TroutTrout
Press release·Integration

Extending Zero Trust into OT: Trout Access Gate and Tailscale

10 August 2026

The convergence problem

IT and OT networks were built for completely different worlds.

  • IT is all about speed and flexibility. Think of a mobile workforce connecting from office to home and airport lounges, and the agility to roll out new apps. Security is "fluid-ish": endpoints are patched (always on-time), software is swapped, and devices are replaced without ceremony.
  • OT is all about stability and safety. A controller installed in 2009 might be expected to run perfectly for fifteen years. It has never been patched, never been rebooted, and like a sourdough starter, everyone is a little afraid of what happens if it stops.

For most of their history these two estates were kept apart, often with an "air gap" between them.

That separation is shrinking. Predictive maintenance continuously moves shop-floor telemetry into cloud analytics. Remote support means a vendor needs a path to their systems, sometimes from another continent. Regulatory regimes including NIS2, CMMC, and NERC CIP now require demonstrable, auditable control over who reaches which asset across both domains.

Convergence is happening, and the hard part is doing it without collapsing OT's segmentation into a flat, reachable network.

What Tailscale solves, and where its model ends

Tailscale is the go-to for modern IT environments. It swaps out clunky, traditional VPNs for a secure, identity-based mesh network. A lightweight control plane allows admins to manage security policies centrally while enforcing them at every individual node, ensuring direct and efficient connections between users and assets. It's encrypted, efficient, and (true to its reputation)... it just works.

Tailscale architecture: an identity-based mesh network with a lightweight central control plane and direct encrypted connections between nodes
The Tailscale model: a central control plane, policy enforced at every node.

This is the correct model for the IT estate, where assets can run an agent. It is more challenging to apply on the OT boundary for a structural reason: the assets there cannot host a client. Tailscale's own answer for these populations is the subnet router: a node that advertises routes to a LAN segment, so that tailnet members can reach devices that can't themselves join the mesh. With ACLs and grants, you can control which people can reach which devices and ports behind the subnet router.

What the subnet router can't do is change how OT devices behind it behave. Once an authorized user has network access, they're talking to the equipment directly...

Where Access Gate extends the Tailscale model

Trout Access Gate is a natural extension of the Tailscale model. It presents to the tailnet as a subnet router, and then enforces Zero Trust inside the segment. It is agentless by design, which is what makes it deployable in front of assets that can offer nothing of their own.

Three capabilities define the difference:

Brokered sessions rather than direct network paths. Access Gate operates as an inline proxy. Authenticated users reach resources through the on-premise gateway, not by sitting directly on the OT network. This allows protocol hardening, time-limited grants, and session recording on connections to assets that have no native capacity for any of these, extending Tailscale SSH recording capabilities to RDP, VNC and multiple OT protocols.

PKI-backed encryption inside the LAN. Access Gate carries (or integrates with) a certificate authority, so encryption can be scaled across segments and assets that were never designed to negotiate it. This closes the gap between an identity-encrypted IT mesh and an OT plant or utility network where traffic has historically moved in the clear.

Glove-on-ready access management. Extending Zero Trust into OT means supporting diverse users, from operators in the field to plant engineers. The Access Gate UI is designed for simplicity, allowing these users to grant and revoke access with traceability in their scoped environments.

Access Gate glove-on UI: a simplified access-management interface for field operators and plant engineers to grant and revoke scoped access
The Access Gate glove-on UI: grant and revoke scoped access, with traceability.

The combined architecture

Together, Tailscale and Trout Access Gate create a unified path from the user to the asset. IT meets OT, but on their own terms, seamlessly and securely.

  • Tailscale carries identity-based, end-to-end encrypted access across everything that can run a client, from laptops and servers to cloud workloads, and delivers the authenticated user to the edge of the production network.
  • Access Gate terminates that path as the subnet router, then enforces per-asset authorization, proxies and records the session, and extends PKI-based encryption into the LAN where no agent can follow.

A user authenticates once against the corporate identity provider. Tailscale routes them efficiently and securely to the plant boundary. Access Gate decides, asset by asset, what they may reach, brokers the connection through the proxy, and writes a tamper-evident audit record that satisfies NIS2, CMMC L2, and NERC CIP evidentiary requirements. Internal staff, external vendors, and equipment with a fifteen-year service life are all governed under one consistent policy model.

Extending Zero Trust into OT: Trout Access Gate and Tailscale.

To deploy the integration, follow the Tailscale VPN configuration guide for Access Gate.

About Trout Software

Trout Software builds Access Gate, an on-premise Zero Trust platform that secures IT, OT and IoT in industrial, defense, utility and critical-infrastructure environments. Founded in 2022, Trout has teams in Paris, Dublin and Kingston, New York. Access Gate deploys alongside existing networks, without agents on equipment, to enforce identity-based access, segmentation and tamper-evident audit, entirely on-premise.

Press contact:press@trout.software