TroutTrout

What is Access Gate? Agentless Zero Trust for OT.

Access Gate is Trout Software's on-premise Zero Trust overlay for OT. It solves the security and compliance problem today, without downtime, then turns that foundation into simple secure services your OT teams actually adopt.

Last updated:

The short answer

Access Gate is an agentless, on-premise Zero Trust overlay for operational technology (OT) networks, built by Trout Software. It plugs into the existing network and enforces identity-bound access, microsegmentation, network-layer MFA, and tamper-evident audit across IT, OT, and IoT, without installing agents on the equipment, rewiring the network, or stopping production.

Who builds it

Trout Software

Trout Software is a cybersecurity company founded in 2022, with offices in Kingston (New York), Paris, and Dublin. It builds Access Gate to bring Zero Trust to the operators of critical infrastructure and industry, water and wastewater utilities, electric utilities, defense manufacturers, and industrial sites, that run legacy OT which cannot support traditional, agent-based security.

Layer 1, today

Solve the security problem now, without downtime

The first job is the one you cannot defer: securing Operational Technology (OT) from PLC & HMI to sensors, desktop in industrial environments, on-premise file servers... and all the critical equipments that run the operations, yet where you cannot install a security agent, bring offline for reconfiguration and tend to be legacy.

Trout Access Gate installs as an appliance, on-site. It delivers the controls compliance asks for from day one, without touching the protected equipment: visibility, access control, identity, logging, encryption among others. Trout Access Gate is unique as it allows to run industrial proxy at scale in your critical environment - deporting the security agent from the untouchable asset to a proxy sitting in front of it - and networking innovation to insert these proxy without downtime. See agentless Zero Trust for OT.

See everything

Passive discovery maps every asset, OT, IT, and IoT, including legacy PLCs and HMIs, without probing fragile equipment.

Segment without rewiring

Microsegmentation as an overlay: logical enclaves with precise flow rules, no VLAN redesign, no recabling.

Bind access to identity

Every connection is tied to a person or service, with MFA enforced at the network layer, even for gear that cannot authenticate on its own.

Prove it

Tamper-evident audit of every session for SIEM, incident response, and CMMC, NERC CIP, NIS2, and DOH/DEC evidence.

Layer 2, next

Then turn the overlay into services OT actually wants

Once the secure fabric is in place, the same overlay delivers simple services the OT teams adopt by choice, not by mandate. Security stops being a tax and becomes an enabler. Secured by design, adopted by default.

Secure remote access

Identity-bound, MFA-protected, session-recorded access for operators and vendors. No shared VPNs, no exposed jump hosts.

Protocol gateways

Safe bridges between zones and protocols, so systems that must talk can, through a controlled and logged path.

DNS and time

Trusted internal name resolution and time sync without exposing OT to the internet.

File sharing

Move files in and out of the OT zone safely, with every transfer attributed and logged.

Historian access

Expose operational data to IT, analytics, or cloud without giving anyone a path to the controllers.

Safe updates

Deliver patches and updates to OT through a single controlled channel, on your schedule.

Questions

Access Gate, in plain terms

Access Gate is an agentless, on-premise Zero Trust overlay for operational technology (OT) networks, built by Trout Software. It plugs into an existing network and enforces identity-bound access, microsegmentation, network-layer MFA, and tamper-evident audit across IT, OT, and IoT assets, without installing agents on equipment, rewiring the network, or stopping production. It is delivered as an appliance or a virtualized network function running Trout CyberOS.

Trout Software is a cybersecurity company founded in 2022, with offices in Kingston (New York), Paris, and Dublin. It builds Access Gate to bring Zero Trust to critical infrastructure and industrial operators, water and wastewater utilities, electric utilities, defense manufacturers, and other industrial sites, that run legacy OT which cannot support traditional, agent-based security.

Those platforms are primarily passive OT monitoring tools: they detect and alert, but they do not enforce access. Access Gate enforces. It sits inline as an overlay and controls, at the network layer, who and what can reach each asset, on which protocols, and when, then records every session. It also differs from agent-based and cloud security tools because it needs no software on the protected equipment, which is essential for legacy PLCs, HMIs, and SCADA that cannot run agents.

No. Access Gate is agentless and installs as an overlay adjacent to the existing network. There are no agents on PLCs, HMIs, or SCADA servers, no VLAN renumbering, no recabling, and no maintenance window. Operations continue uninterrupted during and after deployment.

Access Gate provides the access control, segmentation, MFA, monitoring, and audit evidence required by CMMC (Levels 1 and 2), NERC CIP for electric utilities, the New York DOH and DEC water and wastewater cybersecurity rules, NIS2 and the French LPM in Europe, and IEC 62443 zones and conduits. It maps to NIST CSF 2.0 and NIST SP 800-82 for industrial environments.

As an overlay, in days rather than weeks or months. A typical deployment maps the network and its assets, defines the enclaves and access rules, then hardens progressively. Because nothing is installed on the protected equipment and no rewiring is required, a standard-sized site is usually protected within about three weeks.

Access Gate is sold as an all-inclusive annual subscription covering hardware or virtual appliance, software, updates, and support. Access Gate One, aimed at small and mid-size manufacturers, starts around $9,750 per year. Larger and virtualized deployments (Access Gate Enterprise and Access Gate Inside) are priced by scale.

Access Gate works in two layers. First it solves the immediate security and compliance problem, visibility, identity-bound access, microsegmentation, and audit, deployed as an overlay with no agents and no downtime. Then the same fabric delivers simple secure services the OT teams actually adopt: secure remote access, protocol gateways, DNS and time, file sharing, historian access, and safe updates. Security becomes an enabler rather than a tax, which is what gets OT teams to engage.

See Access Gate on your network

A short walkthrough of how the overlay secures your OT without touching the equipment.