Skip to main content

Isidore Quantum User Manual

Isidore 1 Core Device

Last Updated: August 25, 2026

User Manual

Isidore 1 Core

Copyright 2024 - Forward Edge-AI, Inc.

Confidential and Proprietary Information. This document contains confidential information belonging to Forward Edge-AI, Inc. and shall not be published, reproduced, modified, copied, disclosed, or used for other than its intended purpose without the express written consent of duly authorized representatives of Forward Edge-AI, Inc.


1 Safety Information

1.1 Water, Moisture, and Environmental Protection

NOTICE: No Submersion or Liquid Exposure
Hazard: This device is not designed for submersion or exposure to running or standing liquids. Consequence: Contact with liquids may cause corrosion, electrical short-circuiting, or permanent component failure. To avoid: Do not submerge the device or expose it to running or standing liquids. Such exposure is considered improper use.

General warning (ISO 7010 W001) Caution, risk of electric shock (IEC 60417-6042)

WARNING: Prevent Liquid Ingress
Hazard: Liquids, condensation, or foreign materials can enter ports, seams, ventilation openings, or connectors. Consequence: Liquid ingress may compromise insulation, increase the risk of shock, or impair device operation. To avoid: Do not allow liquids, condensation, or foreign materials to enter any opening; keep connectors and vents covered and dry.

General warning (ISO 7010 W001)

CAUTION: Humidity and Storage Conditions

Hazard: Operating or storing the device outside its rated environmental limits. Consequence: Excessive humidity may cause internal condensation, degraded performance, or electrical hazards. To avoid: Operate and store the device only within the manufacturer's specified environmental limits.

General warning (ISO 7010 W001) Caution, risk of electric shock (IEC 60417-6042)

WARNING: Exposure Response
Hazard: The device has been exposed to moisture. Consequence: Operating a wet device may cause electric shock or component failure. To avoid: Immediately disconnect the power if it is safe to do so, and allow the device to dry completely before reuse. If damage is suspected, contact an authorized service provider.

NOTICE: User Responsibility
Damage resulting from exposure to liquids, moisture, or improper environmental conditions is considered improper care and is the user's responsibility.

1.2 Heat, Fire, and Electrical Safety

General warning (ISO 7010 W001) Caution, hot surface (IEC 60417-5041) No open flame (ISO 7010 P003)

WARNING: Ignition and Heat Sources
Hazard: Open flames, sparks, hot surfaces, or other ignition sources near the device. Consequence: Excessive heat may cause component failure, smoke, or fire. To avoid: Keep the device away from all ignition sources and hot surfaces.

General warning (ISO 7010 W001) Caution, hot surface (IEC 60417-5041)

CAUTION: Operating Temperature and Ventilation
Hazard: Operation outside the rated temperature range or with restricted airflow. Consequence: Overheating may degrade performance or damage the device. To avoid: Operate only within the specified temperature range, keep ventilation openings unobstructed, and do not place the device on soft surfaces or in confined spaces that restrict airflow.

General warning (ISO 7010 W001) No open flame (ISO 7010 P003)

WARNING: Hazardous Locations

Hazard: Use in explosive or hazardous environments containing flammable gases, vapors, or dust. Consequence: Use in such environments may result in fire or explosion. To avoid: Do not operate the device in hazardous or explosive atmospheres; it is not certified for such use.

General warning (ISO 7010 W001) No open flame (ISO 7010 P003) Caution, risk of electric shock (IEC 60417-6042)

WARNING: Emergency Conditions
Hazard: Smoke, unusual odors, excessive heat, or flames from the device. Consequence: These conditions indicate a fire or electrical hazard that may cause injury or damage. To avoid: Immediately disconnect power if safe to do so, evacuate the area, and use only a Class C fire extinguisher for electrical fires. Do not use water.

1.3 General Safety, Handling, and Servicing

Read the instructions (ISO 7010 M002)

NOTICE: Read Before Use
Review this manual and all safety instructions before operating the device. Failure to follow documented guidance may constitute misuse.

General warning (ISO 7010 W001)

CAUTION: Handling and Physical Protection 

Hazard: Dropping, crushing, or applying excessive force to the device. Consequence: Physical damage may expose internal components, increasing the risk of shock or failure. To avoid: Handle the device carefully and protect it from impact and crushing forces.

General warning (ISO 7010 W001)

CAUTION: Approved Accessories Only
Hazard: Use of unapproved power supplies, cables, mounting hardware, or accessories. Consequence: Unapproved components may pose safety hazards or damage equipment. To avoid: Use only manufacturer-approved accessories.

General warning (ISO 7010 W001) Caution, risk of electric shock (IEC 60417-6042)

WARNING: Maintenance and Servicing
Hazard: Servicing a powered or open device. Consequence: Contact with internal components may cause electric shock or damage to the device. To avoid: Do not open, disassemble, or service the device while it is powered; refer all servicing to authorized personnel.

Read the instructions (ISO 7010 M002)

NOTICE: Maintenance and Servicing Practices — observe the following device care practices before and during any maintenance:

Disconnect power before cleaning or inspection.

Do not disassemble, modify, or repair the device. Internal components are not user serviceable.

Servicing must be performed only by authorized service centers or qualified personnel approved by the manufacturer.

General warning (ISO 7010 W001) Keep out of reach of children

WARNING: Children and Pets
Hazard: Access by children or animals to the device, small parts, or cables. Consequence: Small parts and cables may present choking, tripping, or entanglement hazards. To avoid: Keep the device and accessories out of reach of children and animals.

General warning (ISO 7010 W001)

WARNING: Discontinue Use if Abnormalities Occur

Hazard: The device exhibits unusual noise, odor, heat, deformation, discoloration, or erratic behavior. Consequence: Continued operation may result in injury or damage. To avoid: Stop using the device immediately and contact an authorized service provider.

Read the instructions (ISO 7010 M002)

NOTICE: Duty to Report
Users are responsible for promptly reporting suspected defects, safety concerns, or abnormal device behavior. Report to the Isidore Help Desk at [email protected], or through the customer support portal at https://support.forwardedge.ai. Continued use of a device with a suspected defect or safety concern may increase the risk of injury or damage.

Read the instructions (ISO 7010 M002)

NOTICE
These safety guidelines are provided to promote safe installation, operation, and handling of the device. Failure to comply may result in injury, damage, or loss of warranty protection.


2 System Overview

2.1 What is Isidore Quantum®?

Isidore Quantum® is a quantum-resistant inline encryption platform designed to protect data in transit across diverse networks and operational environments. It combines purpose-built hardware, software, advanced cryptography, and embedded artificial intelligence to deliver resilient, future-ready protection against evolving cyber threats.

Deployed as a pair of protocol-, network-, and hardware-agnostic encryptors, Isidore integrates with both legacy and modern infrastructure and supports enterprises, government, and military environments without requiring fundamental changes to the underlying network architecture.

Designed in alignment with NSA CNSA 2.0 requirements, Isidore employs a hybrid cryptographic architecture combining AES‑256‑GCM authenticated encryption, ML‑KEM post‑quantum key encapsulation, and ML‑DSA digital signatures. This approach is designed to protect the confidentiality and integrity of data in transit against both conventional and emerging quantum-enabled threats.

How Data Flows with Isidore

  • Data leaves the sending PC or device and enters the trusted Red side of the first Isidore device.

  • The Isidore device secures and encapsulates the data before transmission.

  • The secured data traverses the untrusted Black side over the applicable communication medium, such as Ethernet or radio.

  • The receiving Isidore device accepts the data on its Black side, then verifies and decapsulates it.

  • Verified, trusted data is delivered to the receiving PC or device through the Red side.

2.2 Red Side VS Black Side Isidore Connections

Red vs. Black Isidore Connection

Black Side (Untrusted Zone)

  • Uses the first Industrial IX Type A Ethernet port

  • Represents the device’s untrusted security zone

  • Designed for connections to external networks or lower-trust devices

  • Keeps untrusted traffic separated to help reduce risk to trusted systems

Red Side (Trusted Zone)

  • Uses the second Industrial IX Type A Ethernet port

  • Represents the device’s trusted security zone

  • Provides secure connectivity for end-user devices or trusted internal networks

  • Intended for environments that require a higher level of security

3 Isidore Prerequistes

3.1 What is the box?

Required (Provided)

  • Isidore 1 Core Encryption Devices

  • Power Supplies

  • Industrial IX Type A Ethernet Cables

  • Quick Start Guide

Additional Items (Not Provided)

  • Ethernet cables

  • Internet Access

  • Network Switch or Router

  • Management PC/ End User Devices (Desktop, Laptop, Mobile Device)

3.2 Confirm Isidore Product Numbers

Isidore Product Number

Isidore device sets are pre-configured and cryptographically paired to enable secure communication and smooth integration.

For easy identification, each device includes a product number, as shown in Figure 4. Devices that belong to the same provisioned set will have matching product numbers.

3.3 Identify Isidore Node Sets

Node Number

To identify a device’s node number, such as Node 0, Node 1, or Node 2, refer to the label on the device. The node number determines the Black side IP address used to access the Management Portal and is required for proper network configuration.

Devices provisioned together form an Isidore set and must remain together for proper routing and secure communication. In each deployment, Node 0 serves as the hub and Node 1 serves as the client.

3.4 Product Identification Label

Identification Label

Serial Number (SN) Format: Each Isidore device is assigned to a unique 16-digit alphanumeric serial number used to identify the product type, hardware and firmware configuration, origin, and production sequence.

Example Serial Number: ISICR10902XETA000001

  • Product Identifier (ISI): Isidore device (product family)

  • Tier (CR1): Core, revision 1

  • Firmware Version (0902): PFED firmware v9.2.0

  • Miscellaneous (XETA000001): Internal configuration and tracking information

4. Isidore Setup

Hardware Setup: Initial Configuration

  • Plug the USB-C cable into the power port, then connect the device to power.

  • Slide the power switch left to the On position.

  • Repeat these steps for the remaining Isidore device(s).

  • Using the IX adapter, connect an Ethernet cable to the Isidore Black port.

  • Connect the other end of the Ethernet cable to a Layer 2 network switch

  • Repeat this step for the second Isidore device.

  • Connect your management PC to the same network switch and ensure it has internet access.

5 Accessing the Management Portal

To configure or manage the Isidore Quantum® Encryptors, connect your PC to the same subnet as the device management interface. By default, the management network uses the 192.168.10.x subnet.

Step

Description

1.0

Set Your PC’s IP Address

Open the Network Adapter Settings on your computer.

Select the Ethernet adapter connected to the Isidore management port.

Manually assign an IP address within the management subnet, such as:

  • IP Address: 192.168.10.50

  • Subnet Mask: 255.255.255.0

  • Default Gateway: 192.168.X.X (optional)

Save the settings and close the network window.

Note: Disable Wi-Fi and any other active network interfaces to ensure the PC communicates directly with the Isidore device.

2.0

Access Node 0 and Node 1

Connect your Ethernet cable directly to Node 0’s Black port or through an unmanaged network switch.

Open a web browser and enter the Node 0 IP address: 192.168.10.254.

If the browser displays a security warning stating “Your connection is not private,” continue by selecting:

  • Advanced

  • Proceed to 192.168.10.254 (unsafe)

After navigating to the Management Portal, log in using the default credentials:

  • Username: admin

  • Password: 123qwe

Note: This warning is expected. Isidore uses a self-signed certificate for local management access.

Security: Change the default password (123qwe) immediately after your first login. Do not operate the device using factory-default credentials.

Repeat the same process for Node 1 by entering its IP address: 192.168.10.1.

Note: These are the default IP addresses unless otherwise configured.

3.0

PFED Server Configurator Dashboard

Once logged in, the PFED Server Configurator dashboard will appear. This dashboard is used to manage each node and monitor the device’s Black-side operations.

  • Node 0: 192.168.10.254

  • Node 1: 192.168.10.1

4.0

Configure Network Setting

This step explains how to configure the device for your network environment.

  • On the left panel, under Configure, select Network.

  • Set the IP configuration based on your network environment.

  • Under Subnet Mask, enter the mask used by your network (for example, 255.255.255.0 for a /24 network).

  • Under Default Gateway, enter the gateway address for your network environment.

5.0

Configure Channel Attributes

From the dashboard:

  • Locate the Channel Number section.

  • Under the Action column, select the three-dot menu.

  • Click Edit Channel Attributes.

In this section, you can configure:

  • Protocol

  • Remote Gateway

  • Remote Port

  • Listening Port

For a Mesh configuration, go to Node 1 and edit Channel 1 so that the Remote Gateway points to Node 2's device IP address.

In a Hub-and-Spoke configuration, spoke devices should use the Node 0 device IP address as their gateway.

Note: For all topologies, use this section to specify the device the PFED gateway will communicate with directly.

6.0

PFED Management API Status

This section displays the current operational status of the PFED Management API. When the system is functioning properly, the status will show as Active, confirming that the device is online and communicating correctly

7.0

PFED Logs

Real-time PFED logs are available for monitoring, troubleshooting, and status checks.

This section displays the operational status of the PFED. When the system is functioning properly, the status will show as Active, providing quick confirmation that the device is connected and communicating correctly.

8.0

Terminal Access

The terminal provides direct command-line access to the device for advanced configuration, diagnostics, and troubleshooting.

Default Terminal Credentials:

  • Login: pfed

  • Password: !QAZ1qaz

Note: The terminal is best viewed using the Microsoft Edge browser.

Security: Change the default terminal credentials immediately after first use. Do not leave factory-default credentials in place on a deployed device.

9.0

Factory Reset

This option resets the device to its factory default settings, clearing existing configurations and restoring it to its original setup.

10.0

Password Reset

Change the factory-default password immediately after your first login.

  • On the left panel, select Admin.

  • On the Change Password screen, enter the Current Password, then the New Password and Confirm Password.

  • Select Update.

Note: Repeat this step on each Isidore node.

6. Network Topology Configurations

The Isidore Quantum® encryption platform supports multiple network topologies to provide secure, quantum-resistant communication across different operational environments.

Each topology uses the Protocol Free Encryption Device (PFED) core to establish encrypted channels, independent of the underlying transport method or routing design.

Isidore supports two topology configurations:

  • Point-to-Point: a single encrypted channel between two devices.

  • Mesh: multiple devices establishing encrypted channels with several peers at once.

Note: This manual provides the basic information needed to get started. Detailed topology design guidance will be provided in future Isidore documentation.

6.1 Point to Point Topology

Configuration for Point-to-point Topology

Use when: Connecting two secure endpoints.

  • Two Isidore devices create a single encrypted channel.

  • Node 0 functions as the hub, and Node 1 functions as the client.

  • Designed for low-latency, high-assurance communication.

  • Commonly used for secure site-to-site links or isolated system-to-system connections.

  • Traffic remains restricted to the authorized endpoints.

6.2 Mesh Configuration

4 Node Mesh Topology Overview

Use when: Multiple systems require secure peer-to-peer communication.

  • Encrypted connections with multiple peers.

  • Eliminates a single point of failure.

  • Supports redundancy and resilient data flow.

  • Intended for dynamic or infrastructure-limited environments.

  • Requires additional planning for proper deployment and configuration.

7. Black Management Plane (BMP)

The Black Management Plane (BMP) provides a single, browser-based interface for monitoring and managing an entire fleet of Isidore encryptors. From one dashboard, an operator can review device status, channel state, network topology, telemetry, and audit history without logging in to individual devices. The BMP is delivered through the Isidore Fleet Management (IFM) Portal.

The BMP operates on the black side of the network and handles only non-cryptographic operations. Keys, cryptographic material, and cryptographic configuration are managed separately on the red side.

7.1 Black Management Plane Capabilities

From a single dashboard, operators can:

  • View every device in the fleet and see whether each is Online, in a Warning state, or Offline briefly.

  • Enable, disable, configure, start, and stop individual channels on each device.

  • Design and apply Full Mesh, Hub & Spoke, or Point-to-Point network topologies across the fleet.

  • Manage portal members within an organization and audit who did what, and when.

7.2 Initial Setup

Complete all network connections before applying power.

Component

Connection

BMP Appliance

Connect the BMP Portal Appliance to an available LAN port on the router using an Ethernet cable.

Network Switch

Connect the network switch to an available LAN port on the router using an Ethernet cable.

Isidore Devices

Connect each Isidore device to the network switch using an Ethernet cable.

Power

After all connections are complete, apply power to the router, network switch, BMP Portal Appliance, and all Isidore devices.

Verify that all devices are powered on and all Ethernet connections are secure before continuing.

7.3 Accessing and Configuring the Black Management Plane

BMP is a centralized web application. Operators do not need direct network access to individual devices, only HTTPS access to the portal URL provided by your administrator, using the current version of Chrome, Edge, or Firefox (Internet Explorer is not supported).

For the initial administrator login, use the username [email protected] with the temporary password provided by Forward Edge-AI. Upon first login, you must set a new password before accessing the portal. The new password must be at least 8 characters and include one uppercase letter, one lowercase letter, and one number.

Step

Action

1.0

Open a browser and navigate to the portal address provided by your administrator. If you have no active session, the Cassian sign-in screen appears.

Attempt to access the portal using http://bmp-portal.local:3000. If the hostname cannot be resolved, determine the IP address assigned by the router and navigate to http://<Portal-IP-Address>:3000. instead.

2.0

Enter your username and password, then click SIGN IN. For the initial login, use the username [email protected] with the password 123qwe; you must change this password on first login. If you have forgotten your password, click Forgot password?.

On first login you are redirected to the Set Your Password screen; if your password has already been set, the Overview dashboard opens instead.

3.0

Enter a new password and confirm it. The password must be a minimum of 8 characters and include an uppercase letter, a lowercase letter, and a number. Click SET PASSWORD.

4.0

The Overview dashboard opens, showing the fleet globe, the Total Devices, Online, Warnings, and Offline counters, and the Black Side panel with device list, channel health, and recent activity.

5.0

Click a device marker on the globe to open its detail panel. The panel shows the device status, the number of active channels, per-channel Running state with STOP controls, and the View Device and Topology actions.

6.0

From the left sidebar, click Devices to open the device inventory. The table lists each registered device with its type, fleet, and status.

7.0

To bring a newly discovered device into the fleet, complete the Activate Discovered Device form. Enter the serial number, latitude, longitude, fleet, topology, and organization, then click Activate.

8.0

Open a device and locate the Channel Navigator. Select the channel tab (for example, CH 1) to view its state and the Black Side Controls.

9.0

To set a peer on an unconfigured channel, open Configure Channel. Enter the peer IP address and port, select the transport protocol (udp or sctp), then click Confirm.

10.0

Once a peer is configured, the channel shows STOPPED. Click Start to bring the link up; the badge changes to RUNNING and a start succeeded confirmation appears.

11.0

To take a channel offline while preserving its peer configuration, click Stop. To clear the peer configuration entirely, click Disable and then Confirm Disable; the channel returns to NOT CONFIGURED and must be reconfigured to reconnect.

12.0

From the left sidebar, click Networks. The topology surface shows the selected network, its device count, active links, and plan status.

13.0

Choose a network topology using the MESH, HUB & SPOKE, and POINT-TO-POINT controls. For Point-to-Point, select the device pair, then click Add Pair.

14.0

Click Generate Point-to-Point Plan, then review the Plan Health tab and resolve any reported issues. When the plan is clear, click Connect All Planned to apply it. The portal configures and starts the underlying channels on each device.

15.0

Select a link on the canvas to inspect it. Links appear in one of four states: Connected (purple, both channels running), Partial (amber, one channel stopped), Configured but Offline (red, both channels stopped), and No Channel Configured (gray). Use Start Link or Stop Link to change a link's state, or Disconnect Link to remove it. A disconnected link remains on the canvas and can be restored with Connect Link.

16.0

To change a device's network settings, open the device workspace and select the NETWORK tab. Review the Data Plane Network details, then under Configure set Mode to Static and enter the IP, netmask, and optional gateway.

17.0

From the left sidebar, click Users to manage organization members and their roles. Only an Organization Administrator or Platform Administrator can invite new members.

18.0

To perform a cryptographic action, first stop the affected channels here, then sign in to the Red Management Plane (RMP) and complete the action. Return to this portal and start the channels. Use Stop rather than disable to preserve peer configuration.

7.4 Core Concepts

Device: A single Isidore unit registered with the portal. Each device has a stable identifier (for example, ISI-N1-001), a fleet, an IP/DNS address, and a current status (Online, Warning, or Offline).

Channel: A logical communication slot on a device. Channel 0 is the always-on Control channel; the remaining channels are user-configurable point-to-point links to peer devices. A channel moves through three states:

  • Not Configured: no peer IP/port has been set.

  • Stopped: peer IP/port are set, but the channel is not passing through traffic.

  • Running: peer is configured, the channel is online, and traffic is flowing.

From the device detail page, you configure a channel (set peer), start it, stop it (peer config preserved), or disable it (clears peer config, returning the channel to Not Configured).

Network: A named collection of devices with a topology mode applied across them. The portal supports Full Mesh (every device peer with every other), Hub & Spoke (one device peers with

8. Red Management Plane (RMP)

The Red Management Plane (RMP) is the operator-facing interface for managing Isidore devices on the red, trusted cryptographic side of the network. All cryptographic operations, including channel provisioning, key lifecycle (provisioning, zeroization, and rekeying), and channel state control, are performed exclusively through the RMP and cannot be done from the black-side portal.

8.1 Hardware Setup

Complete all network connections before applying power.

Component

Connection

RMP Appliance

Connect the RMP appliance to an available LAN port on the router using an Ethernet cable.

Isidore Console Node

Connect the Isidore Console Node to the router using an IX-to-Ethernet cable.

Network Switch

Connect all Isidore nodes to the network switch using IX-to-Ethernet cables.

Power

After all connections are complete, apply power to the router, network switch, RMP appliance, Isidore Console Node, and all Isidore nodes.

8.2 Network Setup

Parameter

Value

RMP server default IP

192.168.1.200

Subnet mask

255.255.255.0 (/24)

Portal port

3000

Default portal URL

Workstation example IP

192.168.1.201 (or any unused address in the subnet)

Warning: The red-side switch must remain isolated from external networks. Connecting it to an internet-facing or untrusted interface violates the cryptographic boundary and may compromise Isidore’s security posture.

8.3 Initial Setup

Topic

Details

Sign-In

Open a supported browser.

Go to the RMP URL (default http://192.168.1.200:3000).

Enter your username and password.

Click Sign In.

Users Page

The Users page displays local users registered in the RMP and provides controls for adding a local user to the Red Side portal.

Registering a Local User

· Click Register User in the upper right of the Users page.

· The Register User modal opens. Use this workflow to add a local user account to the Red Side portal

Devices Page

View all registered Red Side devices and their status

Fleet Summary

Read the four status cards: Total Devices, Online, Degraded, Offline.

Device List and Filter

Filter devices by IP, serial number, or other fields.

Click a device row to open its details.

Adding Devices

· Click Add Device, then Continue under Manual Entry.

· Enter device type, serial number, MAC address, red-side IP, and port.

· Click Add Device.

Details Page

Click on your device row on the Devices page to open its Device Details page

Zeroize a Single Channel

Click Zeroize on a channel row and confirm.

Provision Channel

· Click Provision

· Enter the mode

· c for Client

· s for Server

· Enter the seed

· Click Provision Channel

Start & Stop a Channel

· Starting a channel activates it so it can carry traffic. The Start button is only available when a channel is in the Stopped state.

· Stopping a channel halts traffic but preserves provisioning state (keys remain). The channel can be restarted without re-provisioning. The Stop button is only available when a channel is in the Running state.

Reset Channel

Resetting a channel returns it to its original state. Both sides of the channel pair must be restarted after a reset for communication to resume.

8.4 Portal Troubleshooting (BMP and RMP)

The table below covers issues specific to the Black Management Plane (BMP) and the Red Management Plane (RMP). For device power and network-access issues, see the Troubleshooting section.

Symptom

Probable Cause

Corrective Action

When to Contact Support

Sign-in fails with an authentication error.

Incorrect credentials, or the account is not yet active.

Verify the portal/appliance address and confirm your credentials with your administrator. If you were issued a default password, complete the forced password change on first login.

If sign-in still fails after credentials are confirmed.

The Devices table is empty.

Your role is not scoped to a fleet, or all devices are Offline while the filter is set to Online.

Clear the status filters and confirm with your administrator that at least one device is registered.

If no devices appear after clearing the filters.

A channel shows ERROR.

The peer device is not responding to keepalive.

Verify the Remote Gateway and Remote Port on the Configure Channel form, confirm the peer device is Online, then stop and start the channel.

If the channel remains in ERROR after retrying.

A channel is stuck in STARTING or STOPPING.

The portal is waiting for the device to acknowledge the command.

Wait up to 60 seconds, then refresh the device detail page and confirm the device is Online.

If the state does not resolve after refreshing.

The session expires unexpectedly.

Inactivity, closing all browser windows, or clearing site data ends the session.

Sign in again from the appliance address using your credentials.

If sessions end immediately or repeatedly after signing in.

The map/globe shows fewer devices than the Devices table.

The status filter above the globe is set to a single status.

Reset the filter to All Devices to show the full fleet.

Not usually required; contact support only if the counts still differ.

9 Customer Support

For assistance or questions, contact the Isidore support team by email:

Support Hours

Monday through Friday: 9:00 AM to 6:00 PM ET

Saturday and Sunday: Closed

For all support inquiries, contact the Isidore Help Desk through the customer support portal:

Isidore Customer Support Guide:

You may also visit the Forward Edge-AI website for product information, documentation, and live chat support:

Website and Live Chat:

Follow on Social Media for Announcements:

Live Chat

For immediate assistance, use our live chat feature on our support website. Maven, our support bot, is ready to help you in real-time during support hours. Just ask Maven!

10 GLOSSARY OF KEY TERMS

ACRONYM

DEFINITION

EU

Encryption Unit

EUD

End User Device

IX

Industrial Ethernet (Type A connector used for ruggedized networking)

NID

Network Interface Device

PFED

Protocol-Free Encryption Device (Isidore’s code name at the NSA)

PKI

Public Key Infrastructure

SWaP

Size, Weight, and Power

Red Side

Trusted, secure internal network zone of the device

Black Side

Untrusted external network zone of the device

Hub (Node 0)

Central node responsible for initiating and maintaining encrypted sessions

Client (Node 1, 2, …)

Endpoint nodes paired with the hub for secure communication

Node Number

Unique identifier (0, 1, 2, …) assigned to each Isidore device for addressing

Isidore Pair

Pre-configured and cryptographically linked hub-and-client devices

Management Portal

Web-based interface used for configuration and monitoring of nodes

Trust Boundary

Physical and logical separation between secure (Red) and unsecure (Black) processing units

Processing Units (PU1, PU2, PU3)

Independent CPUs within the device, separated by security boundaries

Encryption Layer

Cryptographic mechanism ensuring confidentiality, integrity, and authenticity of packets

Bi-Directional Configuration

Default setup allowing two-way communication between Red and Black

Channel Assignment

Allocation of communication channels to nodes for encrypted links

Point-to-Point Topology

Direct, secure communication channel between two designated nodes

Hub-and-Spoke Topology

One hub node communicating securely with multiple client nodes

Mesh Configuration

Decentralized topology where each node establishes encrypted peer-to-peer links

PFED System Log Viewer

Monitoring tools for system activity, troubleshooting, and verifying operational status

Factory Reset

Process to restore the Isidore device to its original configuration and clear settings

Red Management Plane (RMP)

Operator-facing management portal for the trusted, cryptographic (Red) side of Isidore devices; handles channel provisioning, key lifecycle, and channel state control.

Black Management Plane (BMP)

Operator-facing management portal for the untrusted, external (Black) side of Isidore devices; handles network transport configuration, device connectivity, and fleet monitoring.


THE INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE.

LIMITED WARRANTY: IT IS EXPRESSLY AGREED THAT NO WARRANTY OF MERCHANTABILITY, WARRANTY OF FITNESS FOR A PARTICULAR PURPOSE, NOR ANY OTHER WARRANTY (EXPRESS, IMPLIED OR STATUTORY) IS MADE BY FORWARD EDGE-AI, EXCEPT THAT FORWARD EDGE-AI WARRANTS THE GOODS TO BE FREE FROM DEFECTS IN MATERIALS AND WORKMANSHIP FOR A PERIOD OF ONE (1) YEAR FROM DELIVERY.

DURING THIS PERIOD, WE WILL REPAIR OR REPLACE, AT OUR DISCRETION, ANY DEFECTIVE PARTS AT NO CHARGE. THIS WARRANTY DOES NOT COVER DAMAGE CAUSED BY MISUSE, ACCIDENTS, UNAUTHORIZED MODIFICATIONS, OR NORMAL WEAR AND TEAR.

IN NO EVENT SHALL FORWARD EDGE-AI OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL OR USE OR MISUSE OF THIS PRODUCT, EVEN IF FORWARD EDGE-AI OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Did this answer your question?