Use cases · OT remote access

Secure file transfer for OT remote access

Remote access is not only about who connects. It is also about what crosses the boundary. Engineering files, configuration exports, diagnostic logs, firmware packages, scripts, screenshots and reports can all introduce risk when they move between vendors, service providers and OT environments. Otector helps control uploads and downloads with file policy, scanning, DLP-style checks, quarantine, approvals, transfer links and audit evidence.

File movement

Remote access often becomes a file transfer problem

During remote support, files frequently move in both directions. A vendor may need to upload a patch, retrieve a diagnostic log, exchange a project file, deliver a script, or collect evidence after a maintenance activity. Without controls, these transfers can bypass policy, introduce malware, expose sensitive OT information or leave no clear record of what moved.

Uploads into OT environments

Downloads from OT assets

Vendor and OEM support files

Diagnostic logs and reports

Project files and configuration exports

Evidence after maintenance work

Common scenarios

Common OT file transfer scenarios

The same platform controls apply whether the file is a vendor support package, a diagnostic export or a release into a specific client environment.

Upload a support package

A vendor needs to provide a patch, script, configuration package or diagnostic tool for approved work.

Download diagnostic evidence

An engineer needs logs, screenshots, reports or exports to investigate an issue.

Exchange engineering files

Automation and maintenance teams need to move project files or controller-related exports through a controlled process.

Release files to a service provider

A provider uploads a file to their workspace, but the client still needs an independent decision before it crosses into a specific client environment.

Share files through a browser

Some endpoints are easier to handle with short-lived transfer links instead of interactive session file movement.

Review suspicious files

Files that match policy or security conditions need to be quarantined and released only after approval.

Otector control model

Uploads and downloads should be governed, not assumed safe

Otector allows file movement to be controlled per connection profile. Uploads and downloads can be independently allowed, denied, inspected, quarantined, approved and logged.

Profile-level direction control

Allow or deny upload and download independently for each connection profile.

Inspection before use

Check files before they can move into or out of the approved workflow.

Quarantine and approval

Hold flagged files for authorized administrator review before release.

Site and organization policy

Apply file rules as organization defaults or scope them to a specific site.

Transfer evidence

Write file actions to the audit log so teams can review what moved, when, by whom and under which session or asset.

Provider-side workflow

Support provider-side libraries while recomputing verdicts independently for each client boundary.

File security pipeline

Policy checks before files cross the boundary

Files can pass through a configurable security pipeline before they are used.

  1. 01

    File policy and DPI

    Evaluate extension, MIME type, file size, archive contents and encrypted-archive rules.

  2. 02

    Malware scanning

    Scan files for malware before release. Use the configured scanning backend.

  3. 03

    DLP-style checks

    Match OT-sensitive terms and patterns such as credentials, private keys, controller exports and network inventory.

  4. 04

    AI content analysis

    Classify file content and create a human-readable description where configured.

  5. 05

    Decision

    Allow, flag, quarantine or block files based on policy.

Transfer methods

Two ways to move files with control

Both methods run under the same file policy, decision model and audit trail.

01 · In-session

In-session transfer panel

Use controlled upload and download during a live remote session, governed by the selected connection profile and file policy.

02 · Browser-based

Transfer Links

Use short-lived transfer links when a browser-based file exchange is more practical. Links can be direction-limited, size-limited, optionally PIN-protected and associated with a session, asset, site and creator.

Service-provider access

Provider uploads should not automatically become client files

The Service Provider Portal can support a provider-side file library. A provider upload can be scanned when it enters the provider workspace, but client release decisions should remain independent. Otector is designed so file checks can run again when a file is released to a particular client, creating a separate verdict for each client boundary rather than reusing trust across tenants.

Evidence

Make file movement reviewable

Otector helps teams answer practical file-transfer questions after the session ends.

  • Who uploaded the file
  • Who downloaded the file
  • Which session, asset and site were involved
  • Which policy was applied
  • Whether the file was allowed, flagged, quarantined or blocked
  • Who approved a release
  • Whether the file was linked to a transfer link
  • Which provider or client boundary was involved
  • When the action happened
Explore audit evidence for remote access
FAQ

Questions about OT file transfer control.

Why does file transfer matter in OT remote access?

Remote support often involves files such as patches, scripts, logs, reports, engineering project files and configuration exports. Without controls, these files can introduce malware, expose sensitive OT information or move without a clear audit trail.

Can Otector control uploads and downloads separately?

Yes. Upload and download permissions can be controlled independently through connection profiles, so a session can allow one direction, both directions or neither depending on policy.

Can files be scanned before release?

Yes. Files can pass through configured checks such as file policy, malware scanning, DLP-style rules and content analysis before they are allowed, flagged, quarantined or blocked.

What happens to suspicious files?

Suspicious or policy-matching files can be quarantined and held for authorized administrator review before release.

Can service providers exchange files with clients?

Yes. Otector can support provider-side file libraries and client-specific release decisions so files are evaluated independently before crossing into a particular client environment.

Are file actions included in the audit trail?

Yes. File actions can be written to the audit log and associated with the relevant user, provider, session, asset, site and decision.

Does Otector guarantee that every malicious file is detected?

No. Otector helps control and inspect file movement, but no scanning or analysis technology can guarantee detection of every malicious file. File transfer controls should be part of a broader OT security process.

Control what crosses the boundary

See how Otector governs file movement around the session.

Bring the files your vendors and engineers actually exchange, and we will walk through policy, scanning, quarantine, approvals, transfer links and the evidence that follows.