Category: Commercial product | Status: Live platform with a public demo — first agency production deployment in progress
Breath Test Connect is a multi-tenant platform for connecting and managing a fleet of evidential breath-alcohol testing instruments in the field. It is the most mature product in the "Connect" family, and the platform whose proven components the other products build on.
The problem it solves
Evidential breath instruments in service today were designed for a different era of networking. They typically reach their backend over legacy, vendor-specific protocols that modern government networks are — correctly — no longer willing to carry across the public internet. That leaves agencies with a hard choice between running obsolete network infrastructure and replacing an entire instrument fleet.
BTc removes that choice. It acts as a secure middlebox: it terminates the legacy protocol at the edge, authenticates the instrument, and re-originates the traffic to the agency's backend server over a modern encrypted tunnel. The instruments do not change. The agency's network stops carrying legacy protocols.
Key capabilities
- Secure instrument connectivity — legacy protocol terminated at the edge, re-originated over WireGuard to the customer's backend.
- Per-instrument identity — unique credentials per instrument (never shared), MAC address binding that rejects unregistered hardware, optional per-instrument source-IP locking, and a static tunnel address per instrument so backend polling stays deterministic.
- Strict traffic isolation — instrument traffic is routed only to the designated backend. No other destination is reachable.
- Fast deactivation — decommissioning an instrument tears down its live session within seconds, not at the next reconnect.
- Encryption throughout — AES-256 at rest for buffered data, credentials and logs; encrypted transport outbound; encrypted portal-to-database traffic.
- Outage buffering — a short-term encrypted buffer rides out transient network cuts and is purged on confirmed delivery.
- Multi-tenant portal — separate operator, field-technician and IT-administrator roles, with MFA and per-tenant single sign-on.
- Full audit trail — every connection event and administrative action is logged.
The dongle: reaching sites that can't be reached
The active engineering workstream is a small hardware appliance for deployment sites that cannot expose direct legacy-protocol egress at all — typically county jails and sheriff's offices sitting on commercial ISP connections with no on-site IT staff.
The dongle is a compact WireGuard-based appliance that is configured before it ships. On site, it is plugged in between the instrument and the network; it dials home on its own and needs no local configuration, no static addressing, and no firewall changes by the host agency. Alongside the firmware, the workstream includes a manufacturing and provisioning engine, so each unit can be built, keyed and tracked as a serialized product rather than hand-configured one at a time.
Current status
Phase 1 is complete. The full stack is built and running: legacy-protocol ingress, the instrument registry with MAC binding, encrypted credential storage, connection-event logging, and the multi-tenant portal with operator and IT-admin roles. It is covered by an automated test suite and deployed on live infrastructure with public demo and staging environments.
So: a complete, working, deployed platform with a public demo. Per-tenant infrastructure isolation and multi-node high availability are deliberately deferred to a later phase.