> For the complete documentation index, see [llms.txt](https://captic-2.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://captic-2.gitbook.io/docs/overview/good-to-know/security/it-ot-separation.md).

# IT/OT Separation

How Captic keeps your IT and OT networks apart.

We know how important it is to keep **IT and OT networks** separate. The Captic architecture is based on:

* Strict network segmentation
* The Purdue Model
* The **IEC 62443** and **NIST 800-82** standards

The OT network is extended into a cloud-based DMZ, sealed off with network rules and role-based access policies. This lets us update devices, collect data and retrain AI models without compromising the separation between IT and OT.

<figure><img src="https://lh7-qw.googleusercontent.com/docsz/AD_4nXcDPtYEXD_Xhdr0olVZftWJxEn2zCUQjwVmxJHuRazxs4ET_Dgmn1-HVe3vFs3H5iAWInYWY2hU71-_xGwG0_jNi4-SCB4YE0KrCYcFQP9e64XxpK_C5fq1XAerGD0GNUG-7S17mMRhiELBjYI7PTRY8bU?key=eLenGbgk8QhJ-tztHYRTKw" alt="IT/OT architecture"><figcaption></figcaption></figure>

For the strictest separation, where OT devices may never reach the internet, see [Network Security, tier 5](/docs/overview/good-to-know/security/security.md#tier-5-no-internet-access).
