One platform for every stage of secure OT access.
From the first access request to the final audit record, Otector controls the whole interaction. Here is what the platform does, organised by capability.
Get people to the right asset, under the right policy.
Access is granted to specific assets through defined connection profiles, not to flat networks. Direct where trust allows, approval-based where it does not.
- Asset and connection-profile based access
- Direct or approval-based access
- Time-bound access windows
- Site and zone organisation
- Role-based permissions
Four protocols. One browser. No client software.
Operators connect from any browser that can reach the platform. The Site Agent brokers the session locally to the asset over an outbound connection.
- Browser-based RDP
- SSH
- VNC
- Isolated HTTP(S) access
- Controlled tunnels for approved native engineering tools
- No client software required for operators
- Outbound Site Agent architecture
Need a native engineering tool instead? Otector Tunnels give approved tools a scoped, audited path to one asset — without a VPN.
Native tools, when a browser isn’t enough.
Some engineering and diagnostic work needs local software. Otector Tunnels give approved native tools a scoped, governed path to a single destination, never a general route into the site network.
- Scoped to an asset, hostname, IP or CIDR, ports and protocol profile
- Direct, request-based or hidden access, like connection profiles
- Registered, device-bound Tunnel Client
- Every flow checked before one destination socket opens
- Flow decisions, alerts and optional packet evidence in the same audit model
Your identity provider, extended to OT access.
Users authenticate through your enterprise identity. Higher-risk actions, such as a service-provider launch, can require a stronger factor before the session starts.
- Enterprise identity integration
- Role-based access
- Step-up authentication for service-provider launches
- Passkeys
- Security keys or phone authentication
- Authenticator fallback where permitted
Watch it live. Replay it later.
Every session is recorded and can be monitored while it runs. Recordings, transcripts and history stay available for review long after the session ends.
- Session recording
- SSH transcripts
- Live session monitoring
- Session history
- Detailed audit trail
Control which files cross the boundary.
Uploads and downloads are inspected and policy-checked before they move. Files that need a closer look are quarantined and released through approval.
- Controlled upload and download
- Malware scanning
- File policy and content inspection
- DLP controls
- Quarantine and approval workflows
- Secure transfer links
Act on what happens during a session.
Activity is evaluated against policy while the session runs. Depending on the rule, Otector can warn the user, alert an administrator, pause or terminate the session.
- Session activity monitoring
- Policy-based detection
- User warnings
- Administrator alerts
- Session pause
- Session termination
One trail across every session and site.
Authentication, access decisions, file activity and alerts land in a central event trail. Session reports and recordings support review, and service providers can share PDF session reports.
- Central event trail
- Authentication events · access decisions
- File activity · security alerts
- Session reports · recording replay
- PDF session reports for service providers
Building a NIS2-focused remote access program? Explore NIS2 remote access controls.
Run access across the whole fleet.
Work at the enterprise level or drill into a single site. Each site runs its own Site Agent, with roles and policies that apply where they should.
- Enterprise and site views
- Site-specific access and administration
- Operational dashboards
- Multiple Site Agents
- Site-aware roles and policies
The best way to understand the platform is to see it.
A live walkthrough on reference assets, tailored to how your organisation manages remote access today.