One-way transfer across the optical link A single optical fiber leaves the transmitter, falls once like water over a spillway, and ends at the receiver, where the signal becomes data again. Light travels only in that direction, and nothing returns.

SerialSpillway

A unidirectional gateway, or data diode, for file transfer across a security boundary, over a dedicated, one-way, optical link.

Drop a file into a watched folder on the sender host. It arrives in an output folder on the receiver host. No network joins the two sides, and the only thing travelling between them is light on a single fiber.

Security, compliance and standards →

One-way is built in, not configured

The sender drives an optical transmitter. The receiver carries only an optical receiver. One fiber joins them, and light travels it in one direction.

There is no return path. The receiver end contains no emitter, so a reverse channel is not something that can be switched on, misconfigured, or compromised into existence.

This is data flow enforcement by optical isolation rather than by firewall rule or software policy. There is no configuration state, software defect, or compromise of the receiver that can create a reverse channel over the link.

A link is two units and one fiber. The grey port is the transmitter; the unit on the right is the receiver. Each half connects to its own host over USB, and nothing but the fiber runs between the two sides.

No network stack on the data path

File transfer rides a raw serial link. There is no TCP/IP, no listening port, and no routable attack surface between the two zones. The transfer service itself is a single small binary running as a locked-down system service on Windows or Linux.

The far end of the fiber, unplugged. That red glow is the signal itself: 650 nm light on its way out of the transmitter, and the only thing that crosses the boundary.

Reliability on a link that cannot answer

A data diode cannot acknowledge. Nothing travels back, so delivery cannot be confirmed and a retransmission cannot be requested. SerialSpillway is engineered for that constraint rather than around it:

Management

SerialSpillway is managed through a terminal interface attached to the running service: status, configuration, and logs. Configuration is sealed at rest under a key the service mints itself.

Status screen showing state running, mode send, port COM19
                 connected, a valid license, an uptime of twenty-four minutes,
                 counters for files sent and queue depth, no last error, and a
                 progress bar for the file currently crossing the link at
                 seventy-one percent.
Status. Attached to a running service in send mode.
Configuration screen, General tab, listing mode, watch folder,
                 log level, and two management endpoint fields marked
                 read-only.
Configuration: General. Tabbed and edited in place. The management endpoint fields are read-only; the instance name is fixed at startup.
Configuration screen, Serial tab, listing serial port, baud
                 rate, data bits, stop bits and parity.
Configuration: Serial. Port and framing. Both ends must agree.
Configuration screen, Transfer tab, listing chunk size of
                 4096, send count of three, resend delay of two seconds,
                 maximum file size, and filename and folder limits.
Configuration: Transfer. Send N Times is the redundancy control, set to three here, so every chunk crosses the fiber three times.
Log screen at the receiving end, showing completed transfers:
                 all 383 chunks of a file accounted for, the file written to
                 disk, and a running byte ledger of everything read from the
                 link against the packets accepted.
Log. The receiving end of a finished transfer: every chunk of the file accounted for, the file written, and a running ledger of bytes read from the link against packets accepted.

Specifications

A link is two units: one transmitter, one receiver. Each half attaches to its own host over USB and presents itself to that host as a serial port.

A transmitter, marked Model SS-TX. It has one optical port, the grey one. The blue connector lying across the case is the far end of that same fiber, looped back into shot so the light coming out of it is visible.
SerialSpillway hardware specifications: connections, optical link, signalling rates and housing dimensions
Specification Value
Units per link Two: one transmitter, one receiver.
Host connection USB-C, one per host. A host connection is required at each end.
Host driver Silicon Labs CP210x USB to UART Bridge.
Optical connector V-Link (Versatile Link).
Wavelength 650 nm.
Fiber supplied 1 mm plastic optical fiber (POF), 3 ft (0.9 m) jumper.
Link distance, as supplied Up to 50 m on the supplied 1 mm POF.
Longer runs 200 µm plastic-clad silica (PCS) reaches up to 200 m. PCS is not supplied as standard. Contact us for runs beyond 50 m.
Serial rate 2,400 to 3,000,000 baud.
Housing, each half 2.00 × 1.05 × 0.88 in (50.8 × 26.7 × 22.4 mm).
Electrical isolation Galvanic isolation between the transmitter and receiver.
Hardware revision Pre-production. The housing is subject to change.

Standards and compliance

SerialSpillway's cryptographic validation, its operating-environment detail, and its framework alignment are set out on their own page. No third-party certification of the product has been performed.

Security, compliance and standards →

Talk to us about an evaluation →