---
title: "Control Third-Party Access by Firevault - Control Blueprint…"
url: https://fire-vault.com/control-blueprints/cp-03
description: "Give third parties access without giving them a permanent doorway."
lang: en-GB
---

FIRE + VAULT · CP-03

# Control Third-Party Access

Give third parties access without giving them a permanent doorway.

- CP-03
- Path and asset together

Read the guide: https://fire-vault.com/learn/guides/controlling-third-party-access-control-blueprint

All Blueprints: https://fire-vault.com/control-blueprints

Image: Control Blueprint CP-03, Control Third-Party Access: an isometric diagram of a time-bound access door granting one hour of supplier entry (https://fire-vault.com/__l5e/assets-v1/74e3125a-2c95-47f7-8f5b-266d8dee7c2f/blueprint-cp-03-hero.webp)

01 At a glance

## What this Blueprint does.

Time-bounded vendor and supplier access

What it does

Where it fits

Time-bounded vendor and supplier access

Who uses it

Financial services, Healthcare, Energy, Public sector

CP-03 topology

## How CP-03 controls third-party access.

A FIRE+VAULT pattern. The vendor path is severed by default and exists only as a validated, time-bound Relay session, with every artefact preserved.

Grounded in NIS2 Art. 21(2)(d), DORA Art. 28-30 and ISO 27001 A.5.15, A.5.19.

Z0

Vendor or supplier

External party

Vendor or supplier zone

External party seeking a maintenance window

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock

Request validated. Window opened for the engagement only.

Z1

Maintenance edge

The only

Maintenance edge zone

The only place a vendor session ever lands

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer
Image: FV-Archive module icon (https://fire-vault.com/assets/archive-icon-B3rc85NY.png)
Archive

Changes scoped, recorded and revocable on signal.

Z2

Managed estate

The systems

Managed estate zone

The systems the vendor is allowed to touch

OSS

Crown jewels · detail callout

Session evidence archive

Every vendor session, command and artefact preserved offline for audit and dispute.

Modules & symbols

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer Controlled move

Image: FV-Archive module icon (https://fire-vault.com/assets/archive-icon-B3rc85NY.png)
Archive Disconnected copy

Conduit Enforced module path

┄┄┄

Crown jewels Offline · detail callout

02 Modules in this Blueprint

## How the CP-03 pattern composes.

How the primary modules compose

1. 1
   Validate VAULT
   Checks the request, command or approval before anything proceeds.
   https://fire-vault.com/control/modules/validate
2. 2
   Relay FIRE
   Opens a temporary, time-bound window for an approved purpose.
   https://fire-vault.com/control/modules/relay
3. 3
   Lock VAULT
   Holds the asset behind identity, role and policy controls.
   https://fire-vault.com/control/modules/lock

Supporting modules

- Transfer VAULT
  Governs what moves between protected environments.
  https://fire-vault.com/control/modules/transfer
- Archive VAULT
  Preserves the records, logs and evidence the control produced.
  https://fire-vault.com/control/modules/archive
- Execute FIRE
  Fires the control action the moment a signal demands it.
  https://fire-vault.com/control/modules/execute

03 How it reads end to end

## The Blueprint in full.

Validate checks the request before any door opens. Relay creates a controlled, time-bound access window. Lock ensures only approved users, roles or conditions can use it. Transfer governs what moves between environments, Archive preserves the activity for audit and Execute can revoke the path on signal.

04 Sector relevance

## Where CP-03 applies.

Financial services Healthcare Energy Public sector

05 Related Blueprints

## Compose alongside.

See all: https://fire-vault.com/control-blueprints

CP-05 FIRE + VAULT

### Protect Critical Infrastructure

Keep critical systems available, controlled and disconnected from unnecessary exposure.

View Blueprint
https://fire-vault.com/control-blueprints/cp-05

CP-08 FIRE + VAULT

### Control AI Systems

The AI Control Blueprint: bound what an AI system can reach, and keep a stop that the model cannot argue with.

View Blueprint
https://fire-vault.com/control-blueprints/cp-08

CP-01 FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint
https://fire-vault.com/control-blueprints/cp-01

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-blueprints/cp-03#webpage",
    "url": "https://fire-vault.com/control-blueprints/cp-03",
    "name": "Control Third-Party Access by Firevault - Control Blueprint…",
    "description": "Give third parties access without giving them a permanent doorway.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/fce21b03-fb5e-4021-b3b9-df9a64549452/og-blueprint-cp-03.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-blueprints/cp-03#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-blueprints/cp-03#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Blueprints",
        "item": "https://fire-vault.com/control-blueprints"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Control Third-Party Access by Firevault - Control Blueprint…",
        "item": "https://fire-vault.com/control-blueprints/cp-03"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "TechArticle",
    "headline": "Control Third-Party Access - Control Blueprint CP-03",
    "description": "Give third parties access without giving them a permanent doorway.",
    "author": {
      "@type": "Organization",
      "name": "Firevault"
    },
    "publisher": {
      "@type": "Organization",
      "name": "Firevault",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png"
      }
    },
    "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-03",
    "about": {
      "@type": "Thing",
      "name": "Control Blueprint CP-03"
    }
  }
]
```