Map the plant
Create assets, zones and conduits — or import the lists you already keep. Criticality, safety impact and exposure are fields, not notes in a margin.
Risk assessment for OT and IACS · IEC 62443 · from Switzerland
Designed, built and operated in Switzerland by RiskZone GmbH
Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.
Document, justify and defend OT/IACS risk decisions on a Swiss-built platform where sensitive project data never leaves your team. Operated from Switzerland as SaaS — your assessment content is encrypted before it ever reaches us.
For operators where one person owns the OT risk assessment — and assembles the evidence from spreadsheets and Word templates today.
How it works
Three steps on one data set. What you enter once carries through to the report.
Create assets, zones and conduits — or import the lists you already keep. Criticality, safety impact and exposure are fields, not notes in a margin.
Threat scenarios per zone and asset class, evaluated under the methodology your project carries. Every rating keeps what it rests on.
A report as PDF, DOCX or HTML, naming the methodology and its version. The underlying data as JSON, CSV or XML — exported in the browser, against your own keys.
Level 5 — Enterprise
ERP, business systems, internet boundary
Level 4 — Site Business
Site IT, scheduling, reporting
Trust Boundary — Industrial DMZ
Patch servers, jump hosts, AV repositories
Level 3 — Site Operations
MES, historians, engineering workstations
Level 2 — Area Supervisory
HMI, SCADA, alarming
Level 1 — Basic Control
PLCs, DCS controllers, RTUs
Level 0 — Process
Sensors, actuators, instrumentation
Reference architecture · zones and conduits
Traceable
A risk rating you cannot explain in an audit is not a rating. So the rule that produced it ships as readable configuration, not as code nobody sees.
Where a methodology brings a derivation, Trausto computes it in the open. In the EN 50701 rail profile, likelihood follows from exposure and vulnerability through a 5×5 matrix that sits cell by cell in the project configuration. You can read it, show it to an assessor — and disagree with it.
Methodologies| Vulnerability ↓ | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 3 | 4 | 4 | 5 | 5 |
| 4 | 3 | 3 | 4 | 4 | 5 |
| 3 | 2 | 3 | 3 | 4 | 4 |
| 2 | 2 | 2 | 3 | 3 | 4 |
| 1 | 1 | 2 | 2 | 3 | 3 |
Exposure →
The shipped matrix, rendered here from its own formula. Exposure 4 × vulnerability 3 yields likelihood 4 of 5.
State today
Not an outlook. This is the state, usable the moment you create a project.
Assets, zones and conduits · SL-T targets per zone · threat scenarios · FR1–FR7 evidence mapping · ISMS register with Statement of Applicability · report as PDF, DOCX and HTML · audit log · export as JSON, CSV and XML.
Deriving SL-T normatively from the assessment is in development — today you set the target yourself. The ISO 27001 Annex A catalogue is in preparation; the register and the Statement of Applicability mechanism already ship.
Why Trausto
Zones, conduits, safety-impact, criticality and consequence-driven risk are first-class objects — not custom columns in a GRC tool. Modelled the way control engineers think and the way IEC 62443 expects, with SL-T targets, evidence and export paths an external auditor will recognise.
Designed, built, operated and supported by a Swiss software company. Engineering, product, security response and customer support all sit under one Swiss legal jurisdiction — one contract, one accountable counterparty, one regulator. No offshore support routing.
Sensitive content — assets, conduits, threat scenarios, supplier evidence — is encrypted on the user device before it leaves your team. Trausto, the hosting providers and third parties only ever hold encrypted data. There is no readable copy to leak, subpoena or mishandle.
Outcomes
What changes in the work, stated so each item can be checked against the product.
IEC 62443 zones, conduits and SL-T evidence are native objects. Exports are structured for assessors and procurement — not stitched together from spreadsheets the night before.
Which requirement a rating rests on, which assumption supports it, who signed it off — in the report, not only in the head of the person who wrote it.
Auditors, suppliers and reviewers see only what you choose to expose. Trausto itself, the hosting layer and lawful third parties cannot read your assessments.
Lost laptops, departing staff, M&A activity, supplier rotation — access revocation is a controlled security event with cryptographic guarantees, not a manual cleanup project.
Insight
Trausto runs as SaaS, operated from Switzerland. That is the whole offer: there is no on-premise edition to evaluate and no deployment matrix to negotiate. The reason is that the question on-premise exists to answer — who can read your assessments — is already answered earlier and more strongly, in the browser, before anything reaches us.
Multi-tenant SaaS, built and operated from Switzerland by a Swiss company on hardened cloud infrastructure. One code path, one set of controls, one thing to audit — for you and for us. Onboarding takes days, not a procurement cycle.
Every project carries its own encryption key, wrapped for each member and each device. Separation is enforced cryptographically, not only by a filter in a query — losing access is a key operation, not a flag in a table.
Ciphertext, plus the operational metadata the service needs in order to run: who holds an account, which project a record belongs to, when it last changed, how much storage you use. We itemise that surface below instead of claiming it away.
Disclosure
Encryption is half a promise until you say what stays unencrypted. This is the other half.
| Readable by us | Why it exists | |
|---|---|---|
| Assessment content | No — ciphertext only | Assets, zones, conduits, scenarios and evidence are encrypted on your device before upload. The one exception is the server-routed AI path below. |
| Uploaded evidence | No — ciphertext only | Supplier documents and attachments follow the same path as assessment content. |
| AI processing | Yes, for the duration of the request | If you use the server-routed AI assistant, the content of that one request passes through our worker in the clear to reach the provider you configured. Running the model in the browser avoids this — that is the honest reason the option exists. |
| AI operational telemetry | Yes — metadata | Which provider was called, whether it failed and how long it took. No request content. |
|---|---|---|
| SIEM export | Yes — audit metadata | If your org configures a SIEM webhook, audit events go to the endpoint you name. Assessment content is not part of that stream. |
| Account identity | Yes | Name and business email. Needed to authenticate you and to address you in support. |
| Project membership | Yes — structure, not content | Which record belongs to which project, and who has access to it. This is what enforces separation. |
| Timestamps | Yes | Created and last-changed times, so concurrent edits and version history work. |
| Audit log | Yes | Who did what, when. Required for the evidence trail the product exists to produce. |
| Usage volume | Yes | Storage consumed and record counts, for billing and capacity. |
Getting started
Three routes, depending on where you stand. Onboarding takes days, not a procurement cycle.
Guided product walkthrough, technical Q&A and access to a sandbox tenant for two named evaluators.
Time-boxed pilot on a representative site or zone, with success criteria agreed up-front and a clean exit if the results do not justify production.
Vendor questionnaires, due-diligence packages and contractual schedules. One operating model and one Swiss counterparty — there is no deployment variant to negotiate, which removes the longest item from most security reviews.
And if you want to leave
Your data is yours, and you can reach it without us. The export runs in the browser against your own keys and produces JSON, CSV or XML — the same data the report is built from. If the last key on your side is lost, the recovery key your organisation receives at setup takes over. Both are part of the product, not a promise in a contract.
Verifiable
Signals you can check yourself, without asking us first.
01
Swiss commercial register · UID CHE-292.851.395
02
TLS 1.3 in transit · client-side encryption at rest
03
Metadata surface itemised, not asserted
04
security.txt published · 5-business-day acknowledgement
05
No certification claimed that we do not hold
Examine the security model Vulnerability disclosure Status page
Compliance
We do not over-claim certifications. Here is where we are today, what we are working toward, and what is already available on request.
Aligned to revFADP / nFADP, GDPR data minimisation, EU CRA, NIS2 and ENISA industrial cybersecurity guidance. IEC 62443 FR1–FR7 control mapping is part of the product.
Three pieces of independent evidence, in this order: an external penetration test of the platform, a cryptography whitepaper reviewed outside the company, and certification against ISO/IEC 27001. We will name dates here once they are booked — not before.
Technical whitepaper, security architecture deck, vendor due-diligence questionnaire and reference contractual schedules for regulated operators.
Trausto is the software in which you build your IEC 62443 risk assessment, keep it current, and put it in front of an auditor.