Unsafe Network
Backup Storage SMB · NFS · S3 ConnectedHardware-Enforced Layer-1 Isolation
Move Backups.
Not Attack Paths.
Bardin Gate ABV moves approved backup data between storage systems, repositories, and supported object-storage targets without creating a permanent network path between isolated environments.
Your Backup Workflow Continues.Your Networks Do Not Connect.
- No routing
- No bridging
- No simultaneous connectivity
- Storage agnostic
Backup data crosses the boundary. The network path does not.
Safe Network
Isolated Repository NAS · Disk · Cloud DisconnectedLayer 1 Physical switching prevents both sides from being connected at the same time.
The Problem
A backup is only safe when attackers cannot reach it.
Traditional replication improves availability, but a permanently reachable backup path can also become an attack path. Ransomware, stolen credentials and lateral movement can follow the same connectivity intended for recovery.
Ransomware Reachability
If the recovery repository remains reachable, ransomware may encrypt, delete or corrupt the very copy intended for recovery.
Credential & Admin Exposure
Compromised credentials, malicious insiders and administrative mistakes can affect every continuously connected repository.
Unverified Offline Operations
Manual offline copies are slow, inconsistent and difficult to verify, audit and repeat reliably at enterprise scale.
Threat Exposure
Designed to stop destructive activity at the physical boundary.
ABV reduces exposure by removing the permanent network path to the safe recovery copy. It does not replace endpoint, identity or backup security controls; it adds a hardware-enforced isolation layer they cannot provide.
Physical Isolation Model
Backup data crosses the boundary. The networks never connect.
ABV alternates between the Unsafe and Safe networks through a hardware-enforced Layer-1 switch. Only one side can be physically connected at any moment.
Backup InfrastructureVeeam · Commvault · NAS · SAN · S3
Recovery RepositoryNAS · Disk · Object Storage · Cloud
No persistent attack path exists.Ransomware and stolen credentials cannot traverse a network connection that is physically absent.
Ransomware
Prevents network-borne encryption from traversing a permanent path to the safe recovery copy.
Insider Threat
Limits direct access to the safe repository from accounts and systems operating on the unsafe network.
Administrator Mistake
Reduces the blast radius of accidental deletion, misconfiguration and destructive administrative actions.
Repository Compromise
Separates the safe recovery copy from compromise of the production backup domain.
Lateral Movement
Terminates network traversal at the Layer-1 boundary instead of extending it into the recovery environment.
Zero-Day Exploitation
Reduces exposure to unknown network exploits by eliminating simultaneous connectivity between security zones.
Architecture
Any storage on the unsafe network.
Any recovery target on the safe network.
ABV acts as a controlled, backup-aware transport layer between heterogeneous storage environments. It does not permanently retain backup data inside the appliance.
Discuss your storage architectureUnsafe Network
Enterprise NASQNAP, NetApp, Synology
Backup RepositoryVeeam, Commvault, Veritas
Object StorageS3-compatible, MinIO, Ceph
File SharesSMB, NFS, local paths
- Backup-aware transfer
- Policy orchestration
- Integrity verification
- Layer-1 isolation
No persistent backup storage
Safe Network
Dedicated StorageExisting or optional appliance
Local / Removable DiskHDD, SSD, removable media
Cloud Object StorageAmazon S3 and compatible targets
Archive StorageNAS, file system, cold repository
Isolation Model
Physical disconnection, not a firewall rule.
ABV does not route packets or bridge Ethernet frames between security zones. Bardin Gate hardware physically selects one side at a time, preventing simultaneous network connectivity by design.
- 01
Connect to unsafe networkRead approved backup objects according to policy.
- 02
Disconnect physicallyThe previous side is removed at Layer 1.
- 03
Connect to safe networkWrite and verify data on the isolated storage.
- 04
Return to isolationNo continuous route survives the transfer cycle.
Live Isolation ModelState A · Unsafe connected
Interoperability
Works with the infrastructure you already trust.
Connect existing storage, backup repositories, file systems and cloud-compatible targets without forcing a single-vendor architecture.
VeeamBackup platform
CommvaultData protection
VeritasData protection
QNAPNAS storage
NetAppEnterprise storage
SynologyNAS storage
MinIOObject storage
Amazon S3Object storage
Storage Agnostic
Move backup data across NAS, file systems, local disks and object storage targets.
Backup Aware
Understand repository structure, transfer state and backup-oriented operational workflows.
Verified Transfer
Validate completion and data integrity before declaring a transfer successful.
Resume After Failure
Continue interrupted movement after link loss, restart or temporary infrastructure failure.
Policy Scheduling
Automate synchronization windows, direction, selection and operational constraints.
Auditable Operations
Record transfer status, timing, unsafe side, safe side and verification evidence.
Flexible Deployment
Use your storage, or deploy a complete solution.
ABV remains the isolation and transfer layer. Storage can be supplied by the customer or delivered as an optional part of the overall solution.
Plan a deployment with our sales teamMost flexible
Existing Infrastructure
Insert ABV between repositories or storage systems already deployed in your environment.
- Preserve current investments
- No forced storage migration
- Vendor-independent architecture
Integrated Vault Solution
Deploy ABV with dedicated storage sized and configured for the required retention and performance profile.
- Turnkey delivery
- Validated configuration
- Single implementation scope
Hybrid Storage
Move approved backup data between local infrastructure and supported object-storage destinations.
- S3-compatible targets
- On-prem to cloud workflows
- Controlled transfer policies
Operational Workflow
Automated movement. Deterministic isolation.
- 01Discover
Identify approved backup objects and repository state.
- 02Read
Acquire approved backup data from the active unsafe side.
- 03Switch
Physically disconnect the unsafe network and connect the safe network.
- 04Write
Transfer data to the selected storage on the safe network.
- 05Verify
Confirm integrity, record evidence and update status.
Comparison
ABV is not conventional backup replication.
Replication copies data over a connected path. ABV is designed to remove that permanent path from the architecture.
| Capability | Traditional Replication | Immutable Online Storage | Bardin Gate ABV |
|---|---|---|---|
| Permanent network path | Present | Present | Absent by design |
| Layer-1 physical isolation | No | No | Yes |
| Heterogeneous unsafe / safe storage | Limited | Storage-specific | Supported by connectors |
| Storage vendor lock-in | Often | Often | Minimized |
| Automated offline workflow | No | No | Yes |
| Integrity verification | Platform dependent | Platform dependent | Integrated |
| Central audit trail | Platform dependent | Platform dependent | Integrated |
| Ransomware path to recovery copy | Present | Present | Physically interrupted |
Use Cases
Designed for environments where backup exposure is unacceptable.
Cyber Recovery Copy
Create an isolated recovery copy outside the continuously connected backup domain.
Repository-to-Repository
Move data between enterprise storage systems while keeping security zones physically separated.
Storage Transformation
Read from one storage technology and write to another without requiring identical platforms.
Offline Archive
Automate controlled copies to disk-based or archive-oriented isolated targets.
Critical Infrastructure
Protect backup workflows for energy, utilities, defense, government and industrial environments.
Hybrid Backup Transfer
Move approved backup objects between local repositories and supported object-storage services.
Technical Capabilities
Built for large backup objects and enterprise operations.
Final throughput depends on storage performance on the unsafe and safe networks, network infrastructure and selected verification policies.
- 10GbE
- Network support
- 1 TB+
- Large-file workflows
- Resume
- Interrupted transfers
- Hash
- Integrity verification
- RBAC
- Controlled administration
- Audit
- Complete event history
- Policy
- Scheduling and direction
- API
- Integration-ready control
FAQ
Common technical questions.
ABV is an isolation and backup-data movement platform, not a replacement for your existing backup software.
No. ABV uses temporary working capacity as required by the transfer process but does not act as the permanent backup repository. The storage systems on the unsafe and safe networks retain the backup data.
No. Storage on the unsafe and safe networks may use different technologies, provided the required protocol or connector is supported and configured.
Yes. It can be deployed with customer-owned storage or supplied as part of a complete solution with appropriately sized storage infrastructure.
No. ABV uses controlled physical switching and may support one-way or approved two-way operational workflows depending on the deployment policy. It does not create a permanent routed path.
ABV does not route or bridge network traffic between the two sides. Only approved backup objects are moved through the controlled transfer process.
No. ABV complements existing backup platforms by adding a physically isolated transfer layer between repositories and storage targets.
Bardin Gate ABV
Place the recovery copy beyond a permanent network path.
Evaluate ABV for isolated repositories, heterogeneous storage environments and cyber-recovery architectures.
