Enterprise : sovereign offline secure storage.
Enterprise is Offline Secure Storage® at national scale, from 300TB upwards. Dedicated hardware your organisation legally owns, installed in your own secure facilities or a Firevault bunker, with the management plane physically separated from the data plane and no standing network route to the archive.
Site survey, rack design, commissioning, integration and support, specified with our solutions team. Vault and LUV can be bought online. Enterprise follows a written proposal covering capacity, sites, clearance requirements and SLAs.
Hospital data is physically disconnected.
National scale hardware, in a place you control, with no route left waiting.
Enterprise is not a larger cloud tier. It is a physical allocation of drives purchased in your name, racked in your own secure facility or a Firevault bunker, managed out of band and disconnected from the network whenever it is not in an authorised session.
The archive itself, offline unless an authorised session is open.
On-premise deployment
Hardware installed and commissioned inside your own secure facilities, so no data has to leave your perimeter to be protected.
Dedicated hardware
Purpose-built, physically identifiable storage arrays purchased in your name. Not shared racks and not virtualised partitions.
Physically disconnected
There is no standing network route to the drives. The path exists for an authorised session and is then physically removed.
Held out of band, physically separated from the drives it governs.
Out-of-band management
The management plane is physically separated from the data plane, which removes the usual lateral movement route into the archive.
Hardware level encryption
AES-256 applied at the hardware layer across every drive, controller and transport, independent of any application staying uncompromised.
Cleared personnel
Commissioning, maintenance and physical handling by vetted engineers, with SC and DV cleared personnel available where a programme requires it.
Organisations where data loss becomes a national problem.
Enterprise is the top tier of Offline Secure Storage®. Vault and LUV protect what one person or one household holds. Storage protects the organisation from 20TB to 300TB. Enterprise takes the same physical principles into critical national infrastructure, defence and sovereign programmes above 300TB.
Critical national infrastructure
Energy, water, telecoms and transport operators where the loss of operational baselines creates systemic national risk.
Defence and government
Sovereign data programmes, classified document holdings and intelligence-grade requirements for physical isolation.
Large enterprises
Organisations holding 300TB and beyond of sensitive data that need physical isolation and provable data sovereignty.
Regulated industries
Banking, healthcare and legal groups whose regulators expect evidence that the gold copy cannot be reached remotely.
Engineering, clearance and reporting, delivered with the hardware.
An Enterprise deployment is a programme rather than a product order. The capability set covers the engineering that installs it, the people who handle it and the evidence your regulators and insurers expect to see.
Deployment engineering
Site survey, rack design, power and cooling planning, commissioning and handover run by a named engineering team.
Multi-site architecture
Capacity split across your own facilities and Firevault bunkers, so the loss of one site does not remove the archive.
Custom integration
API, SFTP and bespoke pathways into existing backup, archive and operational technology workflows.
Evidence and reporting
Every connection, disconnection and identity verification recorded and exportable for SIEM ingestion, audit and insurer packs.
Named account team
A named account manager and technical lead for the life of the programme, with agreed response and escalation paths.
Capacity without limit
Growth continues in 20TB blocks on the same architecture, with no migration and no new platform to adopt.
Your facility, a Firevault bunker, or a sovereign hybrid.
The protection model does not change with the location. What changes is who holds physical custody of the rack, and whether the gold copy sits away from your primary site.
In a Firevault bunker
Your hardware is racked in a protected physical location with controlled entry, held under Firevault custody and separated from your operational network.
On your premises
The same hardware and the same physical disconnection, installed in your own secure facility and under your own physical custody.
A sovereign hybrid
A working set on your sites with the gold copy held in a Firevault bunker, so a single site loss never removes the archive.
Protected physical locations with controlled entry, held under Firevault custody and physically separated from your operational network.
Bespoke does not mean unexplained.
Enterprise from 300TB is quoted against your estate, but the pricing model itself is fixed and published. Two variables drive the figure, and the worked model below shows how they trade against each other.
OSAP, Offline Secure Access Profile
One named person, with their own identity-locked route into the offline capacity. More people means more profiles, never a shared login.
OSSC, Offline Secure Storage Capacity
The disconnected capacity itself, held on dedicated hardware in a Firevault Bunker and mirrored with RAID 1.
Enterprise is built on four physical principles.
Firevault Enterprise is Offline Secure Storage® at national scale. The same four physical principles apply, from 300TB upwards across as many sites as the programme requires.

Physical storage
Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.
Physical drives. Dedicated capacity. Never shared.
The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.
Layer 1 disconnection. Out-of-band command. No standing exposure.
Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.
Named users. Time-limited sessions. Full audit trail.
Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.
Quantum Key Encryption. Dedicated drives. Held apart from live systems.
Governed access that fits the estate you already run.
Enterprise sits behind your primary and backup tiers as the offline gold copy. Access is opened for a named individual over an out-of-band channel, used, then physically removed, with every action recorded.
SFTP endpoint
Standard clients and standard ciphers, reachable only during an authorised connection window. Off window the endpoint is not on the network.
REST scheduling API
An out-of-band control plane to schedule windows, list audit events and trigger emergency offline from your own operations tooling.
Existing backup estate
Sits behind your primary and backup tiers as the offline gold copy, written to on schedule or on demand during authorised windows.
Delegated access
Named individuals hold defined rights over defined data sets, so the archive is usable by a team without becoming open to it.
Same principles, different scale and custody.
Storage covers 20TB to 300TB for a single organisation, held in a Firevault bunker, on your premises or a hybrid of both. Enterprise begins where that ends: capacity above 300TB, installation inside your own secure facilities, out-of-band management and cleared personnel.
Mapped to the frameworks your regulator already uses.
Firevault maps Offline Secure Storage® controls to recognised framework outcomes rather than claiming certification on your behalf. Cyber Essentials Plus is held by Firevault. Framework mapping, including NCSC CAF outcomes, is provided as evidence for your own assessment.
- CNI
- Built for critical national infrastructure duties
- NIS2
- Supports resilience and recovery obligations
- ISO 27001
- Aligns with information security controls
- Cyber Essentials Plus
- Firevault certified
- NCSC CAF
- Control mapping to CAF outcomes on request
- GDPR
- Data sovereignty and retention evidence
Specified with our solutions team, not bought off a shelf.
Every Enterprise deployment starts with the data you hold, the obligations you carry and the sites you control. Pricing follows the specified system, in a written proposal.
- 01
Discovery
The data you hold, the growth you expect, the obligations you carry and the clearance the programme requires.
- 02
Site and survey
Rack design, power, cooling and physical security assessed for your facilities, a Firevault bunker, or both.
- 03
Integration design
API, SFTP and bespoke pathways mapped to your backup, archive and operational technology workflows.
- 04
Proposal and delivery
Commissioning, handover, SLAs and named support, priced against the specified system in a written proposal.
Scope the programme, then take the estate offline.
A short conversation establishes the volume you hold, the clearance the work requires and whether the racks belong in your own facilities, a Firevault bunker, or both.
- Dedicated hardware purchased in your name
- Physical disconnection outside authorised sessions
- Hardware level AES-256 encryption throughout
- Out-of-band management separated from the data plane
- Deployment engineering, commissioning and handover
- Named account manager and technical lead
Enterprise is consultation led. Tell us the capacity, the sites and the obligations, and a member of the team will come back with a written proposal.