Architecture

← Back to start
Technology

Architecture

The architecture in four layers

Four functional layers that also read as the chain of every session — who you are, what you may reach, protected transport, enforced at the device.

Identity Layer

PKI certificates for users and machines, IdP integration, hardware tokens.

Access Control Layer

The XMS: WHO/WHAT/WHERE/WHEN policies, tickets, just-in-time windows and approvals.

Encryption Layer

WireGuard tunnels with continuous mutual authentication inside every session.

Enforcement Layer

The Locks: default deny, filtering enforced directly at the protected asset.

Plug-and-play. Ready to scale. Minimal lift from IT.

Designed to be used by everyday practitioners — in the lab, on the shop floor, in security or IT. No specialist implementation, no changes to existing networks, no downtime.

01

Choose your Key

A desktop client, a browser-based jump-host, or a secured device acts as the Key. PKI certificate identity — no passwords, no shared credentials.

02

Connect existing identity resources

The XMS manages certificates, users, groups and policies — and integrates with existing identity providers, certificate authorities and SIEM/IDS monitoring.

03

Install Locks on relevant platforms

Xertified hardware (XoT-S1), ARM/x86 devices, or virtual machines on-prem or in cloud. WireGuard tunnels, per-identity firewalls, hardened OS and hardware.

04

Secure any device

PLC, HMI, SCADA, DCS, CCTV, embedded servers, medical devices, IoT sensors — legacy equipment protected without modification, new equipment from day one.