Enterprise by Firevault

Enterprise : sovereign offline secure storage.

Enterprise is Offline Secure Storage® at national scale, from 300TB upwards. Dedicated hardware your organisation legally owns, installed in your own secure facilities or a Firevault bunker, with the management plane physically separated from the data plane and no standing network route to the archive.

Delivered as a programmeNo online checkout

Site survey, rack design, commissioning, integration and support, specified with our solutions team. Vault and LUV can be bought online. Enterprise follows a written proposal covering capacity, sites, clearance requirements and SLAs.

Enterprise or Storage
Hospital
Manufacturing
Financial
Enterprise
Offline
Offline
STORAGE
Hospital
Offline
STORAGE

Hospital data is physically disconnected.

Estate session captureLoop
00:0000:14
Sites request access, the control plane authorises out of band, the window opens for the transfer, then the physical path is removed.
Animated illustration, no audio.
Firevault Enterprise Offline Secure Storage cabinets racked inside a protected physical location
Physically disconnected by default
300TB and beyondCapacity
Owned by youHardware
Out of bandManagement
Yours, ours or bothSites
300TB and beyondOffline by defaultDedicated hardware you ownCleared personnel
01What Enterprise is

National scale hardware, in a place you control, with no route left waiting.

Enterprise is not a larger cloud tier. It is a physical allocation of drives purchased in your name, racked in your own secure facility or a Firevault bunker, managed out of band and disconnected from the network whenever it is not in an authorised session.

Data planeOFFLINE

The archive itself, offline unless an authorised session is open.

On-premise deployment

Hardware installed and commissioned inside your own secure facilities, so no data has to leave your perimeter to be protected.

Dedicated hardware

Purpose-built, physically identifiable storage arrays purchased in your name. Not shared racks and not virtualised partitions.

Physically disconnected

There is no standing network route to the drives. The path exists for an authorised session and is then physically removed.

Management planeOUT OF BAND

Held out of band, physically separated from the drives it governs.

Out-of-band management

The management plane is physically separated from the data plane, which removes the usual lateral movement route into the archive.

Hardware level encryption

AES-256 applied at the hardware layer across every drive, controller and transport, independent of any application staying uncompromised.

Cleared personnel

Commissioning, maintenance and physical handling by vetted engineers, with SC and DV cleared personnel available where a programme requires it.

Firevault - offline secure storage
02Who Enterprise is for

Organisations where data loss becomes a national problem.

Enterprise is the top tier of Offline Secure Storage®. Vault and LUV protect what one person or one household holds. Storage protects the organisation from 20TB to 300TB. Enterprise takes the same physical principles into critical national infrastructure, defence and sovereign programmes above 300TB.

Critical national infrastructure

Energy, water, telecoms and transport operators where the loss of operational baselines creates systemic national risk.

Defence and government

Sovereign data programmes, classified document holdings and intelligence-grade requirements for physical isolation.

Large enterprises

Organisations holding 300TB and beyond of sensitive data that need physical isolation and provable data sovereignty.

Regulated industries

Banking, healthcare and legal groups whose regulators expect evidence that the gold copy cannot be reached remotely.

03Capabilities

Engineering, clearance and reporting, delivered with the hardware.

An Enterprise deployment is a programme rather than a product order. The capability set covers the engineering that installs it, the people who handle it and the evidence your regulators and insurers expect to see.

Deployment engineering

Site survey, rack design, power and cooling planning, commissioning and handover run by a named engineering team.

Multi-site architecture

Capacity split across your own facilities and Firevault bunkers, so the loss of one site does not remove the archive.

Custom integration

API, SFTP and bespoke pathways into existing backup, archive and operational technology workflows.

Evidence and reporting

Every connection, disconnection and identity verification recorded and exportable for SIEM ingestion, audit and insurer packs.

Named account team

A named account manager and technical lead for the life of the programme, with agreed response and escalation paths.

Capacity without limit

Growth continues in 20TB blocks on the same architecture, with no migration and no new platform to adopt.

04Deployment

Your facility, a Firevault bunker, or a sovereign hybrid.

The protection model does not change with the location. What changes is who holds physical custody of the rack, and whether the gold copy sits away from your primary site.

In a Firevault bunker

Your hardware is racked in a protected physical location with controlled entry, held under Firevault custody and separated from your operational network.

On your premises

The same hardware and the same physical disconnection, installed in your own secure facility and under your own physical custody.

A sovereign hybrid

A working set on your sites with the gold copy held in a Firevault bunker, so a single site loss never removes the archive.

A Firevault bunker, the protected physical location that holds Enterprise Offline Secure Storage hardware
Firevault bunker

Protected physical locations with controlled entry, held under Firevault custody and physically separated from your operational network.

Pricing

Bespoke does not mean unexplained.

Enterprise from 300TB is quoted against your estate, but the pricing model itself is fixed and published. Two variables drive the figure, and the worked model below shows how they trade against each other.

OSAP, Offline Secure Access Profile

One named person, with their own identity-locked route into the offline capacity. More people means more profiles, never a shared login.

OSSC, Offline Secure Storage Capacity

The disconnected capacity itself, held on dedicated hardware in a Firevault Bunker and mirrored with RAID 1.

The #OSS difference

Enterprise is built on four physical principles.

Firevault Enterprise is Offline Secure Storage® at national scale. The same four physical principles apply, from 300TB upwards across as many sites as the programme requires.

Firevault Offline Secure Storage 2TB, 4TB and 8TB physical drives
Dedicated hardware

Physical storage

Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.

Physical drives. Dedicated capacity. Never shared.

01Controlled connectivity

The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.

Layer 1 disconnection. Out-of-band command. No standing exposure.

02Secured offline access

Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.

Named users. Time-limited sessions. Full audit trail.

03Secured offline data

Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.

Quantum Key Encryption. Dedicated drives. Held apart from live systems.

05Integration and governance

Governed access that fits the estate you already run.

Enterprise sits behind your primary and backup tiers as the offline gold copy. Access is opened for a named individual over an out-of-band channel, used, then physically removed, with every action recorded.

01

SFTP endpoint

Standard clients and standard ciphers, reachable only during an authorised connection window. Off window the endpoint is not on the network.

02

REST scheduling API

An out-of-band control plane to schedule windows, list audit events and trigger emergency offline from your own operations tooling.

03

Existing backup estate

Sits behind your primary and backup tiers as the offline gold copy, written to on schedule or on demand during authorised windows.

04

Delegated access

Named individuals hold defined rights over defined data sets, so the archive is usable by a team without becoming open to it.

06Enterprise or Storage

Same principles, different scale and custody.

Storage covers 20TB to 300TB for a single organisation, held in a Firevault bunker, on your premises or a hybrid of both. Enterprise begins where that ends: capacity above 300TB, installation inside your own secure facilities, out-of-band management and cleared personnel.

CapabilityFirevault EnterpriseFirevault Storage
Physically disconnected by default
Dedicated hardware you legally own
Capacity above 300TB as standard
Installed inside your own secure facilities
Out-of-band management plane
SC and DV cleared personnel available
Multi-site sovereign architecture
Bespoke SLAs and integration engineering
07Compliance alignment

Mapped to the frameworks your regulator already uses.

Firevault maps Offline Secure Storage® controls to recognised framework outcomes rather than claiming certification on your behalf. Cyber Essentials Plus is held by Firevault. Framework mapping, including NCSC CAF outcomes, is provided as evidence for your own assessment.

CNI
Built for critical national infrastructure duties
NIS2
Supports resilience and recovery obligations
ISO 27001
Aligns with information security controls
Cyber Essentials Plus
Firevault certified
NCSC CAF
Control mapping to CAF outcomes on request
GDPR
Data sovereignty and retention evidence
08How a programme runs

Specified with our solutions team, not bought off a shelf.

Every Enterprise deployment starts with the data you hold, the obligations you carry and the sites you control. Pricing follows the specified system, in a written proposal.

  1. 01

    Discovery

    The data you hold, the growth you expect, the obligations you carry and the clearance the programme requires.

  2. 02

    Site and survey

    Rack design, power, cooling and physical security assessed for your facilities, a Firevault bunker, or both.

  3. 03

    Integration design

    API, SFTP and bespoke pathways mapped to your backup, archive and operational technology workflows.

  4. 04

    Proposal and delivery

    Commissioning, handover, SLAs and named support, priced against the specified system in a written proposal.

09Next step

Scope the programme, then take the estate offline.

A short conversation establishes the volume you hold, the clearance the work requires and whether the racks belong in your own facilities, a Firevault bunker, or both.

Every programme includes
  • Dedicated hardware purchased in your name
  • Physical disconnection outside authorised sessions
  • Hardware level AES-256 encryption throughout
  • Out-of-band management separated from the data plane
  • Deployment engineering, commissioning and handover
  • Named account manager and technical lead

Enterprise is consultation led. Tell us the capacity, the sites and the obligations, and a member of the team will come back with a written proposal.

Get started