Skip to content
Trausto

The Platform

The Platform

Three workflow layers. One encrypted backbone. From asset inventory to threat-led risk and audit-ready evidence — engineered for regulated operators that need confidence today.

01

Asset & Zone Management

Capture every IACS asset — PLCs, HMIs, historians, engineering workstations, network gear, safety systems — and group them into isolated zones and conduits. Criticality, safety impact, exposure and ownership are first-class fields.

  • PLCs · DCS Controllers · RTUs
  • HMIs · SCADA · Engineering Workstations
  • Historians · MES · Reporting
  • Network Infrastructure · Firewalls · Switches
  • Safety Instrumented Systems (SIS)
  • Field Devices · Sensors · Actuators

02

Segmented Zone & Conduit Architecture

Model business, operational, supervisory, control and field zones as explicit trust boundaries. Every conduit is enumerated, classified, mapped to security level targets (SL-T), and exportable as IEC 62443 evidence.

Isolated zone architecture · trust boundaries

A session from IT does not reach the plant. It ends at the industrial DMZ; what continues below is a second session, opened there.

  1. L5

    Level 5 — Enterprise

    ERP, business systems, internet boundary

    Terminated at the site firewall

  2. L4

    Level 4 — Site Business

    Site IT, scheduling, reporting

    The session ends on the jump host

  3. DMZ

    Trust Boundary — Industrial DMZ

    Patch servers, jump hosts, AV repositories

    A new session, opened from the DMZ

  4. L3

    Level 3 — Site Operations

    MES, historians, engineering workstations

    Terminated at the operations boundary

  5. L2

    Level 2 — Area Supervisory

    HMI, SCADA, alarming

    Segmented, not terminated

  6. L1

    Level 1 — Basic Control

    PLCs, DCS controllers, RTUs

    Field wiring — copper, not control

  7. L0

    Level 0 — Process

    Sensors, actuators, instrumentation

Reference architecture per IEC 62443-3-2 and the Purdue model (ISA-95/IEC 62264 defines levels 0–4; the enterprise level comes from PERA). Your plant deviates from it — recording and justifying that deviation is the work Trausto exists for.

03

AI in regulated industrial risk

AI accelerates risk work; it does not replace engineering judgement. Trausto separates AI assistance into two clearly bounded capabilities.

AI

AI co-pilot for threat scenarios

Generate plausible threat scenarios per zone and asset class. The co-pilot proposes; engineers approve, edit or reject. Every accepted scenario carries its provenance — which model proposed it and who approved it — reviewable, attributable and exportable.

GOV

Governed integration of internal LLMs

Connect your own internal AI instance instead of a public one. Requests stay scoped to the project and run only against the endpoint you configure — including fully in-browser execution — and accepted results carry attributable provenance. Your own AI becomes part of the security process, not an unmanaged data-leakage channel.

04

Three levels of depth, one data model

W1

Basic

Basic Risk Assessment — component-driven; suitable for first-pass site evaluations and gap analyses.

W2

AI

AI-assisted Risk Assessment — same data model; the co-pilot accelerates scenario generation and evidence drafting.

W3

Extensions

Detailed Risk · IEC 62443 security requirements · supplier evidence portals — for full operator-grade programmes.

05

What comes out at the end

An assessment is worth what you can hand over. These are the artefacts the product produces, and what each of them is good for.

R1

The report

PDF, DOCX and HTML, generated in your browser from your decrypted data. The header carries the applied methodology and its version, so a reader can tell which rules produced the numbers. DOCX exists because the last mile of an assessment is usually somebody else editing your wording.

R2

The data

JSON, CSV and XML. JSON is the lossless one — it is the export to take if you ever want to leave, and it does not depend on our cooperation beyond the service being reachable.

R3

CycloneDX 1.6

Assets export as components, conduits and service assets as services, vulnerabilities as a VDR, and your security requirements as a standard with self-assessed attestations (CDXA). Stated plainly: the mapping is one-way and lossy — zones have no native CycloneDX concept and ride as properties, and threats are deliberately left out. Take the JSON export for completeness, this one for a supply-chain toolchain.

R4

ISMS register and Statement of Applicability

The organisation-level register with the Annex A applicability statement, exportable on its own. It is pinned to the methodology version it was scored under, so a later change to the scales does not silently rewrite last year's posture.

R5

The audit log

Who did what, when. Retained for 90 days in the platform; if you configure a SIEM webhook, the same events go to your endpoint, which is where long-term retention belongs.

Everything you enter here leaves the browser as ciphertext. What stays unencrypted is listed row by row in the security model — including the one row that is not. Read the disclosure →

See Trausto against your own zones

Bring one real site — your zones, conduits and security level targets (SL-T). In a single technical session we show how Trausto turns it into audit-ready IEC 62443 evidence, with your assessment content encrypted before it ever leaves the browser.