Most cement AI pilots don't die on accuracy. They die in the security review, four weeks after the process team has already seen the model work. The vendor needs an outbound tunnel from the control network, the kiln tag history has to land in someone else's cloud region, and the OT security lead — who is accountable for a plant that cannot be safely stopped in a hurry — says no. That answer is correct. The fix is not a better exception request; it's an architecture where raw plant data never leaves the site at all.
iFactory / On-prem AI data center for cement
Run the Kiln and Mill Models Inside Your Own Network — Nothing Egresses
iFactory deploys as a GPU appliance in your Level 3 site operations zone. It reads the historian, runs the process and vision models locally, writes work orders into your on-site CMMS, and opens no outbound conduit from the control network. Zones, conduits and data-flow documentation come with it.
L4/5Enterprise IT / internet
no inbound path to AI · no raw data out
L3.5Industrial DMZ
L3iFactory GPU appliance + historian
L2DCS / CCR operator stations
L0/1Kiln, mills, analysers, drives
Zero egress
of raw plant data
IEC 62443
zone & conduit model
The Problem Isn't the Model. It's the Conduit.
A cement plant's process data is not generic telemetry. Kiln feed chemistry, alternative fuel substitution rates, specific heat consumption, clinker quality curves and mill power draw together describe how a plant makes money — and in a market where a handful of producers compete on cost per tonne, that is commercially sensitive information. It is also operationally sensitive: the same tag set that trains a free-lime model reveals exactly how close the kiln runs to its constraints.
Layered on that is the control-network reality. The Purdue segmentation most plants run means Level 2 and Level 3 have no outbound internet path by design, and the security team is not going to open one for a vendor's inference API. IEC 62443 pushes in the same direction: define zones, define the conduits between them, and justify every one. A cloud-first AI product asks the plant to create a new conduit from the most protected part of the site to the public internet, and to keep it open permanently. Most plants say no, and the pilot ends there.
Where Cloud-First AI Breaks in a Cement Plant
Four separate blockers, and they fail independently — solving connectivity doesn't solve residency, and solving residency doesn't solve latency.
Connectivity
Integrated plants sit next to the limestone, not next to fibre. Where the uplink is a shared VSAT or a single microwave hop, streaming even 2,000 tags at one-second resolution is not viable — and a model that stops predicting when the link drops is a model the control room stops trusting after the second outage.
Data residency
Group policy, national data-localisation rules, and customer contracts frequently forbid operational data leaving the country or the corporate boundary. "Which region is the inference endpoint in" becomes a legal question that takes longer to answer than the pilot was scheduled to run.
Latency & determinism
A free-lime or coating-formation prediction that advises the kiln operator is only useful inside the process time constant. A round trip through a WAN, a queue and a shared inference cluster adds variance you cannot bound — acceptable for a weekly report, not for anything that sits next to a control decision.
OT security policy
Under a zones-and-conduits model, every flow needs a documented purpose, direction, protocol and risk assessment. A permanent outbound TLS tunnel carrying unspecified payloads from Level 3 is the single hardest thing to get approved — and correctly so, because it is also the path an attacker would want.
What Actually Runs on the Appliance
The on-prem deployment is not a thin client calling home. The full inference stack, the feature store and the agent layer live on the plant's own hardware, sized to the plant's tag count and camera count.
Process Models
Free lime, kiln thermal state, coating and ring formation, specific heat consumption, mill throughput and separator efficiency — trained on your own history, running against live historian reads.
Runs: local GPU inference
Vision Agents
Clinker cooler and burning-zone camera feeds, belt and transfer-point monitoring, bag-house and stack observation, PPE and restricted-area checks — video never leaves the site network.
Runs: video stays on site
Feature Store
Time-aligned process, lab and event data held on plant storage with your retention policy — the training set stays an asset you own rather than a copy in a vendor account.
Runs: your disks, your retention
Agent Layer
The natural-language layer the CCR and reliability team query — "why did line 2 heat consumption climb last shift" — served by an on-appliance model, so operator questions and plant answers stay internal.
Runs: no external API call
What Crosses the Boundary, and What Never Does
The useful question in a security review is not "is it on-prem" but "name every flow." This is the full list.
Raw process data
Never leaves
Tag history, lab results, video frames, event logs and derived features remain on plant storage for their whole lifecycle, including model training and retraining.
Model artefacts
Inbound, staged
New model versions arrive as signed packages through your existing change process — file transfer via the DMZ, or physical media on an air-gapped site. One direction only.
Licence & health
Optional, outbound-initiated
Appliance health and licence status can be sent out on a scheduled, plant-initiated push of a defined schema — or disabled entirely, with status read locally instead.
Work orders
Internal to CMMS/ERP
Predictions become notifications and work orders inside your own SAP PM, Maximo or Oracle EAM instance — the write path stays within the corporate boundary.
Ask your OT security lead what would happen to a request to open a permanent outbound conduit from Level 3 for a vendor's inference API. If the answer is a six-month exception process, the deployment model is the blocker — not the AI. Book an OT architecture review and we'll walk your existing segmentation diagram with you.
12-Week Deployment Shape on One Line
One kiln line, one appliance, twelve weeks. The deployment is sequenced so the security work finishes before the first model goes live, not after — the reverse order is how pilots stall.
Weeks 1–2
Architecture & Zone Design
Workshop with OT security, plant IT and automation. Output is a zone-and-conduit drawing, a flow register naming every protocol and direction, and a hardening and patching plan that works without internet access.
Weeks 3–4
Install & Read-Only Connect
Appliance racked in the Level 3 cabinet, connected to the historian over a read-only account. No writes, no control interaction. Tag coverage and data quality verified against what the CCR believes is true.
Weeks 5–8
Models Live in Shadow
Process and vision models running on plant hardware, advising only. Predictions compared against lab results and operator judgement daily. Appliance load, GPU thermals and failover behaviour measured under real plant conditions.
Weeks 9–12
Write-Back & Sign-Off
CMMS write path enabled inside the boundary. Penetration and configuration review completed against the agreed zone model, documentation handed to the security team, and plant staff trained on updates and restore.
Who Signs Off
An on-prem deployment has four separate approvers, and each one needs a number they can defend rather than a reassurance.
OT Security
Outbound conduits opened from Level 3
Owns the segmentation. The target is zero new permanent outbound flows, with every remaining flow in the register carrying a direction, a protocol, a purpose and an owner.
Plant IT
Patch currency without internet access
Owns the appliance lifecycle. Updates arrive through the existing change window as staged packages, so the box stays current without becoming the one server with a special exception.
Process & Production
Prediction availability and response time
Owns whether the CCR uses it. Local inference means availability tracks the appliance and the historian — not a WAN link — and response time stays inside the kiln's own time constant.
Group CISO / Legal
Operational data held outside the boundary
Owns residency and contractual exposure. The answer is a documented nil return covering process history, video and lab data, which is a far simpler thing to attest to than a regional cloud argument.
FAQ
If nothing leaves the plant, how do the models improve?
Retraining happens on the appliance, against your own accumulated history — which is the data that matters most, because a kiln's behaviour is specific to its fuel mix, raw mix and geometry. What we ship inward are architecture and algorithm improvements as signed model packages, delivered through your change process. You get the benefit of engineering work done across our install base without any plant's data being pooled. On an air-gapped site the same packages arrive on reviewed physical media, which is how every other piece of OT software on your network is already updated.
What hardware is this, and who keeps it running at three in the morning?
A single rack-mounted GPU server covers a typical single-line plant, sized on tag count, camera count and retention rather than on plant capacity; multi-line and integrated sites usually take a two-node configuration for redundancy. It runs as standard plant infrastructure — your IT team's monitoring, your backup regime, your spares contract. If the appliance goes down, the DCS, the historian and the control loops are untouched, because nothing in the control path depends on it. You lose predictions until it's back, not production.
Can you give us documentation our auditor will accept against IEC 62443?
Yes, and it's part of the first two weeks rather than an afterthought. You get the zone and conduit assignment for the deployment, a data-flow register listing every interface with protocol, direction, port and purpose, the account and privilege model for historian and CMMS access, and the hardening baseline applied to the appliance. Where your site is working to a defined security level target, we map the deployment against the relevant system requirements and flag honestly which compensating controls sit on your side of the line rather than ours. What we won't do is claim a certification stands in for your own site assessment — your auditor will ask for the site-specific risk assessment regardless, and this documentation is built to feed it.
Stop losing pilots at the security review.
Bring Your Segmentation Diagram. We'll Show You Where the Box Goes.
One session with your OT security lead, plant IT and automation engineer. We map the deployment onto your existing zones, name every flow, and tell you plainly what would need to change on your network — before anyone talks about models.