Next-gen portable security. Bridging remote sites securely through encrypted tunnels — hardware-level protection for critical data flows.
OLED display showing 638 Mbps active throughput · Gigabit Ethernet · USB-C power
127.5 mm × 74.5 mm × 27.3 mm · ~350g
GCM packet-level authentication. Unauthenticated traffic dropped instantly at the hardware level.
All outbound traffic encrypted before reaching the Internet — no exceptions, no bypass possible.
Physical intrusion triggers instant, irrecoverable key erasure. The device self-destructs its secrets.
Dedicated FPGA-based encryption engine with AES-256 GCM and True Random Number Generator (TRNG).
Independent tamper-proof circuits automatically erase all keys the moment physical intrusion is detected.
RJ45 Gigabit, Wi-Fi 6 (802.11ax), and LTE CAT4 — works on any network type, anywhere.
Full gigabit encryption speed despite the compact ~350g form factor. No performance trade-off.
Encryption keys generated on-demand by the embedded TRNG (NIST SP800-90B compliant). Never reused.
OLED touch display and web GUI designed for non-technical users. Deployable without IT specialists.
Instant secure erasure on command — all keys and sensitive data irrecoverably destroyed in seconds.
Powered from phones, laptops, power banks, or standard supply via USB-C. Works in any field condition.
| Processor | NXP i.MX8M PLUS Quad-core Cortex-A53 |
| Encryption Engine | FPGA-based real-time hardware accelerator |
| Operating System | Proprietary Hardened OS |
| Tamper Protection | Hardware detection with secure key erasure |
| Display | OLED 1280 × 720, Capacitive Multi-Touch |
| Dimensions | 127.5 mm × 74.5 mm × 27.3 mm |
| Weight | ~350 g |
| Operating Temperature | -20°C to +60°C |
| Power Input | USB-C 9V/2.5A or 15V/1.5A (Max 30W) |
| Encryption Algorithm | AES-256 GCM |
| Zero Trust Model | Self key management — NO cloud dependency |
| Key Storage | Secure, hardware-isolated |
| TRNG Module | NIST SP800-90B compliant |
| Ethernet | 10/100/1000 Mbps RJ45 (×2) |
| Wi-Fi | 802.11 a/b/g/n/ac/ax dual-band |
| Cellular | LTE CAT 4 — up to 150 Mbps DL |
| USB-C | Connectivity (×1) and Power (×2) |
| Throughput | Up to 1 Gbps |
| Secure Tunnels | 512 standard (up to 1024 custom) |
| Management Interface | Web GUI |
| Remote Management | Web GUI through encrypted tunnel |
| Deployment Modes | Standalone, LAN bridge, tunnel endpoint |
| OS Compatibility | Windows, Linux, macOS, iOS, Android, Harmony OS, IoT, SCADA |
Three deployment models covering every real-world secure networking scenario.
Protecting Home Users, Mobile or Traveling Users
Secures individuals working outside the office — executives, field engineers, remote employees. The HLS-HWE1000 travels with the user, creating an encrypted tunnel from any network (hotel Wi-Fi, mobile data, wired) to the corporate environment.
Typical users:
Connecting Two or More Offices or Locations
Each physical location installs one HLS-HWE1000 at its network entry point. The devices automatically create private encrypted tunnels between sites — all data traveling between locations is encrypted before leaving and decrypted only at the destination.
Typical users:
Combination of Full-Mesh and Hub-and-Spoke
Combines direct site-to-site links (full-mesh) with a central hub serving mobile and remote users (hub-and-spoke). Major offices communicate directly; a headquarters or data center simultaneously provides secure access for field teams or temporary locations.
Typical users:
Contact our team to arrange a demonstration, request a technical datasheet, or discuss custom configuration for your deployment scenario.