Storage by Firevault

Storage : scalable offline secure storage.

From 20TB to 300TB. Start with how much data needs an offline state. Then define how that data is written, how often it needs to move, and when the physical connection should exist. Storage replaces file servers and paid cloud storage with dedicated hardware your organisation legally owns.

Designed with our solutions teamFrom 20TB to 300TB and beyond, specified around your data, retention obligations and where the hardware sits.
No online checkout

Vault and LUV can be bought online. Storage is a business system, so pricing follows the design: a written proposal covering capacity, deployment model, integration and support.

Hospital
Manufacturing
Financial
Enterprise
Offline
Offline
STORAGE
Hospital
Offline
STORAGE

Hospital data is physically disconnected.

Connection window captureLoop
00:0000:14
A site requests access, identity is authorised out of band, the window opens for the transfer, then the path is removed.
Animated illustration, no audio.
Firevault Offline Secure Storage cabinets racked inside a protected physical locationPhysically disconnected by default
Capacity20TB to 300TB+
HardwareOwned by you
DefaultNo network path
AccessAPI and SFTP
40TB to 100TB holds roughly
16M+documents
20M+photographs
10,000+ hrsHD video
160,000+ hrsvoice recordings

Best suited to: Full backup estate, disclosure bundles, design archives and regulated retention sets.

20TB to 300TB+Offline by defaultDedicated hardware you ownAPI and SFTP access
01Step 01 · Size the data

How much data actually needs to be offline?

Not every byte in the estate needs Offline Secure Storage®. The first design decision is the size of the protected data set today and how that volume is expected to change.

Capacity input

Start with usable protected data.

Use the slider as a working design input, not an instant hardware quote. Final usable capacity, redundancy and expansion are confirmed during engineering design.

Working protected data set20 TB
20TBStorage range300TB

Important: this is the volume you want available in the offline tier. It is not automatically the same as total production capacity.

Current volume

How much needs protecting now?

Define the initial data set that should exist in the offline tier, not the whole production estate.

Growth

How quickly will it grow?

Growth changes the capacity requirement and when expansion in 20TB blocks should be planned.

History

How much history needs to remain?

Retention and version requirements affect the true amount of usable storage required.

Headroom

What operating headroom is sensible?

The design should allow for growth rather than size the system to today's exact utilisation.

02Step 02 · How data is written

How does data need to arrive in Storage?

Once the protected volume is understood, the next question is the write path. Data moves during authorised connection windows, so the design should fit the systems already producing the data.

Write path

Choose the way data needs to enter.

This is not a fixed choice. A Storage deployment can use one method or a mix, depending on the workload and the systems already in place.

SourceYour existing systemsProduction storage, applications, backup software or another authorised source.
Write pathApproved transfer methodScheduled sync, SFTP, API, backup integration or a designed combination.
DestinationFirevault Storage20TB to 300TB of dedicated #OSS, physically disconnected again when the job finishes.
03Step 03 · Define the write pattern

Capacity alone does not tell us how the system needs to behave.

The same 100TB requirement can create very different designs depending on how much changes, how often data is written and how long the connection window can remain open.

Initial ingest

How much arrives on day one?

The first load is often materially larger than the ongoing daily or weekly change.

Change rate

How much new data is written each cycle?

Understand the typical delta rather than assuming the full data set moves every time.

Frequency

Hourly, daily, weekly or event driven?

The cadence determines how often Storage must enter an authorised connected state.

Concurrency

How many sources write at once?

Simultaneous data flows change the operational and performance requirement.

04Step 04 · Define the secure state

Then decide when Storage is allowed to be connected.

Write. Verify. Disconnect. Storage is not permanently online waiting for the next job. The operating model defines when the physical path is enabled, what may happen in that window and what closes the session.

Trigger

What starts the window?

A schedule, an authorised individual, an approved system event or another defined trigger.

Duration

How long does the write need?

The window must be long enough for the required data movement, and no longer.

Completion

What confirms the job is done?

Define the success condition before the physical connection is removed.

Disconnect

What closes the path?

End of job, timeout, user action or another defined control returns Storage to offline.

Default state: physically disconnected. Connection exists only for the authorised purpose and disappears again when that purpose is complete.

How #OSS works
05Step 05 · Choose deployment

A bunker, your building, or both at once.

The protection model does not change with the location. What changes is who holds physical custody of the rack, and whether the gold copy sits away from your primary site.

In a Firevault bunker

Your hardware is racked in a protected physical location. Firevault handles the facility, the power and the physical disconnection.

On your premises

The same hardware and the same physical disconnection, racked inside your own building and under your own physical custody.

A hybrid of both

A working set on your premises with the gold copy held in a Firevault bunker, so a single site loss does not remove the archive.

A Firevault bunker, the protected physical location that holds Offline Secure Storage hardware
Firevault bunker

Protected physical locations with controlled entry, held under Firevault custody and physically separated from your operational network.

Pricing

Two things set the price: who reaches it, and how much of it there is.

Storage from 20TB is quoted, not listed, because the build is specified around your estate. The model is fixed and published, so you can see how the number is arrived at before you speak to anyone.

OSAP, Offline Secure Access Profile

One named person, with their own identity-locked route into the offline capacity. More people means more profiles, never a shared login.

OSSC, Offline Secure Storage Capacity

The disconnected capacity itself, held on dedicated hardware in a Firevault Bunker and mirrored with RAID 1.

Worked 500TB model, RAID 1

More named access profiles raise the upfront figure and lower the monthly figure. The same three-option shape is used at every capacity, so you can see the trade before we quote.

Indicative 500TB Offline Secure Storage pricing options over 36 months
Option OSAP OSSC Upfront Monthly 36-month total Saving
Option 1 1 500TB (RAID 1) £150,000 £4,000 £294,000 £206,000
Option 2 3 500TB (RAID 1) £170,000 £3,250 £287,000 £213,000
Option 3 11 500TB (RAID 1) £200,000 £2,000 £272,000 £228,000

Monthly figures run over 36 months. A 20TB to 300TB build is modelled the same way, with your own OSAP count and OSSC sizing. Indicative only, not a quote. Prices are scalable and confirmed in your proposal after the scoping call.

06What Storage is

Real hardware, in a real place, with no route left waiting.

Storage is not a tier of a cloud account. It is a physical allocation of drives, purchased in your name, racked in a protected location and disconnected from the network whenever it is not in an authorised session.

Physically disconnected

There is no standing network path to the drives. The route is enabled for an authorised session and then removed.

Dedicated hardware

Real allocated drives, not a share of a multi-tenant pool. The capacity is yours and is physically identifiable.

You legally own it

The hardware is purchased in your name. The archive does not sit inside another company's balance sheet.

Identity verified access

Every session is opened by a verified individual over an out-of-band channel, separate from the data path.

Hardware level encryption

AES-256 applied at the hardware layer, so the protection does not depend on an application staying uncompromised.

Connect in six seconds

Authorised access is not a ticket queue. The physical path is opened on command and closes when the session ends.

07Who Storage is for

Organisations holding terabytes, not a personal vault.

Storage is the organisation tier of Offline Secure Storage®, the replacement for file servers and paid cloud storage. Vault and LUV protect what one person or one household holds. Storage protects the estate: customer records, financial transactions, operational baselines and intellectual property, measured from 20TB upwards.

Regulated professions

Law firms, accountancy practices and advisers holding client files, disclosure bundles and matter archives under long retention obligations.

Finance and insurance

Transaction records, actuarial models and customer data sets that must survive an incident intact and be evidenced to a regulator.

Industry and infrastructure

Operational technology baselines, engineering drawings and control configurations that restore a plant after a compromise.

Data-heavy operators

Media, research and product organisations whose archives grow in terabytes and cannot be re-created if they are lost.

The #OSS difference

Storage is built on four physical principles.

Firevault Storage is Offline Secure Storage® that scales with your estate. The same four physical principles apply, from 20TB to 300TB and beyond.

Firevault Offline Secure Storage 2TB, 4TB and 8TB physical drives
Dedicated hardware

Physical storage

Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.

Physical drives. Dedicated capacity. Never shared.

01Controlled connectivity

The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.

Layer 1 disconnection. Out-of-band command. No standing exposure.

02Secured offline access

Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.

Named users. Time-limited sessions. Full audit trail.

03Secured offline data

Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.

Quantum Key Encryption. Dedicated drives. Held apart from live systems.

08Integration and governance

API and SFTP access, so it fits the backup estate you already run.

Storage is built for volume movement, not single file retrieval. Governed API and SFTP access lets your existing backup and archive workflows write to the allocation during authorised windows, with a complete audit trail for every action.

SFTP endpoint

Standard clients and standard ciphers, reachable only during an authorised connection window. Off window the endpoint is not on the network.

REST scheduling API

An out-of-band control plane to schedule windows, list audit events and trigger emergency offline from your own operations tooling.

Existing backup workflows

Sits behind your primary and backup tiers as the offline gold copy. Scheduled or on-demand sync during authorised windows.

Complete audit trail

Every connection, disconnection and identity verification recorded and exportable for SIEM ingestion and insurer evidence packs.

Delegated access

Named individuals hold defined rights over defined data sets, so the archive is usable by a team without becoming open to it.

Compliance alignment

Built to support GDPR, NIS2, ISO 27001 and NIST CSF, with NCSC CAF outcome mapping available on request.

09Against the alternatives

Cloud archive and tape both leave something connected.

Cloud archive keeps a permanent route to the data. Tape removes the route but adds hours to retrieval and depends on a library that is itself managed over the network.

CapabilityFirevault StorageCloud archiveTape library
Physically disconnected by default
Dedicated hardware you legally own
No standing network route to the data
Immune to remote credential compromise
Retrieval without third-party dependency
Scales from 20TB to 300TB and beyond
Expansion in fixed 20TB steps
Available in seconds, not hours
10Designed with our solutions team

Storage is designed around your requirements, not bought off a shelf.

Vault and LUV are ready to buy online. Storage is a business system, so every deployment is specified with our solutions team first: the volume you hold, the retention you are obliged to keep, how your people and systems need access, and where the hardware physically sits.

1. Discovery

A short conversation on the data you hold today, the growth you expect and the obligations you carry.

2. Volume and retention

We size the allocation to the volume of storage you actually need, then set the expansion path in fixed blocks.

3. Access and integration

API, SFTP and session controls mapped to your teams and systems, so governed access fits how you already work.

4. Deployment and pricing

Bunker, on premises or hybrid, with commissioning, support and a written proposal priced to the specified system.

11Beyond 300TB

Beyond 300TB, Storage simply keeps growing.

The same architecture continues in 20TB blocks, with no migration and no new platform. Larger estates are consultation led, with pricing, deployment and integration tailored to your sites and retention obligations.

300TB+

Capacity continues in 20TB blocks, no upper limit

On-premise

Hardware installed in your secure facilities

Multi-site

Split capacity across Bunkers and your own sites

Bespoke

Custom integration, SLAs and support

Request a storage design
12Technical discovery

Bring the data numbers. We will design the Storage around them.

Protected capacity, expected growth, write method, write frequency and preferred location. Five useful answers are better than fifty marketing claims, and the final architecture comes after that.

Storage design inputs

Five useful answers are better than fifty marketing claims.

Our engineering team uses these inputs to scope the physical Storage architecture, the connection model and the next technical conversation, rather than pretending a web page can calculate the final solution.

  • Protected capacity today and the expansion path
  • The write path into the offline tier
  • The write pattern: ingest, change rate, frequency, concurrency
  • The connection window and what closes it
  • Where the hardware physically sits
13Next step

Size the allocation, then take the archive offline.

A short conversation establishes the volume you hold, the retention you are obliged to keep and whether the rack belongs in a Firevault bunker, your own building, or both.

Every deployment includes
  • Dedicated hardware purchased in your name
  • Physical disconnection outside authorised sessions
  • Hardware level AES-256 encryption
  • Identity verified, out-of-band session control
  • Expansion in fixed 20TB steps
  • A system specified with our solutions team, not bought off a shelf
  • Setup, commissioning and ongoing support
Request a storage design
Offline Secure Storage drives on a pull out tray inside a Firevault rack
Physically identifiable

Your allocation is a set of drives that can be pointed at, not a line item in a multi-tenant pool.