Cross-reference: Part 1, Comparative summary and Integration compatibility matrix.
The BifrostConnect product stack is organised into three layers: hardware foundation, access methods, and governance and recording.
- Layer 1 – Hardware foundation (two authentication models): Attended Access Unit and Unattended Access Unit. Outbound-only on port 443. Secure-boot fuses. No local users / SSH. Battery + 4G/LTE out-of-band. Manufactured in Denmark. Portable / 249 g.
- Layer 2 – Access methods: Direct Native Access (KVM/Serial/SSH, clientless browser); Direct Tunnel Access (WireGuard IP tunnel, light client); Clientless Tunnel (hardware-to-hardware, air-gapped path).
- Layer 3 – Governance and recording: AccessGuard (station-level control, TOTP, H.264 recording); Manager (identity, policy, JIT, audit, SIEM export); SessionGuard (operator-side screen + keystroke recording).
BifrostConnect offers two authentication models depending on security and access requirements:
- Attended Access: Utilizes One-Time Password (OTP) technology, requiring a physical press on the Bifrost Unit to generate a secure authorization code. This ensures that only on-site personnel can authorize remote sessions, making it ideal for scenarios where access needs to be validated and terminated locally.
- Unattended Access: Enables seamless remote access through BifrostConnect Manager with multi-factor authentication (MFA) and a mobile app for identity verification. This allows authorized personnel to access equipment remotely, even when no on-site staff is available.
Hardware details: 6 GB internal storage; battery for around 1 hour session without charge; portable/light weight, only 249 grams; locked to Bifrost Cloud; WiFi & LTE modem built in.
Direct Tunnel Access with AccessGuard is the canonical Scenario 1 and 2 pairing: AccessGuard on the station, Bifrost Unit outbound-only.
Direct Tunnel Access (DTA): WireGuard IP tunnel via a light installed client, connecting to a Bifrost Unit in the OT environment. Subnet mappings enable scoped access to multiple endpoints for the session duration only. The Bifrost Unit initiates the connection outbound on port 443: OT calls out, OT never accepts inbound.
AccessGuard (AG): Station-level access governance on the on-site Windows engineering station: local MFA (TOTP), scoped application launch, and endpoint-side H.264 session recording (DPAPI-encrypted, stored on the OT network). Bound to localhost (127.0.0.1:7531). No network exposure of the agent.
Direct Tunnel Access with SessionGuard is the canonical Scenario 3 and 4 pairing: SessionGuard records the vendor session to a customer VM.
Direct Tunnel Access (DTA): WireGuard IP tunnel from the vendor’s own laptop or VM to the Bifrost Unit. Scoped, session-only, outbound-initiated by the Unit on port 443.
SessionGuard (SG): Mandatory live-streaming and recording of the technician PC screen and keystrokes during the session, streamed to a customer-owned, customer-controlled log server. Packaged with the DTA client.
| Product | Access type | Role | Primary scenarios |
|---|---|---|---|
| Bifrost Unit | Hardware gateway | Physical access broker. 124 mm × 87 mm × 27 mm, 249 g, battery (~1 hour without charge), 6 GB internal storage, WiFi + LTE built-in, Ethernet, Serial, HDMI, USB-C, SIM card slot. Outbound-only on port 443. Manufactured in Denmark. Industrial embedded Linux; signed, OTA-only firmware; non-reversible secure-boot fuses. | All scenarios |
| Direct Tunnel Access (DTA) | IP tunnel (with client) | WireGuard-based identity-bound IP tunnel. Scoped subnet mappings. Operator PC gets temporary, scoped network connectivity. | 2, 3, 4 |
| Direct Native Access (DNA) | KVM / Serial / SSH (clientless browser) | WebRTC video stream. No network-layer connectivity. Operator PC never joins OT network. Highest isolation. | 1, 3 (commissioning, incident response) |
| Clientless Tunnel Access (CTA) | IP / Serial tunnel (no client software, hardware-to-hardware) | Pure hardware-to-hardware encrypted tunnel. Requires a Bifrost Unit on both the operator and the OT environment side. No software on either side; only active while the session is live. | 2, 4 |
| AccessGuard (AG) | Application-level access control | Station-level access governance on the on-site Windows engineering station. Compatible with Direct Tunnel Access and Clientless Tunnel Access; not applicable to Direct Native Access. Localhost agent. Mandatory TOTP. H.264 session recording. DPAPI encryption. | 1, 2 |
| SessionGuard (SG) | Operator-side recording | WebRTC screen + keystroke recording on the technician PC. Designed to operate with Direct Native Access and Direct Tunnel Access. The recording engine is designed to be packaged with the Direct Tunnel Access client, so the client would be installed on the technician PC even when another access type carries the session. Customer deploys the recording log server. | 3, 4 |
| Bifrost Manager | Governance platform | Identity, groups, policy, JIT, audit log, SIEM integration. SSO available on Dedicated Cloud / on-premises. | All scenarios |
| Direct File Transfer | File transfer (online) | Identity-bound file transfer over the Bifrost Unit’s outbound channel. Audited. | All scenarios |
| Offline File Transfer | File transfer (air-gapped) | Air-gapped media transfer pattern. Used in Scenario 3/4 where the OT zone has no IP path. | Air-gapped operations |
Each Bifrost Unit is produced as either Attended or Unattended, embedded in firmware for the product lifespan.
- Attended Units display an 8-digit TOTP on-screen that the operator must enter, and include a physical disconnect button for on-site authorization.
- Unattended Units allow admin-initiated sessions without on-site presence, through the Bifrost Manager. The two are not interchangeable at runtime.