Hardware-Enforced Layer-1 Isolation

Move Backups.
Not Attack Paths.

Bardin Gate ABV securely moves backup data between storage systems, repositories and cloud targets—without creating a permanent network path between isolated environments.

Your Backups Stay Connected. Your Networks Do Not.
No routing No bridging No simultaneous connectivity Storage agnostic
Backup data crosses the boundary. The network path does not.
UNSAFE NETWORK
Backup Storage
SMBNFSS3
Connected
BARDIN GATE ABV AIR-GAP BACKUP VAULT
SAFE NETWORK
Isolated Repository
NASDiskCloud
Disconnected
PHYSICAL GATE
Layer 1 Physical switching prevents both sides from being connected at the same time.
The Problem

A backup is only safe when attackers cannot reach it.

Traditional replication improves availability, but a permanently reachable backup path can also become an attack path. Ransomware, stolen credentials and lateral movement can follow the same connectivity intended for recovery.

Ransomware Reachability

If the recovery repository remains reachable, ransomware may encrypt, delete or corrupt the very copy intended for recovery.

PrimaryReplica

Credential & Admin Exposure

Compromised credentials, malicious insiders and administrative mistakes can affect every continuously connected repository.

AA

Unverified Offline Operations

Manual offline copies are slow, inconsistent and difficult to verify, audit and repeat reliably at enterprise scale.

0102?
Threat Exposure

Designed to stop destructive activity at the physical boundary.

ABV reduces exposure by removing the permanent network path to the safe recovery copy. It does not replace endpoint, identity or backup security controls; it adds a hardware-enforced isolation layer they cannot provide.

PHYSICAL ISOLATION MODEL

Backup data crosses the boundary. The networks never connect.

ABV alternates between the Unsafe and Safe networks through a hardware-enforced Layer-1 switch. Only one side can be physically connected at any moment.

Unsafe NetworkProduction backup domain
Backup Infrastructure Veeam · Commvault · NAS · SAN · S3
BARDIN GATE ABV AIR-GAP BACKUP VAULT
Layer-1 physical switching
Safe NetworkPhysically isolated recovery domain
Recovery Repository NAS · Disk · Object Storage · Cloud
1
Read from UnsafeSafe is physically disconnected
Break-before-makeBoth sides disconnected during transition
2
Write to SafeUnsafe is physically disconnected
No persistent attack path exists.Ransomware and stolen credentials cannot traverse a network connection that is physically absent.

Ransomware

Prevents network-borne encryption from traversing a permanent path to the safe recovery copy.

Insider Threat

Limits direct access to the safe repository from accounts and systems operating on the unsafe network.

Administrator Mistake

Reduces the blast radius of accidental deletion, misconfiguration and destructive administrative actions.

Backup Repository Compromise

Separates the safe recovery copy from compromise of the production backup domain.

Accidental Deletion

Keeps the isolated copy outside the continuously reachable management and deletion path.

Supply Chain Attack

Prevents a compromised connected platform from gaining a persistent routed path into the safe network.

Credential Theft

Stolen credentials alone cannot create a network route that does not physically exist.

Lateral Movement

Terminates network traversal at the Layer-1 boundary instead of extending it into the recovery environment.

Zero-Day Exploitation

Reduces exposure to unknown network exploits by eliminating simultaneous connectivity between security zones.

Threat Continuously Connected Backup Immutable Online Storage Bardin Gate ABV
Ransomware encryption path Reachable Network path remains Physically interrupted
Credential-based access Broad exposure Policy dependent No persistent route
Lateral movement Path exists Path exists Blocked at Layer 1
Repository compromise blast radius May include replicas Reduced, still connected Separated safe copy
Unknown network exploit Exposed Exposed to connectivity No simultaneous connectivity
Architecture

Any storage on the unsafe network.
Any recovery target on the safe network.

ABV acts as a controlled, backup-aware transport layer between heterogeneous storage environments. It does not permanently retain backup data inside the appliance.

Discuss your storage architecture
Unsafe network
Enterprise NASQNAP, NetApp, Synology
Backup RepositoryVeeam, Commvault, Veritas
Object StorageS3-compatible, MinIO, Ceph
File SharesSMB, NFS, local paths
BARDIN GATEABVAIR-GAP BACKUP VAULT
  • Backup-aware transfer
  • Policy orchestration
  • Integrity verification
  • Layer-1 isolation
No persistent backup storage
Safe network
Dedicated StorageExisting or optional appliance
Local / Removable DiskHDD, SSD, removable media
Cloud Object StorageAmazon S3 and compatible targets
Archive StorageNAS, file system, cold repository
Isolation Model

Physical disconnection—not a firewall rule.

ABV does not route packets or bridge Ethernet frames between security zones. Bardin Gate hardware physically selects one side at a time, preventing simultaneous network connectivity by design.

01

Connect to unsafe network
Read approved backup objects according to policy.

02

Disconnect physically
The previous side is removed at Layer 1.

03

Connect to safe network
Write and verify data on the isolated storage.

04

Return to isolation
No continuous route survives the transfer cycle.

LIVE ISOLATION MODELState A · Unsafe connected
UNSAFE NETWORKProduction Backup RepositoryConnected
BARDIN GATEABVAIR-GAP BACKUP VAULT
SAFE NETWORKRecovery RepositoryDisconnected
Interoperability

Works with the infrastructure you already trust.

Connect existing storage, backup repositories, file systems and cloud-compatible targets without forcing a single-vendor architecture.

VEEAMCOMMVAULTVERITASQNAPNETAPPSYNOLOGYMINIOAMAZON S3SMBNFS VEEAMCOMMVAULTVERITASQNAPNETAPPSYNOLOGYMINIOAMAZON S3SMBNFS

Storage Agnostic

Move backup data across NAS, file systems, local disks and object storage targets.

Backup Aware

Understand repository structure, transfer state and backup-oriented operational workflows.

Verified Transfer

Validate completion and data integrity before declaring a transfer successful.

Resume After Failure

Continue interrupted movement after link loss, restart or temporary infrastructure failure.

Policy Scheduling

Automate synchronization windows, direction, selection and operational constraints.

Auditable Operations

Record transfer status, timing, unsafe side, safe side and verification evidence.

Flexible Deployment

Use your storage—or deploy a complete solution.

ABV remains the isolation and transfer layer. Storage can be supplied by the customer or delivered as an optional part of the overall solution.

Plan a deployment with our sales team
Unsafe NetworkBackup Infrastructure
BARDIN GATEABVAIR-GAP BACKUP VAULT
Safe NetworkCertified Storage

Integrated Vault Solution

Deploy ABV with dedicated storage sized and configured for the required retention and performance profile.

  • Turnkey delivery
  • Validated configuration
  • Single implementation scope
Unsafe NetworkOn-Prem Backup
BARDIN GATEABVAIR-GAP BACKUP VAULT
Safe NetworkObject / Cloud Repository

Hybrid Storage

Move approved backup data between local infrastructure and supported object-storage destinations.

  • S3-compatible targets
  • On-prem to cloud workflows
  • Controlled transfer policies
Operational Workflow

Automated movement. Deterministic isolation.

01Discover

Identify approved backup objects and repository state.

02Read

Acquire approved backup data from the active unsafe side.

03Switch

Physically disconnect the unsafe network and connect the safe network.

04Write

Transfer data to the selected storage on the safe network.

05Verify

Confirm integrity, record evidence and update status.

Comparison

ABV is not conventional backup replication.

Replication copies data over a connected path. ABV is designed to remove that permanent path from the architecture.

Capability Traditional Replication Immutable Online Storage Bardin Gate ABV
Permanent network path Present Present Absent by design
Layer-1 physical isolation No No Yes
Heterogeneous unsafe / safe storage Limited Storage-specific Supported by connectors
Storage vendor lock-in Often Often Minimized
Automated offline workflow No No Yes
Integrity verification Platform dependent Platform dependent Integrated
Central audit trail Platform dependent Platform dependent Integrated
Ransomware network path to recovery copy Present Present Physically interrupted
Lateral movement into safe network Possible Possible Blocked at Layer 1
Use Cases

Designed for environments where backup exposure is unacceptable.

01

Cyber Recovery Copy

Create an isolated recovery copy outside the continuously connected backup domain.

02

Repository-to-Repository

Move data between enterprise storage systems while keeping security zones physically separated.

03

Storage Transformation

Read from one storage technology and write to another without requiring identical platforms.

04

Offline Archive

Automate controlled copies to disk-based or archive-oriented isolated targets.

05

Critical Infrastructure

Protect backup workflows for energy, utilities, defense, government and industrial environments.

06

Hybrid Backup Transfer

Move approved backup objects between local repositories and supported object-storage services.

Technical Capabilities

Built for large backup objects and enterprise operations.

Final throughput depends on storage performance on the unsafe and safe networks, network infrastructure and selected verification policies.

10GbENetwork support
1 TB+Large-file workflows
ResumeInterrupted transfers
HashIntegrity verification
RBACControlled administration
AuditComplete event history
PolicyScheduling and direction
APIIntegration-ready control
FAQ

Common technical questions.

ABV is an isolation and backup-data movement platform—not a replacement for your existing backup software.

Does ABV permanently store backup data?

No. ABV uses temporary working capacity as required by the transfer process but does not act as the permanent backup repository. The storage systems on the unsafe and safe networks retain the backup data.

Does ABV require identical storage on both sides?

No. Storage on the unsafe and safe networks may use different technologies, provided the required protocol or connector is supported and configured.

Can ABV be delivered with storage?

Yes. It can be deployed with customer-owned storage or supplied as part of a complete solution with appropriately sized storage infrastructure.

Is ABV a data diode?

No. ABV uses controlled physical switching and may support one-way or approved two-way operational workflows depending on the deployment policy. It does not create a permanent routed path.

Can ransomware traverse ABV as network traffic?

ABV does not route or bridge network traffic between the two sides. Only approved backup objects are moved through the controlled transfer process.

Does it replace Veeam, Commvault or another backup platform?

No. ABV complements existing backup platforms by adding a physically isolated transfer layer between repositories and storage targets.

Bardin Gate ABV

Make your backup copy unreachable by design.

Evaluate ABV for isolated repositories, heterogeneous storage environments and cyber-recovery architectures.