---
title: "Control Lock Module: lock down access on demand | Firevault"
url: https://fire-vault.com/control/modules/lock
description: "Lock hardens network access on demand, holding paths in a read-only or disconnected state until an authorised release. Read how the guardrails work."
lang: en-GB
---

Control Module - VAULT

# FV-Lock. Access governed as one coherent layer.

Lock restricts access through identity, authority, policy, permission and operational controls. Each of these matters on its own, but the protection comes from treating them as one coherent layer rather than five disconnected ones.

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: FV-Lock module artwork: access governed as one coherent layer (https://fire-vault.com/__l5e/assets-v1/5fea7bee-dada-43e2-b2ee-ba36eccf187a/control-module-lock-hero.webp)

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers

01

Who is asking, established before anything else

Identity Who is asking, established before anything else

02

Under whose authority the request is being made

Authority Under whose authority the request is being made

03

What the policy of the moment actually allows

Policy What the policy of the moment actually allows

04

Controls that reflect the state of the environment

Operational Controls that reflect the state of the environment

The Problem

## Access controls that disagree with each other quietly grant everything.

01

### Fragmented enforcement

When identity, policy and operational controls live in different places and tools, the disagreements between them tend to resolve in favour of access.

02

### Permissions without authority

A user may hold a permission, but without the authority to use it in the current context, the permission alone is not enough to justify the action.

03

### Standing privilege

Privilege that exists permanently is privilege that can be abused permanently, by anyone who reaches the account or the session.

Control Module - VAULT

> Access is a sentence with five clauses. Lock reads all of them before answering.

The Scenario

### Scenario: a permitted user, the wrong moment

An administrator who holds the necessary permission attempts a sensitive operation outside the approved change window. Identity and permission both check out, but the operational controls do not, because the change window is closed. Lock refuses the operation, returns the rationale and notifies the policy owner. The administrator schedules the work for the next window and the operation proceeds in its proper place.

"Lock is what stops a yes from being the answer to the wrong question."

FV-Lock in placement

## Where Lock enforces named, scoped access.

Lock turns access from a long-lived right into a named, scoped event. Reach is granted to a person, for a purpose, for a window, and recorded.

Grounded in NIST CSF PR.AC-1 and PR.AC-4, ISO 27001 A.5.15, A.8.2 and IEC 62443-3-3 SR 1.1, SR 2.1.

Inputs ─┐ Telemetry ─┐

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)

FV-Lock

Control layer

┌─ Outputs ┌─ Control

01 SR 2.1

Privileged operator sessions

Administrative reach into protected zones is granted per session, per person, with explicit scope.

02 A.5.15

Vendor maintenance accounts

Vendor identities are locked to a named engagement. No shared, evergreen credentials.

03 A.8.2

Crown-jewel data access

Sensitive datasets are reachable only by named requestors through an approved Lock event.

04 PR.AC-4

Emergency break-glass

Emergency access is a Lock event with quorum approval, full audit and a hard expiry.

Relies on · prerequisites

- Reliable identity for the named actor
- Scope that is narrower than the access path can technically allow
- Recorded purpose for each grant, not just the grant

Pairs with · companion modules

Image: FV-Relay module icon (https://fire-vault.com/assets/relay-icon-CVhJDRO7.png)
Relay
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute
Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)
Unlink
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Identity as the first clause

Who is asking is established before any other clause is evaluated.

02

### Authority as the second

The authority under which the request is made is treated as a first-class input.

03

### Policy as the third

The policy of the moment, including its exceptions and constraints, is part of the evaluation.

04

### Permission as the fourth

Permissions are necessary but not sufficient, and are evaluated against the other clauses rather than alone.

05

### Operational state as the fifth

Operational controls reflect the current state of the environment, so an answer that suits one moment is not assumed to suit another.

06

### Evidential record

Outcomes and rationales are recorded through Archive on physically separate storage.

Demo to Live

## Adoption Guide

Step 1

#### Map the access surface

Identify the access decisions that matter, the identities involved and the policies that apply.

Step 2

#### Define the five clauses

For each decision, agree the identity, authority, policy, permission and operational expectations.

Step 3

#### Pilot a coherent decision

Move one workflow onto Lock end-to-end, with the rationale returned to the requester.

Step 4

#### Operate and review

Extend Lock across further workflows and review patterns through Archive on a regular cadence.

Step 1

#### Map the access surface

Step 2

#### Define the five clauses

Step 3

#### Pilot a coherent decision

Step 4

#### Operate and review

Organise a Demo: https://fire-vault.com/contact

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

Firevault Leadership Briefing

### The Leaders' Playbook

Sets out authority, custody and succession, including who may open what after a change of control.

Read the playbook: The Leaders' Playbook
https://fire-vault.com/playbook/leaders

Firevault Legal Playbook

### Close the File. Protect the Record.

Covers permission, supervision and client confidentiality obligations on retained records.

Read the playbook: Close the File. Protect the Record.
https://fire-vault.com/playbook/legal

## Explore More

### FV-Validate

Checks ahead of access, action and transfer.

Learn more about FV-Validate
https://fire-vault.com/control/modules/validate

### FV-Unlink

Remove inherited trust before governing access.

Learn more about FV-Unlink
https://fire-vault.com/control/modules/unlink

### FV-Transfer

Approved paths governed by Lock.

Learn more about FV-Transfer
https://fire-vault.com/control/modules/transfer

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control/modules/lock#webpage",
    "url": "https://fire-vault.com/control/modules/lock",
    "name": "Control Lock Module: lock down access on demand",
    "description": "Lock hardens network access on demand, holding paths in a read-only or disconnected state until an authorised release. Read how the guardrails work.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/16185ad5-5940-414a-9f76-80671f146f1d/og-control-lock.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control/modules/lock#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control/modules/lock#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control",
        "item": "https://fire-vault.com/control"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Modules",
        "item": "https://fire-vault.com/control/modules"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Control Lock Module: lock down access on demand",
        "item": "https://fire-vault.com/control/modules/lock"
      }
    ]
  }
]
```