Skip to content
Trausto

Risk assessment for OT and IACS · IEC 62443 · from Switzerland

Designed, built and operated in Switzerland by RiskZone GmbH

Defending What Matters.

Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.

Document, justify and defend OT/IACS risk decisions on a Swiss-built platform where sensitive project data never leaves your team. Operated from Switzerland as SaaS — your assessment content is encrypted before it ever reaches us.

For operators where one person owns the OT risk assessment — and assembles the evidence from spreadsheets and Word templates today.

01
FR1–FR7 evidence mapping
02
Encrypted before it reaches us
03
Swiss software, single jurisdiction
04
IEC 62443 · ISO/IEC 27005 · EN 50701

How it works

How an assessment comes together

Three steps on one data set. What you enter once carries through to the report.

01

Map the plant

Create assets, zones and conduits — or import the lists you already keep. Criticality, safety impact and exposure are fields, not notes in a margin.

02

Assess the risk

Threat scenarios per zone and asset class, evaluated under the methodology your project carries. Every rating keeps what it rests on.

03

Produce the evidence

A report as PDF, DOCX or HTML, naming the methodology and its version. The underlying data as JSON, CSV or XML — exported in the browser, against your own keys.

Isolated zone architecture · trust boundaries

A session from IT does not reach the plant. It ends at the industrial DMZ; what continues below is a second session, opened there.

  1. L5

    Level 5 — Enterprise

    ERP, business systems, internet boundary

    Terminated at the site firewall

  2. L4

    Level 4 — Site Business

    Site IT, scheduling, reporting

    The session ends on the jump host

  3. DMZ

    Trust Boundary — Industrial DMZ

    Patch servers, jump hosts, AV repositories

    A new session, opened from the DMZ

  4. L3

    Level 3 — Site Operations

    MES, historians, engineering workstations

    Terminated at the operations boundary

  5. L2

    Level 2 — Area Supervisory

    HMI, SCADA, alarming

    Segmented, not terminated

  6. L1

    Level 1 — Basic Control

    PLCs, DCS controllers, RTUs

    Field wiring — copper, not control

  7. L0

    Level 0 — Process

    Sensors, actuators, instrumentation

Reference architecture per IEC 62443-3-2 and the Purdue model (ISA-95/IEC 62264 defines levels 0–4; the enterprise level comes from PERA). Your plant deviates from it — recording and justifying that deviation is the work Trausto exists for.

Reference architecture · zones and conduits

Traceable

The arithmetic is on the table

A risk rating you cannot explain in an audit is not a rating. So the rule that produced it ships as readable configuration, not as code nobody sees.

Where a methodology brings a derivation, Trausto computes it in the open. In the EN 50701 rail profile, likelihood follows from exposure and vulnerability through a 5×5 matrix that sits cell by cell in the project configuration. You can read it, show it to an assessor — and disagree with it.

Methodologies
likelihoodDerivation · ceil((e + v) / 2) EN 50701

Vulnerability ↓

Likelihood derived from exposure and vulnerability
Vulnerability 12345
5 3 4 4 5 5
4 3 3 4 4 5
3 2 3 3 4 4
2 2 2 3 3 4
1 1 2 2 3 3

Exposure →

The shipped matrix, rendered here from its own formula: the rounded-up mean of exposure and vulnerability. Exposure 4 and vulnerability 3 yield likelihood 4 of 5.

State today

What is in the product today

Not an outlook. This is the state an evaluation gets to see today.

Available now

Assets, zones and conduits · security level targets (SL-T) per zone · threat scenarios · FR1–FR7 evidence mapping · ISMS register with Statement of Applicability · report as PDF, DOCX and HTML · audit log · export as JSON, CSV, XML and CycloneDX 1.6.

Not in it yet

Deriving SL-T normatively from the assessment is in development — today you set the target yourself. The ISO/IEC 27001 Annex A catalogue is in preparation; the register and the Statement of Applicability mechanism already ship.

Why Trausto

What separates this from a GRC tool with extra columns.

01

Built for OT, not retro-fitted

Zones, conduits, safety-impact, criticality and consequence-driven risk are first-class objects — not custom columns in a GRC tool. Modelled the way control engineers think and the way IEC 62443 expects, with SL-T targets, evidence and export paths an external auditor will recognise.

02

Swiss software, single jurisdiction

Designed, built, operated and supported by a Swiss software company. Engineering, product, security response and customer support all sit under one Swiss legal jurisdiction — one contract, one accountable counterparty, one regulator. No offshore support routing.

03

Your data stays yours

Sensitive content — assets, conduits, threat scenarios, supplier evidence — is encrypted on the user device before it leaves your team. Trausto, the hosting providers and third parties only ever hold encrypted data. Outside the server-routed AI path, which we name line by line further down, there is no readable copy to leak, subpoena or mishandle.

Outcomes

What changes for your team

What changes in the work, stated so each item can be checked against the product.

O1

Audit-ready by construction

IEC 62443 zones, conduits and SL-T evidence are native objects. Exports are structured for assessors and procurement — not stitched together from spreadsheets the night before.

O2

Every rating can be explained

Which requirement a rating rests on, which assumption supports it, who signed it off — in the report, not only in the head of the person who wrote it.

O3

Sensitive risk data stays under your control

Auditors, suppliers and reviewers see what you hand them — as an export from your browser, not as access to your project. Only members of your organisation hold keys. Trausto itself, the hosting layer and third parties cannot read your assessments — the server-routed AI path excepted, which you switch on or leave off.

O4

Continuity under pressure

Lost laptops, departing staff, M&A activity, supplier rotation — revoking access to a project is a key operation, not a manual cleanup: the project key is rotated and every blob under it re-encrypted in one transaction, existing ciphertext included. At organisation level, rotation is still triggered by an administrator rather than by the removal itself.

Insight

What we can see — and what we cannot

Trausto runs as SaaS, operated from Switzerland. That is the whole offer: there is no on-premise edition to evaluate and no deployment matrix to negotiate. The reason is that the question on-premise exists to answer — who can read your assessments — is already answered earlier and more strongly, in the browser, before anything reaches us.

01

One operating model

Multi-tenant SaaS, built and operated from Switzerland by a Swiss company on hardened cloud infrastructure. One code path, one set of controls, one thing to audit — for you and for us. Onboarding takes days, not a procurement cycle.

02

Isolation you can point at

Every project carries its own encryption key, wrapped for each member and each device. Separation is enforced cryptographically, not only by a filter in a query — losing access is a key operation, not a flag in a table. The organisation is the unit you contract and are billed under, and the one that can deposit a recovery phrase; the project is the cryptographic unit.

03

What we hold

Ciphertext, plus the operational metadata the service needs in order to run: who holds an account, which project a record belongs to, when it last changed, how much storage you use. We itemise that surface below instead of explaining it away.

Disclosure

The metadata surface, itemised

Encryption is half a promise until you say what stays unencrypted. This is the other half.

14 items. At exactly 1 of them content is processed in the clear — on a path you do not have to take.

14
items we disclose. All of them are below; nothing is summarised away.
1
path on which content passes through our worker in the clear: the server-routed AI assistant. It is optional.
10
items stay readable to us so the service can run. They say who, when and how much — none of them carries a sentence from a risk assessment.

What happens to your risk assessment?

Everything you enter, everything you upload, and the keys to it. This is the answer to the question you came with.

Assessment content

No — ciphertext only

Assets, zones, conduits, scenarios and evidence are encrypted on your device before upload. The one exception is the server-routed AI path below.

Uploaded evidence

No — ciphertext only

Supplier documents and attachments follow the same path as assessment content.

The one exception

AI processing

Yes, for the duration of the request

only if you use the server-routed AI path

If you use the server-routed AI assistant, the content of that one request passes through our worker in the clear to reach the configured provider — your own endpoint or, where one is set, a platform-wide default your organisation can disable. Running the model in the browser avoids this — that is the honest reason the option exists.

Key material

No — wrapped only

Your private key is wrapped separately per device by the device's secure element; your personal recovery phrase and the optional organisation one are generated in your browser and never leave it in the clear. We hold wrapped forms only.

Reach

An organisation key can unwrap the projects in its permission chain — that is how an organisation keeps access when a person leaves, and it means the organisation recovery phrase reaches those projects too.

What stays readable to us so the service can run?

10 of 14 items. They exist because the software runs hosted, several people work in it, and evidence is supposed to come out at the end. Names, timestamps, counts.

What stays readable to us so the service can run?
Item Readable by us
Account identity Yes
Project membership Yes — structure, not content
Timestamps Yes
Audit log Yes 90 days (default) · SIEM export is the long-term archive
Usage volume Yes
Device and session metadata Yes Sessions valid 30 days, rows purged after 90 · device entries are revoked, not deleted
Transactional email Yes — sent via Mailgun (EU region)
Support and administration access Yes — metadata, never content
AI operational telemetry Yes — metadata only if you use the server-routed AI path 90 days (default), as part of the audit log
SIEM export Yes — audit metadata only with a webhook you configure
Why these 10 items exist — show the reasons
Account identity
Name and business email. Needed to authenticate you and to address you in support.
Project membership
Which record belongs to which project, and who has access to it. That controls who can retrieve; the content becomes readable only through the project key.
Timestamps
Created and last-changed times, so concurrent edits and version history work.
Audit log
Who did what, when. Required for the evidence trail the product exists to produce.
Usage volume
Storage consumed and record counts, for billing and capacity.
Device and session metadata
Per device: the device name you chose (plain text), its public key, when it was added and when its wrapped key was last retrieved; removed devices are revoked, not deleted. Per session: browser identifier, an IP prefix — never the full address — and which device opened the session.
Transactional email
Registration and recovery codes, invitations and account-change notices are delivered by the email provider Mailgun. These mails carry: confirmation codes, device name, organisation name (also in the subject line), role, and the address of the acting person; on an address change, the old address is told the new one. Recipient addresses and mail metadata therefore also sit with the delivery provider.
Support and administration access
Platform administrators can read member lists including email addresses, audit logs and usage statistics; assessment content they cannot — it exists on our side only as ciphertext. Administrative writes are recorded in the audit log; reads currently are not recorded individually.
AI operational telemetry
Which provider was called, whether it failed and how long it took. No request content.
SIEM export
If your org configures a SIEM webhook, audit events go to the endpoint you name. Assessment content is not part of that stream.

Disclosure as of 2026-08-12. Every item is confirmed against the implementation before launch; what is not confirmed is removed rather than softened.

Getting started

What getting started looks like

Three routes, depending on where you stand.

01

Evaluation

Guided product walkthrough, technical Q&A and access to a sandbox organisation for two named evaluators.

02

Pilot deployment

Time-boxed pilot on a representative site or zone, with success criteria agreed up-front and a clean exit if the results do not justify production.

03

Procurement / RFP

Vendor questionnaires, due-diligence packages and contractual schedules. One operating model and one Swiss counterparty — there is no deployment variant to negotiate, which removes the longest item from most security reviews.

And if you want to leave

Your data is yours, and you can reach it without us. The export runs in the browser against your own keys and produces JSON, CSV or XML — the same data the report is built from. If you lose your last device, your personal recovery phrase takes over. For the case where nobody in an organisation holds a key any more, there is an additional recovery phrase at organisation level — deliberately optional, because it lifts exactly the finality that makes the rest of this work. Both are product functions, not promises in a contract.

Verifiable

Trust signals

Signals you can check yourself, without asking us first.

And three statements you can read, but not verify externally

They belong under their own heading, not under "verifiable" — that distinction is the point of this section.

Examine the security model Vulnerability disclosure Status page

Compliance

Compliance posture & roadmap

We do not over-claim certifications. Here is where we are today, what we are working toward, and what is already available on request.

TODAY

Today

Aligned to revFADP / nFADP, GDPR data minimisation, EU CRA, NIS2 and ENISA industrial cybersecurity guidance. IEC 62443 FR1–FR7 control mapping is part of the product.

NEXT

On the roadmap

Three pieces of independent evidence, in this order: an external penetration test of the platform, a cryptography whitepaper reviewed outside the company, and certification against ISO/IEC 27001. We will name dates here once they are booked — not before.

ON ASK

Available on request

Security architecture deck, vendor due-diligence questionnaire and reference contractual schedules for regulated operators. The technical whitepaper no longer sits here — it is published on the security model page.

What Matters.

Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.