Unbreachable Access to
OT Data

Recognized by:

Uncompromising 
Security

Inbound cyber attacks are physically impossible through the Unidirectional Gateway hardware

Unlimited
Visibility

Software replicates industrial systems in real time to external networks using native OT protocols

What is a Unidirectional Gateway

A Unidirectional Gateway is a hardware-enforced cybersecurity solution that permits data to flow in only one direction. As defined by the National Institute of Standards and Technology (NIST):

“Unidirectional gateways are a combination of hardware and software. The hardware permits data to flow from one network to another but is physically unable to send any information at all back to the source network. The software replicates databases and emulates protocol servers and devices.”

A laser on one circuit board, connected to a photocell on a second board, guarantees one-way data flow that is physically impossible to remotely reverse.

There is physically no way to transmit cyber-attacks through a Unidirectional Gateway – proven to a high degree of confidence by Common Criteria certification, in the face of even the most sophisticated imaginable cyber attacks.

"Extremely reliable, easy integration in complex environments, set and forget functionality"

Healthcare & Biotech | <50M USD

Why Operators Choose Unidirectional Gateways

Access OT data with no OT exposure

Gateways replicate OT data. Users access the replicas without ever touching OT servers.

 Confident digital transformation

Enable cloud, analytics, and AI initiatives without increasing OT risk.

No rules to misconfigure

Firewalls are software. All software has bugs that can be misconfigured. A gateway is a physical constraint.

Continuous operations

There is no attack path from IT to OT. Operations stay up during IT cyber emergencies.

Exceeds regulatory & compliance requirements

Future-proof compliance with the strongest IT/OT segmentation.

Easily connect legacy systems

Hundreds of native connectors. Thousands of supported OT systems. No new software needed inside OT.

Built for OT

Connect

Safely share OT data

with IT, cloud &
analytics

Protect

Hardware-enforced one-way

communication blocks all

inbound threats

Replicate

Users and systems

interact with real-time

OT replicas

Waterfall hardware enforces security.
Our software delivers visibility.

Deployed at 1,000s of sites globally

Eliminate Entire Classes of Cyber Attacks

No malware. No remote compromise.
No human error. 
No inbound attack path.

Remote attacks

No inbound path means OT vulnerabilities stop being externally exploitable.

Ransomware

Gateways highlight OT dependencies on IT and eliminate the pathway of IT ransomware propagating to OT.

Malware propagation

No "Abundance of Caution" shutdowns. Attacks cannot move from IT to OT through a Gateway.

Human error at the boundary

Even legitimate administrators cannot misconfigure the product into allowing inbound traffic.

Denial of service against OT

To flood a system, it has to be reached first. Nothing on the external side can send traffic into OT through the Gateway.

AI zero-days

Even if the gateway software is compromised, the hardware cannot propagate that attack into OT targets.

Powered by Axle Software

Strong security shouldn't require complex operations. Waterfall’s Axle Software delivers a modern, intuitive user experience for all our gateway products, designed to streamline OT security management at scale.

Strong security. Efficient operations. 
With Waterfall, you get both

Simplifying Regulatory and Standards Compliance

NERC CIP-005 R1

Rewards unidirectionally-protected sites with 37 requirements exemptions, recognizing the strength of security provided by Waterfall’s gateways.

Recommends unidirectional gateways for protecting high-consequence network zones.

Describes unidirectional gateways as a stronger alternative to firewalls.

Unidirectional gateways satisfy the segmentation and isolation requirements that many nations’ NIS2-compliant regulations demand of essential and important entities.

FAQ
What is the difference between a data diode and a Unidirectional Gateway?

According to the NIST SP800-82 definition, a data diode is the hardware primitive. A unidirectional gateway combines that primitive with protocol connectors, server replication, and a management stack. The diode is the floor; the gateway software is what makes the hardware operationally useful for industrial systems.

A firewall is policy enforced by software, with rules that can drift, or be misconfigured or exploited. A fully-patched, correctly-configured firewall should not allow attacks to reach into OT networks. With Waterfall’s Unidirectional Gateways, it does not matter if the gateway is fully patched, nor if it is correctly configured – the gateway hardware cannot allow attacks into OT targets across the IT/OT consequence boundary.

Some sites do this manually, with write-once CD’s. Others use Waterfall’s FLIP – a variation of the Unidirectional Gateway that can reverse, either manually or on a schedule, to permit disciplined updates of AV signatures, production orders, contract commitments and other “batch” changes.
In most cases, yes. Waterfall’s Unidirectional Gateways have connectors for OPC-DA, for Modbus and Siemens S7, and for old versions of PI and other historians. Most often, the question is not “can we integrate” but “which of these several ways makes the most sense for us to use to integrate?”
Yes. The DiodeCore is one option for smaller sites. Our long-standing DIN-rail offering is another.
Yes. Cloud/AI connectivity is the future of automation. The question is not whether we will integrate with cloud-based AI and other services, but how to do this safely? Waterfall’s Unidirectional Gateways provide safe integration – the benefits of the cloud, without the risks.
This depends entirely on your unique plant infrastructure and data throughput requirements. Because every industrial environment is different, the best way to ensure you select the right architecture is to consult directly with our engineering team. Submit the form below to discuss your specific network boundary and let our experts recommend the right solution for you

Book a Demo

Tell us about the OT network you’re protecting

We’ll help you find the right unidirectional solution for your architecture, throughput, and operational requirements.