Compare Trout & Xage
Xage and Access Gate use the same model: agentless, identity-based access to OT, enforced locally even when the site is offline. They differ in shape. Xage is a security fabric that spans the data center, the cloud and the plant. Access Gate is one appliance that puts compute on the wire at the plant.
The problem
Many OT incidents start with vendor and remote access. A VPN account or a shared jump server on its own gives a third party a route to the whole network. Xage and Access Gate both add identity-based sessions to that access. Both enforce Zero Trust. They differ in what you install, where it runs, and what else it does on the plant floor.
One appliance on the wire, at the asset
Access Gate is a physical appliance that sits in the data path next to the industrial assets. Each session is authenticated with MFA, limited to one asset and one protocol, inspected at the application layer and recorded. Access Gate connects several directories at once: staff sign in with Active Directory or Entra ID, and vendors with a second Active Directory or the directory built into Access Gate. The appliance has compute on site, so it also runs the services a plant needs next to its machines: protocol gateways, DNS and time, file sharing, historian access and a controlled update channel. It works fully air-gapped.
A distributed Zero Trust fabric
Xage describes its Fabric Platform as a distributed mesh of Fabric Nodes, deployed as VMs or containers on premises, in the cloud and at remote sites, managed centrally from a browser, with policy enforced locally. On top sit Secure Remote Access, Extended PAM with a distributed password vault, and Critical Asset Protection, which adds hardware or virtual XEP enforcement points for asset-level segmentation. Xage documents agentless browser access, per-device MFA, session shadowing and recording, and enforcement that continues offline.
| Feature | Access Gate | Xage |
|---|---|---|
| What you install | One appliance per site, cabled into the network you have | Fabric Manager plus Fabric Nodes as VMs or containers; hardware or virtual XEP enforcement points for asset-level segmentation |
| Compute on the wire that hosts plant services | Protocol gateways, DNS and time, file sharing, historian access, update channel | Secure file transfer and machine-to-machine data exchange documented; hosting DNS, NTP or historian services is not publicly documented |
| Agentless for OT assets | No endpoint agents or clients, per Xage | |
| Browser-based vendor access | ||
| MFA for assets that cannot authenticate | Enforced at the network layer | MFA per layer and per device |
| Session recording and supervision | Policy-driven recording and over-the-shoulder shadowing | |
| Enforcement with no internet | Fully air-gapped operation | Local enforcement continues when a site is offline |
| Per-command control inside OT protocols | Modbus TCP, OPC UA, SSH and HTTP inspected at the application layer | Asset- and application-level policy documented; per-command filtering of OT protocols is not publicly documented |
| Network segmentation | Overlay enclaves, no VLAN redesign | Zero Trust segmentation and XEP micro-zones |
| Asset discovery | Passive, without probing fragile equipment | Context-aware discovery in V2P Studio |
| Scope beyond the plant | IT, OT and IoT assets on the site | Data center, cloud, OT and AI agents on one platform |
| Compliance evidence | IEC 62443, CMMC, NERC CIP mapping | NERC CIP, IEC 62443, TSA; Fabric certified to IEC 62443-4-2 |
| What you pay for | One subscription per appliance: hardware, software, updates, support; no per-seat fees | User-based licensing with unlimited assets, per Xage; prices are not publicly documented |
Xage capabilities in this table come from Xage's public pages (checked September 2026). Where a capability is not publicly documented, the cell says so. Sources: Xage Fabric Platform · Secure Remote Access for OT · Vendor Access Management · Critical Asset Protection · Privileged Access Management
Access Gate also hosts plant services
Both products enforce access close to the asset. The Access Gate appliance also hosts protocol gateways, DNS and time, file sharing and historian access next to the machines. Xage documents secure file transfer and machine-to-machine data exchange. Hosting plant services on its nodes is not publicly documented.
One appliance per site, or a platform of nodes
Access Gate is one appliance per site, cabled into the network you already have and sold as one subscription covering hardware, software, updates and support. Xage is a Fabric Manager plus nodes, with XEP enforcement points where you want asset-level segmentation. Xage needs more planning, and it also covers more systems.
Scope: the plant or the whole enterprise
Xage covers data centers, cloud workloads and AI agents as well as OT, with one password vault across all of them. If your goal is a single access platform for the whole enterprise, that breadth is useful. If your goal is to secure a plant this week with your own team, one appliance takes less time.
Access Gate vs Xage FAQ
Access, segmentation, recording and plant services from one appliance at the site, fully air-gapped if you need it.
Yes. Xage positions its Secure Remote Access for OT and cyber-physical systems, documents agentless access to legacy assets such as PLCs, RTUs and HMIs, and states that the Xage Fabric holds IEC 62443-4-2 certification. Both products are built for OT, so the comparison comes down to architecture and scope.
Breadth and credential management. Xage documents a distributed password vault with automatic rotation, account discovery, and one policy model that runs from the data center and cloud down to the asset, including AI agents. For an enterprise that wants one access platform across IT and OT, that scope is a real strength.
According to Xage, not for enforcement. Its pages state that Fabric Nodes can run on premises, that credentials and policy are distributed across nodes, and that enforcement continues when a site goes offline. Access Gate provides the same from a single on-site appliance: it runs fully air-gapped, with no cloud dependency.
It changes where the compute runs. Access Gate is an appliance in the data path next to your machines. In addition to controlling sessions, it hosts the services a plant needs locally: protocol gateways between zones, DNS and time, file transfer into the OT zone, historian access for IT and a controlled channel for updates. Xage deploys its nodes as VMs or containers and offers a hardware XEP for segmentation. Hosting those plant services is not publicly documented.
If you are standardising privileged and remote access across data centers, cloud and several OT sites under one platform, Xage is built for that scope. If you need to secure a plant, or a fleet of sites, with one appliance each, recorded vendor sessions, segmentation behind them and plant services on the same appliance, Access Gate fits more directly. Pilot both on the same asset and compare the effort each one took.
Weighing cloud-delivered Zero Trust too?
If SASE and cloud-delivered Zero Trust are also on your shortlist, our Zscaler competitors and alternatives for OT comparison sets Zscaler, Palo Alto Prisma Access, Netskope and Cloudflare side by side against the constraint that decides it on a plant floor: PLCs and HMIs that will never run an agent.
Not sure which systems to protect first? Start with how to perform a risk assessment on your OT environment, which covers asset discovery and consequence rating without active scans.