Skip to content
Trausto

Company

Company

RiskZone GmbH is a Swiss software company. We build, ship and operate a single product — Trausto — and we do it with an engineering team that has spent years inside industrial cybersecurity programmes. The platform turns that operational reality into workflows that enterprise teams can run, audit and defend.

The company

A Swiss software company, one product

CO1

Who builds Trausto

A focused Swiss engineering team led by founder and managing director Mathias Pfister, headquartered in Rothenburg LU. Practitioner backgrounds in OT / IACS security, secure software engineering, applied cryptography and regulated-industry programmes.

CO2

Where we sit

Headquartered, engineered, operated and supported from Switzerland. Customer engagements across Europe; the service itself runs in Swiss and EU regions.

CO3

One product, no side bets

Trausto is the company's single product. No consulting arm, no side business. Engineering, operations and customer success all report into the same Swiss leadership.

Risk logic

How Trausto reasons about risk

Industrial risk decisions need a visible chain of reasoning: from operational reality to business impact, evidence and accountable human judgement.

Trausto starts with how the plant actually works: zones, conduits, trust boundaries, dependencies, roles and operational constraints. The model is not a detached scorecard; it is a structured explanation of why a scenario matters in a specific environment.

For enterprise teams, this makes decisions easier to challenge and defend. A risk is tied to the dependency that creates impact, the evidence that supports the assessment and the controls that can realistically reduce exposure.

  1. 01

    Map operational reality

    Assets are interpreted in context: which process they support, which zone they belong to and which trust boundary a conduit crosses.

  2. 02

    Evaluate mission impact

    Risk is weighed against continuity, safety and regulated obligations, not only against isolated asset loss or technical severity.

  3. 03

    Keep judgement reviewable

    AI-assisted suggestions remain advisory. Engineers keep authority, decisions stay attributable and relevant reasoning can be reviewed or exported.

Doctrine

Engineering Principles

These principles are product controls, not slogans. They shape how Trausto handles data, releases features and earns trust with regulated customers.

  1. P01

    Treat shared infrastructure as untrusted by default.

  2. P02

    Prefer cryptographic guarantees over policy promises.

  3. P03

    Design every feature to reduce operational burden or audit risk.

  4. P04

    Make critical decisions reviewable, attributable and exportable.

Compliance

Compliance posture & roadmap

We do not over-claim certifications. Here is where we are today, what we are working toward, and what is already available on request.

NOW

Today

Aligned to revFADP / nFADP, GDPR data minimisation, EU CRA, NIS2 and ENISA industrial cybersecurity guidance. IEC 62443 FR1–FR7 control mapping is part of the product.

NEXT

On the roadmap

Three pieces of independent evidence, in this order: an external penetration test of the platform, a cryptography whitepaper reviewed outside the company, and certification against ISO/IEC 27001. We will name dates here once they are booked — not before.

ASK

Available on request

Technical whitepaper, security architecture deck, vendor due-diligence questionnaire and reference contractual schedules for regulated operators.

See Trausto against your own zones

Bring one real site — your zones, conduits and SL-T targets. In a single technical session we show how Trausto turns it into audit-ready IEC 62443 evidence, with your assessment content encrypted before it ever leaves the browser.