MAKING THE COMPLEX SIMPLE
BEYOND
THE CABLE
No Compromise on Security
Modern critical infrastructure demands real-time visibility of every asset — lifts, escalators, BMS controllers, gas monitors, switch rooms — without introducing a single point of vulnerability into your network.

This document sets out dbr's approach to secure, air-gapped, one-way data collection and the hardware and software stack that makes it possible. Designed for IT teams and security architects who understand that connectivity and security are not a trade-off.
ASSET LAYER BMS / Industrial
Controller
READ-ONLY · AES-128
COLLECTION OLYMPUS
Module
TLS 1.2 · JWT AUTH
CLOUD Secure
Cloud Server
HTTPS ONLY
CLIENT Web Dashboard
(any device)
SECURITY ARCHITECTURE & PRODUCT OVERVIEW
CONFIDENTIAL · dbr 2026
IT SECURITY EDITION
In critical infrastructure, connectivity is not optional.
Neither is security.
For too long, these have been treated as opposing forces.
dbr was built to prove they are not.

Every operations team managing lifts, escalators, building management systems, gas monitors, or industrial controllers faces the same dilemma. The data they need — real-time asset health, alarm status, predictive failure indicators — sits locked inside controllers that cannot be safely exposed to the internet. The result is a choice between visibility and security, where most organisations reluctantly choose security and accept the operational blind spot that comes with it.

That blind spot has a cost. Unplanned downtime. Site visits to read numbers that should be on a screen. Regulatory fines when lifts fail in airports that are required by the Civil Aviation Authority to maintain availability standards. Maintenance teams dispatched reactively rather than proactively. Critical infrastructure managed by clipboard rather than by data.

dbr's architecture begins with a single non-negotiable principle: no data connection back to the monitored asset, ever. Every dbr deployment uses a one-way, read-only communication channel between the asset and our data collection hardware. The asset cannot be reached, written to, commanded, or interfered with through the dbr system. The attack surface on your infrastructure is zero.

This is not a software policy. It is a physical architecture. The air gap between the monitored asset and our Olympus data collection unit is enforced at the hardware level via a serial connection — transmit only, no receive path. There is no software configuration, firewall rule, or access control list that can change this. An attacker who compromises the entire dbr cloud infrastructure still cannot send a single byte back to your BMS, your lift controller, or your industrial system.

Beyond the air gap, every layer of the dbr stack is hardened: encrypted storage on each field unit, TLS 1.2 for all cloud communication, JWT authentication with per-unit cryptographic credentials, AES-128 encryption on all radio transmissions, and active monitoring for intrusion attempts. All service ports are closed by default. Maintenance access is via SSH with cryptographic keys only — no passwords.

LAYER 01 Physical Air Gap

Hardware-enforced one-way data path. No return channel to the monitored asset.

LAYER 02 Encrypted Storage

Hardened Debian Linux on fully encrypted storage. All credentials on encrypted partition.

LAYER 03 TLS 1.2 + JWT

All cloud communication via HTTPS. Per-unit JWT tokens. No shared credentials.

LAYER 04 AES-128 Radio

All sub-1GHz radio transmissions encrypted at the hardware level.

LAYER 05 Network Defence

Built-in mitigation against DDoS, flood attacks, port scans, and TCP exploits.

LAYER 06 Active Monitoring

Continuous hardware health metrics. Flags suspicious activity and unauthorised access attempts.

The pages that follow describe dbr's three core hardware modules — Olympus, Atlas, and BusByte — and the system architecture that connects them. Each component has been designed with the same foundational principle: your infrastructure stays yours.

DBR SECURE DATA FLOW — ASSET TO CLIENT
ASSET BMS System Modbus / BACnet / LAN
ASSET Industrial
Controller
RS-485 / CANBus
ASSET Lift / Escalator Serial / Relay Contacts
ASSET Sensors &
Meters
Analogue / Digital
READ-ONLY COLLECTION · AIR-GAP ENFORCED
EXPANSION MODULE BusByte Collector Read-only · Serial TX-only output · Structured data format
SERIAL ONE-WAY · PHYSICAL AIR GAP
DATA SENDER OLYMPUS Module ARM Cortex-A72 · Encrypted storage · JWT auth · TLS 1.2
MOBILE BACKHAUL · ACTIVE IP SWITCHING
NETWORK Industrial Router Hardened config · All ports closed · DDoS mitigation
HTTPS · TLS 1.2 · CERTIFICATE PINNING
CLOUD INFRASTRUCTURE Google Cloud
Managed Platform
Regularly audited · HTTPS-only GUI · Managed containers
HTTPS · USERNAME + PASSWORD PROTECTED
CLIENT ACCESS Web Dashboard Any browser · Desktop / tablet / mobile · Device-agnostic
One-Way by Design

Data flows in one direction only — from the asset toward the cloud. The Expansion Module's Serial output is configured transmit-only. There is no physical or logical path for commands to return to the monitored asset.

Google Cloud Infrastructure

Hosted on a scalable Google Cloud managed container platform, regularly audited for security compliance. The client-facing web interface is accessible exclusively via HTTPS — no HTTP, no direct port access.

DBR-01 OLYMPUS Data Collector
& Sender Unit

The Intelligence Hub

Olympus is the core processing and transmission unit in every dbr deployment. It gathers data from a wide range of sources — legacy industrial controllers, BMS systems, digital and analogue sensors, relay monitors — and transmits it securely to dbr's cloud infrastructure via an encrypted, authenticated channel. Its hardened architecture is designed from the ground up to operate in industrial environments without creating a security liability.

Hardware Specification
CPU ARM Cortex-A72 on module
LAN 1× 10/100/1000 Mbps
USB 1× USB 2.0
Radio 1× internal sub-1GHz (868/922MHz)
Expansion 1× slot (RS-232/422/485, CAN, I²C)
Connector 1× configurable (up to 10-pin terminal)
Wi-Fi Optional
Power 9–36VDC / 9–36VAC · <7W
Enclosure DIN rail mount · IP20
Dimensions 100 × 120 × 35mm · <200g
Temperature −10°C to +55°C
Humidity 0–90% RH non-condensing
Certifications CE, RoHS compliant
Supported Protocols
Modbus BACnet CAN Bus MQTT HTTP(S) SNMP RS-232 RS-422 RS-485 I²C TCP/IP
01
HARDENED OS
Debian Linux on Encrypted Storage

Each unit runs a hardened Debian Linux environment with full storage encryption. All applications and customer data are protected at rest. Credentials stored on an encrypted partition, isolated from the main OS.

02
ACCESS CONTROL
Closed Ports · SSH Key-Only

All service ports are closed by default. Maintenance is conducted exclusively via SSH using cryptographic keys — passwords are not permitted. Remote access from mobile networks is blocked at the router level.

03
COMMUNICATION
TLS 1.2 + JWT Authentication

All communication to cloud servers is via HTTPS (TLS 1.2 minimum). Each Olympus unit uses a unique JWT token for API authentication, stored locally on the encrypted partition. No shared credentials across units.

04
RADIO SECURITY
AES-128 Encrypted Radio

All sub-1GHz radio transmissions between field units and the Olympus module are protected with AES-128 encryption. Typical indoor range 20–50m; outdoor range up to 500m.

Pre-IoT Compatibility

Connects to legacy systems that pre-date IoT standards, bringing them into a modern data platform without hardware replacement.

Multi-Unit Mesh

Multiple remote collectors can connect to a single Olympus sender via the integrated radio link, simplifying deployments across large sites.

Active Threat Monitoring

Continuous hardware health tracking. Suspicious activity — including unauthorised login attempts — is flagged in real time.

DBR-02 ATLAS Volt-Free
Contact Monitor

Relay State Monitoring at Scale

Atlas is a dedicated volt-free contact monitor that provides 16-channel relay state detection — ideal for lifts, escalators, access control systems, and any legacy equipment that communicates through open/closed relay contacts. It continuously monitors the state of every circuit, translates the contact data into a structured format, and transmits it securely to the Olympus unit via AES-128 encrypted radio. No wired network connection is required at the monitored asset. For larger deployments, multiple Atlas units can be combined to scale monitoring capacity without additional infrastructure.

Hardware Specification
Inputs 16× contacts (8 relays)
Radio 1× internal sub-1GHz
Relay Type Omron G2R-2 or compatible · 8-pin
Detection Open / closed states
Precision 20ms
CPU ARM Cortex-M0+
Power 9–36VDC (2-pin 5mm terminal)
Enclosure DIN rail mount · IP20
Dimensions 100 × 120 × 55mm
Weight <200g (<350g populated)
Temperature −10°C to +55°C
Humidity 0–90% RH non-condensing
Certifications CE, RoHS compliant
01
RADIO ENCRYPTION
AES-128 on All Transmissions

Every transmission between Atlas and the Olympus Sender unit is protected with AES-128 encryption. Typical indoor radio range of 20–50m means Atlas can be installed at the asset without any cabling to the network.

02
DATA ISOLATION
One-Way to Olympus

Atlas transmits contact state data to the Olympus unit only. There is no two-way communication channel from the Olympus module back to Atlas. The monitored asset's relay circuit is never exposed to any network.

03
SCALABILITY
Multi-Unit Deployments

Multiple Atlas units can connect to a single Olympus Sender. Scale from a single lift to an entire estate of lifts and escalators using the same architecture, with no additional network infrastructure required.

PRIMARY USE CASES
  • Lift and elevator controller monitoring — floor position, door state, alarms, movement direction
  • Escalator fault monitoring — brake status, speed faults, handrail and step detection
  • Access control state monitoring — door open/closed, lock status
  • Plant and machinery run/stop state
  • Legacy equipment with relay output and no digital interface
20ms Detection Precision

Relay state changes are detected and timestamped to 20ms precision. This enables analysis of door cycle times, lock dwell times, and speed events accurate enough to identify degradation trends before they cause failure.

No Network Cabling Required

Atlas communicates with Olympus entirely over encrypted radio. It needs only a 9–36VDC power supply at the asset location — no Ethernet run, no Wi-Fi, no SIM card. Industrial deployment is straightforward even in remote or confined locations.

DBR-03 BUS
BYTE
Unhackable
Data Transfer

The Unhackable Collection Layer

BusByte addresses the most demanding requirement in industrial IoT security: how do you retrieve data from a critical system — a SCADA controller, a BMS, an industrial process network — without creating any pathway through which that system could be compromised? The answer is a combination of air-gapped architecture and a strict read-only methodology that operates across two independent security layers, making the collection point virtually impervious to external attack regardless of what happens to any other part of the network.

BusByte's core security proposition is architectural, not procedural. It is not a firewall rule that could be misconfigured. It is not a software policy that could be bypassed. The read-only constraint on data collection and the one-way transmission of that data to the Olympus unit are enforced at the hardware level. There is no configuration that enables write-back to the monitored system.

DUAL-LAYER SECURITY ARCHITECTURE
L1
DATA COLLECTION LAYER
Strict Read-Only Enforcement

BusByte's first security layer applies at the point of data collection. The module enforces a strict read-only policy across all supported industrial communication protocols including Modbus and other serial interfaces. It is physically and logically incapable of issuing write commands, control commands, or configuration changes to the connected system. The monitored asset cannot be modified, commanded, or disrupted through BusByte under any circumstances.

L2
DATA TRANSFER LAYER
TCP/IP Isolation & Air Gap

Where TCP/IP-based collection is used, BusByte's second security layer enforces full network isolation between the collection segment and the transfer segment. The data transfer architecture uses a serial transmit-only (TX) connection to the Olympus unit — a physical air gap that ensures the collection network remains completely isolated. No packet from the internet or the wider network can reach the industrial system through BusByte's data path.

ATTACK SURFACE ANALYSIS

Even in a scenario where the entire dbr cloud infrastructure were compromised by an attacker, BusByte's physical air gap prevents any command or malicious payload from reaching the monitored industrial system. The one-way serial connection has no receive path. The industrial protocol interface is read-only at the hardware level. The attack surface on the monitored asset is structurally zero.

SUPPORTED COLLECTION INTERFACES
Modbus RTU Modbus TCP BACnet CANBus RS-485 RS-232 TCP/IP LAN
DEPLOYMENT CAPABILITIES
  • Wired or wireless transfer — data can be forwarded to the Olympus unit over a wired connection or via the encrypted radio link, depending on site conditions.
  • Locked-down OS — the BusByte unit runs on encrypted storage with all unnecessary services disabled.
  • End-to-end protection — all communication from BusByte through to the cloud servers is TLS/SSL encrypted and JWT authenticated.
  • Pre-IoT retrofit — brings legacy industrial systems with no native connectivity into the IoT ecosystem without modifying the original hardware.
  • Validated by blue-chip operators — the BusByte/Olympus air-gapped architecture has been tested and deployed across major critical infrastructure organisations.
TYPICAL APPLICATIONS
  • SCADA and building management system data extraction
  • Industrial controller monitoring in OT/IT-separated environments
  • Metering and sensor data collection from isolated site networks
  • Lift and escalator controller data extraction
  • Gas detection system monitoring
NEXT
STEPS

dbr's engineering team has over 50 years of combined experience in hardware design, data analytics and industrial applications. We work directly with IT teams and security architects to validate that our architecture meets your organisation's requirements before any hardware is deployed.

TELEPHONE
+44 1268 442888
ADDRESS
135 Cannon Workshops
3 Cannon Drive, London, E14 4AS
WEBSITE
WHAT TO EXPECT FROM A DISCOVERY CALL
Architecture Review

We walk through your specific asset environment and confirm how BusByte, Atlas and Olympus would integrate with your existing systems and network segmentation policy.

Security Sign-Off

We provide full technical documentation of our security architecture for review by your IT and cyber security teams, including penetration testing history and compliance evidence.

Pilot Deployment

A single-asset pilot is typically the fastest path to confidence. We can have a monitored asset feeding live data to the dashboard within 48 hours of hardware installation.

BEYOND THE CABLE · NO COMPROMISE ON SECURITY
Real-time visibility of your critical assets, wherever they are, without touching a thing.