---
title: "Firebreak by Firevault, Layer 1 network disconnection hardw…"
description: "Firebreak is Layer 1 hardware that physically cuts and restores network paths on command, from an out-of-band channel that never touches the network it…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/firebreak#webpage",
      "url": "https://fire-vault.com/firebreak",
      "name": "Firebreak by Firevault, Layer 1 network disconnection hardw…",
      "description": "Firebreak is Layer 1 hardware that physically cuts and restores network paths on command, from an out-of-band channel that never touches the network it…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-home.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/firebreak#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/firebreak#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Firebreak by Firevault, Layer 1 network disconnection hardw…",
          "item": "https://fire-vault.com/firebreak"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

What it is

How it worksThe rangeDeploymentsKey featuresProfessional servicesFAQ

Firebreak 

# Firebreak: cut the path, not the business .

Firebreak is Layer 1 hardware that physically opens and closes network paths on command, in milliseconds, per zone. The command path is out of band, so the switch never sits on the wires it is meant to cut.

Organise a demonstration Request a datasheet

L1

Physical

ms

Switching

4

Models

OOB

Command

Disconnected

Path open, path cut, on command

Recognition

![NATO DIANA award logo](/assets/nato-diana-D_ql5tVG.svg) ![Technology Reseller Awards 2023 Winner, Hardware/Endpoint Device of the Year award logo](/__l5e/assets-v1/78131823-f8fb-4976-8fda-3cc64d67c467/tra-2023.png) ![SC Awards Europe 2025 Winner award logo](/__l5e/assets-v1/11e12a77-4a05-458f-b162-fd07e9419426/sc-awards-europe-2025.png) 

01 What Firebreak is 

## A switch, not a sensor.

Firebreak does one job completely: it decides whether the path exists at all. Everything else in your stack keeps doing what it already does.

### What Firebreak is

-   A Layer 1 physical switch in the network path
-   An air gap you can create and reverse on demand
-   Controlled from an out-of-band, non-IP command path
-   Logged, evidential and independent of the estate it protects

### What Firebreak is not

-   A firewall or an inspection appliance
-   Software that can be disabled by a compromised host
-   A protocol-aware device sitting inline in the data plane
-   A forklift upgrade of your existing network

02 How it works 

## Command arrives off the network. The path opens or closes in hardware.

Patented Layer 1 architecture

## A physical disconnect. Not another firewall. 

Globally patented · US + intl 

Three movements

### No software in the data plane.

01 · Trigger 

#### Command over an out-of-band path

An operator, scheduler or third-party system sends the command via cellular SMS, dedicated OOB Ethernet or a token-gated API. Never on the internet or the network being controlled.

Command channel Cellular · OOB · API 

02 · Cut 

#### Reed switches break the wire

High-reliability mechanical switches sever the Layer 1 path in the millisecond range. No inline software stack, no protocol awareness, nothing to compromise.

Physical cut < 10 ms 

03 · Verify 

#### Physical isolation, fully logged

The segment is gone from the network. The action is logged locally and to SysLog for audit. Reversible on the same out-of-band command.

Audit trail Local + SysLog 

Per-zone independence

### Cut one zone. Leave the others connected.

Each port pair is its own mechanical reed-switch. Isolate, schedule or restore a single circuit without touching the rest of the estate.

Firebreak 1U · 12 ports · 06 zones 

05 live · 00 cut · 01 sched 

Z01 · PORT 01/02

HQ Core

WAN edge 

Core switch 

Live 

Z02 · PORT 03/04

OT plant

SCADA ring 

Plant trunk 

Live 

Z03 · PORT 05/06

Finance core

Settlement 

Ledger fabric 

Live 

Z04 · PORT 07/08

Hospital ward

Clinical VLAN 

Imaging store 

Live 

Z05 · PORT 09/10

Vendor link

3rd party 

Jump host 

Sched 

Z06 · PORT 11/12

R&D fabric

GPU cluster 

Lab uplink 

Live 

OT plant restored over the out-of-band path

RESTORED · 12 ms 

Click a row to throw its reed switch · auto-demo resumes in 10 s

12 independent zones per 1U Per-zone schedule and audit Reversible over the out-of-band path 

03 The range 

## Four models: copper, fibre and edge.

Pick the model that matches the port type and the place it sits. The command path and the behaviour are identical across the range.

✓ The range

## Four units. One patented principle.

Pick by media and form factor. Reed-switch Layer 1 architecture and out-of-band command path are shared across the line.

![R1200-12E unit](/__l5e/assets-v1/c2f11d93-b80e-4671-9da2-79d341e2fc5f/r1200-12e-front.png)Flagship · Globally patented 

R1200-12E

### Copper rack, 12 pairs

1U, 19 inch rack

Ports

12 × RJ45 port pairs

Throughput

Up to 10 GbE per pair

Switching

Reed-switch Layer 1, millisecond response

Fail mode

Fail-open or fail-closed

-   Out-of-band control over dedicated Ethernet, 3GPP cellular SMS or token-gated API 
-   Dual redundant AC PSU, 100 to 240 V, 50/60 Hz 

Request datasheetOrganise demo

1U rack & desktop Reed-switch Layer 1 Dual AC PSU Out-of-band command path 

![R1100-4F unit](/__l5e/assets-v1/b9c0cec7-2fac-456e-b58e-bdd81be376a2/r1100-4f-front.png)

R1100-4F Fibre 

### Fibre rack, 4 pairs

1U, 19 inch rack

Ports

4 × SFP / SFP+ / SFP28 pairs

Throughput

1, 10 or 25 Gbps per pair

Switching

Physical optical switching, no inline buffer

Request a quote

![R1200-4E unit](/__l5e/assets-v1/c2f11d93-b80e-4671-9da2-79d341e2fc5f/r1200-12e-front.png)

R1200-4E Copper 

### Copper rack, 4 pairs

1U, 19 inch rack

Ports

4 × RJ45 port pairs

Throughput

Up to 10 GbE per pair

Switching

Reed-switch Layer 1, millisecond response

Request a quote

![S1200 unit](/__l5e/assets-v1/6f6ba319-66e6-4edc-9d73-57765f608e3c/s1200-desktop.png)

S1200 Edge 

### Desktop edge unit

Small-form desktop

Ports

4 × RJ45 port pairs

Throughput

Up to 10 GbE per pair

Switching

Reed-switch Layer 1, millisecond response

Request a quote

04 Deployments 

## Where Firebreak is already in service.

### NATO and defence

Tier-1 programme

Air gap on demand for a classified test range with intermittent partner connectivity.

Operator-triggered disconnect in milliseconds, full audit log, no inline software in the path.

### Critical national infrastructure

Multi-site utility

Severance of the IT and OT boundary during patching windows and SCADA incident response.

Scheduled and ad-hoc cuts over SMS and REST API, with no re-architecture of the control network.

### Regulated finance

Trading floor

Verifiable physical isolation of a settlement enclave from the wider corporate network, on demand.

The out-of-band command path satisfied both internal audit and external regulator review.

05 Key features 

## Everything a Firebreak unit does, in plain terms.

-   Instant remote control
-   Works with any outlet, copper or fibre
-   Protects any device or network
-   Plug and play, stack agnostic, no forklift upgrade
-   Administrator and user-friendly interface
-   No special hardware or software for command and control
-   Out-of-band, non-IP command channel
-   Per-port pair independence

06 Professional services 

## We deploy it with you, not at you.

### Network configuration

We help map ports, zones and command paths to your existing architecture.

### Support model design

Roles, runbooks and on-call patterns so cuts and restores are routine, not heroic.

### Naming and command structures

Clear conventions for ports, zones and Blueprints, so every action reads the same way.

### Secure command processes

Approval, authentication and audit flows that satisfy internal review and external regulators.

07 FAQ 

## Questions engineers ask first.

### Is Firebreak an air gap?

On demand, yes. When Firebreak cuts a path, the segment is severed at Layer 1. It is disconnected on that interface, invisible to scans on it, and independent of any software that might have been compromised.

### Does Firebreak replace firewalls?

No. Firewalls inspect and filter traffic on connections that still exist. Firebreak removes the connection itself. The two complement each other rather than substitute for each other.

### Does Firebreak inspect or filter traffic?

No. Firebreak sits at Layer 1 and has no inline protocol stack in the data path. When the path is cut, there is no payload to inspect because there is no link.

### How are commands authenticated?

The command path is out of band by design. The web interface uses multi-factor authentication with brute-force protection. SMS uses structured commands with number filtering and a secondary code. The API uses scoped access tokens. Every action is logged.

### How does Firebreak fit into Control?

Control is the wider framework of Fire and Vault modules, packaged into Control Blueprints. Firebreak is the physical control point that delivers the Layer 1 cut wherever a Blueprint calls for one.

### How does Firebreak support compliance evidence?

Every cut, restore and command is logged on the appliance with the actor, the channel and the outcome. The evidential trail maps directly to the isolation and operational-resilience expectations in regimes such as NIS2 and DORA.

### Do you offer help with deployment?

Yes. Our professional services team helps you choose the right module, plan the rollout and operate it well, through to handover to your operations team.

## See a path cut in front of you.

A member of the team will show you a live cut and restore, then map the right model to your ports and zones.

Organise a demonstration [How Firebreak fits into Control](/control)

[![Firevault - physical control for critical data](/assets/logo-white-official-BKfZ19hm.png)](/)

International cyber resilience

## Protect what matters. Control what moves. 

Firevault is an international cyber resilience company specialising in Offline Secure Storage® and OT cyber security, helping organisations protect critical data and govern how systems connect and how data moves.

[hello@fire-vault.com](mailto:hello@fire-vault.com)Europe, US and Middle East 

Cyber security certified 

[

![Cyber Essentials Certified](https://fire-vault.com/__l5e/assets-v1/6f8f42a2-89e1-4c20-938f-3f34d30bc90c/cyber-essentials-2026.png)

![Cyber Essentials Plus Certified](https://fire-vault.com/__l5e/assets-v1/8a77bf2c-6711-4762-b093-c4d650153bc9/cyber-essentials-plus-2026.png)

](https://registry.blockmarktech.com/certificates/)

Start here

### Not sure what you need?

Use the OSS Concierge to find the right protection or control approach for your organisation.

[Find your starting point ](/find-my-oss)

01  · Data protection & storage

[](/offline-secure-storage)

[

### Offline Secure Storage®

](/offline-secure-storage)

Physically disconnected by default, identity verified and built on dedicated hardware, from 300GB personal storage to enterprise-scale infrastructure.

[OSS overview](/offline-secure-storage)[LUV](/luv)[Vault](/vault)[Storage](/storage)[Enterprise](/enterprise)[Bunkers](/bunkers)

02  · Network evolution and rapid protection

[](/control)

[

### Control

](/control)

Nine governance modules across FIRE and VAULT, composed into Control Blueprints around the outcome, environment and risk you need to manage.

[Control overview](/control)[Nine modules](/control/nine-modules)[Blueprints](/control-blueprints)[Firebreak](/control/modules/firebreak)[Control by industry](/control-for-industry)

### Knowledge

-   [Knowledge Vault ](/learn/knowledge)
-   [Buyer guides ](/learn/guides/by-role)
-   [Technical guides ](/learn/guides/technical)
-   [Firevault Playbooks ](/playbooks)
-   [White papers ](/learn/whitepapers)
-   [Learn and explainers ](/learn)
-   [Breach tracker ](/learn/breaches)
-   [FAQs ](/learn/faq)

### Firevault

-   [About Firevault ](/about)
-   [Security ](/security)
-   [Partners ](/partners)
-   [Press and media ](/press-media)
-   [Help Centre ](/help)
-   [Careers ](/careers)
-   [Invest in Firevault ](/investors)
-   [Contact ](/contact)

© 2026 Firevault Limited · Company No. 16320803 · VAT No. 490 8551 64 · Registered in England and Wales 

[Site Map](/sitemap)[Privacy Charter](/privacy-charter)[Terms](/terms)[Planet Pledge](/planet-pledge)[Vault Commitment](/vault-commitment)[LUV Commitment](/luv-commitment)[Cookie Policy](/cookies)

[](https://www.linkedin.com/company/firevault-limited)[](https://twitter.com/firevaultuk)

![Firevault](/favicon.svg)

Not sure where to start? Ask us. 

Privacy 

## You decide what we measure

Essential cookies keep this site working. Everything else is optional and off until you say otherwise. Read the [Privacy Charter](/privacy-charter) or the [Cookie Policy](/cookies).

Accept allEssential only

Manage options