Recent Breaches
Breaches
View All →
Control Module - VAULT

FV-Validate. The check before the consequence.

Validate is the deliberate pause between asking and acting. It checks whether a request, command or approval should proceed before access is granted, before an action is executed and before a transfer leaves the protected environment.

Back to Control

Control Module - VAULT

A check after the action is a report. A check before the action is a control.

Pre-action

Checks complete before the consequence is incurred

Multi-factor

Identity, authority, policy and context evaluated together

Recorded

Outcome and rationale captured for every check

Consistent

The same criteria apply regardless of who is asking

The Problem

Decisions made at the wrong moment cannot be undone.

Validation after the fact

Reviewing whether a request should have been allowed only after the consequence has occurred is a poor substitute for checking first.

Inconsistent criteria

When the answer depends on who happens to evaluate the request, the same situation can be approved on Monday and refused on Tuesday.

Identity is not enough

Knowing who is asking is only one part of whether the request should proceed. Authority, policy and context matter as much as the credential.

The Scenario

Scenario: a sensitive transfer that is questioned first

A request is raised to transfer a sensitive dataset out of a protected environment. Validate evaluates the requester, the authority under which the request is made, the policy that governs the dataset and the context of the request. The combination does not satisfy the criteria, so the transfer does not proceed and the rationale is recorded. The requester is informed, the policy owner is notified and the dataset stays where it is.

"Validate is the moment where good intent meets honest scrutiny, and the system is the better for both."

FV-Validate in placement

Where Validate proves the boundary still holds.

Validate is the continuous, evidenced check that what should be severed is severed, what should be open is open, and what was stored is what was stored.

Grounded in NIST CSF DE.CM and ID.GV-4, ISO 27001 A.8.16 Monitoring Activities and IEC 62443-3-3 SR 6.1, SR 6.2.

Inputs ─┐Telemetry ─┐

FV-Validate

Control layer

┌─ Outputs┌─ Control
01SR 6.1

Conduit state attestation

Continuously confirms that each governed conduit is in its expected state, with cryptographic evidence.

02A.8.16

Offline Secure Storage integrity

Scheduled integrity checks across Offline Secure Storage copies, wherever they reside: Remote at a Firevault Bunker, on-premise at your site, or across a hybrid pair. Bit-rot, tamper and silent failure on archived recovery sets surface long before you need to restore from them.

03DE.CM-1

Change verification

Every Execute action is followed by a verification that the intended state was actually reached.

04ID.GV-4

Compliance evidence generation

Generates a continuous evidence trail aligned to IEC 62443, NIS2 and ISO 27001 control statements.

Relies on · prerequisites

  • Read paths that cannot be silenced by the system being checked
  • Cryptographic signing of attestations
  • An immutable place to keep the evidence

Pairs with · companion modules

FirebreakIsolateArchiveExecute

Featured In

TechRadar ProSecurity BuyerYahoo FinanceSecurityBriefChannel Insider

Key Capabilities

Pre-action checks

Validation happens before the consequence, not as a retrospective review.

Multi-factor evaluation

Identity, authority, policy and context are weighed together rather than in isolation.

Consistent criteria

The same criteria apply to the same situation regardless of who happens to be asking.

Approval awareness

Where a request requires approval, the presence and validity of that approval is part of the check.

Returned rationale

Outcomes include the rationale so requesters understand why the answer was what it was.

Evidential record

Every check and its rationale are written through Archive on physically separate storage.

Demo to Live

Adoption Guide

Step 1

Identify the consequential actions

List the access, actions and transfers where a check ahead of the consequence is material.

Step 2

Define the criteria

For each, agree the identity, authority, policy and context that should be evaluated.

Step 3

Pilot the check

Place Validate ahead of one workflow end-to-end, with rationale returned and evidence recorded.

Step 4

Extend across the estate

Move further workflows onto Validate, reviewing outcomes through Archive on a regular cadence.

Step 1

Identify the consequential actions

List the access, actions and transfers where a check ahead of the consequence is material.

Step 2

Define the criteria

For each, agree the identity, authority, policy and context that should be evaluated.

Step 3

Pilot the check

Place Validate ahead of one workflow end-to-end, with rationale returned and evidence recorded.

Step 4

Extend across the estate

Move further workflows onto Validate, reviewing outcomes through Archive on a regular cadence.

Questions

Frequently Asked

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®