| Pricing & Ownership |
One-time perpetual license ($249 lifetime). You legally own the software forever. |
Endless monthly rent ($15–$35/user/mo). Data locked if subscriptions lapse. |
Annual per-gigabyte support contracts and seat renewals ($1,500+/yr). |
| Ransomware Immunity |
Immune. NTFS Hardlink WORM snapshots bypass Volume Shadow Copies. Hardlinks cannot be purged by vssadmin. |
Vulnerable. Ransomware syncs corrupted files to the cloud, overwriting good copies. |
Detects breaches but cannot restore files without expensive hypervisor backups. |
| Active Host Containment |
Win32 thread freeze halts encryption in about a millisecond while preserving RAM keys. Network airlock severs C2. |
None. Passive user-space sync client with zero endpoint defense capabilities. |
Heavy kernel-mode filter driver. Uploads telemetry to vendor cloud; keys not extracted. |
| RAM Key Forensics |
Atomic dbghelp.dll minidump sealed with SHA-256 + BLAKE3 into WORM locker. Recovers plaintext AES keys. |
None. Zero memory capture, evidentiary audit, or key recovery tools. |
Requires third-party forensics suites. RAM keys are permanently lost upon system reboot. |
| Pre-Emptive Shadow Traps |
Intercepts vssadmin / wmic shadow copy deletions seconds before files are touched. FastCDC Shannon entropy radar (H ≥ 7.92). |
None. Encrypted files with high entropy are blindly synchronized to cloud buckets. |
Post-encryption heuristic alerts trigger after user files are already encrypted. |
| Windows Kernel Stability |
0.0% BSOD Risk. Uses Microsoft native WebDAV redirector (MRxDAV.sys) with zero third-party kernel drivers. |
User-space client with heavy memory footprint and frequent sync locks. |
Third-party kernel drivers (fltmgr) risk catastrophic Windows Blue Screens of Death. |