Secure Email Exchange
Without Network Bridging
Bardin Gate AMG is a hardware-based AirGap Mail Gateway for organizations that need email communication between trusted and untrusted networks without creating a permanent network path between them.
Unsafe MTA
External-facing SMTP queue and relay role.
Safe MTA
Internal-facing SMTP queue and relay role.
Hardware Gate
Prevents simultaneous physical connectivity.
Email requires communication. Security requires isolation.
Many organizations need to exchange email with the outside world, but direct Internet exposure of internal mail infrastructure is an unacceptable risk. Traditional gateways reduce risk; AMG is designed to remove the permanent network path itself.
Internet Exposure Risk
Internal mail systems become reachable through a continuously connected chain of network devices and software controls.
Security Zone Boundaries
High-security environments require stronger separation than VLANs, firewall rules, or DMZ routing models.
Configuration Dependency
Conventional designs rely heavily on correct routing, firewall, proxy, and operating system configuration.
The message crosses the boundary. The network connection does not.
AMG contains Safe and Unsafe mail transfer roles. The transfer engine moves email objects between queues while Bardin Gate hardware prevents simultaneous connectivity between the trusted and untrusted networks.
Physical Layer-1 disconnection, not just network policy.
AMG does not route packets, bridge Ethernet frames, or provide Layer-3 reachability between safe and unsafe networks. The separation is enforced by hardware switching and physical link disconnection.
State A: Unsafe side connected
State B: Safe side connected
Built for security-sensitive organizations.
AMG is intended for environments where direct Internet connectivity is the risk, not merely environments with unstable Internet service.
No Persistent Connectivity
Trusted and untrusted environments are never simultaneously connected through the appliance.
SMTP Interoperability
Works with standards-compliant mail platforms such as Zimbra, Exchange, Postfix, Exim, and Sendmail.
Independent Queues
Safe and Unsafe domains maintain independent SMTP queues and retry behavior.
Reduced Attack Surface
Internal mail infrastructure is not directly reachable from Internet-facing networks.
Controlled Flow
Only email message objects cross the security boundary through a controlled transfer process.
Auditable Transfer
Cross-boundary email movement can be logged, monitored, reviewed, and governed centrally.
Insert AMG without redesigning the mail platform.
AMG integrates through SMTP. It does not require agents, plugins, or modifications on the internal mail system.
Typical Mail Flow
Inbound messages are accepted by the Unsafe MTA, transferred through AMG, and delivered by the Safe MTA to the internal mail platform. Outbound messages follow the reverse path.
Designed for environments where exposure is unacceptable.
AMG is valuable anywhere email exchange is required, but direct Internet connectivity to internal mail systems is considered a security risk.
AMG is not a conventional mail gateway.
Traditional gateways control traffic across a connected path. AMG is designed to prevent that path from existing permanently.
| Capability | Traditional Mail Gateway | Bardin Gate AMG |
|---|---|---|
| SMTP Relay | Yes | Yes |
| Permanent Connectivity | Yes | No |
| Layer-3 Path Exists | Yes | No |
| Routing Required Between Zones | Yes | No |
| Firewall Dependency | High | Minimal |
| Physical Isolation | No | Yes |
| Hardware-Enforced Separation | No | Yes |
| Direct Internal Exposure Risk | Present | Eliminated by design |
Ready for a technical evaluation?
Use Bardin Gate AMG as a secure email transfer appliance for isolated, segmented, and high-security environments where internal mail systems must not be directly exposed.