TroutTrout

Compare Trout & Xage

Xage and Access Gate use the same model: agentless, identity-based access to OT, enforced locally even when the site is offline. They differ in shape. Xage is a security fabric that spans the data center, the cloud and the plant. Access Gate is one appliance that puts compute on the wire at the plant.

The Problem

The problem

Many OT incidents start with vendor and remote access. A VPN account or a shared jump server on its own gives a third party a route to the whole network. Xage and Access Gate both add identity-based sessions to that access. Both enforce Zero Trust. They differ in what you install, where it runs, and what else it does on the plant floor.

Trout Access Gate

One appliance on the wire, at the asset

Access Gate is a physical appliance that sits in the data path next to the industrial assets. Each session is authenticated with MFA, limited to one asset and one protocol, inspected at the application layer and recorded. Access Gate connects several directories at once: staff sign in with Active Directory or Entra ID, and vendors with a second Active Directory or the directory built into Access Gate. The appliance has compute on site, so it also runs the services a plant needs next to its machines: protocol gateways, DNS and time, file sharing, historian access and a controlled update channel. It works fully air-gapped.

Xage

A distributed Zero Trust fabric

Xage describes its Fabric Platform as a distributed mesh of Fabric Nodes, deployed as VMs or containers on premises, in the cloud and at remote sites, managed centrally from a browser, with policy enforced locally. On top sit Secure Remote Access, Extended PAM with a distributed password vault, and Critical Asset Protection, which adds hardware or virtual XEP enforcement points for asset-level segmentation. Xage documents agentless browser access, per-device MFA, session shadowing and recording, and enforcement that continues offline.

Feature Comparison
FeatureAccess GateXage
What you install
One appliance per site, cabled into the network you have
Fabric Manager plus Fabric Nodes as VMs or containers; hardware or virtual XEP enforcement points for asset-level segmentation
Compute on the wire that hosts plant services
Protocol gateways, DNS and time, file sharing, historian access, update channel
Secure file transfer and machine-to-machine data exchange documented; hosting DNS, NTP or historian services is not publicly documented
Agentless for OT assets
No endpoint agents or clients, per Xage
Browser-based vendor access
MFA for assets that cannot authenticate
Enforced at the network layer
MFA per layer and per device
Session recording and supervision
Policy-driven recording and over-the-shoulder shadowing
Enforcement with no internet
Fully air-gapped operation
Local enforcement continues when a site is offline
Per-command control inside OT protocols
Modbus TCP, OPC UA, SSH and HTTP inspected at the application layer
Asset- and application-level policy documented; per-command filtering of OT protocols is not publicly documented
Network segmentation
Overlay enclaves, no VLAN redesign
Zero Trust segmentation and XEP micro-zones
Asset discovery
Passive, without probing fragile equipment
Context-aware discovery in V2P Studio
Scope beyond the plant
IT, OT and IoT assets on the site
Data center, cloud, OT and AI agents on one platform
Compliance evidence
IEC 62443, CMMC, NERC CIP mapping
NERC CIP, IEC 62443, TSA; Fabric certified to IEC 62443-4-2
What you pay for
One subscription per appliance: hardware, software, updates, support; no per-seat fees
User-based licensing with unlimited assets, per Xage; prices are not publicly documented

Xage capabilities in this table come from Xage's public pages (checked September 2026). Where a capability is not publicly documented, the cell says so. Sources: Xage Fabric Platform · Secure Remote Access for OT · Vendor Access Management · Critical Asset Protection · Privileged Access Management

Key Differences

Access Gate also hosts plant services

Both products enforce access close to the asset. The Access Gate appliance also hosts protocol gateways, DNS and time, file sharing and historian access next to the machines. Xage documents secure file transfer and machine-to-machine data exchange. Hosting plant services on its nodes is not publicly documented.

One appliance per site, or a platform of nodes

Access Gate is one appliance per site, cabled into the network you already have and sold as one subscription covering hardware, software, updates and support. Xage is a Fabric Manager plus nodes, with XEP enforcement points where you want asset-level segmentation. Xage needs more planning, and it also covers more systems.

Scope: the plant or the whole enterprise

Xage covers data centers, cloud workloads and AI agents as well as OT, with one password vault across all of them. If your goal is a single access platform for the whole enterprise, that breadth is useful. If your goal is to secure a plant this week with your own team, one appliance takes less time.

Questions

Access Gate vs Xage FAQ

One box

Access, segmentation, recording and plant services from one appliance at the site, fully air-gapped if you need it.

Yes. Xage positions its Secure Remote Access for OT and cyber-physical systems, documents agentless access to legacy assets such as PLCs, RTUs and HMIs, and states that the Xage Fabric holds IEC 62443-4-2 certification. Both products are built for OT, so the comparison comes down to architecture and scope.

Breadth and credential management. Xage documents a distributed password vault with automatic rotation, account discovery, and one policy model that runs from the data center and cloud down to the asset, including AI agents. For an enterprise that wants one access platform across IT and OT, that scope is a real strength.

According to Xage, not for enforcement. Its pages state that Fabric Nodes can run on premises, that credentials and policy are distributed across nodes, and that enforcement continues when a site goes offline. Access Gate provides the same from a single on-site appliance: it runs fully air-gapped, with no cloud dependency.

It changes where the compute runs. Access Gate is an appliance in the data path next to your machines. In addition to controlling sessions, it hosts the services a plant needs locally: protocol gateways between zones, DNS and time, file transfer into the OT zone, historian access for IT and a controlled channel for updates. Xage deploys its nodes as VMs or containers and offers a hardware XEP for segmentation. Hosting those plant services is not publicly documented.

If you are standardising privileged and remote access across data centers, cloud and several OT sites under one platform, Xage is built for that scope. If you need to secure a plant, or a fleet of sites, with one appliance each, recorded vendor sessions, segmentation behind them and plant services on the same appliance, Access Gate fits more directly. Pilot both on the same asset and compare the effort each one took.

Keep comparing

Weighing cloud-delivered Zero Trust too?

If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.

Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.