Firebreak: cut the path, not the business.
Firebreak is Layer 1 hardware that physically opens and closes network paths on command, in milliseconds, per zone. The command path is out of band, so the switch never sits on the wires it is meant to cut.
- L1
- Physical
- ms
- Switching
- 4
- Models
- OOB
- Command
Path open, path cut, on command
Recognition


A switch, not a sensor.
Firebreak does one job completely: it decides whether the path exists at all. Everything else in your stack keeps doing what it already does.
What Firebreak is
- A Layer 1 physical switch in the network path
- An air gap you can create and reverse on demand
- Controlled from an out-of-band, non-IP command path
- Logged, evidential and independent of the estate it protects
What Firebreak is not
- A firewall or an inspection appliance
- Software that can be disabled by a compromised host
- A protocol-aware device sitting inline in the data plane
- A forklift upgrade of your existing network
Command arrives off the network. The path opens or closes in hardware.
Patented Layer 1 architecture
A physical disconnect. Not another firewall.
No software in the data plane.
Per-zone independence
Cut one zone. Leave the others connected.
Each port pair is its own mechanical reed-switch. Isolate, schedule or restore a single circuit without touching the rest of the estate.
OT plant restored over the out-of-band path
RESTORED · 12 msClick a row to throw its reed switch · auto-demo resumes in 10 s
Four models: copper, fibre and edge.
Pick the model that matches the port type and the place it sits. The command path and the behaviour are identical across the range.
✓The range
Four units. One patented principle.
Pick by media and form factor. Reed-switch Layer 1 architecture and out-of-band command path are shared across the line.
Flagship · Globally patentedCopper rack, 12 pairs
1U, 19 inch rack
- Ports
- 12 × RJ45 port pairs
- Throughput
- Up to 10 GbE per pair
- Switching
- Reed-switch Layer 1, millisecond response
- Fail mode
- Fail-open or fail-closed
- Out-of-band control over dedicated Ethernet, 3GPP cellular SMS or token-gated API
- Dual redundant AC PSU, 100 to 240 V, 50/60 Hz

Fibre rack, 4 pairs
1U, 19 inch rack
- Ports
- 4 × SFP / SFP+ / SFP28 pairs
- Throughput
- 1, 10 or 25 Gbps per pair
- Switching
- Physical optical switching, no inline buffer

Copper rack, 4 pairs
1U, 19 inch rack
- Ports
- 4 × RJ45 port pairs
- Throughput
- Up to 10 GbE per pair
- Switching
- Reed-switch Layer 1, millisecond response

Desktop edge unit
Small-form desktop
- Ports
- 4 × RJ45 port pairs
- Throughput
- Up to 10 GbE per pair
- Switching
- Reed-switch Layer 1, millisecond response
Where Firebreak is already in service.
NATO and defence
Tier-1 programme
Air gap on demand for a classified test range with intermittent partner connectivity.
Operator-triggered disconnect in milliseconds, full audit log, no inline software in the path.
Critical national infrastructure
Multi-site utility
Severance of the IT and OT boundary during patching windows and SCADA incident response.
Scheduled and ad-hoc cuts over SMS and REST API, with no re-architecture of the control network.
Regulated finance
Trading floor
Verifiable physical isolation of a settlement enclave from the wider corporate network, on demand.
The out-of-band command path satisfied both internal audit and external regulator review.
Everything a Firebreak unit does, in plain terms.
- Instant remote control
- Works with any outlet, copper or fibre
- Protects any device or network
- Plug and play, stack agnostic, no forklift upgrade
- Administrator and user-friendly interface
- No special hardware or software for command and control
- Out-of-band, non-IP command channel
- Per-port pair independence
We deploy it with you, not at you.
Network configuration
We help map ports, zones and command paths to your existing architecture.
Support model design
Roles, runbooks and on-call patterns so cuts and restores are routine, not heroic.
Naming and command structures
Clear conventions for ports, zones and Blueprints, so every action reads the same way.
Secure command processes
Approval, authentication and audit flows that satisfy internal review and external regulators.
Questions engineers ask first.
Is Firebreak an air gap?
On demand, yes. When Firebreak cuts a path, the segment is severed at Layer 1. It is disconnected on that interface, invisible to scans on it, and independent of any software that might have been compromised.
Does Firebreak replace firewalls?
No. Firewalls inspect and filter traffic on connections that still exist. Firebreak removes the connection itself. The two complement each other rather than substitute for each other.
Does Firebreak inspect or filter traffic?
No. Firebreak sits at Layer 1 and has no inline protocol stack in the data path. When the path is cut, there is no payload to inspect because there is no link.
How are commands authenticated?
The command path is out of band by design. The web interface uses multi-factor authentication with brute-force protection. SMS uses structured commands with number filtering and a secondary code. The API uses scoped access tokens. Every action is logged.
How does Firebreak fit into Control?
Control is the wider framework of Fire and Vault modules, packaged into Control Blueprints. Firebreak is the physical control point that delivers the Layer 1 cut wherever a Blueprint calls for one.
How does Firebreak support compliance evidence?
Every cut, restore and command is logged on the appliance with the actor, the channel and the outcome. The evidential trail maps directly to the isolation and operational-resilience expectations in regimes such as NIS2 and DORA.
Do you offer help with deployment?
Yes. Our professional services team helps you choose the right module, plan the rollout and operate it well, through to handover to your operations team.
See a path cut in front of you.
A member of the team will show you a live cut and restore, then map the right model to your ports and zones.