---
title: "Prove Compliance Through Control by Firevault - Control Blu…"
url: https://fire-vault.com/control-blueprints/cp-06
description: "Compliance becomes stronger when control can be demonstrated, not just documented."
lang: en-GB
---

VAULT-led · CP-06

# Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

- CP-06
- Protects the asset

Read the guide: https://fire-vault.com/learn/guides/proving-compliance-through-control-blueprint

All Blueprints: https://fire-vault.com/control-blueprints

Image: Control Blueprint CP-06, Prove Compliance Through Control: an isometric diagram of an approval chain writing evidence into an archive (https://fire-vault.com/__l5e/assets-v1/f32da93c-dfbf-4b9c-9c64-05d979fc2ecd/blueprint-cp-06-hero.webp)

01 At a glance

## What this Blueprint does.

Audit-grade governance of access and evidence

What it does

Where it fits

Who uses it

Financial services, Healthcare, Public sector, Critical infrastructure

CP-06 topology

## How CP-06 proves compliance through control.

A VAULT-led pattern. Every governed action produces signed evidence; every protected dataset is reachable only as a named, recorded event; everything is sealed offline.

Grounded in ISO 27001 A.5.34, A.8.15, A.8.16 and NIST CSF GV.OC-3.

Z0

Operators and analysts

Named individuals

Operators and analysts zone

Named individuals raising requests and acting on them

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock
Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay

Reach is named, time-bound and validated against an authorised request.

Z1

Controlled data zone

Records, evidence

Controlled data zone zone

Records, evidence and sensitive datasets

Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Movement out is governed; the boundary is physical, not just policy.

Z2

Evidence and audit zone

Where signed

Evidence and audit zone zone

Where signed attestations are gathered for review

OSS

Crown jewels · detail callout

Sealed evidence vault

Attestations, audit trails and protected records sealed offline for the retention period.

Modules & symbols

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate Integrity check

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock Named access

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay Time-bound path

Image: FV-Transfer module icon (https://fire-vault.com/assets/transfer-icon-DqGa0PQI.png)
Transfer Controlled move

Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute Approved action

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak Physical sever

Conduit Enforced module path

┄┄┄

Crown jewels Offline · detail callout

02 Modules in this Blueprint

## How the CP-06 pattern composes.

How the primary modules compose

1. 1
   Validate VAULT
   Checks the request, command or approval before anything proceeds.
   https://fire-vault.com/control/modules/validate
2. 2
   Lock VAULT
   Holds the asset behind identity, role and policy controls.
   https://fire-vault.com/control/modules/lock
3. 3
   Archive VAULT
   Preserves the records, logs and evidence the control produced.
   https://fire-vault.com/control/modules/archive

Supporting modules

- Transfer VAULT
  Governs what moves between protected environments.
  https://fire-vault.com/control/modules/transfer
- Relay FIRE
  Opens a temporary, time-bound window for an approved purpose.
  https://fire-vault.com/control/modules/relay
- Execute FIRE
  Fires the control action the moment a signal demands it.
  https://fire-vault.com/control/modules/execute
- Firebreak FIRE
  Physically breaks the connection path so the attack cannot continue.
  https://fire-vault.com/control/modules/firebreak

03 How it reads end to end

## The Blueprint in full.

Validate checks the request or command before it proceeds. Lock proves access was restricted. Archive proves records, logs and evidence were preserved. Transfer proves data movement was controlled, Relay proves access was temporary, Execute proves the control fired and Firebreak proves the control was physical, not just policy-based.

04 Sector relevance

## Where CP-06 applies.

Financial services Healthcare Public sector Critical infrastructure

05 Related Blueprints

## Compose alongside.

See all: https://fire-vault.com/control-blueprints

CP-01 FIRE-led

### Stop Kill-Chain Ransomware

Stop ransomware moving, spreading or reaching the crown jewels.

View Blueprint
https://fire-vault.com/control-blueprints/cp-01

CP-02 FIRE-led

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View Blueprint
https://fire-vault.com/control-blueprints/cp-02

CP-03 FIRE + VAULT

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

View Blueprint
https://fire-vault.com/control-blueprints/cp-03

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Image: David Bailey (https://fire-vault.com/assets/david-bailey-Dgqj8eaE.jpg)

Image: Kenny Phipps (https://fire-vault.com/assets/kenny-phipps-Dy-CtCjw.jpg)

Online Now

Get started

## Build control around your environment

Talk to our team about composing this Blueprint for your estate.

From £360 a month including VAT. 36-month commitment. First payment at checkout.

From £360/mo VAT included 36-month plan

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control-blueprints/cp-06#webpage",
    "url": "https://fire-vault.com/control-blueprints/cp-06",
    "name": "Prove Compliance Through Control by Firevault - Control Blu…",
    "description": "Compliance becomes stronger when control can be demonstrated, not just documented.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/ab945ef5-bb63-4eca-aca5-529f4ee484de/og-blueprint-cp-06.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control-blueprints/cp-06#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control-blueprints/cp-06#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control Blueprints",
        "item": "https://fire-vault.com/control-blueprints"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Prove Compliance Through Control by Firevault - Control Blu…",
        "item": "https://fire-vault.com/control-blueprints/cp-06"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "TechArticle",
    "headline": "Prove Compliance Through Control - Control Blueprint CP-06",
    "description": "Compliance becomes stronger when control can be demonstrated, not just documented.",
    "author": {
      "@type": "Organization",
      "name": "Firevault"
    },
    "publisher": {
      "@type": "Organization",
      "name": "Firevault",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png"
      }
    },
    "mainEntityOfPage": "https://fire-vault.com/control-blueprints/cp-06",
    "about": {
      "@type": "Thing",
      "name": "Control Blueprint CP-06"
    }
  }
]
```