---
title: "Control Unlink Module: physical disconnection | Firevault"
url: https://fire-vault.com/control/modules/unlink
description: "Unlink performs a Layer 1 physical disconnection of your vault from every network path. Read how the module verifies the break and records the state change."
lang: en-GB
---

Control Module - VAULT

# FV-Unlink. Remove the relationships that expose the asset.

Unlink removes persistent connections, live dependencies and inherited trust relationships that quietly keep sensitive assets reachable. Where the relationship is not needed, it should not exist.

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: FV-Unlink module artwork: remove persistent connections and inherited trust relationships (https://fire-vault.com/__l5e/assets-v1/8934a7e5-40ad-4821-ac6d-302728da7173/control-module-unlink-hero.webp)

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers

01

Persistent connections removed where they are not required

Severed Persistent connections removed where they are not required

02

Live dependencies replaced with mediated patterns

Decoupled Live dependencies replaced with mediated patterns

03

Trust does not carry over from one context to another

No inheritance Trust does not carry over from one context to another

04

Every removal is recorded with its reason

Reviewable Every removal is recorded with its reason

The Problem

## Most exposure is paid for by relationships nobody chose to keep.

01

### Persistent connections

Always-on connections between systems remain long after the reason for them has passed, available to anyone who later finds them.

02

### Live dependencies

Direct, live dependencies between sensitive systems and convenience services drag the security posture of one onto the other.

03

### Inherited trust

Trust that exists because two systems share a domain, a directory or a network neighbourhood is trust nobody chose to grant.

Control Module - VAULT

> An asset is as exposed as its weakest relationship. Remove the relationship and you remove the exposure with it.

The Scenario

### Scenario: cutting a quiet path that no longer earns its keep

A review of a sensitive records system shows a long-standing integration with a reporting service that has not been used in over a year, plus an inherited trust relationship with a directory that no longer needs to see those records. Unlink removes both, with the rationale recorded. The records remain available to the work that genuinely needs them and disconnected from the paths that no longer do.

"Unlink is the audit of relationships you forgot you had."

FV-Unlink in placement

## Where Unlink removes inherited trust.

Unlink is the deliberate revocation of a trust relationship. It removes the inherited reach a credential, certificate or federation gave away in the first place.

Grounded in NIST CSF PR.AC-6 and PR.AC-7, ISO 27001 A.5.16 Identity Management and IEC 62443-3-3 SR 1.3.

Inputs ─┐ Telemetry ─┐

Image: FV-Unlink module icon (https://fire-vault.com/assets/unlink-icon-B8GFAVW1.png)

FV-Unlink

Control layer

┌─ Outputs ┌─ Control

01 A.5.16

Departing-staff trust revocation

Identity and certificate trust is revoked at the boundary, not just disabled in a directory.

02 PR.AC-6

Compromised vendor relationship

Severs the standing trust to a compromised vendor's infrastructure. Restoring it is a deliberate act.

03 PR.IP-6

Decommissioned system trust

Removes the inherited reach a retired system had into adjacent zones, even after it is unplugged.

04 SR 1.3

Federation and SSO trust review

Periodic Unlink reviews surface unused federations before they become an attack surface.

Relies on · prerequisites

- An accurate inventory of standing trusts in the first place
- An authoritative revocation path that downstream systems honour
- Evidence that the revocation actually took effect

Pairs with · companion modules

Image: FV-Lock module icon (https://fire-vault.com/assets/lock-icon-UU3vOaKE.png)
Lock
Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)
Validate
Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Connection removal

Persistent connections that no longer serve a purpose are removed rather than catalogued.

02

### Dependency decoupling

Live dependencies are replaced with mediated patterns so the sensitive asset does not inherit the posture of its dependants.

03

### Trust pruning

Inherited trust relationships are reviewed and removed where the inheritance is no longer warranted.

04

### Sensitive-asset focus

Effort is concentrated on the relationships that touch the assets that matter, rather than spread thinly across the estate.

05

### Authorised removals

Removals require the right authority and are scoped to the relationship under review.

06

### Evidential record

Each removal is recorded with the rationale, the approver and the outcome through Archive.

Demo to Live

## Adoption Guide

Step 1

#### Inventory the relationships

Catalogue persistent connections, live dependencies and inherited trust touching the sensitive assets.

Step 2

#### Review with the owners

Work through the inventory with the relevant owners to identify what is no longer warranted.

Step 3

#### Pilot the removals

Remove a defined batch and confirm operational continuity before broadening the work.

Step 4

#### Operate and review

Run Unlink as an ongoing discipline, with reviews recorded through Archive.

Step 1

#### Inventory the relationships

Step 2

#### Review with the owners

Step 3

#### Pilot the removals

Step 4

#### Operate and review

Organise a Demo: https://fire-vault.com/contact

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

Firevault Legal Playbook

### Close the File. Protect the Record.

Closing a matter means removing live dependencies and inherited access that keep the record exposed.

Read the playbook: Close the File. Protect the Record.
https://fire-vault.com/playbook/legal

Firevault Leadership Briefing

### The Leaders' Playbook

Explains why permanently connected data is the exposure boards most often overlook.

Read the playbook: The Leaders' Playbook
https://fire-vault.com/playbook/leaders

A Control Blueprint for AI

### A Control Blueprint for AI: 2026 Playbook

Covers open weights and model assets that should not remain reachable from a production estate.

Read the playbook: A Control Blueprint for AI: 2026 Playbook
https://fire-vault.com/playbook/ai-control-blueprints

## Explore More

### FV-Isolate

Zones the asset should sit within.

Learn more about FV-Isolate
https://fire-vault.com/control/modules/isolate

### FV-Firebreak

Sever paths at the connection layer.

Learn more about FV-Firebreak
https://fire-vault.com/control/modules/firebreak

### FV-Lock

Constrain what an identity may do after pruning.

Learn more about FV-Lock
https://fire-vault.com/control/modules/lock

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control/modules/unlink#webpage",
    "url": "https://fire-vault.com/control/modules/unlink",
    "name": "Control Unlink Module: physical disconnection",
    "description": "Unlink performs a Layer 1 physical disconnection of your vault from every network path. Read how the module verifies the break and records the state change.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/2bf0e913-def8-4eb1-ab6d-e12e3fd441cb/og-control-unlink.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control/modules/unlink#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control/modules/unlink#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control",
        "item": "https://fire-vault.com/control"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Modules",
        "item": "https://fire-vault.com/control/modules"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Control Unlink Module: physical disconnection",
        "item": "https://fire-vault.com/control/modules/unlink"
      }
    ]
  }
]
```