---
title: "Physical Security: Firevault Bunker Protection | Firevault"
description: "Firevault Bunkers protect dedicated Offline Secure Storage hardware with three-factor entry, biometrics, monitored zones, resilient utilities and a complete…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/offline-secure-storage/physical-security#webpage",
      "url": "https://fire-vault.com/offline-secure-storage/physical-security",
      "name": "Physical Security: Firevault Bunker Protection",
      "description": "Firevault Bunkers protect dedicated Offline Secure Storage hardware with three-factor entry, biometrics, monitored zones, resilient utilities and a complete…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/offline-secure-storage/physical-security#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/offline-secure-storage/physical-security#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Offline Secure Storage",
          "item": "https://fire-vault.com/offline-secure-storage"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Physical Security: Firevault Bunker Protection",
          "item": "https://fire-vault.com/offline-secure-storage/physical-security"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Where are Firevault Bunkers?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Firevault Bunkers operate across Europe today, including the United Kingdom, with United States and Middle East sites next."
          }
        },
        {
          "@type": "Question",
          "name": "Can I choose the jurisdiction?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "By default Firevault provisions your Offline Secure Storage in a Bunker of our choosing. If you need a specific jurisdiction, request it and we will confirm it in writing."
          }
        },
        {
          "@type": "Question",
          "name": "What does three-factor physical access mean?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Authorised entry requires three independent checks, including biometric identification, before a person can reach restricted areas."
          }
        },
        {
          "@type": "Question",
          "name": "Are the facilities monitored continuously?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Yes. Security and critical environmental conditions are monitored 24 hours a day, every day."
          }
        },
        {
          "@type": "Question",
          "name": "Does Firevault staff have routine access to my data?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. Physical facility access does not provide customer credentials or create a network route to the data. Those controls remain separate."
          }
        },
        {
          "@type": "Question",
          "name": "Is physical security enough on its own?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "No. It works with dedicated physical storage, defined ownership and physical control of connectivity. The four principles are designed to operate together."
          }
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Co-operative Group 6.5M records ](/learn/breaches)[2026 Harrods Attempted intrusion ](/learn/breaches)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

Buy your Vault

Overview

Why it mattersHow it worksInside the security modelHow it differsFAQ

Offline Secure Storage® (#OSS) 

# Physical security 

Your dedicated hardware is housed inside carefully selected, professionally managed Firevault Bunkers with layered perimeter, access, power and environmental controls around the equipment.

-   3FA site access
-   Biometric identification
-   24/7 monitoring
-   International resilience

[Buy your Vault](/get-started) [Explore Bunkers](/bunkers)

![A secured Firevault Bunker entrance with monitored CCTV, perimeter barriers and biometric access control](/__l5e/assets-v1/96d12176-194a-4c6c-9063-0c76744dec0b/physical-security-oss.webp)

![Physical security icon](/__l5e/assets-v1/142ccda0-8d60-4dd1-b1e1-bc8e08bb4883/firevault-oss-physical-security-icon.webp)Physical security 

Layered site protection 

01 

Authentication required for controlled site access

3FA Authentication required for controlled site access 

02 

Security and environmental monitoring

24/7 Security and environmental monitoring 

03 

Controlled access events audited

100% Controlled access events audited 

04 

International regions in the Bunker roadmap

3 International regions in the Bunker roadmap 

01 Why it matters 

## Offline data still needs a secure physical home

Disconnecting a network route removes remote exposure. The Bunker protects the hardware itself against unauthorised entry, utility failure, environmental events and unrecorded handling.

### Layered perimeter

Controlled approaches, monitored entrances and restricted internal zones place several barriers between the public and the racks.

### Verified human access

Three-factor authentication, including biometric identification, ties physical entry to a verified person.

### Continuous oversight

24/7 monitoring and a complete audit trail record access and protect the operating environment.

02 How it works 

## How the Bunker protects your hardware

Physical security works in layers, from the site boundary to the specific rack and every authorised intervention.

01 

### Site and jurisdiction are selected

By default Firevault provisions your Offline Secure Storage in a Bunker of our choosing. If you need a specific jurisdiction, request it and we will confirm it in writing.

02 

### The perimeter controls approach

Fencing, surveillance and controlled vehicle and pedestrian routes protect the facility boundary.

03 

### Identity is checked in layers

Authorised personnel pass three-factor access controls, including biometric identification, before entering restricted areas.

04 

### Racks and environment remain monitored

Restricted zones, resilient power, cooling and continuous monitoring protect the commissioned hardware.

05 

### Every authorised action is recorded

Entry and operational handling create an audit trail that supports investigation and assurance.

03 Inside the security model 

## Protection around the drives, not just on them

Firevault Bunkers operate across Europe today, including the United Kingdom, with United States and Middle East sites next.

### Professionally managed facilities

Bunkers are selected for resilient operations and layered security rather than ordinary office storage.

### 24/7 monitoring

The site, approaches and controlled areas remain under continuous security oversight.

### Biometric identification

Physical entry includes a factor tied to the authorised person, not only something they know or carry.

### Restricted access zones

Passing the outer entrance does not grant unrestricted movement through the facility.

### Resilient utilities

Power and environmental controls are designed to preserve the hardware and its operating conditions.

### Jurisdiction by agreement

Firevault allocates a Bunker by default, or confirms a requested jurisdiction in writing where required.

04 How it differs 

## The other three physical principles

Physical security answers where and how the hardware is protected. It does not replace dedicated media, customer assignment or control of the network route.

[

### Physical storage

The protected objects are real drives and racks with an identifiable location.

Read more ](/offline-secure-storage/physical-storage)[

### Physical ownership

The hardware inside the Bunker is assigned to a defined customer instance.

Read more ](/offline-secure-storage/physical-ownership)[

### Physical control

The network route is also physically controlled, independently of the Bunker perimeter.

Read more ](/offline-secure-storage/physical-control)[

### Firevault Bunkers

See the international Bunker footprint and how jurisdiction is agreed.

Read more ](/bunkers)

05 FAQ 

## Questions

### Where are Firevault Bunkers?

Firevault Bunkers operate across Europe today, including the United Kingdom, with United States and Middle East sites next.

### Can I choose the jurisdiction?

By default Firevault provisions your Offline Secure Storage in a Bunker of our choosing. If you need a specific jurisdiction, request it and we will confirm it in writing.

### What does three-factor physical access mean?

Authorised entry requires three independent checks, including biometric identification, before a person can reach restricted areas.

### Are the facilities monitored continuously?

Yes. Security and critical environmental conditions are monitored 24 hours a day, every day.

### Does Firevault staff have routine access to my data?

No. Physical facility access does not provide customer credentials or create a network route to the data. Those controls remain separate.

### Is physical security enough on its own?

No. It works with dedicated physical storage, defined ownership and physical control of connectivity. The four principles are designed to operate together.

Next step 

## Protect the hardware as deliberately as the data

Choose your Vault capacity and let Firevault place it inside the physical and operational controls of a Firevault Bunker.

[Buy your Vault](/get-started) [Explore Bunkers](/bunkers)