Access Gate datasheet.
Secure your plants without rebuilding the network. Access Gate connects to your existing network and puts a security proxy in front of each machine. No rewiring, no downtime, nothing to install on machines.
Last updated:
Download the Access Gate datasheet.
Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.
What's inside
Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.
See it in action
Request a live demo. See how Access Gate goes onto your network without rewiring or downtime.
Flat plant networks trust too much.
Industrial networks were built to be isolated. Today they mix IT, OT and decades-old systems, under pressure to digitalize. Every new connection adds exposure.
Isolated networks are now connected.
Industrial networks are more connected than ever, mixing IT, OT, and decades-old systems under pressure to digitalize.
IT and operations want different things.
Operators keep processes running while IT reduces exposure. Different KPIs, conflicting priorities, and fragile integrations.
Rebuilding the network is not an option.
Tearing down and redesigning networks is slow, costly and impractical. Plants can't afford to shut down for weeks.
Regulations keep piling up.
Plants must prove compliance with CMMC, NERC CIP, IEC 62443 and sector rules, on networks never built for it.
One security proxy per machine.
Access Gate protects operations without rewiring or downtime. The on-premise appliance uses network overlays and security proxies. It puts each critical machine in its own micro-DMZ, enforces identity-based access and contains lateral movement.
Proxy added in software.
No rewiring or changes to the underlay network. Asset cloaking and L3-7 protection deployed through software-defined networking.
Runs on-premise.
On-premise data processing, local enforcement, better performance. No cloud dependency for security decisions.
Policy-driven configuration.
A management layer that brings Zero Trust to OT, with policy-driven automation.
Compliance: Aligned with CMMC, NIST 800-82, IEC 62443, and DoD OT Zero-Trust guidance.
Add protection one flow at a time.
Software-defined networking makes the insertion safe. Access Gate builds a 1:1 overlay of the network, called the Secure Twin. Every asset keeps its own IP, gateway and routing. It also gets a twin address that routes through the proxy. To protect an asset, you change where its traffic goes. The wiring stays the same, so there is no cut-over window to negotiate with operations.
- 01
Twin DNS
For assets reached by name: the record resolves to the twin address, and the flow transits the proxy. One record, one asset, verified before the next.
- 02
Twin IPs
For assets reached by address: change one field on the client, the destination, from the real address to the twin. Nothing is spoofed and the operator sees exactly where traffic goes.
- 03
Source-based routing
For a whole subnet at once: one route on the existing switch or router sends its traffic to the twin range. No VLAN change, no renumbering.
- 04
In-line carry
When Access Gate is the site gateway and carries the VLANs and trunks itself, traffic transits natively and no per-asset step is needed.
Rollback: Each step is reversible on its own: revert the record, the field or the route and the asset is back on the underlay. In the adjacent deployment the network keeps running if the appliance is offline.
Common questions about Access Gate.
agents required. Access Gate connects to your existing network and protects machines from the network. Nothing to install on machines.
The Trout Access Gate (TAG) is an on-premise appliance that brings Zero Trust to operational networks. It uses software-defined networking to put a security proxy in front of each OT asset. Each asset gets its own micro-DMZ, without rewiring, downtime or agents.
The appliance is rack-mounted at the site and connects to your existing network. It passively learns OT communications and identifies devices. It then inserts a policy enforcement proxy in front of each asset through an SDN overlay. The underlying network stays exactly as it is.
No. The Access Gate builds a virtual overlay on top of your existing network using standard IP routing and bidirectional NAT. No VLAN changes, no IP renumbering, no recabling. Legacy PLCs, HMIs, and SCADA systems work without modification.
The Access Gate is aligned with CMMC, NIST 800-82, IEC 62443, and DoD OT Zero-Trust guidance (DTM 25-003). It provides the segmentation, identity enforcement, and audit logging required by these frameworks.
Yes. The Access Gate operates at the network level with no agents or software changes on endpoints. It protects assets that cannot be patched, updated, or scanned, including PLCs, HMIs, safety controllers, and equipment that is 10, 20, or 30+ years old.


