
The dedupe backup targets and the tape libraries: the protection's physical shore — including the true air gap.
Backups need a purpose-built home: StoreOnce deduplicates (typically 20:1) and with Catalyst makes the copies invisible to the standard protocols — the ransomware finds no shares to encrypt. And for the last line: LTO tape, the only true physical air gap — the cartridge in the vault has no attack surface.


The ratio depends on YOUR data: the PoC that measures, before the purchase.
The native integration: fast copies, replicas between StoreOnces and no exposed shares.
Who takes the cartridges where, when: the process (and the log) that makes the air gap real.
The tape gets tested: the yearly restore from the vault, minuted.
StoreOnce does variable-block dedupe (20:1 typical): Catalyst is the protocol that changes the game — the dedupe happens at the source (the backup server sends only new blocks: the LAN breathes), the Catalyst stores are invisible to CIFS/NFS (the ransomware hunting for shares doesn't see them), the ISV lock and the immutability block the deletions, the replication between StoreOnces ships only the deduped delta: the offsite over a normal WAN; the Veeam/Commvault/Veritas integration is native.
The dedupe destination for the Veeam estate.
Years of history on the cheapest medium.
The physically offline copy NIS2 appreciates.