Extending the principle of isolation -
without sacrificing it.
Modern energy and OT operations need more than one-way data flow. They need RDP to SCADA, SSH to production systems, real-time APIs across segmented zones - under unified identity and policy. truePass Gravity makes that possible, while preserving every architectural principle these environments are built on.
Where trust is non-negotiable.
The diode isn't the problem. The operational reality is.
For decades, OT environments operated under one assumption: physical isolation with one-way data flow. For that world, data diodes were - and still are - the right tool. They enforce unidirectional communication with hardware-level guarantees that no software can match.
But modern energy, control, and industrial systems require something diodes were never designed to deliver: interactive application connectivity. RDP sessions to SCADA consoles. SSH to production servers. Real-time API integrations. Controlled vendor access. When operations push for these capabilities, organizations either layer multiple complementary products around the diode - increasing attack surface and operational complexity - or staff find "creative" workarounds that bypass security entirely.
Not every environment needs to change. Here's how to know.
truePass Gravity isn't a replacement for every data diode deployment. It's a different architectural choice for a different operational need.
If your scenario is genuinely one-way.
- One-way data replication is sufficient
- Only Historian, Syslog, or UDP file copy required
- No need for interactive sessions (RDP, SSH, Web)
- No identity-aware policy at the boundary
- Vendor access handled outside the diode path
If your operations need interactive connectivity.
- Operations need RDP to SCADA / HMI consoles
- SSH access to production servers required
- Web applications and APIs span isolated zones
- Vendor access requires per-user identity, MFA, audit
- Compliance demands per-request policy and unified audit
- Multiple point products around the diode are unmanageable
The operational gap shows up in four places.
When organizations push diodes beyond what they were designed for, these are the pain points that emerge - every time.
No interactive application connectivity
The modern need to connect APIs, web services, and continuous data synchronization is not natively supported in one-way models. This limits operational capability - and often forces operators to find workarounds that bypass the very isolation the diode was meant to enforce.
Growing architectural complexity
Bridging the gap means layering complementary products: proxy servers, dedicated communication components, embedded TCP connectors. The result is a distributed architecture that makes unified security policy management nearly impossible.
Bidirectional communication challenges
Any scenario involving recurring interaction between systems - vendor maintenance, API responses, application acknowledgments - requires additional solutions on top of the diode. Each addition creates operational complexity and policy consistency gaps.
No identity context at the access layer
Traditional separation mechanisms are infrastructure-level, not identity-level. They cannot enforce dynamic policy based on who the user is, what device they're on, or the context of their action. This is the foundation Zero Trust is built on - and it's missing.
Three modules. Built for the operational reality of OT.
truePass Gravity is the flagship module for Energy & OT environments. Grid and Guard extend its capabilities for full-stack OT security.
Three-layer platform: Reverse Access™ infrastructure + Secure SMB Proxy + Zero Trust App Access. Enables RDP, SSH, HTTP, Web Services, API, and CIFS/ SMB secure access between isolated zones - under unified identity and policy.
Identity-based segmentation within OT networks. Prevents lateral movement between operational zones, controllers, and supporting systems. Each endpoint isolated by identity, not just network location.
Production-grade SMB file services with MFA per file action, TLS-443 transport, CDR sanitization, and relay-attack protection (SMB Signing). For file workflows between IT and OT zones.
What modern Energy & OT teams can finally do.
Remote monitoring & maintenance of SCADA/ICS
Operators access HMI consoles and engineering workstations via RDP - from anywhere - under per-session MFA, clipboard controls, and full session recording. No VPN tunnels into OT. No exposed RDP gateways.
Controlled vendor & integrator access
Equipment vendors and system integrators access specific assets for time-limited, scoped maintenance windows. Per-user identity, MFA, and audit - without giving network-level access to the OT zone.
Real-time OT-to-IT data synchronization
Production data, historian replication, and API integrations between OT and IT zones operate under unified policy with full audit trail. Interactive where needed, one-way where appropriate.
Cross-zone file transfer with content control
Files moving between IT, DMZ, and OT zones pass through CDR sanitization, identity verification, and policy enforcement. Engineering files, configuration updates, operational documents - all controlled.
Built to the standards your auditors expect.
truePass Gravity's architecture supports compliance with the frameworks governing Energy & OT environments worldwide.
Per-request policy enforcement, unified audit trail, and identity-aware access - the architectural building blocks regulators require, delivered out of the box.
Validated where it matters most.
TerraZone is engaged in cooperation with the Israel National Energy, Control & Cyber Laboratory (ICNL) - a national research framework focused on advancing cybersecurity architectures for critical energy and control environments.
The collaboration explores secure connectivity architectures beyond traditional unidirectional models, validates interactive application access scenarios (SCADA, API, RDP) in isolated environments, and analyzes operational continuity under advanced threat scenarios - including Nation-State and APT actors.
- Advanced connectivity architectures for ICS/OT environments
- Application access validation in isolated environments (SCADA, API, RDP)
- Operational continuity under APT & Nation-State threat scenarios
- Micro-segmentation & Zero Trust against breach propagation
- SIEM/SOC integration for real-time anomaly detection
No infrastructure changes. No firewall rule rewrites.
Architecture review
Our architects map your current OT environment, identify connectivity requirements, and define the right deployment topology.
Policy setup
Policy configuration with no changes to existing firewall rules. Native integration with Active Directory, Kerberos, NTLM, and existing SIEM/SOC.
Phased rollout
Side-by-side operation alongside existing systems. Pilot, validate, expand. Production-ready quickly - with full rollback at every stage.
Bring modern connectivity
to your OT environment.
A 30-minute consultation with our security architects who specialize in Energy & OT. We'll review your current architecture, identify where Gravity extends your existing isolation strategy, and propose a tailored Proof of Concept.