Refineries piloting AI for process optimization or predictive maintenance keep hitting the same wall: the control network that keeps a distillation unit safe was never built to talk to a model, and the IT network hosting that model was never built to touch a live DCS. Bridging the two badly is how a promising pilot becomes an incident report. The real fix is not a faster firewall rule, it is a reference architecture that defines exactly where AI sits inside the Purdue Model, what enforces the one-way boundary at Level 3.5, and which IEC 62443 zone the inference engine is actually permitted to live in. See how iFactory is architected around that boundary at ifactory support.
Give AI a Seat Inside the Refinery Network Without Opening a Door Into It
A Purdue Model Level 3.5 reference architecture that lets AI read live process data through network segmentation, data diodes, and IEC 62443 zoning, so an inference engine never has a write path back into the control system.
"Just Connect It to the Historian" Does Not Survive a Process Safety Review
Most refinery AI initiatives start the same way. A vendor asks for a route into the DCS historian, someone on the IT side opens a firewall rule, and within a week a model is pulling live tag data for a pilot. It works, right up until a process safety or cybersecurity review asks a simple question: what stops that same path from being used in the other direction. A firewall rule is a policy, not a physical boundary, and policies get changed, disabled during troubleshooting, or quietly widened six months later when someone needs "just one more" data point. None of that shows up as a problem until an audit, an incident, or an insurance renewal forces the question.
The deeper issue is that IT and OT networks were designed around opposite priorities. IT networks are built around confidentiality and are patched constantly. OT networks are built around availability and safety, and a control system that has run without a reboot for years is often treated as a feature, not a risk. An AI platform that needs continuous, high-frequency access to process data sits exactly on top of that fault line, and treating the connection as a routine IT integration project is where most convergence architectures go wrong before a single model is even trained.
The Purdue Model, Level by Level, and Where AI Is Allowed to Sit
The Purdue Enterprise Reference Architecture is the backbone most refineries already design their control networks around, whether or not anyone calls it by that name. It groups every system into a level based on what it does and how directly it touches the physical process, and each level carries a different tolerance for outside connectivity. An AI platform that respects these boundaries can still see everything it needs; it just never gets to sit where a single compromised model could reach a valve.
Data Diode, Firewall, or Proxy: They Are Not Interchangeable
Nearly every OT-IT convergence conversation eventually circles back to which device actually enforces the boundary. The three options get discussed as if they solve the same problem, and they genuinely do not. A firewall filters traffic based on rules that can be reconfigured by anyone with the right credentials. A proxy or broker terminates the connection and re-originates it, which adds inspection but still runs in software. A data diode removes the return path physically, so there is no rule to misconfigure and no credential that can reopen it.
| Mechanism | Enforcement Type | Can Direction Be Reversed? | Typical Refinery Use |
|---|---|---|---|
| Firewall Rule | Software policy | Yes, by any admin with access | Perimeter filtering between IT zones, not control-to-IT |
| Proxy / Broker | Software, connection re-origination | Only if reconfigured at the application layer | Level 3.5 data brokering with inspection and logging |
| Data Diode | Hardware, one-way physical link | No, no return-path circuitry exists | Control zone to DMZ boundary for AI-fed data streams |
IEC 62443 Zones, Conduits, and Security Levels
IEC 62443 replaces the vague instruction to "segment the network" with a defined model: every asset sits inside a zone grouped by function and risk, and every connection between zones is a conduit that carries its own required security level, from SL0 for no protection needed up to SL4 for resistance to a well-resourced, motivated attacker. A refinery control zone housing safety instrumented systems typically targets SL2 or SL3, while the conduit carrying AI-bound data out of that zone is engineered and documented as its own object, not an afterthought of whatever port happened to be open.
| Level | Protection Against | Refinery Relevance |
|---|---|---|
| SL0 | No specific protection required | Non-critical, isolated test systems |
| SL1 | Casual or coincidental violation | Low-consequence business systems |
| SL2 | Intentional violation, low resources | Standard control zone assets and Level 3.5 DMZ |
| SL3 | Sophisticated, moderately resourced attacker | Safety instrumented systems, critical unit controllers |
| SL4 | State-level, well-funded attacker | Reserved for the highest-consequence national assets |
See Where an AI Platform Would Actually Sit on Your Network
Bring your current network diagram and DCS/historian setup to the call. We will walk through how a Level 3.5 architecture would be structured against your existing zones and conduits.
How Data Actually Moves Through a Diode-Mediated Architecture
A secure architecture is only useful if it still delivers data fast enough for the AI use case to matter. The flow below is how a Level 3.5 deployment typically moves process data from the control zone to an inference engine and back out to the business systems that act on the result, without ever opening a return path into the DCS.
What Each Zone Is Actually Responsible For
A convergence architecture stops being theoretical once every zone has a clearly assigned job and a clearly assigned owner. The breakdown below is what most refineries end up documenting once the architecture moves from whiteboard to implementation.
Direct Connection vs Diode-Mediated DMZ Architecture
The gap between these two approaches only becomes obvious once something goes wrong, whether that is an audit, a penetration test, or an actual incident. By then, retrofitting a proper boundary is far more disruptive than designing it in from the start.
| Factor | Direct DCS Connection | VPN Bridge | Diode-Mediated DMZ |
|---|---|---|---|
| Return Path Risk | High, fully bidirectional | Moderate, encrypted but reversible | None, physically one-way |
| Audit Posture | Difficult to defend | Requires ongoing justification | Matches IEC 62443 documentation directly |
| Data Latency for AI | Lowest, but riskiest | Low to moderate | Near real-time via replica, minimal added delay |
| Typical Outcome | Flagged in security or PSM review | Tolerated short-term, rarely approved long-term | Standard for sanctioned AI deployments |
Four Mistakes That Undo a Well-Designed Architecture
Most convergence failures are not caused by a missing diagram, they are caused by shortcuts taken after the diagram was already approved. These four show up repeatedly across refinery AI deployments.
What Changes Once the Architecture Is in Place
Not sure whether your current historian setup can support a Level 3.5 replica feed? Talk to our team and we will walk through what your architecture would need.
A Common Starting Point: The Retrofit Scenario
Most refineries approaching this are not building a greenfield network, they are retrofitting an architecture around a DCS and historian that have been running for a decade or more. A typical starting point looks like this: a site operations historian already exists at Level 3, a business network sits at Level 4 with no formal DMZ between them, and someone has proposed an AI model for compressor or heat exchanger monitoring that needs continuous access to a specific tag set. The instinct is to open a single route between the two and call it done.
The retrofit path that actually holds up under review looks different. The existing historian is left untouched, and a lightweight replica instance is stood up specifically to mirror the tags the AI model needs, nothing more. A data diode is installed between that replica and a newly defined Level 3.5 segment, and the AI platform is deployed entirely inside that segment rather than on the business network. Outputs are logged and reviewed inside the DMZ before a broker service forwards only the finished recommendations to the CMMS or reliability dashboard the maintenance team already uses. The retrofit takes longer than opening a single firewall rule, but it produces an architecture that a security assessor, an insurer, or a process safety review can actually sign off on without conditions attached.
Frequently Asked Questions
Get a Level 3.5 Architecture Built Around Your Refinery
Bring your current network diagram and historian setup to the call. We will walk through exactly how a diode-mediated, IEC 62443-aligned architecture would be structured against what you already have running.







