---
title: "How Offline Secure Storage Works | Firevault #OSS"
description: "How the Offline Secure Storage platform works: offline by default, authorised access, physical connection, approved use and a return offline."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/how-oss-works#webpage",
      "url": "https://fire-vault.com/how-oss-works",
      "name": "How Offline Secure Storage Works",
      "description": "How the Offline Secure Storage platform works: offline by default, authorised access, physical connection, approved use and a return offline.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/images/og/og-base-platform.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/how-oss-works#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/how-oss-works#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "How Offline Secure Storage Works",
          "item": "https://fire-vault.com/how-oss-works"
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

OverviewEvery Session

Before First UseControl vs DataBy ProductWhat Every #OSS Includes

How Offline Secure Storage® works 

# Offline. Authorised. Connected. Offline again. 

The #OSS platform separates permanent storage from permanent connectivity. Your data remains on dedicated hardware, while access follows a controlled cycle that introduces the physical path only for an approved session.

[Follow an access session](#access) [Explore #OSS products](/offline-secure-storage)

Dedicated hardware Verified identity Out-of-band control Physical return offline 

One #OSS access session

Offline · secure state 

01 **Offline**No standing customer network path. 02 **Authorise**Identity and access rule checked. 03 **Connect**Physical path introduced for the session. 04 **Use**Use the data through the approved interface. 05 **Disconnect**Session closes. Storage returns offline. 

**Offline is the secure state.**The protected storage is physically disconnected from the customer network until an authorised reason to access it exists. 

No standing path 

There are two different moments: set up once , then control every access session. 

Separating those moments makes #OSS easier to understand. The environment is designed and onboarded first. After that, authorised access follows a repeatable physical state cycle.

01 Every access session 

## Five states. One simple cycle. 

The trigger can vary by product, but the universal #OSS behaviour is the same: no standing path, deliberate connection, approved use, then a return offline.

01 **Offline**02 **Authorise**03 **Connect**04 **Use**05 **Disconnect**

Access session

Dedicated #OSS

01 · Offline

### The protected state.

Your dedicated storage sits physically disconnected from the customer network. The data remains stored and encrypted, but there is no active customer network path to it.

Default → offline

02 Before first use 

## Three things establish the protected environment.

The exact implementation varies by product and scale, but the foundations are consistent before normal access begins.

01 

### Design and configure.

Define the protected data, capacity, access frequency and control model that suit the way the information is actually used.

02 

### Choose the physical deployment.

Use a managed Firevault Bunker or, for larger Storage and Enterprise architectures, an appropriate customer deployment.

03 

### Register and onboard identities.

Establish verified users, multi-factor authentication and permissions before normal access begins.

03 Control path vs data path 

## The instruction to connect is separate from the stored asset.

This is the architectural point that turns offline storage into a usable service: control can remain available without requiring the protected storage itself to remain continuously network reachable.

Control path

### Always reachable. Never the data.

Authorisation, identity checks and the out-of-band instruction that changes the connection state travel outside the customer data path. That is what makes a deliberate connection possible.

Identity → policy → instruction

Data path

### Present only for the session.

The customer network route to your dedicated storage exists because an approved session requires it. When the session ends, the route is physically removed again.

Connected for use → offline by default

04 How access varies 

## One physical principle. Different workflows.

LUV, Vault, Storage and Enterprise do not all start an access session in the same way. The physical state model stays consistent while the trigger and interface vary.

[**LUV**

Defined approved access windows for low-use, high-importance data.

Controlled window](/luv) [**Vault**

Identity-verified, on-demand access to dedicated personal or professional storage.

On demand](/vault) [**Storage**

Scheduled or on-demand organisational workflows using SFTP, API or approved data movement.

Workflow driven](/storage) [**Enterprise**

Policy-governed access designed around the larger environment and operating model.

Engineered ](/enterprise)

[Explore all #OSS products](/offline-secure-storage)

05 What every #OSS includes 

## Four physical foundations underneath the workflow. 

Capacity and access patterns can change. These are the architectural foundations the customer experience is built around.

01 **Physical storage**02 **Physical ownership**03 **Physical control**04 **Physical security**

![Firevault Offline Secure Storage 2TB, 4TB and 8TB physical drives](/__l5e/assets-v1/f8902ba1-a487-4bbe-a8eb-2c92c8b200ef/firevault-oss-drives-2tb-4tb-8tb-v3.webp)

Dedicated hardware

### Physical storage

Offline Secure Storage instances are held on dedicated physical hard drives, not in S3 cloud buckets, shared storage pools or multi-tenant infrastructure. Your selected data is assigned to real hardware, with dedicated RAID 1 drives providing resilience.

Physical drives. Dedicated capacity. Never shared.

01 **Controlled connectivity**

The network path to your Offline Secure Storage instance is physically disconnected by default. It is enabled only by an authorised out-of-band command, then closed again, so there is no standing connection to attack.

Layer 1 disconnection. Out-of-band command. No standing exposure.

02 **Secured offline access**

Access happens inside a defined window, by named and identity-verified users only. Sessions are time-limited, encrypted and closed automatically, with a complete record of who connected and when.

Named users. Time-limited sessions. Full audit trail.

03 **Secured offline data**

Your data sits encrypted on dedicated physical drives in a Firevault Bunker, held apart from your live systems, so a compromise of the connected estate does not reach the copy that matters.

Quantum Key Encryption. Dedicated drives. Held apart from live systems.

The whole idea 

## Online when you authorise it. Offline when you do not.

Offline Secure Storage® gives sensitive data a secure physical state to return to. Access becomes a deliberate event, not a permanent network condition.

[Choose an #OSS product](/offline-secure-storage) [Book a technical session](/contact)