📡 STORE-AND-FORWARD — SURVIVES LINK OUTAGES 🔒 OUTBOUND ONLY — THE CA IS NEVER REACHABLE FROM OT ⚡ ZERO SIGNING AUTHORITY — POWERLESS BY DESIGN 🏭 REACHES DEVICES DOWN TO CONTROLLER LEVEL 📡 STORE-AND-FORWARD — SURVIVES LINK OUTAGES 🔒 OUTBOUND ONLY — THE CA IS NEVER REACHABLE FROM OT ⚡ ZERO SIGNING AUTHORITY — POWERLESS BY DESIGN 🏭 REACHES DEVICES DOWN TO CONTROLLER LEVEL
TRUST & COMPLIANCE ORCHESTRATOR

The Relay That Brings PKI
To Where the Devices Are.

The Trust Engine issues certificates. It never has to be reachable from the plant. The Orchestrator sits at every site, collects requests, and brings certificates back — even through links that have been down for hours.

THE GAP

A Governed PKI Still Can't
Reach an Air-Gapped Plant.

Certificate governance solves half the problem. The other half is physical: how does a signed certificate get to a PLC that has no route to the CA, on a link that isn't always up?

No safe path inExposing the CA to the OT network to let devices enrol directly is not an option in a segregated environment.
No constant linkRemote and industrial sites lose connectivity for hours, sometimes days. A request-response enrolment model breaks the moment the link drops.
No uniform deviceSome switches speak EST natively. Most PLCs speak nothing. A single enrolment method can never reach the whole fleet.
ARCHITECTURE

Two Parts. Never on the Same Network.

A central certificate authority the plant can never see, and an Orchestrator that lives where the devices are.

AT EVERY OT SITE

Zone 2 / Zone 3

PLCs & RTUs HMIs & SCADA Switches & Routers Gateways & Firewalls
Trust & Compliance Orchestrator one instance at every site
Outbound HTTPS Only — Initiated by the Site
CENTRAL — ONE FOR THE WHOLE GROUP

Cognisec Trust Engine

Web / Registration AuthorityReceives requests, matches inventory
Intermediate CAIssues the certificates
Root CAOffline, air-gapped, never touched
OCSP ResponderLive revocation status
DEVICE INTAKE

Three Doors In. One Format Out.

Whatever a device can do, there is a door for it — and the Trust Engine only ever sees one request shape.

1

EST

RFC 7030 over HTTPS. Modern switches, routers, and firewalls already speak it — turn it on and they enrol themselves.

2

Web Form

A browser page. An engineer pastes a CSR for a device that can do nothing else — the fallback for the oldest hardware.

3

Direct API

A single HTTPS call — wired into a vendor tool, a build pipeline, or a commissioning script.

INSIDE THE ORCHESTRATOR

State Is the Folder. Nothing Is Ever Lost.

No database. Three folders, and a signed executable that moves requests between them.

incoming

The request has arrived and is waiting to be sent onward.

requested

Sent to the Trust Engine, awaiting the signed certificate.

issued

The certificate has arrived and is ready for the device to collect.

Pull the power out mid-transfer, and nothing is lost — the folder a request sits in is its state.

STORE-AND-FORWARD

The Device and the CA Are
Never Online at the Same Time.

A controller can hold a valid certificate without anything at its level ever reaching the internet.

09:00
A controller submits its request

The Orchestrator writes it to the queue and answers immediately with a ticket.

09:04
The link to head office drops

Nothing fails. Nothing retries in a loop. The request simply waits on disk.

14:20
The link comes back

The Orchestrator notices within a minute and uploads on its own.

14:21
The Trust Engine matches and signs

Metadata is checked against the asset inventory before anything is issued.

14:26
The controller collects it

It asks the same question it asked at nine — and this time the answer is yes.

SEGREGATION

The PKI Is Not on Your OT Network. At All.

The Orchestrator sits at Level 3.5 in the DMZ — or lower, if the site prefers — with zero inbound connections into OT.

LEVEL 4 / 5
Enterprise IT
LEVEL 3.5
DMZ — Trust & Compliance Orchestrator sits here
LEVEL 3
Site Operations
LEVEL 2
Supervisory — HMI, SCADA
LEVEL 1
Control — PLC, RTU, Safety
LEVEL 0
Field — Sensors and Actuators

If the Orchestrator is stolen, cloned, or fully compromised, the attacker gains a queue — not a certificate authority.

CHAIN OF TRUST

Your Own Root — Or a Root the World Already Trusts

The Trust Engine issues under either anchor. Which one you use is a configuration decision, not a product decision.

Run Your Own Root

Total sovereignty. Nothing depends on anyone outside the organisation.

Root CA — self-signed, offline, air-gapped
Intermediate CA — the working issuer
Device certificates — PLCs, HMIs, switches, gateways

Chain to a Public Root

No trust store to push to thousands of devices — they already trust the root.

DigiCert · Thawte · Amazon · Google
Your Intermediate CA, subordinate to it
The same device certificates, now publicly chainable
🔐 GET STARTED

See the Orchestrator on Your Own Network.

A pilot needs one site, one config file, and no changes to your existing PKI.

🔐 Request a Demo See the Full Platform →