SerialSpillway
A unidirectional gateway, or data diode, for file transfer across a security boundary, over a dedicated, one-way, optical link.
Drop a file into a watched folder on the sender host. It arrives in an output folder on the receiver host. No network joins the two sides, and the only thing travelling between them is light on a single fiber.
Security, compliance and standards →
One-way is built in, not configured
The sender drives an optical transmitter. The receiver carries only an optical receiver. One fiber joins them, and light travels it in one direction.
There is no return path. The receiver end contains no emitter, so a reverse channel is not something that can be switched on, misconfigured, or compromised into existence.
This is data flow enforcement by optical isolation rather than by firewall rule or software policy. There is no configuration state, software defect, or compromise of the receiver that can create a reverse channel over the link.
No network stack on the data path
File transfer rides a raw serial link. There is no TCP/IP, no listening port, and no routable attack surface between the two zones. The transfer service itself is a single small binary running as a locked-down system service on Windows or Linux.
Reliability on a link that cannot answer
A data diode cannot acknowledge. Nothing travels back, so delivery cannot be confirmed and a retransmission cannot be requested. SerialSpillway is engineered for that constraint rather than around it:
- Configurable redundant transmission. Each file can be sent more than once, with a configurable delay between transmissions.
- Automatic receiver-side deduplication.
- Error detection on each packet and file. Packets that fail the check are discarded.
Management
SerialSpillway is managed through a terminal interface attached to the running service: status, configuration, and logs. Configuration is sealed at rest under a key the service mints itself.
Specifications
A link is two units: one transmitter, one receiver. Each half attaches to its own host over USB and presents itself to that host as a serial port.
| Specification | Value |
|---|---|
| Units per link | Two: one transmitter, one receiver. |
| Host connection | USB-C, one per host. A host connection is required at each end. |
| Host driver | Silicon Labs CP210x USB to UART Bridge. |
| Optical connector | V-Link (Versatile Link). |
| Wavelength | 650 nm. |
| Fiber supplied | 1 mm plastic optical fiber (POF), 3 ft (0.9 m) jumper. |
| Link distance, as supplied | Up to 50 m on the supplied 1 mm POF. |
| Longer runs | 200 µm plastic-clad silica (PCS) reaches up to 200 m. PCS is not supplied as standard. Contact us for runs beyond 50 m. |
| Serial rate | 2,400 to 3,000,000 baud. |
| Housing, each half | 2.00 × 1.05 × 0.88 in (50.8 × 26.7 × 22.4 mm). |
| Electrical isolation | Galvanic isolation between the transmitter and receiver. |
| Hardware revision | Pre-production. The housing is subject to change. |
Standards and compliance
SerialSpillway's cryptographic validation, its operating-environment detail, and its framework alignment are set out on their own page. No third-party certification of the product has been performed.