
Cyber-Physical Systems (CPS) SecurityIdentity & Access Management
Xage Fabric Platform
Agentless zero trust access, PAM, and segmentation mesh for OT, IT, and cloud infrastructure.
Xage Fabric Platform Overview
What it does
Xage Fabric Platform is a zero trust access and protection platform for cyber-physical systems (CPS), operational technology (OT), IT, data center, and cloud environments. It overlays existing infrastructure as a distributed cybersecurity mesh that enforces identity-based access control, credential management, and asset-level segmentation on systems that cannot run agents, including legacy PLCs, RTUs, and HMIs. Because credentials and policies are distributed across the mesh, there is no single point of failure and enforcement continues when sites lose connectivity.
How it works
Xage Nodes deploy as virtual machines, containers, or Xage Extended Protection hardware appliances across data centers, cloud, and remote sites, brokering every session without endpoint agents or firewall rule changes. Credential and policy data is sharded across the mesh using Shamir's Secret Sharing and Federated Byzantine Agreement, so access enforcement, multi-factor authentication (MFA), and one-time credential issuance keep working offline and in air-gapped conditions. Five products run on the fabric: Secure Remote Access, Extended PAM, Critical Asset Protection, Zero Trust Data Exchange, and Zero Trust for AI, while Visibility-to-Policy (V2P) Studio translates observed asset behavior into enforceable access policies.
Credentials and traction
ISO 27001 certified (certificate ICI-IS-2312025), FIPS 140-3 validated (NIST certificate 5229), and IEC 62443-4-1 and 62443-4-2 Security Level 3 certified, with CISA's Secure by Design pledge signed. Xage is recognized in the February 2026 Gartner Market Guide for CPS Secure Remote Access and the March 2026 Forrester Operational Technology Security Solutions Landscape. Customers include Kinder Morgan, PETRONAS, Ornua, and the U.S. Space Force's Space Systems Command.
Key Capabilities
mapped to solution categoriesEstablishes and manages per-device identity and access over the device lifecycle, including certificate and credential provisioning and rotation.
Generates and enforces least-privilege network segmentation and microsegmentation policies for devices, with pre-deployment impact assessment so new policies do not break device operations.
Discovers and fingerprints purpose-built connected devices (printers, cameras, infusion pumps, smart meters, building systems), classifying make, model, OS, firmware, and function, including unmanaged devices that cannot run an endpoint agent.
Maps actual traffic flows between IT and OT zones and between Purdue model levels, revealing unauthorized cross-zone connections and segmentation failures.
Manages third-party vendor remote access sessions with just-in-time provisioning, time-limited credentials, and session approval workflows, replacing always-on VPN access to OT networks.
Records all remote sessions with full protocol-level capture for forensic review and regulatory compliance, without introducing latency that would affect OT system operation.
Provides secure remote access to OT environments with no internet connectivity using a data diode-compatible or hardware broker architecture, without requiring an internet-connected OT network.
Secure storage, automated rotation, and auditing of privileged account credentials in a vault.
Time-bound, on-demand granting of privileged access that removes standing privilege.
Automated discovery and onboarding of privileged accounts across on-premises and cloud environments.
Brokering, monitoring, and recording of privileged sessions with the ability to audit and terminate them in real time.
Brokers secure remote privileged access for third-party and external IT staff such as vendors and service providers.
Creates net-new permissions per need and removes them after a time-bound session, eliminating standing privileged accounts.
Provides role-based administration and centralized policy management for controlling access to privileged credentials and actions.
Management and rotation of machine and application secrets such as API keys, tokens, and certificates for non-human identities.
Manages the full life cycle of privileged accounts for human and machine identities, covering creation, ownership assignment, modification, recertification, and decommissioning after an account has been discovered and onboarded.
Enforces identity-based allow policies (user identity, workload identity, device posture), rather than IP-based rules, policy follows the workload regardless of network location.
Discovers actual application communication flows by observing traffic before policy creation, producing a dependency map that forms the basis for allow-list policy without manual documentation.
Enforces segmentation via a host agent at the OS network stack or through upstream network controls (cloud security groups, SDN, switch ACLs) where agents are not viable.
Blocks SMB, RDP, and WMI connections between endpoints by default, preventing ransomware from moving laterally via common network shares and remote management protocols.
Compliance
certificationsIntegrations
compatible toolsImplementation & support
Info last updated on July 30, 2026
Buyers
See how Xage Fabric Platform fits your stack
Add Xage Fabric Platform to your shortlist and unlock all evaluation tools.
Vendors
Is this your product?
Claim your profile to connect with the teams looking for your solutions.