How Does CyberRidge Deliver Unrecordable High-Speed Optical Transmission, and How Is It Deployed?

A physical fiber link that can be tapped exposes more than most teams account for. An observer with access to the fiber can often see traffic metadata, who is talking to whom, when, and how much, even while the payload itself stays encrypted. That is a real exposure, but it is secondary. The more serious problem is the payload itself. Standard optical transmission carries a readable, recordable signal, so intercepted traffic can be harvested today and decrypted later once stronger computing power exists.
β
Gartner has said conventional asymmetric cryptography could become unsafe to rely on for confidentiality by 2030, shortening the runway for data that needs to stay protected past that date. Unrecordable optical transmission closes this gap by turning the signal itself into optical noise that cannot be captured or stored in usable form. CyberRidge's Carmel platform delivers this protection at the physical layer through patented photonic-layer security. Deployed as a plug and play replacement for existing transmission line cards.
β
CyberRidge delivers unrecordable, high-speed optical transmission by spreading, encoding, and burying the optical signal so it becomes physically indistinguishable from background noise to anyone without the decryption key applied at the exact instant the light arrives. Having the key is not enough; it must be applied at the correct moment, within a fraction of a second. Carmel performs this transformation in real time, in-line, at Layer 1, so no raw or readable data is ever exposed for an attacker to record and analyze, even if the fiber itself is tapped. Deployment does not require ripping out existing optical infrastructure. Carmel installs as a substitute for a standard transmission line card and is fully compatible with the amplifiers, ROADMs, and generally with complex DWDM settings already in place. This is how CyberRidge gets a live network to Post-Quantum Ready status in weeks instead of years.
β
What Harvest-Now-Decrypt-Later Actually Means
β
Fiber optic lines carry most of the world's data traffic and are often treated as inherently secure. They are not. Documents leaked by former NSA contractor Edward Snowden showed that the NSA's MUSCULAR program and GCHQ's Tempora program tapped fiber backbones to collect data directly from the physical layer, bypassing whatever encryption applications were using. More recently, the Wall Street Journal reported in May 2024 that U.S. officials privately warned telecom companies, including Google and Meta, that undersea cables in the Pacific could be vulnerable to tampering by Chinese-controlled repair ships. Once a signal can be recorded, it can be stored indefinitely and revisited later with better tools, which is the essence of a Harvest Now, Decrypt Later (HNDL) attack. Fiber tapping equipment is also inexpensive and widely available, lowering the bar for who can attempt interception, which is why payload harvesting has to be prevented before the point of interception, not after.
Read to find out which real-world fiber tapping incidents have already exploited this exposure.
β
How the Photonic Layer Security Works
CyberRidge's approach is built on three steps applied directly to the light itself. First, a mode-locked laser spreads the optical signal across a multi-terahertz spectrum, expanding the signal. across a spectral band so wide that, within the timeframe available for harvesting, no material on earth can absorb and record it.Second, a dynamic phase modulator applies an optical key that changes the signal's phase every fraction of a second; this is CyberRidge's Constantly Changing Encryption (CCE), and because the keys live only inside the light stream and are never stored, there is no static key file for an attacker to steal. Third, the signal is attenuated and buried beneath true random optical noise, producing a very low OSNR optical signal-to-noise ratio that makes the data mathematically unrecoverable without the key. The result looks like background noise to an unauthorized observer and must be optically decrypted and reconstructed in real time, before any conversion back to an electrical signal, at the authorized receiver.
Curious how this compares to Post-Quantum Cryptography and Quantum Key Distribution on the same threat? The distinction matters because both of those approaches still leave a recordable data stream on the wire.
β
What This Approach Does Not Solve
Photonic-layer security protects the physical transport of data across fiber. It does not replace application-layer authentication, endpoint security, or protection for data already at rest. CyberRidge positions Carmel as complementary to Post-Quantum Cryptography and other higher-layer protocols, not a substitute, since those layers still handle identity, access control, and key management above Layer 1. The technology also requires a paired unit at each end of a monitored link, so planning has to account for topology. Organizations evaluating this class of protection should treat it as one layer in a defense strategy, not the entire strategy.
β
How Carmel Fits Into a Live Network
CyberRidge supports three deployment patterns depending on the network's shape.
β
β
Practical Takeaways
Organizations with data whose sensitivity outlives 2030, financial records, health data, defense communications, or long-lived intellectual property, are the clearest candidates for physical-layer protection now, since anything recorded today under standard encryption is a future liability. CyberRidge's pitch is that this protection can be added without a network redesign: Carmel substitutes existing line cards, and Trekker centralizes management across whichever topology fits the deployment. The practical question for a security team is not whether to add PQC, but whether to also close the physical-layer gap that PQC alone leaves open.
β
Have a fiber network carrying data that needs to stay confidential past 2030? Visit CyberRidge to evaluate where Carmel fits your topology.
β
β
FAQs
Q: What is the difference between Carmel and standard optical encryption?
β
A: Standard optical encryption still produces a recordable, encrypted data stream on the fiber. Carmel instead manipulates the physical optical signal so it becomes indistinguishable from noise, meaning there is no recordable data stream to intercept in the first place, regardless of how the encryption keys are later compromised.
β
Q: Does deploying Carmel require replacing existing DWDM equipment?
β
A: No. Carmel is designed to substitute a standard transmission line card and can be deployed over existing third-party DWDM systems, without replacing the underlying transport infrastructure.
β
Q: How fast can Carmel be deployed on a live network?
β
A: Carmel reaches Post-Quantum Ready status in weeks rather than years, since it is a plug-and-play addition to existing infrastructure. This is a company-reported figure and will vary by network complexity.
β
Q: Does Carmel replace Post-Quantum Cryptography?
β
A: No. Carmel is complementary to PQC and other higher-layer protocols. Carmel protects the physical transport layer, while PQC and similar protocols continue to handle cryptographic protection above it.
β
Q: What is the Trekker Network Management System?
β
A: Trekker is CyberRidge's centralized platform for monitoring and managing deployed Carmel units, offering real-time visibility, alerting, and lifecycle management across a network, according to CyberRidge's product documentation.
β
Q: Can Carmel be deployed on subsea and long-haul terrestrial routes?
β
A: Carmel supports long-distance transmission over Standard Single Mode Fiber, including terrestrial and submarine links, and that the system introduces no added latency because it processes data in-line at the speed of light.
β
Q: Does harvest-now-decrypt-later protection only matter for government or defense networks?
A: No. Any organization transmitting data with a shelf life beyond a few years, financial services, healthcare, telecom, and enterprise data centers among them, faces the same Harvest Now, Decrypt Later exposure whenever traffic travels over fiber that can be physically tapped. Metadata concealment is a secondary benefit of the same protection, not the main reason to deploy it.
β