Write-Only Spokes. Zero Lateral Risk.

Consolidate multi-site Veeam backups across isolated plants and remote facilities without site-to-site VPNs, open firewall ports, or ransomware propagation risks.

Air-gap resilience with automated central hub consolidation.

Ransomware-Proof Hub and Spoke Backup for Veeam

Multi-Site Centralization Without VPN Vulnerabilities

Protect distributed industrial facilities from catastrophic data loss. Agilicus AnyX enables remote sites to push Veeam backup archives over write-only shares, while your central backup server ingests data in read-only mode, completely eliminating lateral attack vectors.

No Site-to-Site VPN

Write-Only Push Immutability

Outbound-only HTTPS

Organizations managing multiple industrial plants, water utilities, or distributed substations need to consolidate backups to a central Veeam server. However, traditional replication methods introduce dangerous lateral attack surfaces. Agilicus AnyX delivers a resilient, isolated architecture:

The Operational Challenge

Ransomware Lateral Traversal: Site-to-site VPNs create broad network visibility. If malware infects one facility or the central backup server, it spreads across the VPN to corrupt repositories and peer plants.

Costly On-Site Silos: Purchasing, maintaining, and licensing dedicated backup storage appliances at every remote plant creates massive capital expenditure and administrative overhead.

NAT and Firewall Complexity: Remote sites connected via Starlink, cellular SIMs, or double-NAT lack public IPs, making inbound replication and port forwarding impossible without fragile tunnels.

The Customer Outcome

Write-Only Push Security: Remote plants mount the central repository as write-only over outbound HTTPS. Spokes cannot read other sites’ data and cannot pull files back, stopping malware reflection.

Read-Only Veeam Ingestion: The central Veeam Backup Server mounts deposited data read-only. It processes and archives backups without the ability to modify or overwrite pushed immutable files.

Zero-Footprint Deployment: Operates entirely over outbound HTTPS, traversing Starlink, cellular CGNAT, and restrictive firewalls with zero on-site hardware silos required.

Zero Trust architecture engineered to satisfy industrial reliability requirements and strict enterprise cybersecurity standards.

icon-smartphone-2

Write-Only Push Isolation

Spokes contribute data to dedicated incoming directories without read permissions, preventing malicious reverse-injection even if a central storage repository is compromised.

icon-padlock

Zero Lateral Network Exposure

Eliminate complex site-to-site VPN meshes entirely. Branch locations remain completely invisible to each other, stopping the propagation of ransomware across facilities.

icon-connect

Air-Gap & Cellular Traversal

Replicate backups reliably over Starlink, cellular LTE/5G, and double-NAT environments using outbound-only TLS without public IP addresses or firewall port forwarding.

Deploy Connector

Run the lightweight Agilicus connector at each remote spoke facility and the central Veeam backup hub.

Configure Write-Only Spokes

Assign remote plant agents write-only deposit paths for local backup dumps over outbound HTTPS.

Mount Read-Only on Veeam Hub

The central Veeam Backup Server mounts the consolidated repository in read-only mode for ingestion.

Automate & Protect

Automate scheduled backups across all remote facilities with complete audit logging and zero lateral risk.

Ready To Learn More?

Agilicus AnyX enables any user, on any device, secure connectivity to any resource they need: without a client or VPN. Whether that resource is a web application, a programmable logic controller, or a building management system, Agilicus secures it with strong encryption and multi-factor authentication while keeping the user experience simple with single sign-on.