How Offline Secure Storage® works

Offline. Authorised. Connected. Offline again.

The #OSS platform separates permanent storage from permanent connectivity. Your data remains on dedicated hardware, while access follows a controlled cycle that introduces the physical path only for an approved session.

Dedicated hardwareVerified identityOut-of-band controlPhysical return offline

One #OSS access session

Offline · secure state
Offline is the secure state.The protected storage is physically disconnected from the customer network until an authorised reason to access it exists.
No standing path

There are two different moments: set up once, then control every access session.

Separating those moments makes #OSS easier to understand. The environment is designed and onboarded first. After that, authorised access follows a repeatable physical state cycle.

01Every access session

Five states. One simple cycle.

The trigger can vary by product, but the universal #OSS behaviour is the same: no standing path, deliberate connection, approved use, then a return offline.

Access session
Dedicated #OSS
01 · Offline

The protected state.

Your dedicated storage sits physically disconnected from the customer network. The data remains stored and encrypted, but there is no active customer network path to it.

Default → offline

02Before first use

Three things establish the protected environment.

The exact implementation varies by product and scale, but the foundations are consistent before normal access begins.

01

Design and configure.

Define the protected data, capacity, access frequency and control model that suit the way the information is actually used.

02

Choose the physical deployment.

Use a managed Firevault Bunker or, for larger Storage and Enterprise architectures, an appropriate customer deployment.

03

Register and onboard identities.

Establish verified users, multi-factor authentication and permissions before normal access begins.

03Control path vs data path

The instruction to connect is separate from the stored asset.

This is the architectural point that turns offline storage into a usable service: control can remain available without requiring the protected storage itself to remain continuously network reachable.

Control path

Always reachable. Never the data.

Authorisation, identity checks and the out-of-band instruction that changes the connection state travel outside the customer data path. That is what makes a deliberate connection possible.

Identity → policy → instruction

Data path

Present only for the session.

The customer network route to your dedicated storage exists because an approved session requires it. When the session ends, the route is physically removed again.

Connected for use → offline by default

05What every #OSS includes

Four physical foundations underneath the workflow.

Capacity and access patterns can change. These are the architectural foundations the customer experience is built around.

Firevault Offline Secure Storage 2TB, 4TB and 8TB physical drives
Dedicated hardware

Physical storage

Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.

Physical drives. Dedicated capacity. Never shared.

01Controlled connectivity

The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.

Layer 1 disconnection. Out-of-band command. No standing exposure.

02Secured offline access

Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.

Named users. Time-limited sessions. Full audit trail.

03Secured offline data

Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.

Quantum Key Encryption. Dedicated drives. Held apart from live systems.

The whole idea

Online when you authorise it. Offline when you do not.

Offline Secure Storage® gives sensitive data a secure physical state to return to. Access becomes a deliberate event, not a permanent network condition.

    Get started