---
title: "Validate Module Integrity Checks | Firevault"
url: https://fire-vault.com/control/modules/validate
description: "FV-Validate checks whether a request, command or approval should proceed before access, action or transfer is allowed."
lang: en-GB
---

Control Module - VAULT

# FV-Validate. The check before the consequence.

Validate is the deliberate pause between asking and acting. It checks whether a request, command or approval should proceed before access is granted, before an action is executed and before a transfer leaves the protected environment.

Back to Control: https://fire-vault.com/solutions/control

Control at a glance

Image: FV-Validate module artwork: check whether a request, command or approval should proceed (https://fire-vault.com/__l5e/assets-v1/1701bedf-26d4-400e-9458-5b60a381c457/control-module-validate-hero.webp)

Control removes the physical path. Blueprints show where each module sits.

The exposure in numbers

01

Checks complete before the consequence is incurred

Pre-action Checks complete before the consequence is incurred

02

Identity, authority, policy and context evaluated together

Multi-factor Identity, authority, policy and context evaluated together

03

Outcome and rationale captured for every check

Recorded Outcome and rationale captured for every check

04

The same criteria apply regardless of who is asking

Consistent The same criteria apply regardless of who is asking

The Problem

## Decisions made at the wrong moment cannot be undone.

01

### Validation after the fact

Reviewing whether a request should have been allowed only after the consequence has occurred is a poor substitute for checking first.

02

### Inconsistent criteria

When the answer depends on who happens to evaluate the request, the same situation can be approved on Monday and refused on Tuesday.

03

### Identity is not enough

Knowing who is asking is only one part of whether the request should proceed. Authority, policy and context matter as much as the credential.

Control Module - VAULT

> A check after the action is a report. A check before the action is a control.

The Scenario

### Scenario: a sensitive transfer that is questioned first

A request is raised to transfer a sensitive dataset out of a protected environment. Validate evaluates the requester, the authority under which the request is made, the policy that governs the dataset and the context of the request. The combination does not satisfy the criteria, so the transfer does not proceed and the rationale is recorded. The requester is informed, the policy owner is notified and the dataset stays where it is.

"Validate is the moment where good intent meets honest scrutiny, and the system is the better for both."

FV-Validate in placement

## Where Validate proves the boundary still holds.

Validate is the continuous, evidenced check that what should be severed is severed, what should be open is open, and what was stored is what was stored.

Grounded in NIST CSF DE.CM and ID.GV-4, ISO 27001 A.8.16 Monitoring Activities and IEC 62443-3-3 SR 6.1, SR 6.2.

Inputs ─┐ Telemetry ─┐

Image: FV-Validate module icon (https://fire-vault.com/assets/vault-icon-CD3Pv4ri.png)

FV-Validate

Control layer

┌─ Outputs ┌─ Control

01 SR 6.1

Conduit state attestation

Continuously confirms that each governed conduit is in its expected state, with cryptographic evidence.

02 A.8.16

Offline Secure Storage integrity

Scheduled integrity checks across Offline Secure Storage copies, wherever they reside: Remote at a Firevault Bunker, on-premise at your site, or across a hybrid pair. Bit-rot, tamper and silent failure on archived recovery sets surface long before you need to restore from them.

03 DE.CM-1

Change verification

Every Execute action is followed by a verification that the intended state was actually reached.

04 ID.GV-4

Compliance evidence generation

Generates a continuous evidence trail aligned to IEC 62443, NIS2 and ISO 27001 control statements.

Relies on · prerequisites

- Read paths that cannot be silenced by the system being checked
- Cryptographic signing of attestations
- An immutable place to keep the evidence

Pairs with · companion modules

Image: FV-Firebreak module icon (https://fire-vault.com/assets/firebreak-icon-7zSCkB1t.png)
Firebreak
Image: FV-Isolate module icon (https://fire-vault.com/assets/isolate-icon-B9t8fl3o.png)
Isolate
Image: FV-Archive module icon (https://fire-vault.com/assets/archive-icon-B3rc85NY.png)
Archive
Image: FV-Execute module icon (https://fire-vault.com/assets/execute-icon-kJl5Gtmk.png)
Execute

Featured In

Read about Firevault on TechRadar Pro: https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough
Read about Firevault on Yahoo Finance: https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html
Read about Firevault on Channel Insider: https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/
Read about Firevault on Security Buyer: https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/
Read about Firevault on SecurityBrief: https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks

Capabilities

## What you get with every deployment

01

### Pre-action checks

Validation happens before the consequence, not as a retrospective review.

02

### Multi-factor evaluation

Identity, authority, policy and context are weighed together rather than in isolation.

03

### Consistent criteria

The same criteria apply to the same situation regardless of who happens to be asking.

04

### Approval awareness

Where a request requires approval, the presence and validity of that approval is part of the check.

05

### Returned rationale

Outcomes include the rationale so requesters understand why the answer was what it was.

06

### Evidential record

Every check and its rationale are written through Archive on physically separate storage.

Demo to Live

## Adoption Guide

Step 1

#### Identify the consequential actions

List the access, actions and transfers where a check ahead of the consequence is material.

Step 2

#### Define the criteria

For each, agree the identity, authority, policy and context that should be evaluated.

Step 3

#### Pilot the check

Place Validate ahead of one workflow end-to-end, with rationale returned and evidence recorded.

Step 4

#### Extend across the estate

Move further workflows onto Validate, reviewing outcomes through Archive on a regular cadence.

Step 1

#### Identify the consequential actions

Step 2

#### Define the criteria

Step 3

#### Pilot the check

Step 4

#### Extend across the estate

Organise a Demo: https://fire-vault.com/contact

Playbooks

## Which playbook covers this module

Each playbook shows where this module sits in a real deployment, who authorises it and how a pilot scales into rollout.

A Control Blueprint for AI

### A Control Blueprint for AI: 2026 Playbook

Explains how requests from agents and automated pipelines are checked before an action is allowed to proceed.

Read the playbook: A Control Blueprint for AI: 2026 Playbook
https://fire-vault.com/playbook/ai-control-blueprints

Firevault Aerospace Playbook

### A Control Blueprint for Aerospace & Aviation

Covers approval checks on configuration, data release and maintenance actions where airworthiness evidence is at stake.

Read the playbook: A Control Blueprint for Aerospace & Aviation
https://fire-vault.com/playbook/aerospace

Firevault Leadership Briefing

### The Leaders' Playbook

Gives boards the questions to ask about who authorises what, and what evidence comes back.

Read the playbook: The Leaders' Playbook
https://fire-vault.com/playbook/leaders

## Explore More

### FV-Execute

Carries out the action once Validate has confirmed it.

Learn more about FV-Execute
https://fire-vault.com/control/modules/execute

### FV-Lock

Defines what an identity may do, ahead of the check.

Learn more about FV-Lock
https://fire-vault.com/control/modules/lock

### FV-Transfer

Approved paths for sensitive assets, governed by checks.

Learn more about FV-Transfer
https://fire-vault.com/control/modules/transfer

Questions

## Frequently Asked

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/control/modules/validate#webpage",
    "url": "https://fire-vault.com/control/modules/validate",
    "name": "Validate Module Integrity Checks",
    "description": "FV-Validate checks whether a request, command or approval should proceed before access, action or transfer is allowed.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/2fd030ed-294d-42ea-af3d-5429b7dc0062/og-control-validate.webp"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/control/modules/validate#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/control/modules/validate#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Control",
        "item": "https://fire-vault.com/control"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Modules",
        "item": "https://fire-vault.com/control/modules"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Validate Module Integrity Checks",
        "item": "https://fire-vault.com/control/modules/validate"
      }
    ]
  }
]
```