TroutTrout

Compare Access Gate and Secomea.

Secomea is a well-built remote access product with a real self-hosted option. It gets your technician to the machine. This page covers what else the plant needs.

The problem

Remote access covers only the way in.

Remote access solves getting a person to a machine. It does not touch what happens between machines, which is where most OT risk actually lives. A plant that has solved vendor access still has a flat network where any device can reach any other, no inventory of what is on it, and no evidence to hand an auditor.

Trout Access Gate

Trout Access Gate

An appliance that brokers remote sessions as Secomea does, and does more. It segments the plant into enclaves without touching VLANs, inventories every machine it sees, raises alerts from a curated industrial rule set, and produces the compliance evidence IEC 62443 and CMMC ask for. Remote access is one of its functions.

Secomea

Secomea

A mature Danish remote-access platform: SiteManager at the machine, LinkManager for the technician, GateManager brokering between them. GateManager can be hosted by you rather than by Secomea, which matters for sovereignty, and the role-based access and audit logging are solid. For OEM service teams reaching deployed machines, it does its job well.

Feature comparison
FeatureAccess GateSecomea
Deploys without re-cabling or re-addressing
Assets keep their IP, gateway and VLAN
SiteManager sits in front of the machine
On-site hardware gateway
Can be fully self-hosted
No broker at all; enforcement is local
GateManager available as a customer-hosted server
Remote access for OEM and vendor technicians
Session audit trail
Clientless browser access
No software on the technician's machine
LinkManager client, with a mobile browser option
Protects east-west traffic inside the plant
Enforces between assets, not only inbound
Scoped to reaching the machine from outside
Network segmentation
Overlay enclaves, no VLAN redesign
Automatic asset inventory
You register the devices you want reachable
Detection and alerting
Snort rules, curated alert library, SIEM forwarding
Hosts services next to the assets
Protocol gateways, DNS/NTP, file share, historian
Compliance evidence generation
IEC 62443, CMMC, NERC CIP mapping
Access logs you assemble yourself
Scales to a whole site, not per machine
One appliance and one policy set for the site
One SiteManager per machine or cell, managed individually
Key differences

Access Gate covers more of the plant.

Secomea does remote access well. Remote access is one requirement out of several. A plant that buys only that still has a flat network, no inventory and no audit evidence.

Access Gate also controls traffic inside the plant.

Secomea governs the way in from outside. Access Gate also governs traffic between assets inside the plant, which is the path lateral movement actually takes.

Access Gate works behind Secomea.

A connectivity gateway is a door into the plant, and every one you add is another way in that your security stack cannot see. Access Gate does not ask you to remove Secomea. It sits behind it as the OT control point, so whatever arrives through the tunnel still meets identity, protocol policy, recording and a segmented network.

Questions

Questions about Access Gate and Secomea.

Beyond access

Segmentation, inventory, detection and compliance evidence in the same appliance that brokers the session.

Not necessarily. GateManager, the brokering component, can run as a Secomea-hosted service or on a server you own. That self-hosted option is why Secomea holds up better on sovereignty questions than the cloud-brokered alternatives in this category.

It is purpose-built for OEM and machine-builder service workflows, with a long track record and a support model geared to that market. If your only requirement is getting your own technicians to machines you have shipped, it is a focused answer to a focused question.

For the remote-access function, yes: an engineer reaches a named asset through a proxied session with MFA, a time window and a recording, with no client software to install. Whether you should replace it depends on whether remote access is the only thing you need, or the first of several.

Usually not, and we do not recommend it. Secomea is a capable tool for getting a technician to a machine. On sites you do not own, it may be the only thing you can deploy. The risk comes from adding connectivity on its own. A SiteManager per machine adds doors into the plant, with no view of what passes through them and no access control at an OT control point. The solid setup uses both. Keep Secomea where it earns its place and put Access Gate behind it. Every session that arrives then passes identity checks, protocol policy and recording, in a segmented plant.

Not with Access Gate. Sessions are brokered to the browser, so a contractor needs no client and you have nothing to distribute, patch or revoke on their machine.

Keep comparing

Also looking at cloud security tools?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.