Govern every path in and out.
Control governs connectivity in hardware at Layer 1. Paths open on command, close on command and leave an audit trail. Start with the need you have, then move to the blueprint that delivers it.
05
Needs covered for systems and access
07
Deployment blueprints, CP-01 to CP-07
09
Control modules across the platform
L1
Governance enforced in hardware at Layer 1
Physical governance for the paths your systems depend on.
Every Control module runs on a Layer 1 connection controller. It opens and closes network paths in hardware, on command, over an authenticated out-of-band channel. If the path does not exist, no attack can travel it.
Hardware enforcement
The path is broken in physics, not in a rule set that can be misconfigured.
Command and audit
Every open and close is authorised, time-bound and logged for evidence.
Modular deployment
Seven blueprints, CP-01 to CP-07, matched to the environment you run.
What do you need to protect?
Five needs covering systems and access. Each one leads to the Control blueprint built to deliver it.
Critical systems and network exposure
Leads to Blueprint CP-04 and CP-05.
ExploreRansomware and lateral movement
Leads to Blueprint CP-01 and CP-02.
ExploreThird-party and remote access
Leads to Blueprint CP-03.
ExploreAI systems and infrastructure
Leads to the AI Control patterns.
ExploreData centre and colocation exposure
Leads to Blueprint CP-04 and CP-05.
ExploreSeven deployment blueprints.
Each blueprint, CP-01 to CP-07, is an outcome-led pattern for isolating, containing or proving control. Pick the one that matches your environment.
Stop Kill-Chain Ransomware
Stop ransomware moving, spreading or reaching the crown jewels.
Contain Active Breaches
When prevention fails, containment must be physical, immediate and provable.
Control Third-Party Access
Give third parties access without giving them a permanent doorway.
Enforce Physical Segmentation
Segmentation should not just be logical. It should be physically enforceable.
Protect Critical Infrastructure
Keep critical systems available, controlled and disconnected from unnecessary exposure.
Prove Compliance Through Control
Compliance becomes stronger when control can be demonstrated, not just documented.
Protect Aviation and Aerospace Networks
Block incoming traffic by default. Open the air-lock only for verified, time-bound reach.
Control blueprints for your industry.
Sector-specific deployments for the environments where path governance matters most.
AI Systems
Control patterns for AI and model infrastructure.
Data Centres and Colocation
Tenant isolation and cross-connect governance.
Operational Technology
Physical-path governance for SCADA and ICS.
Critical Infrastructure
National-grade path governance.
Telecommunications
Carrier and backbone path governance.
Utilities
Grid and utility SCADA isolation.
Water
Treatment and distribution SCADA control.
Public Sector
Government network isolation.
Military and Defence
Network severance for national security.
Healthcare
Clinical network and device isolation.
Pick the attack pattern you need to contain.
From ransomware to insider risk and supply chain compromise. Each threat maps to a Control response.
Ransomware Containment
Sever the path before ransomware spreads.
Insider Threat
Remove persistent access outside operational windows.
Supply Chain Risk
Disconnect third-party paths when not in active use.
IT/OT Convergence
Physically separate IT from operational technology.
Management Plane Exposure
Isolate management interfaces from production networks.
The platform underneath, and the standards it evidences.
Nine Control modules deliver the enforcement. Compliance frameworks are mapped to outcomes, so audits get evidence rather than assertions.
Control modules
FV-Firebreak
Cut the Path. Physically open or close connection paths.
FV-Isolate
Separate the Zones. Split systems, networks and environments.
FV-Relay
Open Briefly. Connectivity only when needed, for a defined window.
FV-Execute
Trigger Action. Initiate control on rule, approval, alert or override.
FV-Validate
Confirm the Asset. Owner, authority and purpose before access.
FV-Unlink
Remove Exposure. Strip persistent connections and inherited trust.
FV-Archive
Preserve the Asset. For recovery, retention, compliance and evidence.
FV-Lock
Restrict Access. By identity, authority, policy and permission.
FV-Transfer
Move Under Control. Approved paths, defined windows, verified authority.
Frameworks mapped
IEC 62443
Industrial automation security and Purdue model compliance.
MITRE ATT&CK
Map Control modules to MITRE techniques and mitigations.
NIS2
Operational resilience for essential and important entities.
DORA
Digital operational resilience for financial services.
ISO 27001
Information security management and Annex A controls.
NIST CSF
Identify, protect, detect, respond, recover alignment.
Cyber Essentials
UK baseline certification with physical isolation evidence.
Published playbooks
Board-ready briefings for Control decision makers. Free to download after a quick identity check.



Which offline secure storage solution is right for you?
Answer a few quick questions and we will recommend the right solution, whether that is a personal vault or a scalable offline storage system built for your needs.
Takes about 2 minutes. No account needed.