Built for OT/ICS environments

Secure remote access without compromise

Privileged access management that keeps session recordings on-site, injects credentials from a vault, and never exposes your internal network.

Request a demo See how it works
Encrypted Tunnel security
Military-grade Encryption standard
Hardened Secure appliance
MFA Multi-factor auth
The problem

Traditional remote access wasn't built for critical infrastructure

VPNs, jump servers, and shared credentials create risk in environments where uptime and safety are non-negotiable.

Exposed attack surface

Site-to-site VPNs give vendors full network access. One compromised credential and the entire OT network is reachable.

No session visibility

When a vendor connects, you can't see what they're doing. No recordings, no audit trail, no way to review after an incident.

Shared credentials

Passwords shared over email, stored in spreadsheets, reused across systems. No injection, no rotation, no accountability.

How it works

A purpose-built appliance in your DMZ

Users connect through our cloud portal. The appliance in your network handles the actual session — credentials never leave your site.

User
Browser
Any device, anywhere
Cloud
Fylix Portal
Auth, MFA, policy
VPN Tunnel
Encrypted Link
Secure channel
Your Site
DMZ Appliance
On-premise
Target
OT System
Remote protocols

Session recordings stay on the appliance. Credentials are injected securely at session time. Users never see passwords.

Platform

Everything you need for secure remote access

Purpose-built for environments where compliance, auditability, and data sovereignty matter.

Zero-trust architecture

Users never have direct network access to target systems. Every session is brokered, authenticated, and authorized individually.

Session recording

Every remote session is recorded and stored locally on the DMZ appliance. Recordings never leave your site — full data sovereignty.

Credential injection

Passwords stored in a secure vault and injected at session time. Users authenticate to the portal — they never see or handle target credentials.

Multi-tenant isolation

Each customer gets their own dedicated environment, portal subdomain, and isolated policy engine. No data commingling, ever.

Browser-based access

No client software to install. Users open a browser, authenticate with multi-factor authentication, and launch sessions — works from any device.

Time-bound access policies

Define access windows by day-of-week, time range, and maximum session duration. Enforce least-privilege access automatically.

Plans

Flexible plans for every organization

One appliance per site. No per-user fees, no hidden costs. Every plan includes all core features.

Starter

Ideal for small teams
  • 1 DMZ appliance
  • Up to 10 concurrent users
  • Up to 25 target systems
  • Session recording & audit
  • Multi-factor authentication
  • Email support
Contact us

Enterprise

Tailored to your needs
  • Multiple appliances
  • Unlimited users
  • Unlimited target systems
  • Custom domain
  • Dedicated support engineer
  • SLA & compliance reporting
  • On-site deployment assistance
Contact sales
Security

Built for environments where security is the product

Every layer of the platform is designed for the compliance and security requirements of critical infrastructure operators.

Industry-hardened appliance

The DMZ appliance ships as a security-hardened virtual machine, benchmarked against industry standards.

Industrial security aligned

Architecture designed around zone and conduit model. The appliance sits in the DMZ — never in the control zone.

Mutual certificate authentication

Every VPN tunnel uses mutual certificate authentication. No shared secrets, no PSKs.

End-to-end encrypted tunnel

Data sovereignty

Session recordings and credentials stay on the appliance. Nothing sensitive transits or is stored in the cloud.

Mandatory Multi-factor authentication

All users must enroll in multi-factor authentication before their first login. No exceptions, no opt-out.

Dedicated tenant isolation

Each customer's data lives in its own isolated database. No shared tables, no commingling risk.

Immutable audit trail

Audit events written to immutable cloud storage. 365-day retention — no one can delete them.

Process confinement

All processes run under mandatory access control profiles restricting file and network access.

Ready to secure your remote access?

See the platform in action. We'll walk through your environment and show you how Fylix fits.

Request a demo