layer 1 Least-privilege credentials.
The orchestrator's runtime credentials have read and write
permission only. No delete permission exists on the running
service. Even a full compromise of the orchestrator process
cannot issue a DeleteObject call.
layer 2 Object Lock, Compliance mode.
Every backup blob receives S3 Object Lock retention at
registration time. In Compliance mode, no principal (including
the storage account root) can delete or overwrite the object
before retention expires. The retention period matches the
customer's tier: 30 days (Starter), 90 days (Pro), 365 days
(Team).
enforcement
If the retention call fails during backup registration, the
registration is rejected. The agent retries on the next
scheduled run. No backup is ever recorded without immutability
confirmed.
retention Starter 30d · Pro 90d · Team 365d
mode S3 Object Lock, Compliance (WORM)
delete path Scheduled expiry only. No manual override.