Offline. Authorised. Connected. Offline again.
The #OSS platform separates permanent storage from permanent connectivity. Your data remains on dedicated hardware, while access follows a controlled cycle that introduces the physical path only for an approved session.
One #OSS access session
Offline · secure stateThere are two different moments: set up once, then control every access session.
Separating those moments makes #OSS easier to understand. The environment is designed and onboarded first. After that, authorised access follows a repeatable physical state cycle.
Five states. One simple cycle.
The trigger can vary by product, but the universal #OSS behaviour is the same: no standing path, deliberate connection, approved use, then a return offline.
The protected state.
Your dedicated storage sits physically disconnected from the customer network. The data remains stored and encrypted, but there is no active customer network path to it.
Default → offline
Three things establish the protected environment.
The exact implementation varies by product and scale, but the foundations are consistent before normal access begins.
Design and configure.
Define the protected data, capacity, access frequency and control model that suit the way the information is actually used.
Choose the physical deployment.
Use a managed Firevault Bunker or, for larger Storage and Enterprise architectures, an appropriate customer deployment.
Register and onboard identities.
Establish verified users, multi-factor authentication and permissions before normal access begins.
The instruction to connect is separate from the stored asset.
This is the architectural point that turns offline storage into a usable service: control can remain available without requiring the protected storage itself to remain continuously network reachable.
Always reachable. Never the data.
Authorisation, identity checks and the out-of-band instruction that changes the connection state travel outside the customer data path. That is what makes a deliberate connection possible.
Identity → policy → instruction
Present only for the session.
The customer network route to your dedicated storage exists because an approved session requires it. When the session ends, the route is physically removed again.
Connected for use → offline by default
One physical principle. Different workflows.
LUV, Vault, Storage and Enterprise do not all start an access session in the same way. The physical state model stays consistent while the trigger and interface vary.
Defined approved access windows for low-use, high-importance data.
Controlled window VaultIdentity-verified, on-demand access to dedicated personal or professional storage.
On demand StorageScheduled or on-demand organisational workflows using SFTP, API or approved data movement.
Workflow driven EnterprisePolicy-governed access designed around the larger environment and operating model.
EngineeredFour physical foundations underneath the workflow.
Capacity and access patterns can change. These are the architectural foundations the customer experience is built around.

Physical storage
Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.
Physical drives. Dedicated capacity. Never shared.
The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.
Layer 1 disconnection. Out-of-band command. No standing exposure.
Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.
Named users. Time-limited sessions. Full audit trail.
Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.
Quantum Key Encryption. Dedicated drives. Held apart from live systems.
Online when you authorise it. Offline when you do not.
Offline Secure Storage® gives sensitive data a secure physical state to return to. Access becomes a deliberate event, not a permanent network condition.