
Cyber-Physical Systems (CPS) SecurityIdentity & Access Management
Xage Fabric Platform
Agentless zero trust access, PAM, and segmentation mesh for OT, IT, and cloud infrastructure.
Xage Fabric Platform Overview
What it does
Xage Fabric Platform is a zero trust access and protection platform for cyber-physical systems (CPS), operational technology (OT), IT, data center, and cloud environments. It overlays existing infrastructure as a distributed cybersecurity mesh that enforces identity-based access control, credential management, and asset-level segmentation on systems that cannot run agents, including legacy PLCs, RTUs, and HMIs. Because credentials and policies are distributed across the mesh, there is no single point of failure and enforcement continues when sites lose connectivity.
How it works
Xage Nodes deploy as virtual machines, containers, or Xage Extended Protection hardware appliances across data centers, cloud, and remote sites, brokering every session without endpoint agents or firewall rule changes. Credential and policy data is sharded across the mesh using Shamir's Secret Sharing and Federated Byzantine Agreement, so access enforcement, multi-factor authentication (MFA), and one-time credential issuance keep working offline and in air-gapped conditions. Five products run on the fabric: Secure Remote Access, Extended PAM, Critical Asset Protection, Zero Trust Data Exchange, and Zero Trust for AI, while Visibility-to-Policy (V2P) Studio translates observed asset behavior into enforceable access policies.
Credentials and traction
ISO 27001 certified (certificate ICI-IS-2312025), FIPS 140-3 validated (NIST certificate 5229), and IEC 62443-4-1 and 62443-4-2 Security Level 3 certified, with CISA's Secure by Design pledge signed. Xage is recognized in the February 2026 Gartner Market Guide for CPS Secure Remote Access and the March 2026 Forrester Operational Technology Security Solutions Landscape. Customers include Kinder Morgan, PETRONAS, Ornua, and the U.S. Space Force's Space Systems Command.
Key Capabilities
mapped to solution categoriesMonitors remote sessions in real time so that supervisors can watch, join or terminate them, and records every session with full protocol-level capture for forensic review and regulatory compliance, without introducing latency that would affect OT system operation.
Verifies remote user identity with multifactor authentication that adapts to context and risk signals such as location, device posture, time of day and the asset requested, stepping up or denying access when signals are anomalous, rather than the static MFA prompt most OT remote access tools provide.
Moves files such as firmware, patches and project files into and out of OT sessions through a controlled transfer channel that scans every file for malware before release, replacing USB media and unmonitored uploads.
Brokers remote access for third-party vendors, OEM technicians, contractors and internal engineers with just-in-time provisioning, time-limited credentials, per-asset and per-session least privilege and approval workflows, replacing always-on VPN and jump-host access to OT networks.
Brokers native engineering-tool sessions (vendor programming software, RDP, VNC, SSH and OT protocol tunnels) so that remote engineers and OEM technicians can perform hands-on operations, maintenance and firmware upgrades on equipment, not only view-only or jump-host access.
Provides secure remote access to OT environments with no internet connectivity using a data diode-compatible or hardware broker architecture, without requiring an internet-connected OT network.
Writes segmentation rules that reference user and group identity, device posture and workload identity rather than IP addresses or subnets, so access to a segmented resource can be conditioned on who is connecting and the state of their device, and privileged Layer 3 and 4 access such as RDP, SSH and WinRM can be gated by MFA. Topology-independent, label-based policy is table stakes for the niche; this row is for identity and posture conditions layered on top of it. Products differ in identity sources (directory, identity provider, ZTNA or EDR posture signals) and in whether MFA gating is native.
Discovers and classifies every workload and device that communicates on the network, including unknown and unmanaged assets missing from the CMDB, using the product's own agents, network sensors and ingested external inventories, so segmentation policy can cover assets the organization did not know it had. Products differ in fingerprinting depth (device make, model, operating system, function), agentless reach, and use of external data sources.
Enforces segmentation through the existing on-premises network infrastructure, programming switches, DPU-based switches, firewalls, NAC, application delivery controllers or an inline gateway appliance, so devices that cannot run an agent are segmented without rearchitecting the network or replacing hardware. Products differ in the range of network hardware vendors supported, whether enforcement is distributed at the access layer or backhauled to central chokepoints, and dependency on a NAC deployment.
Proposes least-privilege allow-list rules automatically from observed flows, labels and templates, and manages them through the full lifecycle of creation, testing, enforcement, tuning and retirement, so segmentation is not built by writing rules by hand. Products differ in recommendation quality, template coverage for common applications and compliance zones, and support for iterative refinement before enforcement.
Segments purpose-built and unmanaged devices such as medical devices, industrial controllers, building systems and IoT endpoints that cannot host an agent and often run very old operating systems, combining device fingerprinting and classification with network-side enforcement and policy templates tuned to clinical and industrial protocols, without disrupting device operation. Products differ in device fingerprinting depth, protocol awareness, and whether enforcement works with the legacy network equipment typical of hospitals and plants.
Contains an active breach by cutting the paths ransomware and attackers use to spread: pre-staged containment policies that block peer-to-peer SMB, RDP, WMI and other administrative protocols between endpoints and servers, a firebreak around devices that cannot run security agents, and quarantine of compromised workloads that can be triggered from the console, by a severity-level switch, or by SIEM, SOAR and EDR during an incident. Products differ in whether containment can be staged by threat level and activated with a single switch, and in how quickly a quarantine reaches every enforcement point.
Renders the discovered assets, their flows and the current policy state as an interactive map that can be viewed at data center, application, workload and connection level, showing which traffic is allowed, blocked or not yet governed, so teams can author policy and investigate incidents from the same view. Products differ in readability at scale, filtering and drill-down, and whether the map supports policy authoring directly.
Discovers the actual north-south and east-west communication flows between workloads and devices by observing live traffic, producing the dependency data that allow-list policy is built from instead of hand-documented application maps. Products differ in flow sources (host agent, network sensors or switch telemetry, cloud flow logs, virtual switch) and therefore in how completely agentless assets are covered.
Extends the segmentation policy model to remote and campus user access by integrating with a zero trust network access service, so user-to-application access and workload-to-workload segmentation are governed from one policy model, often through a shared agent and console. Products differ in whether the ZTNA is native to the same platform, integrated through a partner, or absent, and in whether identity and device posture from the user session feed east-west policy.
Generates and enforces least-privilege network segmentation and microsegmentation policies for devices, with pre-deployment impact assessment so new policies do not break device operations.
Establishes and manages per-device identity and access over the device lifecycle, including certificate and credential provisioning and rotation.
Time-bound, on-demand granting of privileged access that removes standing privilege.
Brokers secure remote privileged access for third-party and external IT staff such as vendors and service providers.
Management and rotation of machine and application secrets such as API keys, tokens, and certificates for non-human identities.
Automated discovery and onboarding of privileged accounts across on-premises and cloud environments.
Manages the full life cycle of privileged accounts for human and machine identities, covering creation, ownership assignment, modification, recertification, and decommissioning after an account has been discovered and onboarded.
Provides role-based administration and centralized policy management for controlling access to privileged credentials and actions.
Brokering, monitoring, and recording of privileged sessions with the ability to audit and terminate them in real time.
Secure storage, automated rotation, and auditing of privileged account credentials in a vault.
Creates net-new permissions per need and removes them after a time-bound session, eliminating standing privileged accounts.
Tracks OT security posture against IEC 62443, NIS2, NERC CIP and other sector regulations by mapping discovered assets, zones, vulnerabilities and controls to specific requirements and producing audit-ready compliance reports and gap lists. Usability of the tracking workflow varies widely.
Controls local and remote user access to OT assets through brokered, identity-verified sessions with live monitoring and full audit trails, either as a native platform capability or by integrating with and monitoring third-party secure remote access tools. Native access management versus monitoring of customer-selected tools is the main difference between products.
Classifies discovered assets and traffic flows into Purdue Model levels (Level 0-4), supporting IEC 62443 zone and conduit documentation and compliance assessment.
Turns observed OT traffic and Purdue zone assignments into least-privilege zone and conduit policies, simulates their effect before rollout so that legitimate control traffic is not blocked, and enforces them either through the vendor's own firewalls and switches or by pushing rules to integrated third-party firewalls, switches and NAC. Native enforcement versus integration-only enforcement is the main difference between products.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on September 7, 2026
Buyers
See how Xage Fabric Platform fits your stack
Add Xage Fabric Platform to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.