Protecting what must not fail

Zero-trust for IT · OT · IoT

You can’t attack
what you can’t see

Securing the network is not enough. XoT Technology™ makes your critical assets invisible to threats — reachable only by the right people, at the right time, with cryptographic proof at every step.

Covers every access scenario
Remote users On-site employees Contractors Machine-to-machine Site-to-site
Designed & built in Sweden Default deny — always Works fully air-gapped Built for IT. Approved by OT.
Remote users
Remote user On-site employee Third-party access Machine-to-machine Site-to-site
Attackers scan · no assets found
No open ports No implicit trust No standing access
>90%
Reduction in patching requirements for hidden devices
~20 sec
To create a complete WHO / WHAT / WHERE / WHEN access policy
Zero
Changes to existing networks or protected devices
12+
Reseller and technology partners across Europe
The problem

Firewalls guard the perimeter.
Your assets are still exposed to anyone inside.

Legacy assets can’t protect themselves

OT and IoT devices have no built-in security — they are exposed the moment they are networked.

VPNs and perimeters are not enough

Traditional remote access opens broad network entry. Once inside, attackers move freely — nothing stops lateral movement between devices.

Air-gapped networks are still vulnerable from within

Internal threats, on-site contractors, and local LAN access are routinely overlooked by perimeter-focused security.

Standing access is never revoked

Vendor and contractor accounts persist long after the job is done — a quiet, growing attack surface.

Compliance is hard to prove

Auditors demand evidence. Manual access control leaves gaps and blind spots that only show up during the audit.

Foreign technology is a risk in itself

Security technology from high-risk countries introduces supply chain vulnerabilities that are difficult to assess and impossible to fully trust.

Use cases

Built for the assets that can’t protect themselves

One technology — two solutions. Every use case below builds on one of them.

Xertified Remote Access
When external users need to reach in

For users outside the network accessing assets inside, behind Locks. Vendors, technicians and remote staff connect through PKI-authenticated WireGuard tunnels to exactly the assets their policy permits — typically via the XoT Bridge, with no inbound firewall ports opened.

Xertified Hide & Protect
When assets must be hidden from everyone

Full asset isolation — protecting devices from threats on the local LAN and from anywhere else. Default deny on all traffic, restriction of outbound connections, just-in-time access windows, and micro-zoning inside existing subnets and VLANs.

What you get

Security outcomes, not security theatre

Dramatically smaller attack surface

Assets invisible to attackers cannot be compromised. Zero open inbound ports.

Lateral movement stopped by default

A breach cannot spread to assets the compromised device has no policy to reach.

Vendor access you actually control

Up and running in minutes. Scoped, time-limited, identity-verified — automatically revoked when the window closes.

Deploy in hours, not weeks

No agents on protected devices. No IP changes. Plug the Lock in and enroll — done.

Verify access rights at a glance

Built-in visualisation lets administrators instantly see who has access to what — making policy reviews and audits simple.

Works in any environment

Cloud, on-premise, hybrid, or fully air-gapped — XoT Technology™ adapts to your infrastructure, not the other way around.

Compliance evidence built in

Every session is policy-driven and logged. NIS2, IEC 62443, FDA Part 11, EU Annex 11 ready.

No hidden supply chain exposure

Fully designed, developed and built in Sweden. No components from high-risk countries.

Lock & Key

One key. One lock. One policy.

Every connection is a mutually authenticated, encrypted tunnel between a verified user and a policy-enforcing Lock. Enforcement happens directly at the asset — access can be initiated from anywhere, inside or outside the network, with no difference in protection.

The Key — your client

Desktop client, browser-based WebAccess, or headless server client. Authenticated with your existing IdP — MFA, smart cards, YubiKey.

PKI identity

The Tunnel

WireGuard encryption end to end, with mutual challenge-response authentication running continuously inside the tunnel — twice per minute.

Always verified

The Lock — at the asset

XoT-S1 hardware, a VM, or software on existing appliances. Terminates the tunnel and enforces policy right in front of the protected asset.

Policy enforced

Client-based and clientless access — side by side

Both access methods run simultaneously under the same policy framework. Choose per user and per use case — they are not either/or.

Client-based

XoT Desktop Client

Software installed on the PC. The computer gets direct, tunneled access to exactly the assets its policy permits — ideal for daily users, engineers and staff who work against protected assets regularly.

Clientless

XoT WebAccess

No software on the PC — only a browser is needed. The session runs in an isolated environment that also acts as a jump host for added security. Ideal for third parties, unmanaged devices, and situations where installing software is not possible.

Same PKI identity, same policies, same enforcement at the Lock — regardless of which method the user connects with.

Access control

An access policy in 20 seconds

Four questions define every policy. No firewall rule sprawl, no network changes, no touching the protected device.

WHO
Service technicians, GermanyUsers & groups from LDAP or Entra ID
WHAT
X-ray machine CX4300Asset type & group classification
WHERE
Hauptstraße 15, BerlinCountry · city · address · room
WHEN
Thursdays, 09:00–13:30One-off, recurring, or countdown

Just-in-time by design — access expires automatically. Leave nothing open that doesn’t need to be.

Trusted partners

A growing ecosystem across Europe

Reseller partners

PlantvisionTelia CygateFujitsu Orange CyberdefenseMV Cyber

Technology partners

PointsharpNexusPrimeKey ExpisoftPone BiometricsIntercede

Technology you can trust

Fully designed, developed and built in Sweden. No components from high-risk countries. No hidden supply chain exposure.

Why Xertified

Security you can trace to its source

Made in Sweden

Designed, developed, and manufactured in Sweden — full supply-chain transparency for the XoT-S1 hardware.

Legacy-friendly

Works for 20-year-old PLCs and brand-new devices alike. No agents, no OS requirements on the protected asset.

Fast to deploy

Inline installation, QR-code enrollment, and policies written in seconds. Days to production, not months.

Zero trust, literally

Default deny on every Lock. If no policy permits it, not a single packet passes. No implicit trust anywhere.

WireGuard encryption

Modern, lean, independently audited VPN protocol — smaller attack surface than IPSec or OpenVPN. Every session encrypted end-to-end.

PKI identity, no passwords

Cryptographic certificate identity per device and per user. Eliminates password attacks, credential sharing and phishing vectors entirely.

Supports compliance with
NIS2 IEC 62443 FDA 21 CFR Part 11 EU Annex 11
FAQ

Frequently asked questions

What is XoT Technology™?

XoT (Xertified-of-Things) Technology is Xertified’s proprietary security framework that protects individual IT, OT and IoT devices at the asset level rather than the network level. It combines PKI certificate identity, WireGuard encryption and hardware edge proxies to make protected devices invisible to all unauthenticated parties on any network.

How is XoT Technology™ different from a VPN?

A VPN grants access to a network segment — anyone authenticated can potentially reach any device on that segment. XoT grants access to a specific device, for a specific user, from a specific location, during a specific time window. Every other device remains invisible. No network access is granted — only device access.

How is this different from segmenting with firewalls?

Firewall segmentation works at the network level: rules are tied to IP addresses, VLANs and topology. Devices inside the same segment can still see and reach each other, rule sets grow into sprawl over time, and every change requires network reconfiguration. XoT segments at the device level instead — each protected asset is its own zone with default deny, and access is granted to cryptographic identities, not IP addresses. Policies are independent of network topology, take effect without re-addressing or firewall changes, and expire automatically. In IEC 62443 terms: each Lock forms its own zone, with conduits defined by policy rather than by network design.

Does every device need its own Lock?

No. A single Lock can protect one device, several devices, entire subnets, or multiple VLANs simultaneously. Protected devices keep their IP addresses — no re-addressing is required, neither at installation nor in operation.

Does XoT Technology™ require changes to existing devices or networks?

No. XoT Locks are installed adjacent to the protected device with no modification to the device itself and no changes to the existing network. This makes it possible to protect legacy OT equipment that cannot be patched, modified or taken offline.

Which compliance frameworks does Xertified support?

XoT Technology™ supports compliance with IEC 62443, NIS2 Directive Article 21, NIST Cybersecurity Framework 2.0, NIST SP 800-207 Zero Trust Architecture, ISO 27001 and the EU Cyber Resilience Act. Detailed compliance mapping documentation is available on request.

Where is Xertified technology designed and manufactured?

XoT hardware and software is designed, developed and manufactured in Sweden. Xertified maintains full supply chain transparency with no geopolitical dependencies on US or Chinese component ecosystems.

See your assets disappear

Book a live demo and watch a Lock go from unboxing to enforced policy in minutes.

Book a demo