Trout Software and CUI Vault, powered by NtelSec Inc., today announced a partnership designed to extend the secure handling of Controlled Unclassified Information (CUI) from CUI Vault's managed Microsoft GCC High environment directly to authorized physical assets through Trout's Access Gate technology.
The partnership addresses a critical challenge in defense manufacturing: the "last hop."
CUI Vault provides organizations with a secure environment to store, process, collaborate on, and transmit CUI. But for manufacturers, laboratories, and research organizations, the workflow often does not end in the cloud. Technical drawings need to reach printers, toolpaths need to reach CNC machines, and test profiles may need to reach laboratory or production equipment.
Historically, that last step often requires downloading files to local workstations or transferring them through removable media, introducing additional systems, security requirements, and chain-of-custody concerns into the CUI boundary.
Together, CUI Vault and Trout provide a secure, controlled path from the cloud enclave directly to the authorized physical assets that need to use that information.
How the integration works
CUI Vault connects natively to Access Gate over a FIPS 140-3 validated site-to-site tunnel. Access Gate sits on the plant or lab network in front of the equipment, terminates the tunnel, and runs a protocol-aware proxy. A job is pushed from inside the enclave, through the tunnel, to the proxy, and onto the device. The file never lands on an intermediate workstation, and nothing is installed on the OT device itself.
The result is a controlled chain of custody from the cloud to the machine. CUI Vault secures the information in the cloud, the tunnel protects it in transit, and Access Gate governs which authorized identity can communicate with which physical asset while recording the session.
The combined architecture reports to a unified System Security Plan, so the enclave and the shop floor stop being two separately assessed worlds with undocumented gaps between them.
Deployment is plug-and-play by design, requiring no agents on the protected equipment, no network rewiring, and no changes to how the underlying machine communicates.
A few real-world use cases
Printing from the enclave. An engineer opens a controlled drawing inside CUI Vault and sends it directly to an authorized shop-floor printer. The print job travels through the secure tunnel and is brokered by the proxy to the approved printer without requiring the file to be downloaded or emailed to a local workstation, and the spool file never exists on a laptop.
Pushing a job to a CNC. A toolpath generated from a controlled model can be sent from CUI Vault directly to a specific machine for an authorized job, inside a set time window, with the transfer recorded. When legacy equipment cannot support modern identity or authentication capabilities, Access Gate enforces identity and authorization at the proxy in front of the machine rather than on the machine itself.
Bringing results back into the enclave. This is the half most programs forget. Inspection and metrology output, including CMM results, as-built records, and machine logs, is frequently derivative CUI generated on the equipment outside the enclave. The same path runs in reverse: the proxy collects the output from the device and returns it into CUI Vault, so the record of what was made is stored under the same controls as the drawing it was made from.
Why the companies partnered
Extending CUI traceability from IT all the way to the machine is one of the hardest problems in defense manufacturing today. That last hop is where many programs slow down. Together with CUI Vault, we cover the whole perimeter from the enclave to the physical part, so manufacturers stay secure and compliant, and build faster.
CUI Vault was built to give organizations a secure, practical, and cost-effective way to protect CUI without rebuilding their entire IT environment. We solved that challenge in the cloud with a fully managed GCC High environment, but many customers still need CUI to reach printers, CNC machines, and other physical assets. Trout was a natural partner because we share the same mission of making cybersecurity simpler and more effective. Together, we can provide a secure, controlled path for CUI from the cloud enclave all the way to the physical assets that use it.
