The storage architecture designed for SEALFAIL is a way to integrate permanent storage into a volatile, read-only machine.
Applications
are launched within LXC containers spawned in TMPFS (RAM storage) which are then communicating with the permanent storage thought CIFS. The CIFS shares are located on a virtual machine's virtual encrypted disk, itself running read-only with its data disk located on another partition. In case of an emergency,
a kill switch can be triggered to mangle the data disk and prevent leaks.
click on the picture to see it on fullscreen