Reach any machine, securely.
Secure remote access for OT means a vendor or engineer reaches one machine, for one task, for a set time, and the whole session is recorded. Trout Access Gate is the on-premise appliance that does this on top of your VPN or 4G link.
Last updated:

Access Gate is an appliance, physical or virtual, that sits in front of your OT assets. It keeps your VPN or 4G link and controls every remote session that arrives through it:
- MFA authentication of every user, against your corporate directory for staff and a separate directory for vendors
- Time-limited access to the authorized asset and protocol only
- A recording of each session, which closes automatically
- Nothing installed on the PLC, HMI or SCADA server
It is sold as an all-inclusive annual subscription covering hardware, software, updates and support, with no per-seat fees.
What is secure remote access for OT?
OT remote access is how engineers, integrators and equipment vendors reach PLCs, HMIs and SCADA servers from outside the site. It is secure when the VPN or 4G link only carries the connection and a gate in front of the assets decides the rest: every user signs in with a named identity and MFA, reaches one authorized asset over one protocol, and the session is recorded and closes on time. Nothing is installed on the asset.
Access for an outside company is the hardest case. Our guide shows, step by step, how to give a vendor secure remote access to one machine, and what CISA and NIST ask for.
How does a secure remote access session work?
- 01
Authenticate
The vendor signs in through the browser with MFA. Staff use your corporate directory, and vendors use a separate directory. The vendor installs no client.
- 02
Limit to one asset
The gate connects the session to one authorized asset over one authorized protocol. The vendor never receives an IP address on your network.
- 03
Inspect and record
The gate inspects every command and screen at the application layer. It records and indexes each session, and you can replay it for an audit or an incident response.
- 04
Close automatically
Access is limited to the maintenance window and closes when the window ends. No standing account stays open.
How Access Gate controls each remote session.
You assign each vendor machines from the asset inventory, and the vendor reaches only those.
Access Gate keeps your VPN or 4G link and passes each session through a protocol-aware proxy. The remote user authenticates in the browser, gets a session to one authorized resource over one authorized protocol, and never receives an IP address on your network. Access Gate connects several directories at once: staff sign in with your Active Directory or Entra ID, and vendors sign in with a second Active Directory or the directory built into Access Gate, with MFA at the gate. SSH, RDP, VNC, HTTP, Modbus and OPC UA are inspected at the application layer, so you can allow a protocol and limit what it may do.

Two phases: the plant first, then remote access.
Control who reaches what inside the plant.
Access Gate deploys as an overlay and first brings the internal network under identity-based access control, with no agents and no rewiring. Before any remote access is opened, internal flows are already authenticated, least-privilege and logged. Remote access is then added to a controlled network instead of a flat one.
Give remote users access to specific systems.
Remote users keep their VPN or 4G link, connect to the gate through the browser, and reach specific assets. Each session is authenticated, limited per asset, protocol, method and time window, recorded, and closed automatically when the window ends. You can require an access agreement before a session starts, and the acceptance is logged. Vendors install nothing, and IT manages no devices it does not own.
Where teams use Access Gate for remote access.
Third-party and OEM maintenance
A drive vendor or integrator needs access to one machine for a service window. They get a browser session to that asset over the agreed protocol, time-limited and recorded, and nothing else. Access ends with the window, and no standing access stays open.
Learn moreInternal engineers across sites
Engineers support plants they cannot visit. They authenticate with their existing identity and MFA and reach the specific PLCs, HMIs or historians they are allowed to use. Each session is least-privilege and logged, and shared jump-host credentials are no longer needed.
Learn moreRegulated and air-gapped sites
ITAR, CMMC and classified environments cannot route sessions through a cloud proxy. Access Gate controls and records remote sessions entirely on-premise, so controlled remote access works where the internet does not reach and where data cannot leave the site.
Learn moreOne machine per session, recorded.
Access Gate adds protocol-aware access control to your VPN, 4G link or jump server. It is designed for OT, legacy systems and regulated environments.
One machine per session
The vendor's VPN or 4G connection ends at the Access Gate. The vendor reaches one asset and cannot move to the rest of the network.
Protocol inspection
The gate inspects and filters HTTP, SSH, RDP, Modbus and other protocols at the application layer before traffic reaches the target.
Session recording
Every remote session is recorded and indexed, and you can replay it. The recordings give a full audit trail for compliance and incident response.
Per-session policies
Define access by user, resource, protocol, time window and HTTP method. Each session is authorized individually.
Access agreements
Require vendors to accept your security policies before every session. Each acceptance is logged with a timestamp.
Nothing to install
Access works through the browser. Vendors install no software, and IT does not manage devices it does not own.
Download the Access Gate Datasheet.
Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.
What's Inside
Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.
See It in Action
Request a live demo to see how the Access Gate deploys on your network without rewiring or downtime.
Questions about buying secure remote access for OT.
Nothing is installed on your PLCs, HMIs or SCADA servers. Access Gate controls each session at the application layer, in front of the machine.
Vendors keep the VPN or 4G link they already use, and that link ends at the Access Gate. They open a browser and authenticate at the gate with MFA. The gate connects their session to the target resource at the application layer. They never get an IP address on your network, and they can only use the specific resource and protocol you have authorized.
The Access Gate supports HTTP/HTTPS, SSH, RDP, VNC, Modbus TCP and OPC-UA out of the box. It inspects each protocol at the application layer. For example, you can allow SSH but block specific commands, or allow HTTP GET but deny POST.
Yes. Access rules support time limits. You can allow a vendor to connect only during a scheduled maintenance window. The gate closes the session automatically when the window ends.
Every remote session is recorded at the protocol level. SSH sessions capture terminal input and output, RDP sessions capture screen activity, and HTTP sessions log all requests. Recordings are indexed and searchable, and you can replay them for audits and incident response.
Yes. The Access Gate runs entirely on-premise with no cloud dependency. All session proxying, recording and policy enforcement happens locally. It is designed for ITAR, CMMC and air-gapped environments.
A VPN or jump host alone places the remote user on your network, with a route to every system once connected. Access Gate keeps that connection and adds a gate that controls who reaches which machine. The user authenticates with their own identity, reaches one authorized asset over one authorized protocol and never gets an internal IP address. The gate inspects and records the session and closes it after a set time. The user gets access to one system instead of the whole network.
Access Gate is sold as an all-inclusive annual subscription covering hardware, software, updates and support, with no per-seat fees. Access Gate Essential is the model for small and mid-size sites. Access Gate Performance covers plants, control centers and large estates. Current list prices are on the pricing page.
Access Gate deploys as an overlay, with no agents on the equipment, no VLAN renumbering and no recabling, so production keeps running. A typical deployment maps the network and its assets, defines the enclaves and access rules, then hardens the site step by step. The appliance itself is installed in a day.
No. Across the site, the same appliance controls who reaches which machine, enforces MFA at the network layer and keeps a tamper-evident audit trail. It also runs the services OT teams use: secure remote access, protocol gateways, DNS and time, file sharing, historian access and safe updates.
CISA's guidance for critical infrastructure asks for phishing-resistant MFA on every remote connection, no single-factor exposure of OT to the internet, least-privilege access instead of a flat tunnel, and logs detailed enough to reconstruct a session after an incident. In OT, the assets cannot enforce MFA themselves, because a PLC or an RTU cannot ask for a second factor. Access Gate connects to your existing network and meets the requirement with no change to the equipment. The identity check, the second factor and the recording all happen at the gate, and the asset communicates exactly as before.