Connect Every PLC, Sensor, and Device — Without the Exposure.
Give engineers and vendors software-defined, outbound-only access to industrial control systems, SCADA, PLCs, and IoT fleets — without ever placing a legacy device on a routable, discoverable network.
Legacy-Safe by Design
Wraps PLCs, RTUs, and HMIs that were never built for internet exposure in an invisible identity layer.
Fleet-Scale IoT Onboarding
Provision thousands of sensors and edge gateways with zero-touch, cryptographic identity at boot.
Zero Inbound Holes
No open firewall ports into the plant floor. All sessions are outbound-only and mutually authenticated.
IT/OT Convergence Broke the Old Perimeter.
Plant floors were designed for isolation, not connectivity. Now sensors, historians, and remote vendors all need a path in — and every VPN or flat network you bolt on becomes a new way to reach a PLC that has no concept of authentication. Most industrial control protocols were never built to defend themselves.
- warning Legacy PLCs and RTUs can't run modern encryption or agents, yet still end up network-visible
- warning Third-party vendors are given broad VPN access to service one machine, and can reach everything else on the segment
- warning Thousands of unmanaged IoT sensors ship with default credentials and no patching path
One Overlay Network for Every Machine, Sensor, and Vendor.
CloakNet drops a lightweight software-defined perimeter in front of your OT and IoT assets. Devices and vendors connect out to CloakNet — never the other way around — so the plant floor stays completely dark to the internet.
Connect a Device or Vendor in Five Steps
Lightweight Edge Gateway
A small connector sits in front of the PLC, RTU, or sensor network — no agent needed on the legacy device itself.
Cryptographic Device Identity
Every gateway and sensor is issued a unique certificate at enrollment — no shared keys, no default credentials.
Outbound-Only Connection
The gateway calls out to CloakNet over an encrypted tunnel. No inbound port is ever opened on the OT network.
Scoped, Time-Boxed Access
Vendors and engineers get a session mapped to one asset for a defined window — never full network reach.
Full Session Recording
Every remote session against a control system is logged and replayable for audit and incident response.
See Every Connected Asset.
Control Exactly Who Reaches It.
Governance is visibility plus control. The OT & IoT console gives you both from one identity-first dashboard.
Live Fleet Telemetry
Connection health, session volume, and device status across every plant and site, in real time.
Full Asset Inventory
Every PLC, RTU, sensor, and gateway tied to a site and an owner. Auditable across every plant.
Zero-Touch Fleet Onboarding
sensorsShip devices pre-enrolled. They receive identity and policy automatically the moment they power on.
Instant Access Revocation
flash_onCut off a vendor session or quarantine a compromised sensor immediately, from one console.
Built for Every Connected Environment You Run
From plant-floor SCADA to distributed sensor fleets, the same identity model governs every connection.
Industrial Control Systems
Cloak PLCs, RTUs, and SCADA historians so they're never visible to a network scan.
Distributed IoT Sensor Fleets
Onboard thousands of field sensors with unique identity instead of shared network credentials.
Third-Party Vendor Access
Give OEM technicians scoped, time-boxed access to one machine — never the whole plant network.
Speaks the protocols your plant floor already runs
Full Connectivity. No Exposed Attack Surface.
Transform how the plant floor connects, from open and flat to identity-governed and invisible.
Reduced OT Attack Surface
Legacy devices stay dark to scanners and reconnaissance tools, with no inbound path to exploit.
Invisible Plant Floor
No open firewall rules or public IPs on control systems — nothing to discover from the outside.
Compliance-Ready Audit Trail
Every vendor and engineer session against OT assets is logged for IEC 62443 and NERC CIP reviews.
Fast Rollout, No Rewiring
Drop a gateway in front of existing equipment and get identity-based access without re-architecting the plant network.
We connected eleven plants and over four thousand sensors without opening a single inbound port. Vendor access that used to take a week of change requests now takes fifteen minutes.
Director of OT Security
Global Manufacturing Group
Bring Your Plant Floor Online, Safely
Connecting new sensors or opening access for another vendor? Get a governed overlay in front of every OT and IoT asset with hands-on help from our team.