Skip to main content
Learn • 2 mins read

How Arion stores your data

How Arion stores your data

Drive, S3 Storage and Hub are what you see. Underneath, your data lives on Arion — a storage network built for it — and Confidential Computing (coming soon) keeps its encrypted backups there too. This page explains how a file is split, placed, checked and repaired across the network, and what is encrypted at each step.

The short version​

When you upload a file:

  1. It is split into 30 pieces (10 data + 20 parity) with Reed-Solomon erasure coding
  2. Each piece is placed on a different miner by the CRUSH algorithm
  3. To download, only 10 of the 30 pieces are needed — the other 20 are redundancy

Up to 20 miners can fail at the same time and your file is still fully recoverable.

Architecture​

You
│ HTTPS
▼
Gateway (:3000) ← HTTP ingress, handles auth and chunking
│ P2P
▼
Validator (:3002) ← encodes with Reed-Solomon, runs CRUSH placement
│ QUIC (Iroh)
├──► Miner A ← piece 1
├──► Miner B ← piece 2
├──► Miner C ← piece 3
│ ...
└──► Miner N ← piece 30

Warden (:3003) ← audits miners with proof-of-storage challenges
Chain Submitter (:3004) ← publishes cluster maps to the Hippius chain

Reed-Solomon erasure coding​

Files are encoded with Reed-Solomon, k=10, m=20, in 2 MiB stripes:

  • 10 data pieces carry the original content
  • 20 parity pieces allow reconstruction when data pieces are lost
  • Any 10 of the 30 pieces rebuild the original file
  • Tolerates up to 20 miners failing at once

CRUSH placement​

Instead of a central index that answers "which miner has piece 7?", CRUSH computes the answer from a cluster map. This means:

  • No central lookup — any node can compute where a piece lives on its own
  • Deterministic — the same input always gives the same placement
  • Topology-aware — pieces are spread across different miners to reduce correlated failures

The cluster map is published to the Hippius chain by the chain submitter, so placement is verifiable and tamper-resistant.

Network layer (Iroh and QUIC)​

Pieces travel over QUIC connections using Iroh:

  • Encrypted and authenticated by default
  • Multiplexed — several pieces transfer in parallel over one connection
  • Direct UDP paths between nodes with hole-punching, relay fallback when needed
  • Each miner's identity is its Ed25519 public key

Proof of storage​

A miner does not just claim to hold your pieces; it has to prove it, continuously.

  1. When a piece is stored, it is split into chunks, each chunk is hashed, and the hashes form a Merkle tree. The root of that tree is the piece's commitment.
  2. The Warden picks pieces to audit and, every 30 seconds, challenges miners on 4 random chunks of a piece.
  3. The miner answers with a zero-knowledge proof, built with Plonky3, that it holds exactly those chunks. It has 60 seconds.
  4. The Warden verifies the proof against the commitment. A failed proof or a timeout counts against the miner's reputation, which feeds its on-chain score and rewards.

The audited set is re-sampled every hour, so a miner cannot predict which pieces will be checked.

Automatic repair​

The Validator runs a rebuild agent that:

  1. Monitors miner health through heartbeats
  2. Detects when a miner goes offline
  3. Fetches 10 pieces from the remaining miners
  4. Reconstructs the missing pieces
  5. Places them on new miners with CRUSH

What is encrypted, and where​

Arion moves and stores bytes; it does not decide what they mean. Encryption happens in the product above it, before anything reaches the network:

  • Drive encrypts on your device. Only you hold the key, and the recovery seed restores it. Nobody at Hippius can read your files.
  • S3 Storage encrypts at rest with AES-256-GCM, every chunk under its own key, and those keys are wrapped by a key management service. The S3 gateway decrypts when you download.
  • Confidential Computing (coming soon): a virtual machine's disk lives on the miner's own machine, encrypted with a key held only inside the VM — the host cannot read it. Its backups are encrypted before they reach Hippius S3.

In both cases, miners only ever hold encrypted pieces. A miner cannot read your data, and a single miner never holds enough pieces to rebuild a file.

Using it​

You never talk to Arion directly. Drive does it for you in the console and the apps, and S3 Storage does it behind a standard S3 API: aws s3 cp, boto3, rclone all work as they do anywhere.