Hardware-Enforced Layer-1 Isolation

Secure Email Exchange
Without Network Bridging

Bardin Gate AMG is a hardware-based AirGap Mail Gateway for organizations that need email communication between trusted and untrusted networks without creating a permanent network path between them.

No routing No bridging No simultaneous connectivity SMTP compatible
AMG Appliance
AirGap Mail Gateway
Two isolated mail domains, controlled message transfer, and physical link disconnection at Layer 1.
โšก

Unsafe MTA

External-facing SMTP queue and relay role.

Connected
๐Ÿ›ก

Safe MTA

Internal-facing SMTP queue and relay role.

Disconnected
๐Ÿ”’

Hardware Gate

Prevents simultaneous physical connectivity.

Layer 1
Problem

Email requires communication. Security requires isolation.

Many organizations need to exchange email with the outside world, but direct Internet exposure of internal mail infrastructure is an unacceptable risk. Traditional gateways reduce risk; AMG is designed to remove the permanent network path itself.

๐ŸŒ

Internet Exposure Risk

Internal mail systems become reachable through a continuously connected chain of network devices and software controls.

๐Ÿงฑ

Security Zone Boundaries

High-security environments require stronger separation than VLANs, firewall rules, or DMZ routing models.

โš™๏ธ

Configuration Dependency

Conventional designs rely heavily on correct routing, firewall, proxy, and operating system configuration.

Architecture

The message crosses the boundary. The network connection does not.

AMG contains Safe and Unsafe mail transfer roles. The transfer engine moves email objects between queues while Bardin Gate hardware prevents simultaneous connectivity between the trusted and untrusted networks.

Untrusted NetworkInternet, partners, public SMTP infrastructure, cloud email relays.
โžœ
Bardin Gate AMGUnsafe MTA queue, controlled transfer engine, Safe MTA queue, hardware-enforced isolation.
โžœ
Trusted NetworkZimbra, Exchange, Postfix, internal mail hubs, enterprise messaging platforms.
Isolation Model

Physical Layer-1 disconnection, not just network policy.

AMG does not route packets, bridge Ethernet frames, or provide Layer-3 reachability between safe and unsafe networks. The separation is enforced by hardware switching and physical link disconnection.

State A: Unsafe side connected

Unsafe Network
Unsafe MTA

Safe Network
Safe MTA

State B: Safe side connected

Unsafe Network
Unsafe MTA

Safe Network
Safe MTA
Benefits

Built for security-sensitive organizations.

AMG is intended for environments where direct Internet connectivity is the risk, not merely environments with unstable Internet service.

๐Ÿ”

No Persistent Connectivity

Trusted and untrusted environments are never simultaneously connected through the appliance.

๐Ÿงฌ

SMTP Interoperability

Works with standards-compliant mail platforms such as Zimbra, Exchange, Postfix, Exim, and Sendmail.

๐Ÿ“ฅ

Independent Queues

Safe and Unsafe domains maintain independent SMTP queues and retry behavior.

๐Ÿงฏ

Reduced Attack Surface

Internal mail infrastructure is not directly reachable from Internet-facing networks.

๐Ÿงญ

Controlled Flow

Only email message objects cross the security boundary through a controlled transfer process.

๐Ÿ”Ž

Auditable Transfer

Cross-boundary email movement can be logged, monitored, reviewed, and governed centrally.

Deployment

Insert AMG without redesigning the mail platform.

AMG integrates through SMTP. It does not require agents, plugins, or modifications on the internal mail system.

โœ“Safe MTA connects to internal mail platforms such as Zimbra, Exchange, or Postfix.
โœ“Unsafe MTA handles external SMTP communication and public-facing relay behavior.
โœ“Transfer engine moves queued email messages without creating routed network access.
โœ“Policy extensions may include DKIM, SPF, DMARC, antivirus, antispam, auditing, and SIEM integration.
๐Ÿ“ก

Typical Mail Flow

Inbound messages are accepted by the Unsafe MTA, transferred through AMG, and delivered by the Safe MTA to the internal mail platform. Outbound messages follow the reverse path.


1External sender โ†’ Unsafe MTA
2Unsafe queue โ†’ Transfer engine
3Transfer engine โ†’ Safe queue
4Safe MTA โ†’ Internal mailbox system
Use Cases

Designed for environments where exposure is unacceptable.

AMG is valuable anywhere email exchange is required, but direct Internet connectivity to internal mail systems is considered a security risk.

๐Ÿ›GovernmentControlled email exchange across separated administrative networks.
๐Ÿ›กDefenseMessage transfer between restricted and external communication domains.
โšกCritical InfrastructureEmail communication for energy, utilities, and industrial operators.
๐ŸฆFinancial SectorReduced exposure for sensitive internal messaging platforms.
Comparison

AMG is not a conventional mail gateway.

Traditional gateways control traffic across a connected path. AMG is designed to prevent that path from existing permanently.

Capability Traditional Mail Gateway Bardin Gate AMG
SMTP Relay Yes Yes
Permanent Connectivity Yes No
Layer-3 Path Exists Yes No
Routing Required Between Zones Yes No
Firewall Dependency High Minimal
Physical Isolation No Yes
Hardware-Enforced Separation No Yes
Direct Internal Exposure Risk Present Eliminated by design

Ready for a technical evaluation?

Use Bardin Gate AMG as a secure email transfer appliance for isolated, segmented, and high-security environments where internal mail systems must not be directly exposed.