Case Studies/

Decentralized Storage · Security

Koneksi

Ransomware protection via decentralized storage — secure data backups with real-time ransomware defense and content authentication. Built on IPFS and Filecoin infrastructure to solve the backup-immutability problem that centralized cloud can't.

Visit site

The problem

Ransomware attacks increased dramatically in the last two years, and traditional backup solutions have a critical vulnerability: if the attacker can reach the backup server, they encrypt the backups too. Organizations need immutable, distributed backups that cannot be encrypted or deleted by an attacker who compromises the primary network — the class of protection that requires immutability at the protocol level, not policy level. Centralized cloud backups replicate data but don't solve the immutability problem at the protocol level. "Write-once" object storage helps but is still administered by credentials that live somewhere on the primary network. Air-gapped tape backups solve immutability but have restoration windows measured in days, which for most organizations is a business-ending outage.

Key challenges

Decentralized storage promises immutability, but production-grade decentralized backup for enterprise workloads is hard. You need consistent write performance at scale, verifiable retrieval, cost that competes with cloud object storage, and a security model that legal and compliance teams can actually evaluate. The client also needed real-time detection of ransomware-like behavior on the primary side, so backups can be isolated before the encryption wave reaches them — which is a completely different problem from the storage layer itself.

What we built

Koneksi uses IPFS for content-addressed, immutable storage and Filecoin for long-term archival with cryptographic proofs of storage. The system creates verifiable backups distributed across the IPFS network — no single point of failure, no central server to compromise, and content addressing means restored data cryptographically matches what was originally stored. On the primary side, a real-time monitor watches for file-system behaviors consistent with ransomware (rapid encrypt-in-place patterns, atypical rename velocity, unusual extension changes). On detection, the backup pipeline isolates — new writes stop landing in the durable store, current backup snapshots are pinned harder, and alerts fire to the customer's IR team. This turns the storage layer from passive infrastructure into active defense.

Our approach

  1. 1

    Content-addressed immutability first

    The core primitive is CID-based storage. Every backup produces a content-addressed hash; verifying restore integrity is trivial because the hash IS the address. This is the property that makes tamper detection cheap and provable.

  2. 2

    Filecoin deals for durability guarantees

    IPFS handles addressing; Filecoin handles durability. Backups get pinned into Filecoin storage deals with cryptographic proofs of storage over time. This gives customers a verifiable answer to "is my backup still there" without trust in a central provider.

  3. 3

    Real-time ransomware behavior monitoring

    A lightweight agent on the primary side watches for behavioral signatures of ransomware in progress. On trip, the backup pipeline isolates — this is the difference between recovering yesterday's clean backup and recovering last month's.

  4. 4

    Compliance-ready audit trail

    Every backup, retrieval, and isolation event produces a signed, timestamped log entry. Legal, compliance, and cyber-insurance teams can audit the full chain.

Key architectural decisions

IPFS + Filecoin over cloud object storage

The threat model is a primary-network compromise that reaches backup credentials. Decentralized storage removes the credential vector — there's no admin console for the attacker to reach.

Content addressing as the integrity mechanism

Hash-based addressing makes tamper detection free. Every restore verifies against the original hash; no need for a separate integrity system.

Behavioral ransomware detection at the primary side

Waiting for encryption to propagate to backups defeats the point. Behavioral detection catches the pattern before it reaches durable storage.

Signed audit trail from day one

Backup systems live and die on their audit story during a real incident. Building it early avoids the retrofitting cost when the first insurance audit lands.

Results

  • Immutable backups distributed across the IPFS network
  • Filecoin-backed durability with cryptographic storage proofs
  • Real-time ransomware detection with automatic backup isolation
  • Content-authenticated restore verification (hash equals address)
  • Compliance-ready audit trail for every operation
  • Production deployment protecting enterprise data across multiple client verticals
  • Restoration validated cryptographically — no trust required in the storage layer

Impact

Koneksi turned decentralized storage from an ideological choice into a practical enterprise security control. The value isn't "it's on IPFS" — it's that customers can prove their backup is intact, immutable, and beyond the attacker's reach without depending on the honesty of a central provider. That verifiability is the property that makes cyber-insurance underwriters and CISOs pay attention.

Tech stack

IPFSFilecoinContent AddressingNode.jsReactRustCryptographic VerificationPostgreSQL

Want a case study like this?

30 minutes. We scope the real problem and figure out what to build.

Book a call
AR Logo

AR Data Intelligence Solutions Inc. · Agentic Workflow Transformation · AI, Blockchain, and Decentralized Tech

7030 Woodbine Avenue, Suite 500, Markham, Ontario, L3R 6G2, Canada

AnthropicAnthropic PartnerClaudeClaude Partner Network

©2026 AR Data Intelligence Solutions, Inc. All Rights Reserved.