---
title: "Digital Asset Preservation for Law Firms | Firevault"
url: https://fire-vault.com/oss-for-legal/digital-asset-preservation
description: "Protect client files, legal records and critical firm data with physically disconnected storage. Mapped to CBA preservation guidance, SRA duties and UK GDPR."
lang: en-GB
---

Digital asset preservation for law firms

# Client files deserve a copy the network cannot reach.

Offline Secure Storage® gives legal practices a physically disconnected home for client files, matter records and critical firm data, aligned with the preservation principles legal-sector guidance now expects.

- Physically disconnected
- Customer-held keys
- Recovery evidence

Buy your Vault: https://fire-vault.com/get-started

Legal sector overview: https://fire-vault.com/oss-for-legal

Image: Legal records prepared for physically disconnected preservation (https://fire-vault.com/assets/oss-industry-legal-OLbc5vp8.jpg)

01 What the guidance expects

## Digital file preservation: what legal-sector guidance expects.

The Canadian Bar Association brings together professional duties around confidentiality, integrity, availability, retention and recovery. Its guidance is international good practice rather than UK regulation, and it maps closely to what SRA, ICO and NCSC sources expect of UK firms.

01

## Preserve integrity

Records must be protected from alteration, corruption and destruction, with recoverable copies of important files maintained.

02

## Keep records accessible

Files must remain readable and usable over the long term, not merely exist somewhere in storage.

03

## Document backup and recovery

A written backup and disaster-recovery plan is part of competent data and file management.

04

## Keep several copies and versions

Multiple backups, staggered at different points in time, rather than reliance on one current copy.

05

## Test that recovery works

The existence of a backup is not enough. Firms should routinely verify that data can actually be restored.

06

## Separate full backups from the network

Connected backups face the same risks as production systems. Guidance recommends moving a full backup off-network, described as air gapped, to a secure location.

07

## Encrypt backup information

Backups should be fully encrypted, at rest and in transit.

08

## Protect copies like originals

Recovery copies must be protected to the same standard as the original information, or the recovery architecture itself becomes a confidentiality risk.

09

## Define recovery objectives

Firms should set a recovery time objective and recovery point objective that reflect obligations to clients and the regulator.

10

## Control third-party risk

Due diligence on providers, clarity on where data is stored, and a preference for services where the firm can hold its own encryption keys.

11

## Retain and delete properly

Keep information for the period professional and statutory obligations require, then destroy it securely. Clicking delete is not sufficient for confidential data.

12

## Know what is protected

A documented approach covering what is backed up, how frequently, who is responsible and which records are recovered first.

02 Principle to practice

## The strongest line in the guidance is the air gap.

CBA guidance states that full backups should be separated from the rest of the network, because connected backups face the same risks as production systems. That is precisely what Firevault is.

Image: The production estate under attack on one side, the offline vault on the other, with the path between them crossed out (https://fire-vault.com/__l5e/assets-v1/7db485e7-d9b8-4755-83b5-611dbdffa864/offline-separation-concept.png)

The air gap the guidance asks for: the backup copy sits behind a physically closed connection, out of reach of anything inside the production network.

Guidance principle

Separate full backups from the network

Firevault answer

Physically disconnected hardware with no standing network path.

Guidance principle

Secure off-site copies

Firevault answer

Dedicated storage held in a separate secure environment.

Guidance principle

Integrity and recoverability

Firevault answer

Dedicated physical storage, controlled access and offline audit records.

Guidance principle

Confidentiality and control over third parties

Firevault answer

One Vault to One User, controlled access and customer-held key options.

Guidance principle

Withstand ransomware and disruption

Firevault answer

The protected copy is unreachable while physically disconnected.

03 Choose the access pattern

## LUV for deep archives. Vault for on-demand records.

Recovery objectives are set by the firm's plan. The storage simply has to honour them without staying exposed.

300GB fixed

## LUV

One nominated day each week, within a 12-hour window

Closed matters and preserved records that are rarely reopened

Explore LUV (https://fire-vault.com/luv)

2TB, 4TB or 8TB

## Vault

24/7 on-demand access

Active preservation copies and records the firm may need quickly

Explore Vault (https://fire-vault.com/vault)

From 20TB

## Storage

Designed around organisational requirements

Firm-wide preservation above 8TB and multi-office programmes

Explore Storage (https://fire-vault.com/storage)

04 Authoritative sources

## International guidance, UK obligations.

CBA guidance is persuasive international practice. The obligations that bind UK firms come from the SRA, UK GDPR and NCSC. Firevault supports the controls; the firm and its advisers own compliance.

## CBA preservation guidance

The Canadian Bar Association's guidance on digital record preservation, backup and business continuity, including air-gapped full backups and tested restoration.

Read the official source
https://www.cba.org/

## SRA confidentiality

Paragraph 6.3 requires the affairs of current and former clients to remain confidential unless disclosure is required or permitted by law or the client consents.

Read the official source
https://www.sra.org.uk/solicitors/guidance/confidentiality-client-information/

## SRA practice closure

Closed files should be stored securely to protect confidentiality and archived or destroyed promptly where appropriate.

Read the official source
https://www.sra.org.uk/solicitors/guidance/closing-down-your-practice/

## UK GDPR storage limitation

ICO guidance says personal data must not be kept longer than needed, with documented retention periods and periodic review.

Read the official source
https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/data-protection-principles/a-guide-to-the-data-protection-principles/storage-limitation/

## NCSC backup advice

NCSC recommends keeping important backups separate from the network so ransomware cannot reach them.

Read the official source
https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/always-back-up-your-most-important-data

Questions

## Digital asset preservation for law firms FAQ

Straight answers on how Offline Secure Storage® behaves in practice.

### Is the CBA guidance a legal requirement for UK law firms?

### Why does legal-sector guidance recommend air-gapped backups?

### Can a firm still meet recovery objectives with offline storage?

### Who holds the encryption keys?

### Does offline storage help with secure deletion duties?

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/oss-for-legal/digital-asset-preservation#webpage",
    "url": "https://fire-vault.com/oss-for-legal/digital-asset-preservation",
    "name": "Digital Asset Preservation for Law Firms",
    "description": "Protect client files, legal records and critical firm data with physically disconnected storage. Mapped to CBA preservation guidance, SRA duties and UK GDPR.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/images/og/og-base-home.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/oss-for-legal/digital-asset-preservation#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/oss-for-legal/digital-asset-preservation#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Oss For Legal",
        "item": "https://fire-vault.com/oss-for-legal"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Digital Asset Preservation for Law Firms",
        "item": "https://fire-vault.com/oss-for-legal/digital-asset-preservation"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Service",
    "name": "Digital Asset Preservation for Law Firms",
    "serviceType": "Offline digital file preservation for legal practices",
    "description": "Physically disconnected storage for client files, legal records and critical firm data, aligned with legal-sector preservation guidance.",
    "provider": {
      "@type": "Organization",
      "name": "Firevault",
      "url": "https://fire-vault.com"
    },
    "areaServed": [
      {
        "@type": "Country",
        "name": "United Kingdom"
      },
      {
        "@type": "Country",
        "name": "Canada"
      }
    ],
    "url": "https://fire-vault.com/oss-for-legal/digital-asset-preservation"
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "Is the CBA guidance a legal requirement for UK law firms?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "No. The Canadian Bar Association publishes professional guidance for the legal sector, and it states that a lawyer's actual obligations depend on the rules and legislation of their own jurisdiction. UK firms are governed by the SRA, UK GDPR and related law. Firevault presents CBA guidance as authoritative international practice and maps it to the UK sources that do apply."
        }
      },
      {
        "@type": "Question",
        "name": "Why does legal-sector guidance recommend air-gapped backups?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Because a backup that remains connected to the production network is exposed to many of the same risks as the systems it protects, including ransomware. CBA guidance recommends regularly moving a full backup off-network to a secure location. Firevault provides that separation as a physical default rather than a configuration setting."
        }
      },
      {
        "@type": "Question",
        "name": "Can a firm still meet recovery objectives with offline storage?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Yes. Vault provides 24/7 on-demand access through an identity-verified connection window, so recovery time objectives are set by the firm's plan rather than limited by the storage. LUV suits deep archives accessed on one nominated day each week. The firm defines its RTO and RPO; Firevault provides the protected copy and the recorded access event."
        }
      },
      {
        "@type": "Question",
        "name": "Who holds the encryption keys?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Legal-sector guidance prefers services where the lawyer retains custody and control of confidential records, including sole ownership of encryption keys where possible. Firevault offers customer-held key options so the firm, not the provider, controls decryption."
        }
      },
      {
        "@type": "Question",
        "name": "Does offline storage help with secure deletion duties?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Guidance is clear that clicking delete is insufficient for confidential data. Firevault supports the firm's retention schedule with controlled storage and evidence of access; secure destruction of a dedicated instance removes the physical copy entirely rather than relying on file-level deletion in a shared cloud."
        }
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  }
]
```