TroutTrout
Secure remote access for OT

Reach any machine, securely.

Secure remote access for OT means a vendor or engineer reaches one machine, for one task, for a set time, and the whole session is recorded. Trout Access Gate is the on-premise appliance that does this on top of your VPN or 4G link.

Last updated:

Trusted by leading companies

John CockerillOrange CyberdefenseElna MagneticsThales
Access Gate grants a named user a brokered, access-controlled remote session to an OT asset
What you buy

Access Gate is an appliance, physical or virtual, that sits in front of your OT assets. It keeps your VPN or 4G link and controls every remote session that arrives through it:

  • MFA authentication of every user, against your corporate directory for staff and a separate directory for vendors
  • Time-limited access to the authorized asset and protocol only
  • A recording of each session, which closes automatically
  • Nothing installed on the PLC, HMI or SCADA server

It is sold as an all-inclusive annual subscription covering hardware, software, updates and support, with no per-seat fees.

Definition

What is secure remote access for OT?

OT remote access is how engineers, integrators and equipment vendors reach PLCs, HMIs and SCADA servers from outside the site. It is secure when the VPN or 4G link only carries the connection and a gate in front of the assets decides the rest: every user signs in with a named identity and MFA, reaches one authorized asset over one protocol, and the session is recorded and closes on time. Nothing is installed on the asset.

Access for an outside company is the hardest case. Our guide shows, step by step, how to give a vendor secure remote access to one machine, and what CISA and NIST ask for.

How does a secure remote access session work?

  1. 01

    Authenticate

    The vendor signs in through the browser with MFA. Staff use your corporate directory, and vendors use a separate directory. The vendor installs no client.

  2. 02

    Limit to one asset

    The gate connects the session to one authorized asset over one authorized protocol. The vendor never receives an IP address on your network.

  3. 03

    Inspect and record

    The gate inspects every command and screen at the application layer. It records and indexes each session, and you can replay it for an audit or an incident response.

  4. 04

    Close automatically

    Access is limited to the maintenance window and closes when the window ends. No standing account stays open.

Reach any machine, securely.

How Access Gate controls each remote session.

You assign each vendor machines from the asset inventory, and the vendor reaches only those.

Access Gate keeps your VPN or 4G link and passes each session through a protocol-aware proxy. The remote user authenticates in the browser, gets a session to one authorized resource over one authorized protocol, and never receives an IP address on your network. Access Gate connects several directories at once: staff sign in with your Active Directory or Entra ID, and vendors sign in with a second Active Directory or the directory built into Access Gate, with MFA at the gate. SSH, RDP, VNC, HTTP, Modbus and OPC UA are inspected at the application layer, so you can allow a protocol and limit what it may do.

Reference architecture: a remote user reaching a single OT asset through the Access Gate proxy, with no route to the wider network.
The remote user's VPN or 4G link ends at Access Gate. The user authenticates at the gate and reaches one asset over one protocol, with no IP address on the internal network. The gate inspects and records the session. Covers: 1. northbound monitoring flows and 2. southbound control flows.
How Access Gate deploys

Two phases: the plant first, then remote access.

PHASE 1

Control who reaches what inside the plant.

Access Gate deploys as an overlay and first brings the internal network under identity-based access control, with no agents and no rewiring. Before any remote access is opened, internal flows are already authenticated, least-privilege and logged. Remote access is then added to a controlled network instead of a flat one.

PHASE 2

Give remote users access to specific systems.

Remote users keep their VPN or 4G link, connect to the gate through the browser, and reach specific assets. Each session is authenticated, limited per asset, protocol, method and time window, recorded, and closed automatically when the window ends. You can require an access agreement before a session starts, and the acceptance is logged. Vendors install nothing, and IT manages no devices it does not own.

Control who reaches what.

One machine per session, recorded.

Access Gate adds protocol-aware access control to your VPN, 4G link or jump server. It is designed for OT, legacy systems and regulated environments.

One machine per session

The vendor's VPN or 4G connection ends at the Access Gate. The vendor reaches one asset and cannot move to the rest of the network.

Protocol inspection

The gate inspects and filters HTTP, SSH, RDP, Modbus and other protocols at the application layer before traffic reaches the target.

Session recording

Every remote session is recorded and indexed, and you can replay it. The recordings give a full audit trail for compliance and incident response.

Per-session policies

Define access by user, resource, protocol, time window and HTTP method. Each session is authorized individually.

Access agreements

Require vendors to accept your security policies before every session. Each acceptance is logged with a timestamp.

Nothing to install

Access works through the browser. Vendors install no software, and IT does not manage devices it does not own.

Datasheet

Download the Access Gate Datasheet.

Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.

Done

What's Inside

Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.

2 pages

See It in Action

Request a live demo to see how the Access Gate deploys on your network without rewiring or downtime.

Request a demo
FAQ

Questions about buying secure remote access for OT.

0

Nothing is installed on your PLCs, HMIs or SCADA servers. Access Gate controls each session at the application layer, in front of the machine.

Vendors keep the VPN or 4G link they already use, and that link ends at the Access Gate. They open a browser and authenticate at the gate with MFA. The gate connects their session to the target resource at the application layer. They never get an IP address on your network, and they can only use the specific resource and protocol you have authorized.

The Access Gate supports HTTP/HTTPS, SSH, RDP, VNC, Modbus TCP and OPC-UA out of the box. It inspects each protocol at the application layer. For example, you can allow SSH but block specific commands, or allow HTTP GET but deny POST.

Yes. Access rules support time limits. You can allow a vendor to connect only during a scheduled maintenance window. The gate closes the session automatically when the window ends.

Every remote session is recorded at the protocol level. SSH sessions capture terminal input and output, RDP sessions capture screen activity, and HTTP sessions log all requests. Recordings are indexed and searchable, and you can replay them for audits and incident response.

Yes. The Access Gate runs entirely on-premise with no cloud dependency. All session proxying, recording and policy enforcement happens locally. It is designed for ITAR, CMMC and air-gapped environments.

A VPN or jump host alone places the remote user on your network, with a route to every system once connected. Access Gate keeps that connection and adds a gate that controls who reaches which machine. The user authenticates with their own identity, reaches one authorized asset over one authorized protocol and never gets an internal IP address. The gate inspects and records the session and closes it after a set time. The user gets access to one system instead of the whole network.

Access Gate is sold as an all-inclusive annual subscription covering hardware, software, updates and support, with no per-seat fees. Access Gate Essential is the model for small and mid-size sites. Access Gate Performance covers plants, control centers and large estates. Current list prices are on the pricing page.

Access Gate deploys as an overlay, with no agents on the equipment, no VLAN renumbering and no recabling, so production keeps running. A typical deployment maps the network and its assets, defines the enclaves and access rules, then hardens the site step by step. The appliance itself is installed in a day.

No. Across the site, the same appliance controls who reaches which machine, enforces MFA at the network layer and keeps a tamper-evident audit trail. It also runs the services OT teams use: secure remote access, protocol gateways, DNS and time, file sharing, historian access and safe updates.

CISA's guidance for critical infrastructure asks for phishing-resistant MFA on every remote connection, no single-factor exposure of OT to the internet, least-privilege access instead of a flat tunnel, and logs detailed enough to reconstruct a session after an incident. In OT, the assets cannot enforce MFA themselves, because a PLC or an RTU cannot ask for a second factor. Access Gate connects to your existing network and meets the requirement with no change to the equipment. The identity check, the second factor and the recording all happen at the gate, and the asset communicates exactly as before.