What OSS stores
Offline Secure Storage holds the data you cannot re-create. Records, gold copies, keys and archives sit on dedicated hardware inside a Firevault Bunker, physically disconnected between access windows.
- Any file format
- Dedicated hardware
- Physically disconnected
- Identity-verified access

- LUV, deep cold personal vault
- 300GBLUV, deep cold personal vault£74.99 per month, 36-month commitment
- Vault, 24/7 business vault
- 2–8TBVault, 24/7 business vault
- Storage, scales in 20TB steps
- 20TB+Storage, scales in 20TB steps
- Enterprise, jurisdiction-aligned
- 300TB+Enterprise, jurisdiction-aligned
If losing it would change the business, it belongs offline
OSS is not general-purpose storage. It is the place for the small share of your data that carries disproportionate consequence: the copy of record, the evidence, the keys, the archive. Everything else can stay where it is.
Cannot be re-created
Originals, signed records and historic archives with no upstream source to pull from again.
Cannot be exposed
Client, personal and commercially sensitive data where a breach is a regulatory and reputational event.
Not needed hourly
Data whose value is integrity and custody over time, not constant read and write access.
Four questions that decide what should be secured offline
Run each candidate data set through these questions. If it is rarely accessed and meets any one of the other three, it belongs on dedicated, physically disconnected storage.
Is it accessed every day?
Data used continuously by people and applications should stay connected. Offline suits information that is important but infrequently opened.
Rarely opened → offline candidate
Would losing it, or losing control of it, be serious?
Judge by consequence rather than volume. A single folder of board papers can matter more than terabytes of routine files.
High consequence → offline candidate
Is it the copy you would rebuild from?
Anything you depend on during an incident should not share the same connected environment as the systems it may need to restore.
Recovery source → offline candidate
Must you retain it, whether or not you use it?
Records kept for legal, regulatory or contractual reasons carry obligation without needing permanent availability.
Retained obligation → offline candidate
The eight classes we see most
Each class maps to a Firevault product and a defined access pattern. Follow a class through to see how it is handled end to end.
Personal records
Passports, birth and marriage certificates, wills, deeds, insurance policies and family archives. The documents that are slow, expensive or impossible to replace.
See how it is storedBusiness records
Board minutes, shareholder agreements, statutory registers, contracts and finance records held as a clean, offline copy of record.
See how it is storedClient and case files
Matter files, engagement records, evidence bundles and client identity documents held by regulated firms with a duty of confidentiality.
See how it is storedGold copy backups
The final, verified copy of your critical systems and datasets, held physically apart from production and from your online backup estate.
See how it is storedKeys and recovery material
Recovery codes, root and signing keys, certificate material and break-glass credentials kept off every network until they are needed.
See how it is storedMedia, IP and research
Masters, design files, source code archives, research datasets and trade secrets that carry long-term commercial value.
See how it is storedSystem configurations
Golden images, controller configurations and network documentation for OT and ICS environments, held offline so a rebuild is always possible.
See how it is storedRegulatory archives
Long retention sets held for GDPR, NIS2, DORA and sector rules, where the requirement is integrity and provable custody rather than daily access.
See how it is storedThe same split, in four different operating models
What stays connected and what moves offline changes with the work. The judgement behind it does not.
Active matter files in the practice management system
Closed matters, wills, deeds, privileged evidence and client identity records
Live client reporting and workflow platforms
Audit evidence, statutory records, key material and retained client documentation
Operational control systems and current process data
Known-good configurations, PLC backups and recovery images
Current board portal and meeting collaboration
Board minutes, transaction papers, succession plans and shareholder records
Capacity, access and what each product holds
Pick the product by the volume you need to hold and how often you need to reach it. LUV and Vault can be bought online. Storage and Enterprise are designed with our solutions team.
- Access
- One nominated day each week, 12-hour window
- Holds
- About 60,000 high-resolution photos, or 150,000 PDF documents
- Suits
- Personal records, keys and a single household archive
- Access
- 24/7 on-demand access
- Holds
- About 400,000 to 1.6 million high-resolution photos
- Suits
- Business records, client files and working archives
- Access
- Scheduled transfer, designed with our solutions team
- Holds
- About 2 million high-resolution photos, or 5 million PDF documents
- Suits
- Gold copies, media libraries and server replacement
- Access
- Dedicated, jurisdiction-aligned deployment
- Holds
- About 60 million high-resolution photos, or 150 million PDF documents
- Suits
- Critical national infrastructure and regulated estates
| Product | Capacity | Access | Roughly holds | Best suited to |
|---|---|---|---|---|
| LUV | 300GB | One nominated day each week, 12-hour window | About 60,000 high-resolution photos, or 150,000 PDF documents | Personal records, keys and a single household archive |
| Vault | 2TB to 8TB | 24/7 on-demand access | About 400,000 to 1.6 million high-resolution photos | Business records, client files and working archives |
| Storage | 20TB and above, in 20TB steps | Scheduled transfer, designed with our solutions team | About 2 million high-resolution photos, or 5 million PDF documents | Gold copies, media libraries and server replacement |
| Enterprise | 300TB and above | Dedicated, jurisdiction-aligned deployment | About 60 million high-resolution photos, or 150 million PDF documents | Critical national infrastructure and regulated estates |
Volume figures are indicative estimates based on typical file sizes, not guarantees.
What OSS deliberately does not do
Being clear about the boundary is part of the product. OSS is the offline copy of record, not a replacement for the systems that run your day.
Live production systems
OSS is not a hosting platform. Applications, databases and virtual machines keep running where they run today. OSS holds the copy of record you would rebuild from.
Always-on file sync
There is no continuous sync client. Data moves during a defined access window, which is precisely why ransomware cannot follow it.
Your only backup
OSS sits alongside your day-to-day backup, as the final offline copy. It replaces the online third copy, not your operational restore point.
Systems and access control
Governing who can reach which systems is a Control problem, not a storage one. That work sits with Control and Control Blueprints.
Questions about what goes in
What kind of data should go into Offline Secure Storage?
Data you cannot re-create, cannot afford to lose and do not need every hour. Personal and statutory records, client and case files, gold copy backups, keys and recovery material, long-term media and regulatory archives.
Are there file types OSS cannot hold?
No. OSS is block-level storage on dedicated hardware, so any file format is supported. The decision is about value and access frequency, not file type.
How is this different from a backup?
A backup usually lives on network-connected infrastructure and can be discovered and encrypted with the rest of the estate. OSS is physically disconnected between access windows, so there is no network path to it at all.
How do I get data in and out?
Data is written during an identity-verified access window. LUV uses one nominated day each week within a 12-hour window. Vault is available 24/7 on demand. Storage and Enterprise are designed with our solutions team around your transfer schedule.
Where does the hardware sit?
In carefully selected Firevault Bunkers. Europe, including the United Kingdom, is live today, with the United States and Middle East next. Firevault provisions your vault where it chooses unless you request a specific jurisdiction.
Should everything be moved offline?
No. Offline Secure Storage® is not a replacement for cloud or day-to-day storage. It gives high-consequence data a different availability model, so connectivity becomes an authorised event rather than a permanent condition.
How do I decide what qualifies?
Apply four tests: how often is it accessed, how serious is compromise or loss, is it the copy you would rebuild from, and are you obliged to retain it. Data that fails the frequency test and passes any of the other three is an offline candidate.
Is offline storage the same as an immutable backup?
No. Immutability prevents change while the storage remains network reachable. Offline Secure Storage® removes the network path itself, so there is no standing route to the protected data between authorised sessions.
Decide what belongs offline, then size the vault
Tell us what you need to hold and how often you need to reach it. We will match it to LUV, Vault, Storage or Enterprise.