Security Architecture

Hardware-Enforced Security at Every Layer

BusByte's security model starts with a physical constraint — a hardware air gap that no software vulnerability can bridge — and adds hardened cryptographic protections at every subsequent layer.

No software vulnerability can bridge a physical air gap

The Physical Air Gap

The core of BusByte's security is a serial connection between the Expansion Module and the Olympus Unit. The Expansion Module's serial interface is configured for transmit-only (TX) operation — the receive (RX) line is not connected. This is not a firewall rule. It is not a software policy. It is the absence of a physical wire. There is no electrical path by which the Olympus Unit, cloud servers, or any internet-connected system can send a signal to the Expansion Module or the asset network it is connected to.

Protected Zone
Asset Network
Expansion Module
Physical Air Gap
TX
TX only — no RX path
No signal can travel this direction ←
Olympus Unit
Cloud
HTTPS · TLS 1.2
Client Devices

Security at Every Layer

Hardened Architecture

Industrial ARM Compute Module running hardened Linux with full storage encryption. Applications and customer data are protected even if the hardware is physically removed.

Restricted Access

All service ports are closed by default. Maintenance is conducted exclusively via SSH using cryptographic keys. Passwords are not permitted.

Secure Cloud Communication

All communication between the Olympus Unit and cloud servers uses HTTPS over TLS 1.2. No unencrypted upload path exists.

Robust Authentication

JWT (JSON Web Tokens) secure all API communication. Each unit uses a unique credentials stored on an encrypted partition — not shared, not reused.

Network Defence

Built-in mitigation against DDoS, flood attacks, port scans, and TCP-based exploits at both the Olympus Unit and the industrial router.

Active Monitoring

The system continuously tracks hardware health metrics and flags suspicious activity, including unauthorised login attempts, in real time.

Three Defence Layers

Physical Layer

  • Hardware air gap
  • TX-only UART. No RX connection
  • Read-only data collection
  • No command path to assets

Network Layer

  • Closed service ports
  • Industrial router with hardened port configuration
  • Mobile back-haul with active IP switching
  • No inbound mobile access. Packet forwarding disabled

Cloud Layer

  • TLS 1.2 HTTPS uploads
  • JWT authentication
  • Unique per-unit credentials on encrypted storage
  • Google Cloud infrastructure. Regular audits. HTTPS-only dashboard

Download the Security Architecture Sheet

A two-page technical overview of BusByte's security design, suitable for IT security reviews and compliance assessments.

Questions about compliance? Get in touch →
Download PDF