TroutTrout
What is Overlay Networking|Learn More

Zero Trust for the plant floor. Built to industrial grade.

One 1U appliance in your rack, in front of the machines that cannot be patched or taken offline. It decides who reaches what, records every session, and keeps working whether or not the site has internet.

Access control in front of every machine

Every connection to a PLC, HMI or SCADA server is checked against a named person and a named asset. The machines themselves are never touched.

One console for the whole site

Cells, lines and the office network under one policy, managed from one screen. If you add a second site later it works the same way.

Automated OT compliance

CMMC, NIS2 and IEC 62443 evidence produced by running the system rather than by a separate project: access records, the permission matrix per zone, and a change history you export when an auditor asks.

Core Capabilities

Built for a working plant. Not a data centre.

It does everything Access Gate Essential does: asset discovery, secure remote access, protection for equipment that cannot be patched. This is what the bigger appliance adds on a site that runs around the clock.

Hardware that survives the floor

Industrial-rated components, redundant power, and a hardware bypass. Rated for continuous duty in a warm cabinet, because the line does not stop for a reboot.

Sized for the whole site

Port density and inspection headroom for a large plant with many cells and zones, not a single line. One appliance in the rack instead of a box per area.

In the path, without slowing the line

Segmentation and encryption run in hardware, so traffic passes at wire speed. The cyclic traffic between a PLC and its I/O never crosses the appliance at all.

Goes in without rewiring

No re-cabling, no re-addressing, no VLAN redesign. It sits alongside the network you already have, so there is no outage window to negotiate with production.

Nothing leaves the site

Policies, logs and session recordings stay on the appliance. No vendor cloud sits in the access path, so it runs in air-gapped and restricted environments without an exception.

The second layer of value

Secured by design. Adopted by default.

Security is the technical win. The organizational win is giving operations services they actually want, so teams stop routing around you.

The easier path becomes the secure one. That's how security sticks.

Remote access

Grant vendor and staff access to machines, through the proxy, never the flat network.

Protocol gateways

Let production data flow out, inspected and controlled, not through an open port.

DNS & time

Machines and apps resolve names and share accurate time, so OT just works and logs line up.

File sharing

Swap USB sticks and open shares for file access through a simple login built for operators.

Historian & dashboards

Expose production data on-site, without punching a hole to the cloud.

Update server

Deliver patches from on-site proxy, balancing patching requirements with a secure architecture.

Trusted by manufacturers and critical industries.

Thales
4h

to deploy compliance for on-premise application in restricted on-premise environments.

Trusted by leading companies

Orange Cyberdefense
Carahsoft
John Cockerill
Elna Magnetics
NeverHack
Kyron
Millbrook Machine
Eden Cluster
Airicom
Mountain Men
Skynopy
Pricing

Access Gate Performance.

Tailored to your infrastructure. Pricing based on deployment scale, site count, and throughput requirements.

Find a distributor

Volume and multi-year discounts available.

Enterprise Hardware & Software

The appliance, Trout CyberOS, enforcement in hardware, overlay networking and the management console. All of it runs on site.

Resilient Solution

Premium Support

A direct line to Trout engineers, or a vetted local partner, for the install and for tuning as the plant changes.

Dedicated SLA
The Trout Access Gate gave us a clear path to CMMC compliance without disrupting our manufacturing operations.
D
Director of IT
Defense Contractor, Elna Magnetics

Ready to get started?

Talk to our team to see how the Trout Access Gate fits your environment.

FAQ

Common Questions About Access Gate Performance.

6ms

Added latency on a brokered session. The control loop does not cross the appliance at all.

A 1U rack appliance on server-grade hardware, with redundant power and a hardware bypass. It is rated for continuous duty in a plant cabinet, not just a clean data centre.

CyberOS is the hardened operating system the appliance runs. It is set up for security enforcement rather than general use: a hardened kernel, a verified boot chain, and none of the extra services a general-purpose install would carry.

Yes. Policies, logs, recordings and management all live on the appliance. Nothing calls home for access to work, so it runs in air-gapped and restricted environments without needing an exception.

It sits alongside the network you already have rather than replacing it. Devices keep their IP addresses, the cabling does not change, and the appliance takes over only the paths you point at it. That is why it goes in without an outage window.

NIS2, IEC 62443 and CMMC at the same time. The evidence is a by-product of running it: access records, the permission matrix per zone, and a change history, exported when someone asks for them.

No. Segmentation and encryption run in hardware at wire speed, and the cyclic traffic between a PLC and its I/O stays on the underlay, so the control loop is never in the path.