Map the plant
Create assets, zones and conduits — or import the lists you already keep. Criticality, safety impact and exposure are fields, not notes in a margin.
Risk assessment for OT and IACS · IEC 62443 · from Switzerland
Designed, built and operated in Switzerland by RiskZone GmbH
Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.
Document, justify and defend OT/IACS risk decisions on a Swiss-built platform where sensitive project data never leaves your team. Operated from Switzerland as SaaS — your assessment content is encrypted before it ever reaches us.
For operators where one person owns the OT risk assessment — and assembles the evidence from spreadsheets and Word templates today.
How it works
Three steps on one data set. What you enter once carries through to the report.
Create assets, zones and conduits — or import the lists you already keep. Criticality, safety impact and exposure are fields, not notes in a margin.
Threat scenarios per zone and asset class, evaluated under the methodology your project carries. Every rating keeps what it rests on.
A report as PDF, DOCX or HTML, naming the methodology and its version. The underlying data as JSON, CSV or XML — exported in the browser, against your own keys.
A session from IT does not reach the plant. It ends at the industrial DMZ; what continues below is a second session, opened there.
Level 5 — Enterprise
ERP, business systems, internet boundary
Terminated at the site firewall
Level 4 — Site Business
Site IT, scheduling, reporting
The session ends on the jump host
Trust Boundary — Industrial DMZ
Patch servers, jump hosts, AV repositories
A new session, opened from the DMZ
Level 3 — Site Operations
MES, historians, engineering workstations
Terminated at the operations boundary
Level 2 — Area Supervisory
HMI, SCADA, alarming
Segmented, not terminated
Level 1 — Basic Control
PLCs, DCS controllers, RTUs
Field wiring — copper, not control
Level 0 — Process
Sensors, actuators, instrumentation
Reference architecture per IEC 62443-3-2 and the Purdue model (ISA-95/IEC 62264 defines levels 0–4; the enterprise level comes from PERA). Your plant deviates from it — recording and justifying that deviation is the work Trausto exists for.
Reference architecture · zones and conduits
Traceable
A risk rating you cannot explain in an audit is not a rating. So the rule that produced it ships as readable configuration, not as code nobody sees.
Where a methodology brings a derivation, Trausto computes it in the open. In the EN 50701 rail profile, likelihood follows from exposure and vulnerability through a 5×5 matrix that sits cell by cell in the project configuration. You can read it, show it to an assessor — and disagree with it.
MethodologiesVulnerability ↓
| Vulnerability | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 3 | 4 | 4 | 5 | 5 |
| 4 | 3 | 3 | 4 | 4 | 5 |
| 3 | 2 | 3 | 3 | 4 | 4 |
| 2 | 2 | 2 | 3 | 3 | 4 |
| 1 | 1 | 2 | 2 | 3 | 3 |
Exposure →
The shipped matrix, rendered here from its own formula: the rounded-up mean of exposure and vulnerability. Exposure 4 and vulnerability 3 yield likelihood 4 of 5.
State today
Not an outlook. This is the state an evaluation gets to see today.
Assets, zones and conduits · security level targets (SL-T) per zone · threat scenarios · FR1–FR7 evidence mapping · ISMS register with Statement of Applicability · report as PDF, DOCX and HTML · audit log · export as JSON, CSV, XML and CycloneDX 1.6.
Deriving SL-T normatively from the assessment is in development — today you set the target yourself. The ISO/IEC 27001 Annex A catalogue is in preparation; the register and the Statement of Applicability mechanism already ship.
Why Trausto
Zones, conduits, safety-impact, criticality and consequence-driven risk are first-class objects — not custom columns in a GRC tool. Modelled the way control engineers think and the way IEC 62443 expects, with SL-T targets, evidence and export paths an external auditor will recognise.
Designed, built, operated and supported by a Swiss software company. Engineering, product, security response and customer support all sit under one Swiss legal jurisdiction — one contract, one accountable counterparty, one regulator. No offshore support routing.
Sensitive content — assets, conduits, threat scenarios, supplier evidence — is encrypted on the user device before it leaves your team. Trausto, the hosting providers and third parties only ever hold encrypted data. Outside the server-routed AI path, which we name line by line further down, there is no readable copy to leak, subpoena or mishandle.
Outcomes
What changes in the work, stated so each item can be checked against the product.
IEC 62443 zones, conduits and SL-T evidence are native objects. Exports are structured for assessors and procurement — not stitched together from spreadsheets the night before.
Which requirement a rating rests on, which assumption supports it, who signed it off — in the report, not only in the head of the person who wrote it.
Auditors, suppliers and reviewers see what you hand them — as an export from your browser, not as access to your project. Only members of your organisation hold keys. Trausto itself, the hosting layer and third parties cannot read your assessments — the server-routed AI path excepted, which you switch on or leave off.
Lost laptops, departing staff, M&A activity, supplier rotation — revoking access to a project is a key operation, not a manual cleanup: the project key is rotated and every blob under it re-encrypted in one transaction, existing ciphertext included. At organisation level, rotation is still triggered by an administrator rather than by the removal itself.
Insight
Trausto runs as SaaS, operated from Switzerland. That is the whole offer: there is no on-premise edition to evaluate and no deployment matrix to negotiate. The reason is that the question on-premise exists to answer — who can read your assessments — is already answered earlier and more strongly, in the browser, before anything reaches us.
Multi-tenant SaaS, built and operated from Switzerland by a Swiss company on hardened cloud infrastructure. One code path, one set of controls, one thing to audit — for you and for us. Onboarding takes days, not a procurement cycle.
Every project carries its own encryption key, wrapped for each member and each device. Separation is enforced cryptographically, not only by a filter in a query — losing access is a key operation, not a flag in a table. The organisation is the unit you contract and are billed under, and the one that can deposit a recovery phrase; the project is the cryptographic unit.
Ciphertext, plus the operational metadata the service needs in order to run: who holds an account, which project a record belongs to, when it last changed, how much storage you use. We itemise that surface below instead of explaining it away.
Disclosure
Encryption is half a promise until you say what stays unencrypted. This is the other half.
14 items. At exactly 1 of them content is processed in the clear — on a path you do not have to take.
Everything you enter, everything you upload, and the keys to it. This is the answer to the question you came with.
Assessment content
No — ciphertext only
Assets, zones, conduits, scenarios and evidence are encrypted on your device before upload. The one exception is the server-routed AI path below.
Uploaded evidence
No — ciphertext only
Supplier documents and attachments follow the same path as assessment content.
The one exception
AI processing
Yes, for the duration of the request
only if you use the server-routed AI path
If you use the server-routed AI assistant, the content of that one request passes through our worker in the clear to reach the configured provider — your own endpoint or, where one is set, a platform-wide default your organisation can disable. Running the model in the browser avoids this — that is the honest reason the option exists.
Key material
No — wrapped only
Your private key is wrapped separately per device by the device's secure element; your personal recovery phrase and the optional organisation one are generated in your browser and never leave it in the clear. We hold wrapped forms only.
Reach
An organisation key can unwrap the projects in its permission chain — that is how an organisation keeps access when a person leaves, and it means the organisation recovery phrase reaches those projects too.
10 of 14 items. They exist because the software runs hosted, several people work in it, and evidence is supposed to come out at the end. Names, timestamps, counts.
| Item | Readable by us |
|---|---|
| Account identity | Yes |
| Project membership | Yes — structure, not content |
| Timestamps | Yes |
| Audit log | Yes 90 days (default) · SIEM export is the long-term archive |
| Usage volume | Yes |
| Device and session metadata | Yes Sessions valid 30 days, rows purged after 90 · device entries are revoked, not deleted |
| Transactional email | Yes — sent via Mailgun (EU region) |
| Support and administration access | Yes — metadata, never content |
| AI operational telemetry | Yes — metadata only if you use the server-routed AI path 90 days (default), as part of the audit log |
| SIEM export | Yes — audit metadata only with a webhook you configure |
Disclosure as of 2026-08-12. Every item is confirmed against the implementation before launch; what is not confirmed is removed rather than softened.
Getting started
Three routes, depending on where you stand.
Guided product walkthrough, technical Q&A and access to a sandbox organisation for two named evaluators.
Time-boxed pilot on a representative site or zone, with success criteria agreed up-front and a clean exit if the results do not justify production.
Vendor questionnaires, due-diligence packages and contractual schedules. One operating model and one Swiss counterparty — there is no deployment variant to negotiate, which removes the longest item from most security reviews.
And if you want to leave
Your data is yours, and you can reach it without us. The export runs in the browser against your own keys and produces JSON, CSV or XML — the same data the report is built from. If you lose your last device, your personal recovery phrase takes over. For the case where nobody in an organisation holds a key any more, there is an additional recovery phrase at organisation level — deliberately optional, because it lifts exactly the finality that makes the rest of this work. Both are product functions, not promises in a contract.
Verifiable
Signals you can check yourself, without asking us first.
01
Swiss commercial register · UID CHE-292.851.395
Open the cantonal commercial-register excerpt — retrievable directly by UID, no account needed.
02
TLS 1.3 in transit
The padlock in your browser shows it for exactly this connection.
03
security.txt published · acknowledgement within 5 business days
Open the file itself: /.well-known/security.txt
And three statements you can read, but not verify externally
They belong under their own heading, not under "verifiable" — that distinction is the point of this section.
04
05
06
No certification claimed that we do not hold
Examine the security model Vulnerability disclosure Status page
Compliance
We do not over-claim certifications. Here is where we are today, what we are working toward, and what is already available on request.
Aligned to revFADP / nFADP, GDPR data minimisation, EU CRA, NIS2 and ENISA industrial cybersecurity guidance. IEC 62443 FR1–FR7 control mapping is part of the product.
Three pieces of independent evidence, in this order: an external penetration test of the platform, a cryptography whitepaper reviewed outside the company, and certification against ISO/IEC 27001. We will name dates here once they are booked — not before.
Security architecture deck, vendor due-diligence questionnaire and reference contractual schedules for regulated operators. The technical whitepaper no longer sits here — it is published on the security model page.
Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.