The OT Data Edge (OTDE) connects your factory floor to your business — securely, with no compromises.
- ⚡ Unified Namespace (UNS) — all machine and process data is published to a single, structured data space. Any system that needs it can subscribe. No point-to-point integrations, no data silos.
- 🔒 Zero inbound firewall ports — OTDE only pushes data outward. Your OT network never accepts incoming connections from IT or the internet, eliminating the most common attack surface in industrial environments.
- 🔄 Legacy protocol termination — old industrial protocols (Modbus, S7, BACnet, OPC-DA…) are translated and isolated at the edge. They never cross the IT/OT boundary, and all onward transport is encrypted and monitorable.
- 🏗️ Purdue model compliance — the architecture follows the industry-standard Purdue Reference Model, keeping field devices, control systems, and IT networks in clearly separated security zones with controlled data flow between them.
- 🧩 Connect once, consume everywhere — once a machine or system is connected to the UNS, any authorised application (analytics, dashboards, alerting, R&D tools) can access its data immediately. Adding a new consumer takes minutes, not months.
- 🔐 Access control built in — data access is governed by role-based access control (RBAC) at the broker level. Every consumer sees only what it is authorised to see, with a full audit trail.
OT Data Edge (OTDE) — Architecture Overview
Purdue Network Security Model · Unified Namespace (UNS) · Zero Inbound Firewall Ports
⬆ Subscribe (outbound only) · User Access Control · MQTT / AMQP over TLS
⬆ Publish outbound only from OTDE · No open inbound ports in domain firewall
🔒 Zero Inbound Exposure
⬆ OT protocols collected & terminated at OTDE — Modbus, OPC-UA, S7, Profinet, BACnet…
⬆ Field signals, sensor data, PLC outputs
Key Principles
OTDE terminates all legacy OT protocols and re-publishes structured, named data via secure outbound transport only
Zero inbound open ports — domain firewalls never expose OT network to IT or cloud
UNS Broker in DMZ provides a single structured data source with RBAC for all consumers
Any new analytics, monitoring or alerting application can subscribe to live data in minutes
Zero inbound open ports — domain firewalls never expose OT network to IT or cloud
UNS Broker in DMZ provides a single structured data source with RBAC for all consumers
Any new analytics, monitoring or alerting application can subscribe to live data in minutes