Xertified Remote Access gives employees, suppliers and service technicians device-level access to specific IT and OT assets from any location — without granting access to the surrounding network. Replace broad VPN access with precise, auditable, time-limited connections to individual machines.
Book a demo See Xertified Hide & Protect
A VPN authenticates once, then opens a segment
A technician connecting to maintain one machine can see — and potentially reach — every other device on that segment. A compromised contractor credential becomes a full network breach.
This is architectural, not a misconfiguration
Network-level access control cannot express “this user, this device, this hour”. No amount of tuning changes what the model grants.
OT carries the consequences
Legacy controllers, SCADA systems and industrial HMIs were never designed to face the internet. Once reachable from a VPN session they are exposed to anyone holding a valid credential.
One Key. One Lock. One device.
Every user gets a PKI identity
Each user receives a unique certificate identity — their Key. No passwords, no shared logins. Credential theft alone cannot grant access.
Every asset gets a Lock
A Lock is installed adjacent to the protected asset. The device itself is never modified — no agent, no firmware update, no maintenance window.
Policy scopes the connection
WHO / WHAT / WHERE / WHEN, defined in about 20 seconds and effective immediately. No firewall, VLAN or routing changes.
A tunnel opens to that asset only
When Key and Lock match and policy permits, a WireGuard tunnel is established directly to the device. Nothing else on the network is visible or reachable.
What you get
Device-level access control
Access is scoped to individual assets, not network segments. A technician authorised to reach one PLC cannot see any other device.
PKI identity for every user
Every user and every device holds a unique cryptographic certificate. No passwords to phish, no credentials to share.
Time-limited third-party access
Grant an OEM technician access to one machine for a defined window. Access expires automatically — no manual revocation.
No infrastructure changes
Locks install inline with no modification to the asset and no changes to networks, firewalls or routing.
Full session audit trail
Who connected to what, from where, when and for how long. Exportable to SIEM and aligned with NIS2 reporting obligations.
Works with any networked device
Regardless of age, operating system or manufacturer. If it has a network port, it can be protected.
Works over any network
Corporate LAN, 4G/5G or public internet — connections work regardless of the underlying transport.
Third-party and OEM maintenance
External technicians reach exactly the machine they service — never the rest of the operational network. Access closes with the maintenance window.
Remote work for OT engineers
Your own team reaches SCADA systems, PLCs and HMIs from home or the field, with the same precision and audit trail as on site.
Cross-organisation access
Partners, customers or regulators reach specific assets without any network interconnection between the organisations.
Mobile and non-stationary assets
Vehicles, portable equipment and field devices stay protected and reachable as they move between networks.
Addresses NIS2 Article 21 access control (21.2i), supply chain security (21.2d) and incident logging (21.2b). Supports IEC 62443 least privilege (SR 2.1) and remote session management (SR 2.6), and implements the device-level access principles of NIST SP 800-207.
Ready to replace your VPN?
Book a 30-minute demonstration and see broad network access replaced with precise, auditable, device-level control — without touching your existing infrastructure.
Book a demo