Compare Trout & Ewon (HMS Talk2M)
The Cosy dials out, Talk2M brokers, eCatcher connects. It is elegant, cheap and everywhere. It is also a third-party cloud in the path and a VPN that lands on the machine LAN.
The problem
Ewon was designed for a machine builder who needs to reach one machine on a customer site without asking that customer's IT for a firewall rule. For that, it is close to perfect. Used as a plant's remote-access strategy, two things follow: your access depends on a service you do not run, and once the tunnel is up the engineer is on the machine's LAN with no policy between them and anything else on it.
Trout Access Gate
The broker runs on your own network, so nothing depends on a third-party service staying available or staying in jurisdiction. Each session is scoped to a named asset and a named protocol, authenticated with MFA and recorded. Behind it the plant is divided into enclaves, so an engineer with a job on one machine cannot reach the rest.
Ewon (HMS Talk2M)
A Cosy or Flexy gateway sits at the machine and opens an outbound connection to Talk2M, the HMS-hosted service. The technician joins the same rendezvous through eCatcher and gets a VPN to the machine. No inbound firewall rules, no public IP, a free tier, and an installed base measured in hundreds of thousands. For its intended job it is genuinely excellent.
| Feature | Access Gate | Ewon (HMS Talk2M) |
|---|---|---|
| Deploys without re-cabling or re-addressing | Assets keep their IP, gateway and VLAN | Cosy sits in front of the machine |
| No inbound firewall rules needed | No inbound exposure; the gate brokers locally | Outbound-only connection to Talk2M |
| On-site hardware gateway | ||
| Fast to stand up for one machine | ||
| Runs with no third-party cloud service | Nothing leaves your network | Talk2M is the broker; self-hosting is not the standard path |
| Per-session, per-protocol policy | This user, this asset, this protocol | VPN lands on the machine LAN |
| Corporate directory identities (Entra ID / AD) | Users and groups synced from Entra ID, OIDC sign-in | Local Talk2M accounts; no directory federation documented |
| Offboarding revokes access automatically | Disable in the directory, access ends | Delete the Talk2M account by hand |
| Session recording and playback | Connection logs, not session content | |
| Protects east-west traffic inside the plant | Scoped to the machine behind the box | |
| Network segmentation | Overlay enclaves, no VLAN redesign | |
| Automatic asset inventory | ||
| Detection and alerting | Snort rules, curated alert library, SIEM forwarding | |
| Compliance evidence generation | IEC 62443, NIS2, CMMC mapping | Connection logs only |
| Scales to a whole site, not per machine | One appliance and one policy set for the site | One Cosy per machine, each with its own config and firmware |
Whose cloud is in the path
Talk2M is the rendezvous, and it is operated by HMS. That is a dependency and, under NIS2 supply-chain scrutiny, a question you will be asked. Access Gate has no rendezvous outside your network.
A tunnel is not a policy
Once the VPN is up the engineer sits on the machine LAN. Access Gate brokers per session, so the policy names the asset and the protocol, and everything else stays unreachable.
Better behind it than instead of it
A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove Ewon. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.
Access Gate vs Ewon (HMS Talk2M) FAQ
The broker runs on your network, so access does not depend on a third-party service being available or in jurisdiction.
No. The transport is encrypted, the outbound-only model avoids inbound exposure, and HMS operates it seriously with regional data centres. The issue is not whether it is secure but whether you are willing to depend on a third-party rendezvous for access to your own plant, which is increasingly a procurement and NIS2 question rather than a technical one.
Cost and speed for a single machine. A Cosy plus a Talk2M account gets a machine builder connected in an afternoon with no involvement from the customer's IT team, and the free tier makes it trivial to start. Nothing in this comparison beats that for that specific job.
Yes. There is no inbound exposure to open, because the gate brokers sessions locally rather than publishing a service. You get the property that makes Ewon attractive without the external rendezvous.
Usually not, and that is not what we recommend. Ewon is a capable spot solution for getting a technician to a machine, and on sites you do not own it may be the only thing you can deploy. The risk is not the product, it is deploying connectivity on its own: a Cosy per machine gives you doors into the plant with no visibility of what passes through them and no access control at an OT control point. The solid architecture is both. Keep Ewon where it earns its place, put Access Gate behind it, and every session that arrives still has to pass identity, protocol policy and recording, in a plant that is segmented rather than flat.
With a cloud-brokered model, remote sessions stop, because the rendezvous is unreachable. Access Gate keeps enforcing locally: on-site access, segmentation and policy all continue, since none of them depend on an external service.