The architecture in four layers
Four functional layers that also read as the chain of every session — who you are, what you may reach, protected transport, enforced at the device.
PKI certificates for users and machines, IdP integration, hardware tokens.
The XMS: WHO/WHAT/WHERE/WHEN policies, tickets, just-in-time windows and approvals.
WireGuard tunnels with continuous mutual authentication inside every session.
The Locks: default deny, filtering enforced directly at the protected asset.
Plug-and-play. Ready to scale. Minimal lift from IT.
Designed to be used by everyday practitioners — in the lab, on the shop floor, in security or IT. No specialist implementation, no changes to existing networks, no downtime.
Choose your Key
A desktop client, a browser-based jump-host, or a secured device acts as the Key. PKI certificate identity — no passwords, no shared credentials.
Connect existing identity resources
The XMS manages certificates, users, groups and policies — and integrates with existing identity providers, certificate authorities and SIEM/IDS monitoring.
Install Locks on relevant platforms
Xertified hardware (XoT-S1), ARM/x86 devices, or virtual machines on-prem or in cloud. WireGuard tunnels, per-identity firewalls, hardened OS and hardware.
Secure any device
PLC, HMI, SCADA, DCS, CCTV, embedded servers, medical devices, IoT sensors — legacy equipment protected without modification, new equipment from day one.