Demarcation
tx edge
Secure, monitored handoffs between every network, department and third party.
Live media changes hands many times before it reaches air. Demarcation gives each of those handoffs a clean, monitored boundary, so networks stay isolated, quality is verified on both sides and faults are located in seconds rather than hours.
Why demarcation matters
In live broadcasting, the connection between organisations matters as much as the content itself. Modern workflows involve a host broadcaster, an outside broadcast company, a playout provider and multiple internal departments, each with a specific role and responsibility. Managing the flow of live media across those boundaries is what makes accountability, visibility and swift rectification of problems possible.
A media firewall provides that boundary. It receives media on one network interface, removes the network and transport layers, then re-encapsulates the payload for the next network. Nothing else passes between the two. Without that sanitisation your network is exposed to your neighbour’s, whether through protocol clashes, conflicting IP address allocation or through unsolicited and unexpectedly high bandwidth signals.
Because every demarcation point should also be a measurement point, monitoring each handoff turns a chain of separate responsibilities into one observable workflow. Teams can verify the quality of incoming and outgoing video, establish where a fault originated and act before it reaches the viewer.
Key Capabilities
Media traffic sanitisation
Network protection
A real trust boundary
Monitoring at every handoff
Deploy anywhere
Built Around Your Workflow
A broadcaster came to Techex with a live workflow that took content from many third parties, moved it across the organisation for processing, playout and distribution as linear channels, and passed it on to the Cloud for delivery. The requirement was to manage the flow of live media between all of those entities while keeping accountability, visibility and fast fault resolution intact.
Techex deployed tx edge as a media firewall wherever a boundary was needed: on premise, in the data centre and in the Cloud. With as many network interfaces as each site required, tx edge received authorised multicast content from third parties, verified it, then translated it via NAT into the broadcaster’s internal addressing scheme. Monitoring at every handoff meant the teams passing on and receiving traffic could each prove the quality of the stream.
Resilience was built into the same boundary. Where a third party feed arrived as a single path, tx edge dual launched it internally with SMPTE ST 2022-7 seamless switching, so errors on one path are healed from the other. Bridge Technologies VB transport stream probes were installed alongside tx edge for deeper IP and transport stream analytics, and to cross check the tx edge statistics during root cause analysis.
tx edge has been independently security tested against OWASP principles, achieving a Level 3 rating – required for military and medical tier platforms. Combined with its performance as a media firewall, that led the broadcaster to prescribe tx edge as their only validated route for moving live media into and out of the Cloud, and gave them real-time visibility of overall system health as they scaled their work with third parties.
Every Handoff. Every Network. Full Accountability.
Demarcation is not only about keeping networks apart. It is about knowing, at every point in the chain, that the media arriving is the media you expected, and being able to demonstrate it.
Techex builds demarcation points around tx edge, adding third party probes and content analysis wherever an extra layer of certainty is required.
Why choose Techex for demarcation?
Broadcast specialists, not general IT
Proven at national scale
Security you can evidence
Designed, deployed and supported
Powered by tx edge
tx edge is the Techex software-defined transport and monitoring node at the heart of every demarcation point we build.
It runs as a container, virtual machine, Cloud machine image or on bare metal, on x86 or Arm, so the same boundary behaviour applies whether you are handing off in a machine room or between Cloud availability zones.
Every node monitors what passes through it at IP, transport stream and content level, and reports to tx core for alarming, historic interrogation and root cause analysis.
tx edge has been independently tested against OWASP ASVS principles to Level 3, and supports the trust boundary model described in SMPTE RP 2129.

Trusted by
Ready to Secure Every Handoff?
Bring accountability, visibility and network protection to every point where your live media changes hands. Whether you are interconnecting departments, onboarding third parties or building a trust boundary for Cloud operations, our specialists can help.