Executive Summary
Who this guide is for: CISOs, Risk and Compliance Officers, Governance Leaders, and technology decision-makers in heavily regulated industries.
What you will learn: How Firevault Control gives organisations modular, physical control over data flows and asset protection, beyond what software policies can achieve.
Key takeaway: Firevault Control delivers physical path control, not software policies. Nine modules govern when data can flow, who can access assets, and how the most critical records are protected.
What is Firevault Control?
Firevault Control is a modular, offline-first platform built for enterprise-grade, multi-site deployments across governments, enterprises and critical national infrastructure. It sits alongside Offline Secure Storage (Vault and Storage) as the governance and path-control layer of the Firevault product family.
The platform is delivered as nine composable modules that control:
- When data can flow (connectivity and transfer windows)
- Who can access assets (identity, authorisation and multi-party approval)
- How assets are protected (offline storage, isolation and validated recovery)
What Firevault Control is not
- Not a cloud service. Every module can be deployed offline in a Firevault Bunker, on-premises or hybrid.
- Not software-only security. Controls are enforced at the physical layer of the network and storage stack.
- Not a single product. Modular architecture, so customers deploy only what their risk model requires.
- Not a replacement for existing security. A complementary offline layer beneath the software stack.
Who is Firevault Control for?
- Organisations under stringent regulatory requirements (NIS2, DORA, FCA, GDPR)
- Operators of critical national infrastructure
- Regulated firms needing demonstrable offline capability for audit
- Multi-site, multi-zone estates requiring physical segmentation
The Nine Modules
Firevault Control ships as nine modules. Each is deployable independently and composes with the others into a governed data-path architecture.
- FV-Archive — physically disconnected copies of system configurations and gold-copy data for rapid restore after any incident.
- FV-Execute — runs approved workloads on isolated hardware, only re-connecting under authorised windows with full audit.
- FV-Firebreak — physically severs network paths in seconds, containing breaches before they spread across IT or OT.
- FV-Isolate — enforces physical separation between zones, with no shared paths between trusted and untrusted infrastructure.
- FV-Lock — multi-party physical authorisation before any sensitive data path can be opened, with full evidence trail.
- FV-Relay — moves data between disconnected zones through a controlled, one-way physical transfer window with integrity checks.
- FV-Transfer — scheduled, identity-verified data movements between physically disconnected Firevault zones with audit.
- FV-Unlink — removes persistent vendor and third-party paths, only re-establishing them under controlled authorised windows.
- FV-Validate — integrity checks on offline data before every recovery, so restored copies are known-good, not corrupted.
Deployment Architecture
Firevault Control supports the same deployment models as Storage and Enterprise:
- Firevault Bunker — modules operated in a Firevault-managed offline facility.
- On-premises — deployed inside the customer estate on dedicated hardware.
- Hybrid — a blend of Bunker-held and on-premises modules governed as one estate.
- Sovereign — fully contained within national boundaries for regulated workloads.
Regulatory Alignment
Firevault Control is designed to support:
- NIS2 resilience and incident-handling requirements
- DORA operational resilience
- NIST CSF and NIST 800-53 control mapping
- ISO 27001 and 27002 Annex A controls
- GDPR Article 32 (security of processing)
- Sector-specific requirements including FCA, HIPAA and PCI-DSS
Integration
Firevault Control integrates with existing infrastructure through:
- SIEM and SOC evidence forwarding
- Backup and DR systems as an offline gold-copy layer
- Identity providers (SAML, OIDC) for authorisation workflows
- Scheduled, audited transfer windows rather than continuous API exposure
Pricing
Firevault Control is priced by:
- Modules selected
- Deployment scale, sites and zones
- Service level and support requirements
Enterprise deployments (300TB+) start with a discovery engagement to size modules against the estate.
Getting Started
- Requirements workshop — define protection objectives and crown-jewel data.
- Architecture design — select modules and deployment model.
- Proof of concept — validate in your environment.
- Deployment — phased rollout with integration into existing controls.
- Operational handover — training and support transition.
Next Steps
If your organisation requires demonstrable offline capability for regulatory compliance or operational resilience, book a technical consultation to scope a Firevault Control deployment.



Put this guide into practice
Ready to apply what you have learned? Explore how Firevault delivers the offline protection covered in this guide.
Takes about 2 minutes. No account needed.


