Edge Rewrite
// HTMLRewriter · presentation

This page was redesigned at the edge.

Cloudflare fetched the original article and streamed it through HTMLRewriter to apply an entirely new visual system without rebuilding the source page.

// request.cf · coarse context

A page that knows where it met you.

Only coarse request metadata is shown. This demo does not display or persist visitor IP addresses.

Country
US
Cloudflare location
CMH
Connection
HTTP/2
Language
Not provided

Ray ID: a42ffba809d8910d

Jump to content

Draft:Offline Secure Storage

From Wikipedia, the free encyclopedia

Offline Secure Storage

Offline Secure Storage, or OSS, is an approach to protecting sensitive data and valuable digital assets by keeping selected information on dedicated physical storage that is disconnected from connected networks when it is not being accessed.

Firevault uses the term Offline Secure Storage for an architecture built around removing standing reachability. In its implementation, protected information is held on dedicated hardware and the network path to that hardware is physically disconnected by default. Access is provided only during an approved, identity-verified and time-limited session, after which the storage is returned to its offline state.

Firevault describes its platform as the world's first Offline Secure Storage platform. The underlying principles of offline storage, isolation and air-gapping existed before the term, but Firevault applies them as a broader custody model for sensitive information and valuable digital assets rather than limiting the approach to backup and disaster recovery.

The company's technical model is centered on critical data, intellectual property, crown-jewel information and trusted recovery assets. It defines the protected dataset as offline by default and reachable only during a controlled access window.

Concept

The basic principle behind Offline Secure Storage is that important data does not always need to remain continuously reachable.

Most modern storage is designed around constant availability. Data may be accessible through production networks, cloud platforms, administrative systems, APIs, backup software, synchronisation services or remote-management tools.

Those systems can be protected by authentication, permissions, encryption, firewalls and monitoring, but a route to the data still exists.

Offline Secure Storage changes that starting point.

For selected information, the network route is removed when access is not required. Instead of keeping the storage permanently connected and relying only on controls around that connection, OSS changes whether the route exists at all.

Sensitive data and valuable digital assets

Offline Secure Storage is intended for data where the value, sensitivity or consequence of compromise justifies removing continuous network reachability.

This may include intellectual property, legal documents, client records, financial information, board papers, identity information, regulated records, commercial data, archives, master copies and recovery assets.

It is not intended to move an organisation's entire data estate offline.

Everyday collaboration data, live databases and information required continuously by applications or operational systems will generally remain connected. OSS is aimed at the subset of information that does not need permanent availability but would have serious consequences if it were stolen, altered, encrypted, deleted or exposed.

Firevault's technical material specifically positions the model around crown jewels, intellectual property, critical data and trusted recovery assets.

Reachability

Reachability is central to the OSS model.

Firevault defines reachability as any live route through which protected information could be discovered, accessed, changed, deleted or exfiltrated.

That can include a normal IP connection, but it can also include management systems, backup agents, cloud synchronisation, remote administration, APIs and authorised human workflows.  

This distinction matters because even strongly secured storage can remain reachable.

If an attacker compromises credentials, an administrative console, a backup system or another trusted path, the data behind that route may also become exposed.

OSS therefore focuses on removing the route itself when the information is not required.

Firevault's stated control objective is to reduce residual risk by removing standing reachability rather than relying only on stronger authentication.

Architecture

Offline Secure Storage separates selected protected information from the normal connected environment.

In Firevault's implementation, data is stored on dedicated physical hardware. In its protected state, the network path to that storage is physically disconnected.

This is different from leaving the storage connected and relying solely on firewall rules, permissions, software segmentation or other logical controls.

The architecture instead treats connectivity as something that is deliberately created when it is required and removed when it is not.

The technical model separates source systems, controlled transfer, offline custody, authorised access and retrieval or restoration. Data enters through a controlled process, is verified, held offline and accessed through an approved event rather than being presented as an always-available network share.

Storage state and controlled access

Offline is the normal state of an OSS instance.

Active connectivity is the exception.

A typical access process can be represented as:

Offline or closed -> Requested -> Approved -> Active access -> Closed and evidenced

An access requirement is first raised for a defined reason. The user, purpose and access period are then approved.

The physical path is enabled for the authorised session, allowing the user to access the protected information.

When the session ends, the route is closed and the storage returns to its offline state.

Firevault's technical model describes the default state as closed and states that active use should be the exception rather than the baseline. Access windows should have clear start and end conditions, and closure should not depend on informal processes or someone remembering to disconnect the storage.  

Physical storage

Firevault's implementation of OSS uses dedicated physical storage.

The protected information is held on hardware assigned to the storage instance rather than relying solely on a pooled or shared logical storage service.

Dedicated hardware allows the state of the storage and its physical network connection to be controlled independently.

This is one of the characteristics that separates Firevault's OSS model from conventional shared cloud storage.

Physical ownership

Firevault uses the term physical ownership to describe the allocation of dedicated storage capacity to the customer.

The protected data is held on dedicated storage rather than being mixed within a general shared storage pool.

In this context, physical ownership refers to the allocation and custody of the storage infrastructure. It is separate from the legal ownership of the data itself.

Physical control

Physical control refers to whether the network path to the protected storage exists.

The connection is physically disconnected by default.

Access is initiated through an authorised out-of-band process rather than through the normal network route. When the request is approved, the physical connection is established for the permitted session.

When the session ends, that connection is removed again.

The result is that the storage does not depend solely on an always-available software management path to determine whether it is connected.

Physical security

Physical disconnection does not remove the need to protect the hardware itself.

Offline Secure Storage therefore also relies on suitable physical security.

Depending on the deployment, this can include restricted access to the storage environment, monitoring, resilient power, environmental protection, controlled custody and audit records.

Physical security and physical network disconnection address different risks and are intended to work together.

Data transfer and custody

Offline Secure Storage is not simply a matter of moving files onto a disconnected drive.

The process also needs to consider how information enters the protected environment, how it is verified, who owns it, who may access it and how that access is recorded.

Firevault's model includes selection of the protected dataset, pre-transfer checking, controlled transfer, verification, manifests, integrity information and records of custody.  

The technical design specifically states that the storage should not be treated as another always-on file share. It should instead operate as a custody state that is opened, used and closed under control.  

Integrity and evidence

Physical disconnection deals with reachability. It does not by itself prove that the data stored offline is complete, current or usable.

Integrity therefore needs to be managed separately.

Controls may include file manifests, cryptographic hashes or other integrity markers, retention rules, validation checks and periodic retrieval testing.

The OSS model also places emphasis on evidence around access.

An access event should provide enough information to establish who approved it, who used the storage, why access was required, what was accessed, when the session ended and whether the offline state was successfully restored.  

This creates a traceable custody record around sensitive information.

Relationship to air gaps

Offline Secure Storage is related to the established concept of an air gap, but the two terms are not identical.

A strict air gap normally refers to physical separation between systems or networks.

OSS uses physical disconnection as its default state but also provides a controlled method of reconnecting the storage when legitimate access is required.

It is therefore more accurate to describe the model as offline by default rather than permanently inaccessible.

The important principle is that there is no standing network path to the protected data outside the authorised access period.

Relationship to backup

Offline Secure Storage can be used for backup and recovery information, but backup is only one possible use.

Traditional backup is primarily concerned with restoring data after deletion, corruption, hardware failure or another incident.

OSS can also be used for information where custody is the primary requirement rather than restoration.

That could include intellectual property, legal records, board material, commercial information, archival records or other valuable digital assets.

This distinction matters because the purpose of OSS is broader than keeping a recovery copy. Its focus is on reducing continuous reachability for selected information.

Relationship to immutable storage

Offline storage and immutable storage address different security properties.

Immutability concerns whether information can be changed or deleted.

Offline isolation concerns whether the storage can be reached.

An immutable storage system can remain continuously connected while preventing protected information from being altered.

An offline storage system may allow authorised changes while it is connected but remain unreachable outside the approved session.

The two controls can therefore be used together.

Ransomware and cyber resilience

Ransomware is an important use case for Offline Secure Storage, but it is not its only purpose.

Ransomware operators often attempt to compromise backup and recovery infrastructure so that an organisation cannot easily recover without paying.

Where every copy of important information remains reachable from the same connected environment, a sufficiently privileged attacker may be able to encrypt, delete or alter those copies as well.

Offline isolation reduces this exposure by ensuring that selected data does not retain a standing path from the connected environment.

The same principle can also apply to compromised credentials, malicious administration, cloud synchronisation errors and other incidents where connected infrastructure itself becomes part of the problem.

Recovery and testing

Offline storage is valuable only if the protected information can still be used when it is required.

Testing should therefore establish more than simply whether the data exists.

A recovery or retrieval process should demonstrate that the information can be identified, validated, authorised, retrieved and used within the required timescale.

Firevault's technical model includes recovery objectives, integrity validation, clean-environment assumptions, testing frequency and evidence of the outcome.  

The purpose is to ensure that the offline copy is not merely protected, but usable.

Limitations and operational considerations

Offline Secure Storage is intended for selected sensitive data and valuable digital assets rather than information that requires permanent network availability.

Its suitability depends on factors including the sensitivity and value of the data, how often it needs to be accessed, how quickly it must be made available and the consequences of compromise.

During an approved access session, the storage temporarily becomes reachable. Authentication, access control, endpoint security and session management therefore remain important during this period.

Physical disconnection is also separate from data integrity. Information may need to be checked before entering offline custody, and integrity checks, manifests and retrieval testing can be used to provide confidence that it remains usable.

OSS is not intended to replace identity management, endpoint protection, backup, monitoring or other cybersecurity controls.

Firevault's technical model explicitly positions it alongside identity, endpoint, SIEM, backup and network controls rather than as a replacement for them.  

Its additional control is the ability to remove standing reachability from selected information.

Development and use of the term

Offline Secure Storage is the term used by Firevault for its storage architecture.

Firevault describes its platform as the world's first Offline Secure Storage platform.

The company's use of the term refers to a combination of dedicated physical storage, customer-specific allocation, physical disconnection, out-of-band control, identity-verified temporary access, custody evidence and deliberate return to an offline state.

The broader principles behind the architecture are older than the term itself. Offline storage, air-gapping, isolated recovery environments and physically disconnected backup media have long been used as security and resilience techniques.

What Firevault describes as Offline Secure Storage applies those established isolation principles more broadly to the custody of sensitive data and valuable digital assets that do not need to remain continuously reachable.