Take sensitive data offline and out of reach.
Firevault stores selected data and digital assets on dedicated hardware in protected physical locations. The network path is physically disconnected by default and only enabled through controlled, identity-verified access.
A simple idea: data that is not connected cannot be reached.
Offline Secure Storage® (#OSS) is dedicated storage hardware, held in a secure facility, that is physically disconnected from any network unless you are in an approved, identity-verified session. It is the NCSC-aligned, common-sense answer to protecting the data your organisation cannot afford to lose.
What it protects
Crown-jewel records, client and matter files, intellectual property, financial and board papers, gold-copy backups, and anything you must still hold after the wider environment is compromised.
How access works
Identity is verified at onboarding. Each session needs multi-factor authentication, runs for a defined window, and is fully logged. Outside that window there is no network interface and no IP address.
How it differs from cloud
Cloud, NAS and immutable storage all defend a live connection. An OSS instance removes the connection, so remote attack paths do not exist rather than being filtered.
Layer 1
Physical disconnection, not a firewall rule
RAID 1
Dedicated mirrored hardware, single tenant
36 months
Commitment on every OSS instance
Every data storage platform apart from Firevault is IP controlled.
If a system has an IP address, it is remotely reachable. It can be discovered, scanned and targeted. Software defences, firewalls, encryption and access controls can all be misconfigured, bypassed or exploited. That is not a flaw in any one product, it is a structural limitation of IP-connected architecture. Offline Secure Storage removes the connection physically instead of defending it in software, and that is the defining #OSS difference.
IP controlled by design
- Public cloudAWS, Azure, GCP
- Private cloudVMware, OpenStack
- NAS and SANSynology, QNAP, NetApp
- Immutable backupVeeam, Rubrik, Cohesity
- Air-gapped tapeLTO, offline rotation
Reachable means discoverable. Discoverable means targetable.
Firevault removes the connection
Physical ownership
Each instance is allocated to a specific customer with dedicated physical capacity. Your data is never pooled, commingled or held in a shared storage estate.
Physical storage
Dedicated physical hard drives assigned to you. Not S3, shared storage pools or multi-tenant infrastructure. RAID 1 resilience.
Physical control
Access begins outside the normal network path. An authorised out-of-band command, such as SMS, controls the physical Layer 1 connection. No permanent network path.
Physical security
Carefully selected, professionally managed data centres with layered physical security, 3FA access, biometric identification, 24/7 monitoring and a complete audit trail.
That is not a feature. It is a fundamentally different architecture.
See the full Why OSS breakdownCyber attacks need a route.
Attackers cannot remotely reach storage when no live network path exists to it.
Remove the pathwayPeople make mistakes.
Architecture should limit the damage caused by misconfiguration, oversharing, deletion and compromised credentials.
Reduce the blast radiusAlways-on creates exposure.
Permanent availability creates a permanent condition to defend, monitor and trust.
Change the default stateSecurity cannot depend on perfection.
Physical design continues to protect the stored data even when people, processes or connected controls fail.
Use physics as a controlNot another cloud service. Real hardware, really offline.
Your data. Your terms. Offline by default. Physics, not promises.
What OSS is not
- Cloud storage or a SaaS platform
- A data diode or write-only vault
- Shared tenancy with other organisations
- Software-only protection bypassable with credentials
- Vendor-controlled with admin backdoors
- Connected to the internet when not in use
Always connected means always exposed.
What OSS is
- Physical disconnection by default
- Out-of-band control, no IP address and no network interface
- Dedicated hardware allocated to you alone
- Full read and write access when you authorise a session
- Time-boxed sessions with automatic disconnection
- Four tiers, from 300GB to 300TB and beyond
Prevention through architecture.
Every OSS product is built on the same physical foundation.
Select each principle to see the part it plays. Together they define what makes Offline Secure Storage® different from cloud, backup and conventional network storage.

Physical storage
Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.
Physical drives. Dedicated capacity. Never shared.
See the difference a disconnection makes.
Connected storage keeps a live route to your data, so every cyber attack, human error, network gap and weak setup has a path in. An OSS instance removes the route entirely, so the same attempts land on nothing.
Tap the vault to switch between the exposed and protected states.
With Firevault
Click vault to toggle
Online when you need it. Offline when you do not.
Access is intentional, identity-verified and time limited. The storage does not remain connected waiting for the next session. Every route has a beginning and an end.
Every route has a beginning and an end.
The authorised access process is separate from the four physical principles. It describes what happens each time a user needs to reach their OSS instance.
Out-of-band command
Access starts with an authorised command sent outside the normal network path, such as SMS. Nothing on the internet can begin a session.
Physical route enabled
Once authorised, the physical path to your OSS instance is enabled in under 10 milliseconds. Until then there is no route to enable.
Identity verified
You sign in with your issued username, password and multi-factor authentication. Identity is checked at onboarding through KYC and AML, or Dun & Bradstreet for organisations.
Time-limited session
You work with your files through File Manager for up to 120 minutes. Every upload, retrieval and share is logged.
Physical disconnection
Access is revoked automatically at the end of the session, or earlier when you log out. No network connection, no IP address, no standing route.
Defined by the responsibility you carry.
The same physical control model protects very different things: a private digital life, the information that creates a firm’s value, or the records that must survive compromise of the wider environment.
LUV
Individuals and familiesUp to 300GB
For Low Use, Important data
Sensitive records kept offline by default and reachable only during an approved access window.
- 1 × 12-hour access window per week
- Multi-factor authenticated access
- Fail-safe recovery
£74.99/month inc VAT
36-month commitment · £0 due today
Vault
Founders, partners and HNW2TB to 8TB
A Digital Safe Deposit Box
Your most valuable files on dedicated hardware in a Firevault Bunker, physically disconnected when closed.
- 24/7 x 365 access
- Identity verified access
- Vault Buddy succession
From £360/month inc VAT
36-month commitment · £0 due today
Storage
Mid-market and regulated firmsFrom 20TB
Scalable Offline Secure Storage
Customer, commercial and crown jewel data at scale, on dedicated hardware with governed access.
- 3-2-1-0 compliant
- API and SFTP integration
- On-premises or managed
Custom pricing
36-month commitment
Enterprise
Government, defence and CNI300TB+
Enterprise-Grade Offline Storage
Built to defence and intelligence standards, with physical isolation at every layer.
- On-premises deployment
- Out-of-band management
- CNI-grade infrastructure
Pricing on application
36-month commitment
Included with every OSS instance
File Manager
Browse, upload and retrieve files inside your OSS instance. Every access attempt, approval and session is logged and retained.
Offline Secure Share
Share files with authorised recipients without data leaving your closed OSS instance group. No email. No open networks.
Vault Buddy
A second trusted person nominated to support continuity. Your data outlasts you, on your terms.
The difference begins with the network path.
Cloud, NAS, data diodes and immutable backup each have valid roles. Offline Secure Storage® is designed for the selected data that should not remain remotely reachable.
| Control | OSS | Cloud | NAS | Diode | Immutable |
|---|---|---|---|---|---|
| Network state when unused | Physically disconnected | Connected | Connected to LAN / WAN | Live one-way link | Connected |
| Hardware model | Dedicated to you | Shared tenancy | Customer managed | Appliance pair | Varies |
| Access model | Intentional and time limited | Standing availability | Standing availability | Write-only ingest | Standing service access |
| Primary role | Protect high-consequence data | Convenient live storage | Local file access | One-way transfer | Recover intact copies |
| Remote attack surface | None while offline | Full | Significant | Reduced | Full |
| Identity-verified access | Out-of-band command plus MFA | Software MFA | Password / AD | Not applicable | Software MFA |
This overview stays deliberately short. The full comparison goes deeper on architecture, recovery and cost.
Open the full comparisonDeployment options that match your sovereignty needs.
Choose where your hardware lives. Every option keeps the same physical disconnection model.
Bunkers
Carefully selected physical colocation facilities providing resilient power, cooling, connectivity, and 24/7 on-site physical security.
On Premise
Installed at your location. Full physical sovereignty with Firevault's managed platform.
Hybrid
Combination of Bunkers and On-Premise. Split workloads across locations for resilience and compliance.
From personal vaults to national infrastructure.
Offline Secure Storage® is built for anyone holding data that cannot afford to be reachable.
Individuals
Protect personal records, financial papers and digital memories from theft.
Read moreDirectors and officers
Shield board papers, deal documents and personal liability evidence.
Read moreC-suite and executives
Secure strategic plans, M&A records and executive communications.
Read moreSMEs
Affordable offline protection for trade secrets and operational data.
Read moreLegal and professional services
Privileged client files, case evidence and compliance archives.
Read moreHealthcare
Patient records, research data and regulatory submissions.
Read moreFinancial services
Transaction records, KYC data and audit-critical documentation.
Read morePE and family offices
Fund documents, succession plans and high-value asset records.
Read moreCritical infrastructure
SCADA configurations, OT backups and CNI-grade operational data.
Read moreFamiliar. Simple. Secure.
Drag and drop files just like any other storage. Organise with folders, search instantly and preview documents. The security happens in the background.
- Drag and drop upload from any device
- Create folders and organise your way
- Preview documents without downloading
- Secure sharing with password protection
- Download during your authorised session only
+ 2,847 files. Simple, controlled access with no specialist tools.
Questions people ask before they take data offline.
What is Offline Secure Storage®?
Offline Secure Storage® (#OSS) is dedicated storage hardware held in a secure facility and physically disconnected at the hardware level. It connects only during an approved, identity-verified session, then disconnects again, so there is no network path to the data the rest of the time.
How is OSS different from cloud backup or immutable storage?
Cloud backup and immutable storage remain connected and rely on software controls to defend that connection. An OSS instance removes the connection itself, so remote attack paths do not exist rather than being filtered or logged.
How do I get to my files if the storage is offline?
You request a session. Multi-factor authentication triggers a physical connection for a defined access window, you work in the file manager, and the instance disconnects when the session ends. Every action is logged for audit.
Where is the hardware held?
In carefully selected UK colocation facilities, known as Firevault Bunkers, with resilient power, controlled environmental conditions and 24/7 on-site physical security. On-premises and hybrid deployments are also available.
What does it cost?
LUV starts at £74.99 per month inclusive of VAT. Vault starts from £360 per month inclusive of VAT. Storage and Enterprise are quoted on requirements. Every OSS instance carries a 36-month commitment with £0 due today.
Get your crown-jewel data out of reach.
Speak with a member of the Firevault team about which OSS instance fits your data, your sector and your compliance obligations.


