---
title: "Control for Colocation &amp; Data Centres | Firevault"
description: "Protect colocation providers and their tenants with physical path governance. Control modules isolate customer cages, govern cross-connects and remove shared…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/control-for-colocations#webpage",
      "url": "https://fire-vault.com/control-for-colocations",
      "name": "Control for Colocation & Data Centres",
      "description": "Protect colocation providers and their tenants with physical path governance. Control modules isolate customer cages, govern cross-connects and remove shared…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/control-for-colocations#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/control-for-colocations#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Control for Colocation & Data Centres",
          "item": "https://fire-vault.com/control-for-colocations"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Co-operative Group 6.5M records ](https://www.bbc.co.uk/news/articles/cly7z9zj3l1o)[2026 Harrods Attempted intrusion ](https://www.reuters.com/business/retail-consumer/uk-luxury-retailer-harrods-latest-target-cyber-attack-2025-05-01/)[2026 Legal Aid Agency (Ministry of Justice) 2.1M records ](https://www.gov.uk/government/news/legal-aid-agency-data-breach)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Network Evolution & Rapid Protection (#NEARP) 

# Physical Path Governance for Colocation & Data Centres 

Colocation facilities share power, cooling, fibre and management planes across many tenants. One compromised environment can become a launchpad into neighbouring cages. Control removes the shared paths that attackers rely on.

Schedule a Demo[Back to Control](/solutions/control)

![Corridor of offline storage racks inside a Firevault bunker](/assets/hero-square-bunker-BC9Flanh.jpg)

Exposure

How it worksExplore moreQuestions

The exposure in numbers 

01 

Shared attack surface between customer cages

Zero Shared attack surface between customer cages 

02 

Modules governing every physical path

9 Modules governing every physical path 

03 

Auditable cross-connect and remote-hands activity

100% Auditable cross-connect and remote-hands activity 

04 

Tenant isolation evidence for SLA and compliance

Full Tenant isolation evidence for SLA and compliance 

The Challenge 

## Shared infrastructure should not mean shared risk.

01 

### Flat Cross-Connects

Legacy cross-connects remain live indefinitely, creating persistent paths between customer environments that bypass normal network controls.

02 

### Shared Management Plane

Provider remote hands, out-of-band management and smart hands tools often reach every cage from a single console.

03 

### Tenant-to-Tenant Lateral Movement

A breach in one tenant estate can traverse shared infrastructure and reach another customer through a path that should never have existed.

Network Evolution & Rapid Protection (#NEARP)

> In a colocation facility, the only thing that should be shared is the building. Power, cooling and physical security are the provider's responsibility. Reachability between tenants is not.

The Scenario

### Scenario: a compromised tenant reaches its neighbour

A managed service provider (MSP) tenant in a London colocation facility is compromised through a stolen VPN credential. The attacker discovers live cross-connects left open after a completed data migration six months earlier. They move laterally through the provider's shared switching fabric into the cage of a financial services tenant, exfiltrate customer database backups and encrypt storage arrays before the incident is detected. The provider faces contractual liability, reputational damage and a regulator asking why one tenant could reach another. With Control, the Relay module would have closed the cross-connect at the end of the migration window. The Unlink module would have removed the persistent trust relationship. The Firebreak module would have physically severed the path between the shared fabric and the customer cage, so the attack could not have travelled the cable.

"We thought each cage was isolated because the VLANs were different. Then we discovered a cross-connect had been left live for months. Logical separation is not enough when the physical cable still exists."

Module deployment · colocation and data centre facility 

## Where each Control module is deployed across provider fabric and customer cages.

A colocation facility runs a shared provider edge and switching fabric, then breaks out into individual customer cages. Control puts a physical boundary between the provider fabric and each cage, and between cages, so shared infrastructure never becomes shared risk.

Grounded in ISO 27001 Annex A.13, PCI DSS v4 network segmentation guidance, SOC 2 CC6.1 and ENISA data centre security guidance.

P0 

Internet / WAN

External

DDoS 

Peering 

WAN 

Untrusted traffic terminates at the provider edge.

Untrusted traffic terminates at the provider edge.

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

External traffic terminates at the provider edge.

P1 

Provider edge

DMZ · trust boundary

Border routers 

IXP 

Provider-controlled demarcation point.

Provider-controlled demarcation point.

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

The shared fabric is reached only through controlled points.

P2 

Shared fabric

IT

Core switches 

Provider firewall 

Shared switching. Not a trusted zone for tenants.

Shared switching. Not a trusted zone for tenants.

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak 

Tenant A is on its own physical fabric.

A 

Customer cage A

Data

Tenant routers 

Servers 

Storage 

One tenant's environment.

One tenant's environment.

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

Cross-connects exist only for approved windows.

B 

Customer cage B

Data

Tenant routers 

Servers 

Storage 

Another tenant's environment.

Another tenant's environment.

C 

Customer cage C

Data

Tenant routers 

Servers 

Storage 

A third tenant's environment.

A third tenant's environment.

M 

Provider management

DMZ · trust boundary

Remote hands 

OOB console 

Smart hands 

Provider access to tenant kit. Named and time-bound.

Provider access to tenant kit. Named and time-bound.

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate 

Remote hands access is named and time-bound.

S 

Shared facilities

Field

Power 

Cooling 

Physical security 

Building services only. No data path.

Building services only. No data path.

OSS 

Crown jewels

Off-network

Detail callout · A

Offline Secure Storage

Provider configuration backups, tenant isolation evidence, audit logs and the recovery sets you need after a facility incident.

Offline by design · secure by default 

Modules & symbols

![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)Firebreak Physical sever 

![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)Validate Integrity check 

![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)Isolate Zone boundary 

![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)Lock Named access 

![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)Relay Time-bound path 

![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)Transfer Controlled move 

DMZ boundary Trust transition 

OSS callout Off-network detail 

### Where each module is deployed, and what it does there.

One row per module. Placement on the network, then plain-English purpose at that point.

1.  ![FV-Isolate module icon](/assets/isolate-icon-B9t8fl3o.png)
    
    Isolate
    
    Between the shared fabric and every customer cage
    
    Each tenant sits on its own physical fabric. A broadcast storm, misconfigured route or compromised switch in the shared fabric cannot reach a customer cage.
    
2.  ![FV-Firebreak module icon](/assets/firebreak-icon-7zSCkB1t.png)
    
    Firebreak
    
    On the P0 to P1 link and every P2 to CAGE link
    
    The provider has a real hardware off switch on the internet boundary and on every tenant boundary. An incident can be contained by severing the physical path.
    
3.  ![FV-Validate module icon](/assets/vault-icon-DWJpRH8k.png)
    
    Validate
    
    On the P0 to P1 link and every P2 to CAGE link
    
    Inbound traffic and any request to open a tenant path are checked for origin, integrity and authority before they progress.
    
4.  ![FV-Relay module icon](/assets/relay-icon-CVhJDRO7.png)
    
    Relay
    
    Between customer cages
    
    Cross-connects between tenants open for the approved window of work and close automatically. No path persists beyond the business need.
    
5.  ![FV-Transfer module icon](/assets/transfer-icon-DqGa0PQI.png)
    
    Transfer
    
    Between customer cages
    
    When data must move between tenant environments, Transfer governs the route, the landing point and the audit trail.
    
6.  ![FV-Lock module icon](/assets/lock-icon-UU3vOaKE.png)
    
    Lock
    
    On every P2 to CAGE link and every MGMT to CAGE link
    
    Access to a tenant cage or its equipment ties to a named, verified individual with the right authority. Shared remote-hands credentials are eliminated.
    
7.  ![FV-Unlink module icon](/assets/unlink-icon-B8GFAVW1.png)
    
    Unlink
    
    Between customer cages and on the MGMT to CAGE links
    
    When a project ends or a tenant departs, the cross-connects and remote-hands access rights are removed. Residual trust does not accumulate.
    

Featured In

[![TechRadar Pro logo](/press/techradar-pro-logo.svg) ](https://www.techradar.com/pro/uk-startup-put-physical-disconnect-switch-in-its-cloud-storage-offering-to-mitigate-ransomware-attacks-but-will-that-be-enough "Read about Firevault on TechRadar Pro") [![Yahoo Finance logo](/assets/yahoo-finance-logo-white-aNkUpCH7.png) ](https://uk.finance.yahoo.com/news/firevault-launches-help-businesses-directors-074500961.html "Read about Firevault on Yahoo Finance") [![Channel Insider logo](/assets/channel-insider-logo-white-CFFo4iu7.png) ](https://www.channelinsider.com/security/tools-and-platforms/firevault-security-offline-platform-offering/ "Read about Firevault on Channel Insider") [![Security Buyer logo](/assets/security-buyer-logo-white-o6oIaBWz.png) ](https://securitybuyer.com/uk-cybersecurity-startup-launches-firevault/ "Read about Firevault on Security Buyer") [![SecurityBrief logo](data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAT8AAAA1CAYAAAA3Sux5AAAL+0lEQVR4nO2dT4gdSRnAf++Ri5ODEcTJvoB0PIjgxdkFlejsTkBExFlhzWhEWPDkYWfXxZfoRSK73vKPJQrePHjamLhg5iAswrzNkFVyyBz04kqYJ2tmM6CQS2bxss9Dvcrr6emu+qq7ql/3e/WDZv50dVW9ftVff1Xfn+qMRiMiEY/cBpZTf78M/HpKfYlECukIhd8Z4IalzBbwIjCs2KdIO1kHfmU436mrI5FIih5wKvX3fWAb7MKvrFq4BTxb8tpI++gBDwTlogCM1IFEWVvr5vxzBSX0qsyHl8fX71SoI9IeXvVUz8hyLHlqJ1LMEmrpIn3fH6I0+6ZzGdVfm+ADOJ4Vfn1g02NnEqoJ0Ug7+Jyw3ELFdr5f8frQPMQuwCXHLdSzUzc94B4H12wBFlFLGpdr75Gc2yj5JSYt/NYJ9+GiAJxtficstx+0F9Nn0VM9q6hZ04jqLwwX3rScdxIuNZI1sonQwq+HebHaB1EAzi43BWWeDt6L2eQxShOsA2cB0gDWKdlvLfzu+euLkbhmM7t0gI2Cc+cYW9gipVgF7tTQzl4NbfimrNL2UAs/ibq+gRKWnczRRQ1uCW+59jDSKp5HjYkT40OPlyvT7NSMcIrwU2CbUWMrcPuhyMqtLnCzi+yGrqEGdt7UdYQa3BI3hkTS00jr2R0fcanDL48D138TOEq+BrhG89zXzljO76HkUnYcjgCOAL8UNCJZ0wH1ZmjjukEkEpot4CwHZ1kfB54BnkNNbZvAPnAcpRQdG/9vd2q9MfOK5fwl08kjwJf99YVrzLbwy9Nu50W7yX5235971u/jXSYacZoBk2WBW9iF4Mr4mtDs03zr/Gct539jOpnn5FyF+57rW8fNN6rnse2LOW18lHPoczYVPI12Yyg6XFwKbPclfU8WLGV3OCjkzlD82Ueoe6S549CPvPMSzlvaWBHeE+l31RPUJV2H+0hQ5nlBmWeE7c0DNluFUXh3gT/764s3a5EeWC6WnFVUiFVV3yj9wJ93vO4GcsGVWM67tm3ihdTvn7KUTYCnxr9LPOXT/TxVWEqhHZRDLtr/RFhOEgEgrc+3dnTdcv5/HtpIUC+KPmq81+FL2Bu3tUJD1v67wC8E5aRv5t1xnScMh4nXHNoy8Rjl+OiKNDTGhA6xaSsuhoqmWv+GnuqZhlPvPyzn/57526SVpp+BpdT/d1CRXJdR4/0xSnPvWOqT3o8eh2cCD8ZtbXJ45rMiqLPMbMF4X1ymvdIPP2KytpF3mK674NAfG8uocCMJWtvzSXaq1xZc7oPP78snPjVnE0V+jVX4keX8wKEuvf5+Gbsv71+YaP1FPGc5v4R65h5gnwmk2eTwMkpIloEF1zU/rdX4fiNKhZQri4K6V6iu7RUhyXTSZgbT7kABEu8EWyiXhKse6kjTwV+InOYKsuf1rxXbuYUSsFX6r9d0a0ELP9t0NIsWglpVrsIt/H/haRYxhwdtBmwb2j0FnmW+ZzkviUYaOLRnUzR62I0iZZ416Trofco/h7fx66ozoob0Z/oL2aWcF/4p8i1/UnrIb9qQw9Ela8Jri9qoSzDt1NTOvPN26nfXF3oW2zTR1bjXR72Es8dtJlNFEyGm2Glsa41FPCSMe5vEOl6J9NvoHHZLkwmtsro86NJp4QngZM7/b6KEoKTfWUHnEmd8lcOCtwOcFl6f0O5EnpdQ4+M0Ki09yEMas+yTfy8l9+eS4doOB9PlSxxzXxP3+jBlEjWs5hzL2DWuDWRuMFUoY7XuI9cWhygD2QZyQ1kZo6WUD49k/nEW+DfV1vQSlKDx9YVJHgppvxMmlkBpMocuxRriANW/O9gXeF+ifXtZHOXwQzGgPZ/jOubp7QXyvR0SQd11RT2Yxl9ZrjLp/2XKW8clKfBOUHyv+pY6llHGyJvjej7InLdph3nXPDX+3yhvHeIcfrSUVdSXVvThJALW5e0q0UT0+p708+XFBebxFUGZnwvbbAodmu/hb+NsyeuuWc77NnQUYQzPcmTIREPuo5a5dEx+3qzKhkRrPor5JXFlXMaENkZqFywXV5e8a564cpkWYV3W1EwUSXfJW2PbsS1bf5Pxz5cEdfke4CGNOr5p8xTdlbzlD9s6dF3+f+dR2k3VfH5blBNwJmxuTmvIXp772DXPIOMxO+3NotfUQBZ3WEQfFYfnOg0OZZD4uqCM6wDvYhbooResI/lsYB63P6D5uQb1LKqsEPCdjUXivypNhgLwQ8xeF0GWjGzCL40WXAnlrJerTObv02QB+GKAekP4P06Dl+1FWsVVzMKvz8ElkxVLfVWiWoqulVpLywjAEN/nC/Yi7AAfE9ZnmxV9lSkLP80Q9QUsAK/j9sDfGF+blGjXF8do1xS0brLhU21n4Fj+m5bztvXAIi4BPzWcXwL+hH1sXrTUk+W3DmWlSGZOicf2vuSxridUyeqyz8Q44mr2/0SFdqsSBZ+Z96bdgQAMHcraQuPKzlxsO9xto/Lo2TRL19C9EEarYwHqNJGEqFSb0U2HZLF1G7k6vkB5h0of7OEv8D3SDj5vOe+Sjiw0kvW5NsaMNw6J5udi5JB41f+M6bpQPALen2L7EqTaadwQSoZtvElju6VO7aGxJfEMzaMpt++FMmt+JiSOn19DlkYLwrlc/B77IvMSblbANzE71A7x725Q1657s8AadiFnW78e+OmKlSHmqd4n6+lGIW9jVoqu49ew+a7Hup7gW/hJ+O8U2swi2QbwHm7C1xYonzjUJWHFc32zju1h7NEcV6WkxrbK8BbmRMMrlHcwr40uMtO9z+nVO+OfEi1I4gidRidDNR0g1+h8ptpy9da3rUOFzkYzb9hSXIWOrXXhP1Nu3zbDW8R91rZQcCSunZPSBb4hKCedXkkCkXX2mKGgbB+5hrOAW3JNSRabRew+jXqfBxtvpH4fCsqbpmjzmibrxYrXm15ATdl4S/LdvmMvEhxbMhGXrCwXUdmk844dAhmkusiNDyOUJrSOeuB13v8llEV4hPsAkkwlNsftJgXnk/F5yZ6m6QVraVaShEmMsn6b6f0IdHpuCem3pcRJFCba6kMOpv6eVxY5vN+Ey/4Tb5Rsd1jyOgkJ6gWvnyEJTRgDkmmtpJ/r2N13gq75SffbXUTN9V02FkqTnWIXbYSe166PnHiDzN9PI9dq+5SP4MhawV3DqaJv4oS8l5x0ilU2E4uP6AIdolaVJkXgDLFPS0eo5/7HKBe3Y6jNrNYF14JyTQuSQUcLv2ep522S58PUpYbEheQ/INvIvsAqrNHcTZ/nEVusbx5lEv2GoknpxD6D7NldprxnwvGS11lJ+/mF9mEq8gEcYU9rE6pt8O9+kqXIylgmGeas4yOLkI0mGS5caVq2nRHVM2abCCoX0sJvQLgP0sWs/ewTbuCbkilqOoRZ1zENVq11hqq/jUw76UUedQhkCSGFTBV2CTMOTxM4GCIb4aE/yNBT/UPkCUF1+ixfG5/r1PPSKedJ/Gm/J5ENiJOUv9ezJvg0PsdAES7a/rQFsk442vSlkw5+lgc2xnUNPNRlpCi8TfrwmiibIfY41dTd15lkq3VlQLUkrlrgDh2uOYnqsxTXTNuuvorZtN+++JdD2eOEdSoeei7nmz0mY6nsXim6Hp/l/2k5r8dmmbRfG6jn3mVZYliinSd0RiORnaOH2gLvO+QbB/ZQ2UCu4f9N2Qe+zWFr9B7wISpO94/AH/A/WBPgW6gU9HkW1yHwN1S4j4+F6DPAKxz8rPreXiD/bWhzQM9alk3lq1jWOsAXHPohZR34Lvnf/11UqGSZuiUD31UB6GDf+NvEB7gbHk1tlqnPlDTBdWysoJ6fdP7MR+Of76H2Cn63RL2aSp9dKvwikVkjhPCLtIgq+fwikbYiiUSqkrE50gKi5heZNxJkDvOnqS+LS2QKRM0vMk/0kUcKDQL2I9IAppHSKhIJTQ+Vtux9VO7GT+OW/j2043ukAUThF5lFXkVNbxPck20MidsczAVx2huJHCRqfXNCFH6RyISmhpBFAhCnvZGIQu9kGJkTouYXmXeuI48/j8wQUfhFZpG7gjI6drbxG+1EwhCdnCPzQDpetenZUSI18X+Dj/KN9NJspQAAAABJRU5ErkJggg==) ](https://securitybrief.com.au/story/firevault-unveils-offline-digital-vault-to-combat-rising-cyber-risks "Read about Firevault on SecurityBrief") 

Capabilities

## What you get with every deployment

01 

### Tenant Isolation at Layer 1

Customer environments are separated by physical path control, not only VLANs or ACLs. No exploit, misconfiguration or insider action can bridge the gap.

02 

### Shared Infrastructure Protection

Power, cooling, connectivity and management planes remain shared, but the attack surface is not. The provider's core infrastructure is protected from a single tenant compromise.

03 

### Cross-Connect Lifecycle Governance

Cross-connects are requested, approved, opened, audited and automatically closed. No cross-connect lives beyond its approved purpose.

04 

### Scheduled Maintenance Windows

Remote hands and engineering access open only during agreed windows, with full identity verification and session logging.

05 

### Audit-Ready Isolation Evidence

Every physical path change is recorded immutably, giving providers and tenants defensible evidence for SLAs, SOC 2, ISO 27001 and customer assurance questionnaires.

06 

### Offboarding Without Residual Trust

When a tenant leaves or a project ends, Unlink removes the cross-connects, access rights and inherited trust relationships that would otherwise persist for years.

Demo to Live

## Adoption Guide

Step 1 

#### Cross-Connect Inventory

Catalogue every live cross-connect, remote-hands access path and management-plane route between the provider fabric and customer cages.

Step 2 

#### Tenant Isolation Architecture

Map Control modules to the provider's physical topology, designing isolated fabrics per cage while preserving shared power, cooling and building security.

Step 3 

#### Pilot with One Hall

Deploy Control in a single data hall or cage row, validating cross-connect lifecycle governance without disrupting existing tenants.

Step 4 

#### Facility-Wide Go-Live

Extend physical path governance across all halls, activate tenant-facing isolation reports, and integrate audit logs into the provider's compliance workflow.

Step 1 

#### Cross-Connect Inventory

Catalogue every live cross-connect, remote-hands access path and management-plane route between the provider fabric and customer cages.

Step 2 

#### Tenant Isolation Architecture

Map Control modules to the provider's physical topology, designing isolated fabrics per cage while preserving shared power, cooling and building security.

Step 3 

#### Pilot with One Hall

Deploy Control in a single data hall or cage row, validating cross-connect lifecycle governance without disrupting existing tenants.

Step 4 

#### Facility-Wide Go-Live

Extend physical path governance across all halls, activate tenant-facing isolation reports, and integrate audit logs into the provider's compliance workflow.

[Organise a Demo](/contact)

Relevant Control Blueprints

## Deployment patterns that apply here

[

CP-04 FIRE 

### Enforce Physical Segmentation

Segmentation should not just be logical. It should be physically enforceable.

View blueprint ](/control-blueprints/cp-04)[

CP-03 FIRE+VAULT 

### Control Third-Party Access

Give third parties access without giving them a permanent doorway.

View blueprint ](/control-blueprints/cp-03)[

CP-02 FIRE 

### Contain Active Breaches

When prevention fails, containment must be physical, immediate and provable.

View blueprint ](/control-blueprints/cp-02)[

CP-06 VAULT 

### Prove Compliance Through Control

Compliance becomes stronger when control can be demonstrated, not just documented.

View blueprint ](/control-blueprints/cp-06)

## Explore More

[

### Control for IT Networks

Policy-enforced path control across IT infrastructure.

Learn more about Control for IT Networks ](/control-for-it-networks)[

### Control for Critical Infrastructure

National-grade security for essential services.

Learn more about Control for Critical Infrastructure ](/control-for-critical-infrastructure)[

### Firevault Bunkers

Carefully selected colocation facilities for offline secure storage.

Learn more about Firevault Bunkers ](/bunkers)

Questions

## Frequently Asked

How does Control help a colocation provider meet its SLA obligations? 

Does this require changes to existing cage layouts or cabling? 

Can tenants still request emergency cross-connects outside normal windows? 

What happens when a tenant leaves the facility?