Air-gapped, hardware-bound, out-of-band cordon.
Energy, water, transport, telecom, and the IT-side of every OT environment operate inside an audit perimeter that doesn't tolerate downtime. Tessarac's air-gapped install, hardware-bound TPM agent identity, and out-of-band cordon let you run security without giving up operational independence.

Regulatory posture
NIST 800-82 + NERC CIP + TSA SD + sector-specific.
Critical infrastructure maps to NIST SP 800-82 (Industrial Control Systems Security), NERC CIP for the bulk electric system, TSA Security Directives for pipeline and rail, plus sector-specific guidance from CISA, the EPA (water), and the FCC (telecom). Tessarac's per-tenant compliance preset configures the baselines and ships the evidence.
- NIST SP 800-82 — Industrial Control Systems security alignment for the IT-side of OT environments
- NERC CIP-005 / CIP-007 / CIP-010 — electronic security perimeter, system security management, configuration change management evidence
- TSA Security Directives — pipeline and rail cybersecurity baselines
- CISA Cross-Sector Cybersecurity Performance Goals (CPGs) — control mapping documented
- Air-gapped install — Federal-plan offline bundle for sovereign and OT-adjacent deployments
The critical-infrastructure deployment
Air-gapped install, hardware-bound agent identity, out-of-band cordon backstop, and a deployment shape that respects operational availability requirements.

Air-gapped install
Federal plan offline bundle — no outbound network required during install or operation. Updates ship as signed offline bundles you verify before applying. Reference deployment for OT-adjacent IT environments documented end-to-end.

Hardware-bound TPM identity
Sentinel's ECDSA P-384 keypair is generated inside the workstation's TPM — private half never leaves hardware. Defeats the credential-extraction class of attack against ICS-adjacent IT operators.

Out-of-band cordon backstop
If the agent is compromised, the control plane cordons via cloud / network APIs (security group, firewall rule, identity lockout) so isolation works even when the host can no longer be trusted. Critical for OT-adjacent fleets.

Tamper-evident audit
Hash-chained audit log — verify the chain from any starting block to any ending block. Export to your existing historian, SIEM, or to a syslog destination. Customer opt-out of Tessarac retention entirely — operationally-sensitive data never leaves the boundary.
Why this is different from commercial SaaS
Operational availability comes first. Security ships around it.
In commercial SaaS, security can hold a deploy. In critical infrastructure, security has to fit between the deploy windows. Tessarac is built to operate inside availability budgets that don't bend — air-gapped, low-footprint, out-of-band cordon, and a control plane that can be paused without breaking the data plane.
- Sentinel's < 100MB RAM and < 1% CPU steady-state footprint fits inside ICS-adjacent workstation budgets
- Sentinel operates fully on local rules + signatures while disconnected; reconciles when connectivity returns — air-gap-friendly by design
- Out-of-band cordon decouples isolation from the agent's runtime trust
- Reference deployment for energy utility (HQ + substations + DR site)
- Reference deployment for water utility (HQ + treatment plants + telemetry network)
Talk to a Tessarac critical-infrastructure architect
Federal plan deployment for OT-adjacent IT environments. Air-gap-friendly, sovereign-deployable, FIPS 140-3 enforced.