It controls the actual path
A rule is an instruction to software. A Layer 1 cut is a change in the physical state of the link. Only one of those stays true when the management plane goes wrong.
The ultimate defence is disconnection. Place a connection controller at high-risk access points and protect the network at the wire, in milliseconds, over an out-of-band channel the governed network cannot reach.
Recognition


What Firebreak is
Firebreak governs whether a network path exists at all. It lets you remotely, securely and physically connect or disconnect any asset on any network, without sending the command over the internet. Containment becomes a property of the wire, not a property of the software that runs on it.
Why Layer 1 matters
A rule is an instruction to software. A Layer 1 cut is a change in the physical state of the link. Only one of those stays true when the management plane goes wrong.
A closed Firebreak path cannot be scanned, negotiated with or routed around. There is nothing on the other side to answer.
Always-on becomes a choice rather than a default. Every link that is up is up because someone agreed it should be.
Key features
Eight things that matter when a network needs a physical control point you can trust under pressure.
Patented Layer 1 architecture
Per-zone independence
Each port pair is its own mechanical reed-switch. Isolate, schedule or restore a single circuit without touching the rest of the estate.
Twelve ports, six independent zones, all live
06 LIVEClick a row to throw its reed switch · auto-demo resumes in 10 s
✓The range
Pick by media and form factor. Reed-switch Layer 1 architecture and out-of-band command path are shared across the line.
Flagship · Globally patented1U, 19 inch rack

1U, 19 inch rack

1U, 19 inch rack

Small-form desktop
Per-zone independence
Each protected port pair is governed on its own, so containing one zone does not interrupt the next. Supplier links, OT segments, backup routes, finance enclaves and R&D networks each keep their own state.
Place Firebreak at high-risk access points and protect the network at the physical layer from day one. No re-architecture, no forklift upgrade, no special hardware or software to run the command path.
Extend your existing architecture with physical segmentation control for full traffic isolation. Advance your cyber and operational resilience plans without tearing up what already works.
Explore deployment patternsA no-brainer. It should be used by any large company.
Deployed in the field
Air gap on demand for a classified test range with intermittent partner connectivity.
Operator-triggered disconnect in milliseconds, full audit log, no inline software in the path.
Severance of the IT and OT boundary during patching windows and SCADA incident response.
Scheduled and ad-hoc cuts over SMS and REST API. No re-architecture of the control network.
Verifiable physical isolation of a settlement enclave from the wider corporate network, on demand.
The out-of-band command path satisfied both internal audit and external regulator review.
Professional services
Firebreak is plug and play, and most teams want a partner for the first rollout. We help you choose the right module, configure it for your environment and run it well, so the value lands quickly and the operations team owns it with confidence.
We help map ports, zones and command paths to your existing architecture.
Roles, runbooks and on-call patterns so cuts and restores are routine, not heroic.
Clear conventions for ports, zones and Blueprints, so every action reads the same way.
Approval, authentication and audit flows that satisfy internal review and external regulators.
Common questions
Still have questions?
NATO DIANA recognised · Globally patented · UK and US manufacture
Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.
© 2026 Firevault Limited. Disconnect to Protect®