Recent Breaches
Breaches
View All →
Control Module - VAULT

FV-Unlink. Remove the relationships that expose the asset.

Unlink removes persistent connections, live dependencies and inherited trust relationships that quietly keep sensitive assets reachable. Where the relationship is not needed, it should not exist.

Back to Control

Control Module - VAULT

An asset is as exposed as its weakest relationship. Remove the relationship and you remove the exposure with it.

Severed

Persistent connections removed where they are not required

Decoupled

Live dependencies replaced with mediated patterns

No inheritance

Trust does not carry over from one context to another

Reviewable

Every removal is recorded with its reason

The Problem

Most exposure is paid for by relationships nobody chose to keep.

Persistent connections

Always-on connections between systems remain long after the reason for them has passed, available to anyone who later finds them.

Live dependencies

Direct, live dependencies between sensitive systems and convenience services drag the security posture of one onto the other.

Inherited trust

Trust that exists because two systems share a domain, a directory or a network neighbourhood is trust nobody chose to grant.

The Scenario

Scenario: cutting a quiet path that no longer earns its keep

A review of a sensitive records system shows a long-standing integration with a reporting service that has not been used in over a year, plus an inherited trust relationship with a directory that no longer needs to see those records. Unlink removes both, with the rationale recorded. The records remain available to the work that genuinely needs them and unreachable from the paths that no longer do.

"Unlink is the audit of relationships you forgot you had."

FV-Unlink in placement

Where Unlink removes inherited trust.

Unlink is the deliberate revocation of a trust relationship. It removes the inherited reach a credential, certificate or federation gave away in the first place.

Grounded in NIST CSF PR.AC-6 and PR.AC-7, ISO 27001 A.5.16 Identity Management and IEC 62443-3-3 SR 1.3.

Inputs ─┐Telemetry ─┐

FV-Unlink

Control layer

┌─ Outputs┌─ Control
01A.5.16

Departing-staff trust revocation

Identity and certificate trust is revoked at the boundary, not just disabled in a directory.

02PR.AC-6

Compromised vendor relationship

Severs the standing trust to a compromised vendor's infrastructure. Restoring it is a deliberate act.

03PR.IP-6

Decommissioned system trust

Removes the inherited reach a retired system had into adjacent zones, even after it is unplugged.

04SR 1.3

Federation and SSO trust review

Periodic Unlink reviews surface unused federations before they become an attack surface.

Relies on · prerequisites

  • An accurate inventory of standing trusts in the first place
  • An authoritative revocation path that downstream systems honour
  • Evidence that the revocation actually took effect

Pairs with · companion modules

LockIsolateValidateFirebreak

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Connection removal

Persistent connections that no longer serve a purpose are removed rather than catalogued.

Dependency decoupling

Live dependencies are replaced with mediated patterns so the sensitive asset does not inherit the posture of its dependants.

Trust pruning

Inherited trust relationships are reviewed and removed where the inheritance is no longer warranted.

Sensitive-asset focus

Effort is concentrated on the relationships that touch the assets that matter, rather than spread thinly across the estate.

Authorised removals

Removals require the right authority and are scoped to the relationship under review.

Evidential record

Each removal is recorded with the rationale, the approver and the outcome through Archive.

Demo to Live

Adoption Guide

Step 1

Inventory the relationships

Catalogue persistent connections, live dependencies and inherited trust touching the sensitive assets.

Step 2

Review with the owners

Work through the inventory with the relevant owners to identify what is no longer warranted.

Step 3

Pilot the removals

Remove a defined batch and confirm operational continuity before broadening the work.

Step 4

Operate and review

Run Unlink as an ongoing discipline, with reviews recorded through Archive.

Step 1

Inventory the relationships

Catalogue persistent connections, live dependencies and inherited trust touching the sensitive assets.

Step 2

Review with the owners

Work through the inventory with the relevant owners to identify what is no longer warranted.

Step 3

Pilot the removals

Remove a defined batch and confirm operational continuity before broadening the work.

Step 4

Operate and review

Run Unlink as an ongoing discipline, with reviews recorded through Archive.

Questions

Frequently Asked

    Unlink

    Unlink removes persistent third-party and vendor paths, only re-establishing them through controlled, multi-party authorised transfer windows.

    © 2026 Firevault Limited. Disconnect to Protect®