TroutTrout
Zero Trust for on-premise and industrial

Zscaler alternatives for OT and on-premise networks

Zscaler is built to connect a distributed workforce to cloud applications. If your endpoints are PLCs and HMIs that will never run an agent, here is how the Zero Trust options actually compare, and where an in-path, on-premise approach fits.

The real question

A question of category fit, not a scoreboard

Zscaler is genuinely good at what it was built for: connecting a distributed workforce to cloud applications. Its model assumes an agent on the endpoint and a network path out to a cloud point of presence. For a fleet of laptops reaching SaaS, that is the right design, and nothing here argues otherwise.

A water treatment plant or a machine shop breaks both assumptions. The endpoint is a PLC or an HMI that will never run an agent, and it often sits on a segment with no route to the internet. Cloud-delivered Zero Trust has nothing to install on the device and nowhere to send the traffic. That is a category mismatch, not a product flaw.

So the useful comparison is not who is better. It is which model fits a plant floor. The table below is built from each vendor's own public documentation, and where a capability is not documented it says so rather than guessing.

Side by side

How the Zero Trust options compare for industrial environments

Competitor cells are drawn from each vendor's public documentation, linked below. Where a capability is not publicly documented, the cell says so rather than assuming.

CapabilityZscalerPalo Alto Prisma AccessNetskopeCloudflare Zero TrustTrout Access Gate
Cloud dependencyCloud service; on-prem data-plane optionCloud-delivered SASECloud (NewEdge)Cloud only (global network)None; on-premise and in-path
Agent requiredClient Connector; clientless browser via PRAGlobalProtect; clientless browser via PRANetskope client; clientless browserWARP client; some clientless accessNone; agent-free
Works with legacy PLC / HMIBrokers clientless access to OT systemsBrokers OT and ICS remote accessMarkets access to SCADA, PLCs, HMIsNot documented for OT devicesYes; the device is never touched
Functions air-gappedNo; needs the cloud control planeNo; cloud-deliveredNo; needs the NewEdge cloudNo; needs Cloudflare's networkYes; no cloud dependency
Typical deployment timeNot documentedNot documentedNot documentedNot documentedHours; no rewiring, no downtime
Session recording and playbackYes; PRA session recordingYes; Browser PRA recordingNot documented; monitoring onlyCommand logging only; no replayYes; recorded and replayable
OT protocol awarenessRDP, SSH, VNC; no OT parsing documentedRDP, SSH, VNC; OT parsing lives in the NGFW, not the brokerRDP, SSH; OT discovery, not enforcementTCP, HTTP, SSH; no OT parsingProtocol-aware enforcement, including Modbus
Compliance mapping (CMMC L2 / NIS2 / NERC CIP)NIS2 published; CMMC and NERC not documentedNIS2 and NERC referenced; CMMC not documentedNIS2 published; CMMC and NERC not documentedNIS2 and FedRAMP; CMMC and NERC not documentedCMMC L2, NIS2, and NERC CIP

Sources: Zscaler · Palo Alto · Netskope · Cloudflare

What to look for

The questions that decide it on a plant floor

Does enforcement stay on site?

Cloud-delivered Zero Trust routes the access decision through a vendor point of presence. In-path, on-premise enforcement keeps every decision and every packet inside the fence, which is what an isolated OT segment and a data-sovereignty mandate require.

Can it protect a device that will never run an agent?

A modern proxy terminates the session, authenticates the person, applies policy, records what happened, and forwards a clean request. The PLC or HMI never knows anything changed, and it never needs software installed on it.

Is the audit trail ready for an assessor?

Tamper-evident logs of who connected, to which device, and what they did are what a CMMC, NIS2, or NERC CIP assessor asks for. Generated at the enforcement point, not reconstructed after the fact.

In production

This runs where agents cannot

Trout Access Gate secures defense manufacturers, research institutions, and critical-infrastructure operators: environments built on legacy PLCs, SCADA, and equipment that cannot take an agent. Among them are Thales, Millbrook Machine, Elna Magnetics, Irish Manufacturing Research, HUN-REN SZTAKI, and STBMA.

See customer stories

Questions about Zscaler alternatives

Access Gate is an agent-free, on-premise Zero Trust appliance for IT and OT, built for the assets a cloud ZTNA cannot reach.

Not for what Zscaler does best. If your job is connecting a remote workforce to SaaS, Zscaler is a strong fit and Access Gate is not trying to be. Access Gate is for the other half of the problem: securing on-premise IT and OT assets, including PLCs and HMIs that cannot run an agent and often have no path to the cloud. Many sites run both.

Yes. Enforcement happens in-path on the network, not on the endpoint. A modern proxy terminates the session, authenticates identity, applies enclave policy, and records the session, then forwards a clean request to the device. A twenty-year-old PLC gets the same Zero Trust treatment as a modern workstation, with nothing installed on it.

Yes. Access Gate runs fully on-premise as a virtual machine on a host that owns the network path. There is no cloud control plane and no cloud point of presence to reach, so it keeps working on an isolated or air-gapped segment. Cloud-delivered Zero Trust services depend on reaching their provider's network.

It maps to the access-control, system-and-communications-protection, and audit families those frameworks assess: identity-bound access, segmentation, network-layer MFA, and tamper-evident logs generated at the enforcement point. Treat it as one documented control in a broader program, not a compliance box on its own.

Access Gate enforces policy over the protocols on the wire, not just the ports. For a protocol like Modbus that has no native authentication, a protocol-aware proxy can bind access to identity, restrict which function codes and registers a source may use, and record every transaction, without touching the controller.

Start from your endpoints. If they are laptops reaching SaaS, a cloud ZTNA such as Zscaler, Prisma Access, Netskope, or Cloudflare fits. If they are PLCs, HMIs, RTUs, or air-gapped servers, an in-path on-premise appliance such as Access Gate fits, because it needs no agent and no cloud. The table above shows where each one lands.

See whether Access Gate fits your plant

Thirty minutes with an engineer is usually enough to tell whether an in-path, agent-free approach fits your network, or whether a cloud ZTNA is the better call. We will tell you honestly either way.