The TAPP Gateway
The TAPP Gateway is the device that stands between your critical equipment and everything else. It is what makes it safe to monitor equipment that must never be exposed to a network. This page explains what the TAPP Gateway does and why its one-way design is the foundation of TAPP’s security posture. For the full site topology, see System Architecture.
What It Is
The TAPP Gateway is a one-way data transfer gateway. It creates a protected network for your control systems. Equipment control systems connect to the gateway’s protected side; TAPP’s cloud connectivity lives on its transport side. Equipment data is carried from the protected side outward to the transport side — and nothing is carried back.
A helpful way to picture it is a check valve for data — we call this the Digital Checkvalve. Just as a check valve in a piping system passes flow in one direction and closes against flow in the other, the TAPP Gateway carries equipment data outward and provides no path for anything to travel back toward your equipment.
How Data Moves Through It
Data moves left to right only. There is no return path from the transport side to the protected side — not for a command, not for a query, not for a configuration change, not for a software update.
Why One-Way Matters
Most monitoring products create a two-way connection to the equipment they watch — which means the same link that carries data out can, in principle, carry something in. The TAPP Gateway removes that possibility by design:
- No inbound commands. Nothing on the transport side — or anything beyond it, including the internet — can send a command, write a value, or change a setting on a connected control system.
- Not a setting. The one-way path is established in hardware, not configured in software. It is not a configuration option, it is not adjustable in the field, and it cannot be changed remotely — not by an attacker, and not by TAPP.
- No remote path to controls. The protected side is reachable only by physical presence at the equipment. There is no network route to it from anywhere.
The TAPP Gateway’s one-way design is what lets TAPP read from safety-critical equipment without becoming a way into it. The question a reviewer usually has to ask about a boundary device — who can change this, and how would we know? — has a short answer here: no one can change it remotely, because the direction of data flow was decided when the device was built.
What It Does Not Do
- It does not connect equipment control systems to your network.
- It does not accept inbound connections from the transport side.
- It does not issue control commands — TAPP reads equipment data using read-only requests (see System Architecture for the Modbus detail).
Where It Fits
The TAPP Gateway handles the controls / critical path. A second device, the Network Router, handles internet egress and the wireless sensor radio. The two are separate physical devices with separate roles. The two-device layout and the full data path are described in System Architecture.