Zero-Trust SCADA Alarm Monitoring
Setting up tools like VTScada and Ignitiion, with SMS / Callout / IVR alarm monitoring systems such as Twilio, forces a dangerous trade off for your network.
SCADA servers live on internal networks, secured with a firewall protecting the perimeter.
You believe that it is secure. However, the Twilio integration required bi-lateral network traffic over a public IP for TCP/IP and webhooks.
- Inbound Port Exposure: Open VPN and TCP/IP ports invite automated port-scanners directly into your OT environment.
- Public IP Dependency: Bi-directional webhooks turn air-gapped SCADA nodes into internet-facing endpoints.
- Punching Holes in Firewall: A hardened perimeter firewall is useless when third-party SaaS integrations pave dedicated inbound pathways through it.
Secure your SCADA servers, while maintaining alarm monitoring, without the need of a VPN
Secure, Simple Remote Access for Industrial Sites
(Even on Starlink or Cellular)
The Challenge: Why Connecting to Remote Sites is a Headache
Keeping remote industrial sites running smoothly for tools like VTScada and Ignition requires constant monitoring and occasional outside help. But connecting to these locations securely shouldn’t require an expensive IT overhaul.
If you are trying to manage remote water, energy, or municipal infrastructure, you are likely running into a wall where traditional networking just doesn’t work anymore.
Starlink/Cellular Trap:
Because remote sites are isolated, you likely use Starlink or cellular data. What most people don’t realize is that these services are designed for outbound traffic (like browsing the web). They use a technology (CGNAT) that blocks standard inbound connections.
You cannot use traditional “port-forwarding” to dial into a Starlink connection. The internet provider blocks it. and or something like that.
- Tricky Connections: Your sites are remote. You rely on cellular data or satellite connections like Starlink. Because of how these providers handle internet traffic (a hurdle called CGNAT), it is notoriously difficult to connect into these sites from the outside.
- Internal Constraints: Company A’s IT has a different opinion than company B. Neither has a firewall that will do what you want.
- Budget Constraints: Small, isolated sites simply can’t justify the cost (of running or buying) of complex, heavy-duty enterprise firewalls.
- VPN Hell: You need your internal staff AND outside contractors (third parties) to access the equipment for support, from their device, without software complexities. Setting up, managing, and turning off VPNs for a rotating cast of third-party workers across multiple isolated sites is needlessly complex and increases your risk.
- Dangerous Workarounds: To make things work, e.g. allowing staff to view monitoring software (like VTScada) from a tablet people often resort to “port forwarding.” This is the digital equivalent of leaving a backdoor wide open to the internet. It is highly unsafe.
- Automated Alerting: You want your monitoring software to send automated SMS or voice alerts through a service like Twilio. But for Twilio to work, it has to be able to “talk” to your remote site (both inbound and outbound). Letting an external service punch through your firewall safely over a Starlink/cellular connection is nearly impossible with traditional tools, and impossible in the inbound direction.
Who We Built This For
One network or dozens, if you use tools like VTScada, Twilio, Ignition, this product is designed for you:
- Site Operator: “I run these sites and manage my team. I need things to just work, and I need a safe way to invite third-party contractors in to fix things without handing over the keys to the kingdom.”
- Managed Operations “I provide ongoing support and monitoring to multiple different customers. I need a single, scalable way to manage access across all their isolated networks without juggling a dozen different VPN clients.”
MTTR Killer:
Because you can’t easily get secure, inbound remote access, a simple software reset or diagnostic check requires a physical drive to the site. This turns a 5-minute remote fix into a 4-hour ordeal, destroying your MTTR.
The Solution: Agilicus AnyX
Agilicus AnyX is the only product that safely bridges the gap between modern cloud services (like Twilio), standard internet connections (like Starlink), and your remote industrial equipment: all without requiring complex hardware.
Twilio Misconception:
To keep uptime high, you rely on monitoring software (like VTScada) to trigger automated SMS or voice alerts via Twilio when something breaks. But Twilio doesn’t just push messages out; it requires an inbound connection to your VTScada server to function. If you are on Starlink or cellular, that inbound connection is blocked. Your alerts simply won’t fire.
- Unified, Simple Login (No Shared Passwords) You don’t need to create new accounts for every contractor. With Agilicus, internal staff and external third parties log in using the credentials they already have (like their existing Google or Microsoft accounts). When a contractor’s job is done, their access is easily revoked.
- Seamless, “Invisible” Access There is no clunky software to install on your team’s devices, and no VPNs to turn on and off. Staff can safely monitor the site from a tablet’s web browser, and automated systems like Twilio can communicate flawlessly, even over Starlink or cellular connections. It just works.
Agilicus AnyX replaces risky VPNs with a Zero Trust, identity-aware proxy that operates on an outbound-only connection.
Clientless Remote Operations: Allow operators to securely monitor and control VTScada in real-time from any web browser, on any device, backed by single sign-on (SSO) and multi-factor authentication (MFA).
Invisible to Scanners: Keep VTScada invisible to public port scans and threat actors while maintaining two-way alarm monitoring / messaging with Twilio.
Learn more
You don’t need a bigger, more expensive firewall. You need a smarter way to connect. Agilicus AnyX lets your team and your automated tools talk to your remote sites securely, easily, and exactly when they need to.