Recent Breaches
Breaches
View All →
Firebreak

The drop-in defence,
at the physical layer.

The ultimate defence is disconnection. Place a connection controller at high-risk access points and protect the network at the wire, in milliseconds, over an out-of-band channel the governed network cannot reach.

Connected

Recognition

NATO DIANATechnology Reseller Awards 2023 Winner — Hardware/Endpoint Device of the YearSC Awards Europe 2025 Winner

What Firebreak is

A connection controller. Nothing more, nothing less.

Firebreak governs whether a network path exists at all. It lets you remotely, securely and physically connect or disconnect any asset on any network, without sending the command over the internet. Containment becomes a property of the wire, not a property of the software that runs on it.

  • Nota firewall
  • Notpacket inspection
  • Nota monitoring tool
  • Notsoftware-defined

Why Layer 1 matters

Control the path, and you decide what is reachable.

01

It controls the actual path

A rule is an instruction to software. A Layer 1 cut is a change in the physical state of the link. Only one of those stays true when the management plane goes wrong.

02

It removes reachability

A closed Firebreak path cannot be scanned, negotiated with or routed around. There is nothing on the other side to answer.

03

It turns connectivity into a decision

Always-on becomes a choice rather than a default. Every link that is up is up because someone agreed it should be.

Key features

Built to drop in, built to last.

Eight things that matter when a network needs a physical control point you can trust under pressure.

  • Instant remote control
  • Works with any outlet, copper or fibre
  • Protects any device or network
  • Plug and play, stack agnostic, no forklift upgrade
  • Administrator and user-friendly interface
  • No special hardware or software for command and control
  • Out-of-band, non-IP command channel
  • Per-port pair independence

Patented Layer 1 architecture

A physical disconnect. Not another firewall.

Globally patented · US + intl
Three movements

No software in the data plane.

Per-zone independence

Cut one zone. Leave the others connected.

Each port pair is its own mechanical reed-switch. Isolate, schedule or restore a single circuit without touching the rest of the estate.

Firebreak 1U · 12 ports · 06 zones
06 live·00 cut·00 sched

Twelve ports, six independent zones, all live

06 LIVE

Click a row to throw its reed switch · auto-demo resumes in 10 s

12 independent zones per 1UPer-zone schedule and auditReversible over the out-of-band path

The range

Four units. One patented principle.

Pick by media and form factor. Reed-switch Layer 1 architecture and out-of-band command path are shared across the line.

R1200-12E unitFlagship · Globally patented
R1200-12E

Copper rack, 12 pairs

1U, 19 inch rack

Ports
12 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response
Fail mode
Fail-open or fail-closed
  • Out-of-band control over dedicated Ethernet, 3GPP cellular SMS or token-gated API
  • Dual redundant AC PSU, 100 to 240 V, 50/60 Hz
1U rack & desktopReed-switch Layer 1Dual AC PSUOut-of-band command path
R1100-4F unit
R1100-4FFibre

Fibre rack, 4 pairs

1U, 19 inch rack

Ports
4 × SFP / SFP+ / SFP28 pairs
Throughput
1, 10 or 25 Gbps per pair
Switching
Physical optical switching, no inline buffer
R1200-4E unit
R1200-4ECopper

Copper rack, 4 pairs

1U, 19 inch rack

Ports
4 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response
S1200 unit
S1200Edge

Desktop edge unit

Small-form desktop

Ports
4 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response

Per-zone independence

Cut one path. Leave the others live.

Each protected port pair is governed on its own, so containing one zone does not interrupt the next. Supplier links, OT segments, backup routes, finance enclaves and R&D networks each keep their own state.

  • Supplier links
  • OT and SCADA
  • Backup routes
  • Finance enclaves
  • R&D networks
  • Management plane
Rapid protection

Drop in. Defend at the wire.

Place Firebreak at high-risk access points and protect the network at the physical layer from day one. No re-architecture, no forklift upgrade, no special hardware or software to run the command path.

Network evolution

Unlock new segmentation patterns.

Extend your existing architecture with physical segmentation control for full traffic isolation. Advance your cyber and operational resilience plans without tearing up what already works.

Explore deployment patterns
A no-brainer. It should be used by any large company.
Head of UK National Cyber Security Centre
NATO DIANA recognisedBroadband-Testing GoldGlobally patented

Deployed in the field

Three anonymised programmes.

01 · Case

NATO / Defence

Tier-1 programme

Air gap on demand for a classified test range with intermittent partner connectivity.

Outcome

Operator-triggered disconnect in milliseconds, full audit log, no inline software in the path.

02 · Case

Critical national infrastructure

Multi-site utility

Severance of the IT and OT boundary during patching windows and SCADA incident response.

Outcome

Scheduled and ad-hoc cuts over SMS and REST API. No re-architecture of the control network.

03 · Case

Regulated finance

Trading floor

Verifiable physical isolation of a settlement enclave from the wider corporate network, on demand.

Outcome

The out-of-band command path satisfied both internal audit and external regulator review.

Professional services

Adopt the right module, the right way.

Firebreak is plug and play, and most teams want a partner for the first rollout. We help you choose the right module, configure it for your environment and run it well, so the value lands quickly and the operations team owns it with confidence.

01

Network configuration

We help map ports, zones and command paths to your existing architecture.

02

Support model design

Roles, runbooks and on-call patterns so cuts and restores are routine, not heroic.

03

Naming and command structures

Clear conventions for ports, zones and Blueprints, so every action reads the same way.

04

Secure command processes

Approval, authentication and audit flows that satisfy internal review and external regulators.

Common questions

Straight answers.

Still have questions?

Firebreak

NATO DIANA recognised · Globally patented · UK and US manufacture

    Firevault

    Firevault is Offline Secure Storage. Hardware you own, physically disconnected by default, with KYC-verified access. Ransomware-proof by design, not by patch.

    © 2026 Firevault Limited. Disconnect to Protect®