Company
Support
Login
BifrostConnect BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel

    Create a Zero Trust network without VPN Tunneling

    Clientless Serial Tunnel

    Establish a Serial (RS232) connection without borders

    Offline File Transfer

    Transfer files without exposing endpoints to the internet

  • Who We Help
    Case Studies
    Damgaard Automatik Case Study
    SGS Case Study
    Luságua Case Study
    Operational Technology
    Engineering & Commissioning
    Cybersecurity & Compliance
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • OT Cybersecurity
    Best-practice Guide for Secure 3rd party remote access in OT
    NIS2 Remote Access WHITE PAPER
    Blog
Contact Us
BifrostConnect
  • How it Works
    Zero Trust by design
    How it Works
    Direct Native Access (DNA)
    Direct Tunnel Access (DTA)
    Clientless Tunnel Access (CTA)
    Clientless IP Tunnel
    Clientless Serial Tunnel
    Offline File Transfer
  • Who We Help
    Cybersecurity & Compliance
    Engineering & Commissioning
    Operations
    Industries
    Energy & Utilities
    Water Management
    Vandværker
    Industrial Automation & Manufacturing
    Pharma, Life Science & Healthcare
    Testing, Inspection & Certification
    Logistics, Transportation & Maritime
    Banking & Financial Services
  • Resources
    Company
    Zero Trust by design
    Release Notes
    Knowledge Center
    Tours & Tutorials
    FAQ
  • Pricing
  • Support
  • OT Cybersecurity
    OT Cybersecurity Landscape: Denmark 2027
    NIS2 Remote Access WHITE PAPER
    Blog
Book a Demo
Contact Us

Getting Started

12
  • Admin
    • Set up your organization
    • User roles and permissions
  • Onsite User Guides
    • Onsite Step Guide
    • Connect KVM
    • Connect IP Tunnel
    • Connect Offline File Transfer
    • Connect USB Tunnel
    • Connect Serial Tunnel
    • Connect SSH
    • Connect Serial Terminal (Console Access)
  • Datasheets
    • Technical Specifications
    • Requirements

Technical Support

2
  • Feedback & Feature requests
    • Share your ideas and feedback
  • Report a bug
    • Reporting Bugs 

Release Notes

21
  • 2026
    • Remote Access Interface Release 25 June 2026
    • Direct Tunnel Release 1 June 2026
    • Bifrost Release 13 January 2026
  • 2025
    • Bifrost Release 30 Oktober 2025
    • Bifrost Release 19 August 2025
    • Bifrost Release 30 June 2025
    • Bifrost Release 11 February 2025
  • 2024
    • Bifrost Release 04 December 2024
    • Bifrost Release 16 November 2024
    • Bifrost Release 2 Oktober 2024
    • Bifrost Release 14 August 2024
    • Bifrost Release 7 May 2024
    • BifrostConnect Firmware V4.8.0
  • 2023
    • BifrostConnect Firmware V4.7.0
    • BifrostConnect Firmware V4.6.0
    • BifrostConnect Firmware V4.5.0
    • BifrostConnect Firmware V4.4.0
  • 2022
    • BifrostConnect Firmware V.4.3.2
    • BifrostConnect Firmware V.4.3.1
    • BifrostConnect Firmware V.4.2.0
  • 2021
    • BifrostConnect Firmware V.4.0.0

Best Practice Guide

14
  • About this guide
  • Core Framework
  • Architecture & Principles
  • Threat Context
  • Zero Standing Privilege
  • Four OT Access Patterns
  • Degraded Mode & Legacy Equipment
  • Defence in Depth
  • Compliance & Implementation
  • Residual Risks
  • Definitions
  • References
  • Operational Lifecycle 
  • Procurement Appendix

Implementing the OT Best Practice Framework with BifrostConnect

13
  • Overview and Framework Mapping
  • Threat Model
  • Scenario Implementation – Scenario 1
  • Scenario Implementation – Scenario 2
  • Scenario Implementation – Scenario 3
  • Scenario Implementation – Scenario 4
  • Product Reference
  • Architecture & Differentiation
  • Hardening & Deployment Guidance
  • Security Architecture Reference
  • Legacy OT & Air-Gapped Environments
  • Incident Response & Degraded Mode
  • Sources & References
  • Home
  • Knowledge Center
  • Implementing the OT Best Practice Framework with BifrostConnect
  • Product Reference
View Categories

Product Reference

PRODUCT REFERENCE
What products make up the BifrostConnect stack, and what does each layer do?

Cross-reference: Part 1, Comparative summary and Integration compatibility matrix.

The BifrostConnect product stack is organised into three layers: hardware foundation, access methods, and governance and recording.

  • Layer 1 – Hardware foundation (two authentication models): Attended Access Unit and Unattended Access Unit. Outbound-only on port 443. Secure-boot fuses. No local users / SSH. Battery + 4G/LTE out-of-band. Manufactured in Denmark. Portable / 249 g.
  • Layer 2 – Access methods: Direct Native Access (KVM/Serial/SSH, clientless browser); Direct Tunnel Access (WireGuard IP tunnel, light client); Clientless Tunnel (hardware-to-hardware, air-gapped path).
  • Layer 3 – Governance and recording: AccessGuard (station-level control, TOTP, H.264 recording); Manager (identity, policy, JIT, audit, SIEM export); SessionGuard (operator-side screen + keystroke recording).

BifrostConnect offers two authentication models depending on security and access requirements:

  1. Attended Access: Utilizes One-Time Password (OTP) technology, requiring a physical press on the Bifrost Unit to generate a secure authorization code. This ensures that only on-site personnel can authorize remote sessions, making it ideal for scenarios where access needs to be validated and terminated locally.
  2. Unattended Access: Enables seamless remote access through BifrostConnect Manager with multi-factor authentication (MFA) and a mobile app for identity verification. This allows authorized personnel to access equipment remotely, even when no on-site staff is available.

Hardware details: 6 GB internal storage; battery for around 1 hour session without charge; portable/light weight, only 249 grams; locked to Bifrost Cloud; WiFi & LTE modem built in.

CANONICAL PAIRINGS
What is the canonical BifrostConnect pairing for Scenarios 1 and 2 (software on the engineering station)?

Direct Tunnel Access with AccessGuard is the canonical Scenario 1 and 2 pairing: AccessGuard on the station, Bifrost Unit outbound-only.

Direct Tunnel Access (DTA): WireGuard IP tunnel via a light installed client, connecting to a Bifrost Unit in the OT environment. Subnet mappings enable scoped access to multiple endpoints for the session duration only. The Bifrost Unit initiates the connection outbound on port 443: OT calls out, OT never accepts inbound.

AccessGuard (AG): Station-level access governance on the on-site Windows engineering station: local MFA (TOTP), scoped application launch, and endpoint-side H.264 session recording (DPAPI-encrypted, stored on the OT network). Bound to localhost (127.0.0.1:7531). No network exposure of the agent.

CANONICAL PAIRINGS
What is the canonical BifrostConnect pairing for Scenarios 3 and 4 (software on the vendor’s PC)?

Direct Tunnel Access with SessionGuard is the canonical Scenario 3 and 4 pairing: SessionGuard records the vendor session to a customer VM.

Direct Tunnel Access (DTA): WireGuard IP tunnel from the vendor’s own laptop or VM to the Bifrost Unit. Scoped, session-only, outbound-initiated by the Unit on port 443.

SessionGuard (SG): Mandatory live-streaming and recording of the technician PC screen and keystrokes during the session, streamed to a customer-owned, customer-controlled log server. Packaged with the DTA client.

COMPATIBILITY MATRIX
Which BifrostConnect products are compatible with which access types and scenarios?
ProductAccess typeRolePrimary scenarios
Bifrost UnitHardware gatewayPhysical access broker. 124 mm × 87 mm × 27 mm, 249 g, battery (~1 hour without charge), 6 GB internal storage, WiFi + LTE built-in, Ethernet, Serial, HDMI, USB-C, SIM card slot. Outbound-only on port 443. Manufactured in Denmark. Industrial embedded Linux; signed, OTA-only firmware; non-reversible secure-boot fuses.All scenarios
Direct Tunnel Access (DTA)IP tunnel (with client)WireGuard-based identity-bound IP tunnel. Scoped subnet mappings. Operator PC gets temporary, scoped network connectivity.2, 3, 4
Direct Native Access (DNA)KVM / Serial / SSH (clientless browser)WebRTC video stream. No network-layer connectivity. Operator PC never joins OT network. Highest isolation.1, 3 (commissioning, incident response)
Clientless Tunnel Access (CTA)IP / Serial tunnel (no client software, hardware-to-hardware)Pure hardware-to-hardware encrypted tunnel. Requires a Bifrost Unit on both the operator and the OT environment side. No software on either side; only active while the session is live.2, 4
AccessGuard (AG)Application-level access controlStation-level access governance on the on-site Windows engineering station. Compatible with Direct Tunnel Access and Clientless Tunnel Access; not applicable to Direct Native Access. Localhost agent. Mandatory TOTP. H.264 session recording. DPAPI encryption.1, 2
SessionGuard (SG)Operator-side recordingWebRTC screen + keystroke recording on the technician PC. Designed to operate with Direct Native Access and Direct Tunnel Access. The recording engine is designed to be packaged with the Direct Tunnel Access client, so the client would be installed on the technician PC even when another access type carries the session. Customer deploys the recording log server.3, 4
Bifrost ManagerGovernance platformIdentity, groups, policy, JIT, audit log, SIEM integration. SSO available on Dedicated Cloud / on-premises.All scenarios
Direct File TransferFile transfer (online)Identity-bound file transfer over the Bifrost Unit’s outbound channel. Audited.All scenarios
Offline File TransferFile transfer (air-gapped)Air-gapped media transfer pattern. Used in Scenario 3/4 where the OT zone has no IP path.Air-gapped operations
HARDWARE SPECIFICATIONS
What is the difference between Attended and Unattended Bifrost Units?

Each Bifrost Unit is produced as either Attended or Unattended, embedded in firmware for the product lifespan.

  • Attended Units display an 8-digit TOTP on-screen that the operator must enter, and include a physical disconnect button for on-site authorization.
  • Unattended Units allow admin-initiated sessions without on-site presence, through the Bifrost Manager. The two are not interchangeable at runtime.
Updated on July 24, 2026
Scenario Implementation – Scenario 4Architecture & Differentiation
Essentials Logo
Islands Brygge 55
2300 Copenhagen S, Denmark
+45 70 60 20 56
[email protected]
About Us
Release Notes
Privacy Policy
Terms & Conditions
FAQ
Book a Demo
Book a Demo

Subscribe to Our Newsletter

Copyright BifrostConnect ApS. 2026
All Rights Reserved