> For the complete documentation index, see [llms.txt](https://captic-2.gitbook.io/docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://captic-2.gitbook.io/docs/your-captic-system/tier-5-no-internet-access.md).

# Tier 5: No internet access

No internet access for the device. All cloud traffic runs privately through your Azure network.

For sites where devices on the OT network may never reach the internet, not even through a proxy. The device has **no internet access at all**. Instead, it reaches the Captic cloud over a private connection through your own Azure network.

## How it works

The Captic device sits on your OT network. Your network routes its cloud traffic to **Azure Private Endpoints** in your own Azure virtual network. Those endpoints connect privately, Azure to Azure, to the Captic cloud services the device needs:

* **IoT Hub:** device management and messaging
* **Blob Storage:** images and results
* **Container Registry:** software and AI model updates

The traffic stays on your network and the Microsoft backbone, and never crosses the public internet.

## What you set up

1. **Private Endpoints** in your Azure virtual network for the Captic IoT Hub, Blob Storage and Container Registry. We send you the resource IDs.
2. **Private DNS zones**, so these services resolve to their private addresses, including for the device on the plant floor.
3. **Network connectivity** from the device's OT network to your Azure virtual network.
4. **DNS and NTP** available locally on the device's network.
5. **Remote access** for the Captic team through your own solution, as in [Tier 4](/docs/your-captic-system/tier-4-without-teleport.md).

## What we set up

* We **mirror** all container images the device needs into the Captic Container Registry, so the device never has to reach public registries.
* We **approve** the cross-tenant Private Endpoint connection requests on our side.
* We configure the device to use the private endpoints.

{% hint style="info" %}
This tier needs your own Azure environment connected to your plant network, and it involves your network and cloud architects. Start the conversation early, well before commissioning. Contact <security@captic.com> to plan it.
{% endhint %}
