Use cases
OSS Use Cases

Master Passwords & Recovery Keys Offline

All use cases

80%

Of breaches involve stolen or weak credentials

Threats addressed

Cloud vault master-key theftSession-token exfiltrationPhishing of vault credentialsInsider export of secrets
01The problem

Why the current setup leaves this data exposed.

Password managers are cloud-connected by design. That means your master password, recovery keys, and every credential they protect are only as safe as the cloud infrastructure they sit on. When a password manager is breached, and several major providers have been, attackers gain access to entire credential vaults. Crypto seed phrases stored in notes, 2FA backup codes saved in documents, and master recovery keys kept in cloud storage are all reachable from anywhere in the world.

02How it plays out

The scenario, and what physical disconnection changes.

One realistic sequence of events, then the controls that break it.

Scenario

A high-net-worth individual stores their crypto wallet seed phrases and master passwords inside a leading cloud password manager. The provider suffers a breach, and encrypted vaults are exfiltrated. Within weeks, attackers brute-force weaker master passwords and begin draining crypto wallets. The individual loses access to £2.3M in digital assets. Recovery keys stored in the same cloud ecosystem are also compromised, leaving no fallback.

Protection

  • Master passwords and recovery keys stored on physically air-gapped media, no network path exists for attackers to reach them
  • Crypto seed phrases and wallet backups kept in tamper-evident, monitored offline storage
  • 2FA backup codes and emergency access credentials secured beyond cloud reach
  • Physical retrieval ensures only authorised individuals can access critical credentials
03The outcome

Credentials exposed

Zero

With master passwords and recovery keys stored offline in Firevault OSS, the individual's critical credentials remained physically disconnected during the cloud breach. No crypto assets were lost, no accounts were compromised, and full access was restored using offline-stored recovery keys.

Hardware

The data sits on Firevault hardware, not a shared cloud tenancy.

Disconnect

Offline by default. No standing network path in or out.

Command

Access opens on your instruction, identity checked and logged.

Location

Held in a Firevault Bunker. Firevault provisions the location unless you request one in writing.

Mark Fermor
David Bailey
Kenny Phipps
Online Now
Concierge

Which offline secure storage solution is right for you?

Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.

Takes about 2 minutes. No account needed.

Free2 minsNo sign-up

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy