AS393941
AS393941
  • Home
  • Products and Services
    • DataFort - Encryption
  • Support
  • Billing Portal
  • Policies
    • Privacy Policy
    • Terms of Use
    • Peering Policy
  • More
    • Home
    • Products and Services
      • DataFort - Encryption
    • Support
    • Billing Portal
    • Policies
      • Privacy Policy
      • Terms of Use
      • Peering Policy
  • Home
  • Products and Services
    • DataFort - Encryption
  • Support
  • Billing Portal
  • Policies
    • Privacy Policy
    • Terms of Use
    • Peering Policy
Encryption Solutions

AS393941 DataFort

Secure site-to-site or group-to-space encryption / connectivity for critical secure infrastructure.


AS393941 DataFort (DataFort) is a purpose built encryption system / appliance that creates high performance encrypted tunnels between sites or space systems using AES-256-GCM (other ciphers available) over GRE/UDP/TCP. 

Find out more

What It Does

DataFort sits between your red (plaintext) and black (ciphertext) networks, encrypting all traffic that crosses the boundary. It operates as a hardened Linux appliance with dedicated network zones, zone-based policy routing, and a tamper-resistant key vault replacing fragile VPN configurations with a managed, auditable encryption layer.

Operating Modes

  •  Point-to-Point - Encrypted tunnel between two sites with automatic session rekeying
  •  Hub-and-Spoke - Central server accepting connections from multiple remote client sites, each with its own pre-shared key and tunnel
  •  CCSDS Spacecraft - Red-to-Black and Black-to-Red UDP encryptors for CCSDS telemetry frames, with bypass SA support for ground station integration

Key Capabilities

  • AES-256-GCM & AES-256-GCM-SIV encryption with 3-way PSK session handshake and HKDF key derivation
  •  Automatic session rekeying on time and byte thresholds for forward secrecy
  •  Encrypted key vault with Argon2id key derivation, token-based access control, and optional USB Crypto Ignition Key (CIK) for two-factor vault authentication
  •  Zone-based nftables firewall with management, red, and black network isolation
  •  Zone policy routing — dedicated kernel routing tables per zone prevent cross-zone traffic leakage
  •  Ed25519 licence system with hardware-bound device fingerprinting and per-NIC resilience for virtualised deployments
  •  Signed secure updates with Ed25519 signature verification, atomic deployment, and automatic rollback on failure
  •  Encrypted backup/restore for disaster recovery with passphrase-protected encrypted bundles

Security by Design

Built for Compliance in Critical Environments

Security by Design

  • Three-zone network architecture (management / red / black). with hardware NIC separation
  •  OS hardening: SSH lockdown, restricted ciphers, sysctl hardening, audit logging, optional USB storage blacklisting
  •  Secure zeroisation: 3-pass overwrite of all keys, vault, certificates, configuration, and logs with SSD-aware secure erase
  •  Key export controls with runtime-toggleable lockdown
  •  Timing-safe cryptographic comparisons and path traversal protection throughout

Deployment Options

Built for Compliance in Critical Environments

Security by Design

  • Bare metal — Ubuntu 24.04 / Debian 12+ installer for x86_64, ARM64, and RISC-V
  • Bootable ISO — Ready-to-image for servers and virtual machines (AMD64, ARM64)
  • Armbian images — Pre-built for Raspberry Pi 5, Banana Pi F3, OrangePi RV2, Custom SoC
  • Virtual machines — Full support for VirtualBox, KVM, and VMware with VM-aware hardware fingerprinting

Built for Compliance in Critical Environments

Built for Compliance in Critical Environments

Built for Compliance in Critical Environments

DataFort is designed for environments that demand verifiable encryption boundaries, auditable key management, and tamper-evident operation. The appliance model - dedicated hardware, zone-isolated networking, hardware-bound licensing provides the physical and logical separation required by security frameworks governing high-security and controlled data.


DataFort was designed for and by aerospace engineers to meet and exceed governmental, environmental, and life-critical needs.

Patent Pending — 🇨🇦 CA 🇪🇺 EU 🇺🇸 US

Copyright © 2026 AS393941 - All Rights Reserved.

Connecting People Through Light and Space

  • Support
  • Billing Portal

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept