Firebreak

Firebreak: cut the path, not the business.

Firebreak is Layer 1 hardware that physically opens and closes network paths on command, in milliseconds, per zone. The command path is out of band, so the switch never sits on the wires it is meant to cut.

L1
Physical
ms
Switching
4
Models
OOB
Command
Disconnected

Path open, path cut, on command

Recognition

NATO DIANA award logoTechnology Reseller Awards 2023 Winner, Hardware/Endpoint Device of the Year award logoSC Awards Europe 2025 Winner award logo
01What Firebreak is

A switch, not a sensor.

Firebreak does one job completely: it decides whether the path exists at all. Everything else in your stack keeps doing what it already does.

What Firebreak is

  • A Layer 1 physical switch in the network path
  • An air gap you can create and reverse on demand
  • Controlled from an out-of-band, non-IP command path
  • Logged, evidential and independent of the estate it protects

What Firebreak is not

  • A firewall or an inspection appliance
  • Software that can be disabled by a compromised host
  • A protocol-aware device sitting inline in the data plane
  • A forklift upgrade of your existing network
02How it works

Command arrives off the network. The path opens or closes in hardware.

Patented Layer 1 architecture

A physical disconnect. Not another firewall.

Globally patented · US + intl
Three movements

No software in the data plane.

Per-zone independence

Cut one zone. Leave the others connected.

Each port pair is its own mechanical reed-switch. Isolate, schedule or restore a single circuit without touching the rest of the estate.

Firebreak 1U · 12 ports · 06 zones
05 live·00 cut·01 sched

OT plant restored over the out-of-band path

RESTORED · 12 ms

Click a row to throw its reed switch · auto-demo resumes in 10 s

12 independent zones per 1UPer-zone schedule and auditReversible over the out-of-band path
03The range

Four models: copper, fibre and edge.

Pick the model that matches the port type and the place it sits. The command path and the behaviour are identical across the range.

The range

Four units. One patented principle.

Pick by media and form factor. Reed-switch Layer 1 architecture and out-of-band command path are shared across the line.

R1200-12E unitFlagship · Globally patented
R1200-12E

Copper rack, 12 pairs

1U, 19 inch rack

Ports
12 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response
Fail mode
Fail-open or fail-closed
  • Out-of-band control over dedicated Ethernet, 3GPP cellular SMS or token-gated API
  • Dual redundant AC PSU, 100 to 240 V, 50/60 Hz
1U rack & desktopReed-switch Layer 1Dual AC PSUOut-of-band command path
R1100-4F unit
R1100-4FFibre

Fibre rack, 4 pairs

1U, 19 inch rack

Ports
4 × SFP / SFP+ / SFP28 pairs
Throughput
1, 10 or 25 Gbps per pair
Switching
Physical optical switching, no inline buffer
R1200-4E unit
R1200-4ECopper

Copper rack, 4 pairs

1U, 19 inch rack

Ports
4 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response
S1200 unit
S1200Edge

Desktop edge unit

Small-form desktop

Ports
4 × RJ45 port pairs
Throughput
Up to 10 GbE per pair
Switching
Reed-switch Layer 1, millisecond response
04Deployments

Where Firebreak is already in service.

NATO and defence

Tier-1 programme

Air gap on demand for a classified test range with intermittent partner connectivity.

Operator-triggered disconnect in milliseconds, full audit log, no inline software in the path.

Critical national infrastructure

Multi-site utility

Severance of the IT and OT boundary during patching windows and SCADA incident response.

Scheduled and ad-hoc cuts over SMS and REST API, with no re-architecture of the control network.

Regulated finance

Trading floor

Verifiable physical isolation of a settlement enclave from the wider corporate network, on demand.

The out-of-band command path satisfied both internal audit and external regulator review.

05Key features

Everything a Firebreak unit does, in plain terms.

  • Instant remote control
  • Works with any outlet, copper or fibre
  • Protects any device or network
  • Plug and play, stack agnostic, no forklift upgrade
  • Administrator and user-friendly interface
  • No special hardware or software for command and control
  • Out-of-band, non-IP command channel
  • Per-port pair independence
06Professional services

We deploy it with you, not at you.

Network configuration

We help map ports, zones and command paths to your existing architecture.

Support model design

Roles, runbooks and on-call patterns so cuts and restores are routine, not heroic.

Naming and command structures

Clear conventions for ports, zones and Blueprints, so every action reads the same way.

Secure command processes

Approval, authentication and audit flows that satisfy internal review and external regulators.

07FAQ

Questions engineers ask first.

Is Firebreak an air gap?

On demand, yes. When Firebreak cuts a path, the segment is severed at Layer 1. It is disconnected on that interface, invisible to scans on it, and independent of any software that might have been compromised.

Does Firebreak replace firewalls?

No. Firewalls inspect and filter traffic on connections that still exist. Firebreak removes the connection itself. The two complement each other rather than substitute for each other.

Does Firebreak inspect or filter traffic?

No. Firebreak sits at Layer 1 and has no inline protocol stack in the data path. When the path is cut, there is no payload to inspect because there is no link.

How are commands authenticated?

The command path is out of band by design. The web interface uses multi-factor authentication with brute-force protection. SMS uses structured commands with number filtering and a secondary code. The API uses scoped access tokens. Every action is logged.

How does Firebreak fit into Control?

Control is the wider framework of Fire and Vault modules, packaged into Control Blueprints. Firebreak is the physical control point that delivers the Layer 1 cut wherever a Blueprint calls for one.

How does Firebreak support compliance evidence?

Every cut, restore and command is logged on the appliance with the actor, the channel and the outcome. The evidential trail maps directly to the isolation and operational-resilience expectations in regimes such as NIS2 and DORA.

Do you offer help with deployment?

Yes. Our professional services team helps you choose the right module, plan the rollout and operate it well, through to handover to your operations team.

See a path cut in front of you.

A member of the team will show you a live cut and restore, then map the right model to your ports and zones.

How Firebreak fits into Control