Skip to main content

New Blog Series - Veeam 13.1 & Wasabi - BLOG #3 - Wasabi Covert Copy – The Invisible Air Gap Your Backups Need

  • September 14, 2026
  • 2 comments
  • 11 views

Chris.Childerhose
Forum|alt.badge.img+22

For my third blog in my new series which covers both Veeam and Wasabi, I wanted to look at something new in Wasabi called “Covert Copy”.   It is very interesting technology and you can read about it below.

Blog #3 - Wasabi Covert Copy – The Invisible Air Gap Your Backups Need

 

Wasabi Covert Copy – The Invisible Air Gap Your Backups Need

 

Ransomware attackers have gotten sophisticated. They do not just encrypt your production data anymore — they go after your backups first. If an attacker can find and destroy your backups, your recovery options disappear. That is the threat Wasabi designed Covert Copy to solve, and it is one of the most interesting data protection features to land in cloud storage in a while.

 

What is Covert Copy?

 

Wasabi Covert Copy is a feature of Wasabi Hot Cloud Storage that creates a locked, hidden copy of a selected S3 bucket. The copy is completely invisible to anyone accessing your Wasabi account through normal means — including authenticated users and, critically, any malware or ransomware that compromises your credentials.

The five pillars of Covert Copy are:

  1. Invisible — The copy cannot be seen, listed, or targeted because it does not appear in standard bucket enumeration

  2. Perfect replica — It is a full, accurate copy of your data at the time of creation

  3. Immutable — Once locked, it cannot be modified, deleted, or encrypted by anyone

  4. Inaccessible — Access requires multi-user authentication approval, even if your account is fully compromised

  5. Account protection — The multi-user authorization requirement protects both the data and the storage account itself

This is not just marketing language. Each of these properties addresses a real attack vector.

 

How Does It Work?

 

Setting up Covert Copy requires a root user on a paid Wasabi account (trial accounts are not eligible). Before you can enable it, you must have:

  • Multi-Factor Authentication (MFA) configured on your account

  • Multi-User Authorization set up

  • Bucket versioning enabled on the source bucket

Once those prerequisites are in place, you select the bucket you want to protect and initiate the Covert Copy. Wasabi then creates the hidden copy in the background. You can choose to replicate the entire bucket or filter to specific content.

Going forward, Incremental Support means the Covert Copy can be resynchronized with the source bucket periodically, so your hidden copy stays reasonably current without requiring a full re-copy each time.

 

The Air Gap That Does Not Require Hardware

 

Traditional air-gap solutions require physical tape, separate networks, or offline storage. All of that works, but it adds complexity, cost, and operational overhead. Covert Copy delivers a logical air gap — your data is completely isolated from your operational environment without requiring any additional hardware or network segmentation.

Wasabi recommends refreshing your Covert Copy every 30 to 120 days to keep it reasonably current. For longer-term retention, they also suggest creating copies in different geographic regions to protect against regional disasters.

 

Retention and Pricing

 

There is a 30-day minimum retention period before a Covert Copy can be deleted. Once that window opens, deletion still requires MFA and multi-user authorization — so there is no accidental or malicious removal.

Storage charges apply at your standard Wasabi rates for the Covert Copy bucket. Wasabi’s pricing model (no egress fees, no API fees beyond a threshold) makes this more predictable than similar features on other cloud platforms.

 

Use Cases

 

Covert Copy is a strong fit for:

  • Backup data — protecting your Veeam or other backup copies stored in Wasabi

  • Compliance archives — SEC, FINRA, HIPAA, and GDPR all have data integrity and retention requirements that Covert Copy helps address

  • AI training data and proprietary datasets — intellectual property that absolutely cannot be lost or tampered with

  • Financial records and customer data — anything where integrity is non-negotiable

 

Limitations to Be Aware Of

 

Buckets with more than 300 million objects require a special request form to enable Covert Copy. For most organizations this is not a constraint, but very large-scale deployments should be aware of it.

The Covert Copy also requires ongoing management — you need to periodically refresh it and track when retention periods expire and auto-renewal is set. This is not a set-and-forget feature; it requires some operational discipline.

 

My Take

 

Covert Copy is genuinely clever. The concept of making your backup copy invisible and inaccessible to anyone — including authenticated users — rather than just immutable is a meaningful step beyond basic Object Lock. When ransomware attackers have your credentials (and they will, if they are determined enough), Object Lock alone does not stop someone from enumerating your buckets and understanding your backup topology.

Covert Copy removes that visibility entirely. What attackers cannot find, they cannot target.

For anyone using Wasabi as a backup target, this feature is worth enabling on your most critical data sets.

-----------------------------------------------------------------------------------------------------------------------------

Interested in how Covert Copy fits into a Veeam + Wasabi architecture? Stay tuned — the next post covers Veeam + Wasabi, then we explore the Veeam + Wasabi 3-2-1 strategy to cover exactly that.

2 comments

coolsport00
Forum|alt.badge.img+23
  • Veeam Legend
  • September 15, 2026

Very cool Wasabi feature. I’ve not heard of it. Looking fwd to the other posts Chris! 👍🏻


Chris.Childerhose
Forum|alt.badge.img+22
  • Author
  • Veeam Legend, Veeam Vanguard
  • September 15, 2026

Yeah it is pretty cool but does use space so you need to monitor. 😜