17a-4.
Complying with SEC17a-4
Blockchain Verify supports regulatory compliance for customers in highly-regulated industries, or customers who have strict data audit and storage requirements. Blockchain Verify provides irrefutable evidence of unchanged backups.
With Blockchain Verify, we have enhanced our cloud-based backup and recovery platform for cloud-resident data, to help support companies with their stringent compliance requirements for electronic records storage, retrieval, and management.
The Securities and Exchange Commission's (SEC) sets out five specific requirements for regulated entities that choose to store and retain books and records on electronic storage media. In addition to books and records, the regulated entities must retain copies of all communications related to their business.
The requirements are:
- Records may be preserved consistent with the WORM Requirement, or the use of an
electronic recordkeeping system that maintains and preserves electronic records in a
manner that permits the recreation of an original record if it is modified or deleted.
Specifically, the electronic recordkeeping system must maintain a complete time-stamped
audit trail that includes:
- All modifications to and deletions of a record or any part thereof.
- The date and time of operator entries and actions that create, modify, or delete the record.
- The individual(s) creating, modifying, or deleting the record.
- Any other information needed to maintain an audit trail of each distinct record in a way that maintains security, signatures, and data to ensure the authenticity and reliability of the record and will permit re-creation of the original record and interim iterations of the record.
- Automatically verify the quality and accuracy of the storage media recording process.
- Serialize the original, and if applicable, duplicate units of storage media, and time-date the data for the required period of retention.
- Have the capacity to readily download indexes and records.
- Store separate, duplicate copies of all retained data.
Our Approach to Compliance
We offer cloud-based archiving solutions that allow customers to implement retention policies for regulated records stored in their Salesforce, ServiceNow, or Microsoft Dynamics instance(s).
Preservation
To ensure that data is preserved properly, our products employ an automated mechanism that compares an algorithmic, computational hash of the data before and after it has been written to storage in order to validate the backup and match it to the source. Furthermore, we store the backup in a compressed form, which has built-in cyclic redundancy checks (CRC) to provide error-detection and integrity verification. Industry standard security protocols of Transport Layer Security (TLS 1.2) are utilized when uploading data, reducing the risk of network-level errors during transmission.
Record Recreation
Using the archived data, our products provide capabilities to find and recover records that have been lost or corrupted in the original SaaS data source. Using our comparative analysis features, the user identifier that last modified a record can be determined in certain situations.
Audit-trail
We also store a detailed audit log of actions that create, modify, and delete archives alongside the acquired data, and presents certain entries in the user interface. The audit trail displayed in the user interface can be exported to a report in CSV format. These features fulfills the requirement that the electronic recordkeeping system have the capacity to readily download and transfer copies of a record and its audit trail (if applicable) in both a human-readable format and in a reasonably usable electronic format.
Verification
To help customers prove the authenticity and reliability of archived data, Recover computes cryptographic hash values of copied data segments to verify their integrity. In addition, an overall SHA256 hash value of combined segment hashes can be computed and stored in a public blockchain using the Blockchain Verify solution, which supports independent integrity verification.
Record Retention
Organizations are required to retain financial records for a set durations of time. While the exact length of time varies by record type, retention periods fall within 2-6 years. This requirement can be fulfilled by using our solutions to build custom retention policies to ensure that regulated data is kept for the proper length of time.
Why Blockchain?
Blockchain Verify leverages blockchain technology to ensure an archive can’t be overwritten, updated, or altered.
Blockchain is a distributed database that keeps continuously growing lists of transaction records without holding actual files and without making copies. Blockchain technology extends well beyond cryptocurrencies (such as Bitcoin), and its decentralized nature is perfect for the prevention of tampering, revision, and malicious editing.
Through Blockchain Verify, the integrity of backup files can be irrefutably and independently confirmed by us, or any third party with authorized access to the blockchain. With the digital signatures of the files stored on the Blockchain, they can be accessed whenever needed to provide irrefutable evidence that the records contained within have not been modified.
Irrefutable Evidence of Unchanged Backups
Using the timestamp and the content of the original backup, Blockchain Verify, uniquely provides irrefutable evidence of backup data integrity. This is achieved by generating verified backup signatures and indexes. This signature is then stored on a public blockchain, which is a decentralized ledger and permanent record facility.
If the backup is subsequently modified, the original backup signature will no longer be producible using the combination of the current backup content and the original timestamp. The ability to produce the same backup signature and easily access non-modified backups is paramount in ensuring you have the evidence needed to support regulatory inquiries pertaining to data integrity.
Accurate Recording Process
Blockchain Verify compares an algorithmic, computational hash of the file before and after it has been written to storage in order to validate the backup and match it to the source. Furthermore, we store the backup in a compressed form, which has built-in cyclic redundancy checks (CRC) to provide error detection and integrity verification. Industry-standard security protocols are utilized when uploading data, reducing the risk of network-level errors during transmission.
Once the data has been written, it is then replicated across multiple areas for redundancy. Should an integrity check fail during this replication process, our self-healing capabilities will rewrite the data from the source to ensure all replicated data is exactly the same.
Serialize and Time-Date for the Required Retention Period
Our infrastructure captures the necessary index and metadata information to address this requirement. We ensure metadata has been created for each backup, including an index, unique ID, backup hash, and a serialized timestamp. Additionally, our solution collects data points about the backup, containing when it started and was completed, warnings, errors, size, records count, and record IDs.
Capacity to Download Indexes and Records
Blockchain Verify provides customers and authorized auditors with multiple capabilities for downloading and exporting the data.
- Download/Export full indexes of all backups over specific periods of time.
- Download/Export specific files and metadata from within a backup into CSV or industry-standard MySQL format.
- Download/Export indexes, time stamps, and associated hashes to validate that the data’s integrity has been maintained throughout the data lifecycle.
Duplicate Copy of the Records Stored Separately
Our infrastructure creates and replicates encrypted snapshots across two separate storage systems, in multiple zones within the customer's storage region. Wen the ensures the replicated data’s integrity is maintained throughout the data lifecycle across multiple zones.
Verify Data Integrity with Blockchain
Use Blockchain Verify for Salesforce to confirm that your electronically stored data is authentic and hasn't been altered. Prevent fraud through verification that protects your data from falsifying changes or deletions.
Identify Behavior of a Service with Blockchain Verify
- On the Services screen, a service card with Blockchain Verify enabled, will display the blockchain icon.
- On the service’s Options screen, the Edit Retention Policy option will be disabled, as the retention for Blockchain Verify can not be changed.
- On the GDPR Subject Requests screen, the option to make a new GDPR request will be disabled.
- On the Backup History screen, each backup with Blockchain Verify applied to it (all backups since Blockchain Verify was enabled for the account), will also show the blockchain icon.
- In the top right corner of the Backup screen, click Integrity details.
- The hash created for the backup and the transaction ID of the blockchain provider, which stores the hash, are displayed.
- Click the Transaction ID link to open the transaction with the blockchain provider (e.g. Ethereum or Polygon).
