TroutTrout
Control who reaches what · Zero Trust access control

Control who reaches every machine. Nothing to install on them.

Trout Access Gate is an on-premise appliance to enforce Zero Trust access control across OT: every user and device is verified by identity, granted only what it needs, and fully recorded.

Last updated:

Trusted by leading companies

John CockerillOrange CyberdefenseElna MagneticsThales
Access Gate
by Trout Software

You are about to access ACME CUI Server:

  • Proceed according to our internal security policy.
  • You can contact IT at it@acme.com
I agree
The short answer

On-premise identity and access control for OT means enforcing authentication and least-privilege access from inside your own network, with no cloud dependency and no agent on the device.

Trout Software's Access Gate does this as an identity-aware industrial proxy in the access path. Before traffic reaches the PLC, HMI, or SCADA server, every session:

  • authenticates against your existing identity provider
  • is authorized per asset and protocol
  • is recorded
What is actually happening

Flat networks run on implicit trust.

Inside most plants and sites the network is flat: once a user, contractor, or device is on it, it can reach almost everything. Trust is implicit, granted by network location rather than identity. A single phished laptop, an over-permissioned vendor, or a compromised jump host inherits that trust and moves laterally to the systems that matter.

Traditional fixes do not fit OT. Agents cannot be installed on PLCs, HMIs, or RTU. Cloud-routed proxies break availability and data-residency rules. VPN extend the flat network to remote users instead of constraining them. The control layer keeps running on the assumption that everyone inside is trustworthy.

Zero Trust replaces location-based trust with verified identity on every session. The hard part in OT is enforcing it without touching the endpoints or rewiring the network, which is exactly where a network-layer overlay earns its place.

The model

Zero Trust, applied where agents cannot go.

Zero Trust, as set out in NIST 800-207, rests on a few principles: never trust by default, verify every request by identity, grant least privilege, and assume breach so one compromised account cannot reach the whole estate. The model is well understood. Implementing it on equipment that cannot run an agent is the gap.

Access Gate enforces those principles at the network layer. Every session is authenticated against your existing identity provider, authorised per asset and protocol, and continuously logged. Resources a user is not entitled to are cloaked, invisible at the network layer, so the attack surface shrinks to exactly what each identity is allowed to see.

How Access Gate deploys

Zero Trust in a day, with no rewiring.

PHASE 1

Live in a day.

Access Gate connects to your existing network. Nothing to install on machines, no VLAN changes, no downtime. Identity-based access, encryption and session logs work from day one. Each machine stays hidden from people not allowed to reach it.

PHASE 2

Give each person only what they need.

Sessions move behind the gate, which becomes the control point. Rules are written per machine in the asset inventory, then per user and protocol, with MFA from your existing identity provider. A change in risk triggers a new login. Adding machines or plants is a configuration change, with no network redesign.

Compliance mapping

Audit evidence for NIST 800-171, CMMC and IEC 62443.

Identity-bound access maps directly onto the access-control families auditors look for: NIST 800-171 AC and IA controls that CMMC Level 2 assesses, and the IEC 62443 requirements for identification, authentication, and use control. MFA is enforced at the proxy, least privilege is the default, and every decision is recorded.

Because enforcement and logging happen at the gate, audit evidence is generated continuously, with user, asset, protocol, and timestamp on every session, instead of being reconstructed from scattered device logs the week before an assessment.

Control who reaches what.

Zero Trust that works on the plant floor.

Access Gate brings Zero Trust to legacy OT, air-gapped networks and production floors, where identity tools usually cannot reach.

Every user is verified first.

Every user and device logs in before reaching any machine. No implicit trust.

Each person sees only their machines.

Everything else stays hidden at the network level.

Sessions are checked continuously.

Sessions are watched live. A change in risk triggers a new login.

Ready for your audit.

Maps to NIST 800-171 access controls, CMMC and IEC 62443.

Every session on record.

Every access attempt, decision and session is logged and searchable.

Connects to your existing network.

No rewiring, no cloud, no downtime.

Deployment

Access Gate adapts to your network

Pick your environment to see where the Access Gate sits, how much Zero-Trust coverage you get, and the migration path, from full coverage to partial coverage.

Access Gate: deploy Zero-TrustSelect an option to highlight its path
See the full deployment guide
Datasheet

Download the Access Gate Datasheet.

Get the complete product overview with technical capabilities, deployment model, compliance alignment, and customer references.

Done

What's Inside

Product architecture, deployment model, key capabilities (proxy enforcement, micro-DMZs, identity-based access), compliance alignment, and real-world customer deployments.

2 pages

See It in Action

Request a live demo to see how the Access Gate deploys on your network without rewiring or downtime.

Request a demo
FAQ

Questions about Zero Trust access control.

0

Nothing to install. Access Gate enforces Zero Trust at the network level, with no software on machines, PLCs or legacy equipment.

A VPN extends your flat network to remote users, once connected, they can reach everything. The Access Gate enforces per-user, per-device, per-resource policies. Users only see what they're authorized to access. Everything else is cloaked at the network layer.

Yes. The Access Gate enforces access control at the network layer, not on the endpoint. Legacy PLCs, HMIs, and SCADA systems are protected without installing agents or modifying their configuration. The overlay sits between users and resources.

The Access Gate integrates with Active Directory, Entra ID, Okta, and any SAML or OIDC-compatible provider. Users authenticate with their existing credentials and MFA. No separate identity system to manage.

Yes. The Access Gate operates entirely on-premise with no cloud dependency. Identity verification, policy enforcement, and audit logging all happen locally. It's designed for classified, air-gapped, and regulated environments.

You can add new assets, plants, or sites without re-architecting. The overlay is software-defined, adding a new enclave or extending policies to a new location is a configuration change, not a network redesign.

Access Gate implements the NIST 800-207 pillars at the network layer: every session is verified by identity, granted least privilege per asset and protocol, and continuously evaluated, with unauthorised resources cloaked. It does this without agents on endpoints, so it covers the OT and legacy systems that agent-based Zero Trust tools cannot reach.

Put an identity-aware industrial proxy in the access path in front of the OT assets, on-premise, with no agent on the device and no cloud dependency. Every session authenticates the user against your existing identity provider, authorizes the specific action, and is recorded, before traffic reaches the PLC, HMI, or SCADA server. Because OT prioritizes uptime, the proxy runs with failover and a break-glass path so enforcement never costs availability. Trout's Access Gate delivers this and has been validated by a NATO navy for its most critical workloads.