TroutTrout

Compare Trout & Ewon (HMS Talk2M)

The Cosy dials out, Talk2M brokers, eCatcher connects. It is elegant, cheap and everywhere. It is also a third-party cloud in the path and a VPN that lands on the machine LAN.

The Problem

The problem

Ewon was designed for a machine builder who needs to reach one machine on a customer site without asking that customer's IT for a firewall rule. For that, it is close to perfect. Used as a plant's remote-access strategy, two things follow: your access depends on a service you do not run, and once the tunnel is up the engineer is on the machine's LAN with no policy between them and anything else on it.

Trout Access Gate

Trout Access Gate

The broker runs on your own network, so nothing depends on a third-party service staying available or staying in jurisdiction. Each session is scoped to a named asset and a named protocol, authenticated with MFA and recorded. Behind it the plant is divided into enclaves, so an engineer with a job on one machine cannot reach the rest.

Ewon (HMS Talk2M)

Ewon (HMS Talk2M)

A Cosy or Flexy gateway sits at the machine and opens an outbound connection to Talk2M, the HMS-hosted service. The technician joins the same rendezvous through eCatcher and gets a VPN to the machine. No inbound firewall rules, no public IP, a free tier, and an installed base measured in hundreds of thousands. For its intended job it is genuinely excellent.

Feature Comparison
FeatureAccess GateEwon (HMS Talk2M)
Deploys without re-cabling or re-addressing
Assets keep their IP, gateway and VLAN
Cosy sits in front of the machine
No inbound firewall rules needed
No inbound exposure; the gate brokers locally
Outbound-only connection to Talk2M
On-site hardware gateway
Fast to stand up for one machine
Runs with no third-party cloud service
Nothing leaves your network
Talk2M is the broker; self-hosting is not the standard path
Per-session, per-protocol policy
This user, this asset, this protocol
VPN lands on the machine LAN
Corporate directory identities (Entra ID / AD)
Users and groups synced from Entra ID, OIDC sign-in
Local Talk2M accounts; no directory federation documented
Offboarding revokes access automatically
Disable in the directory, access ends
Delete the Talk2M account by hand
Session recording and playback
Connection logs, not session content
Protects east-west traffic inside the plant
Scoped to the machine behind the box
Network segmentation
Overlay enclaves, no VLAN redesign
Automatic asset inventory
Detection and alerting
Snort rules, curated alert library, SIEM forwarding
Compliance evidence generation
IEC 62443, NIS2, CMMC mapping
Connection logs only
Scales to a whole site, not per machine
One appliance and one policy set for the site
One Cosy per machine, each with its own config and firmware
Key Differences

Whose cloud is in the path

Talk2M is the rendezvous, and it is operated by HMS. That is a dependency and, under NIS2 supply-chain scrutiny, a question you will be asked. Access Gate has no rendezvous outside your network.

A tunnel is not a policy

Once the VPN is up the engineer sits on the machine LAN. Access Gate brokers per session, so the policy names the asset and the protocol, and everything else stays unreachable.

Better behind it than instead of it

A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove Ewon. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.

Questions

Access Gate vs Ewon (HMS Talk2M) FAQ

No rendezvous

The broker runs on your network, so access does not depend on a third-party service being available or in jurisdiction.

No. The transport is encrypted, the outbound-only model avoids inbound exposure, and HMS operates it seriously with regional data centres. The issue is not whether it is secure but whether you are willing to depend on a third-party rendezvous for access to your own plant, which is increasingly a procurement and NIS2 question rather than a technical one.

Cost and speed for a single machine. A Cosy plus a Talk2M account gets a machine builder connected in an afternoon with no involvement from the customer's IT team, and the free tier makes it trivial to start. Nothing in this comparison beats that for that specific job.

Yes. There is no inbound exposure to open, because the gate brokers sessions locally rather than publishing a service. You get the property that makes Ewon attractive without the external rendezvous.

Usually not, and that is not what we recommend. Ewon is a capable spot solution for getting a technician to a machine, and on sites you do not own it may be the only thing you can deploy. The risk is not the product, it is deploying connectivity on its own: a Cosy per machine gives you doors into the plant with no visibility of what passes through them and no access control at an OT control point. The solid architecture is both. Keep Ewon where it earns its place, put Access Gate behind it, and every session that arrives still has to pass identity, protocol policy and recording, in a plant that is segmented rather than flat.

With a cloud-brokered model, remote sessions stop, because the rendezvous is unreachable. Access Gate keeps enforcing locally: on-site access, segmentation and policy all continue, since none of them depend on an external service.