# Cybersecurity Architecture

> Where each Yellow Cube product sits on the network — from the OT bus and PLCs, through the air gap, into enterprise IT, cloud and internet. Pairs with our Product Matrix, which weighs the same portfolio by contribution to your security posture. Click any product below for what it is and why it sits there. Dashed boxes are third-party platforms already common in the estate (identity providers, etc.) — not part of the Yellow Cube portfolio.

- Canonical URL: https://yellowcube.eu/purdue-model-architecture/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Where each Yellow Cube product sits on the network — from the OT bus and PLCs, through the air gap, into enterprise IT, cloud and internet. Pairs with our Product Matrix, which weighs the same portfolio by contribution to your security posture. Click any product below for what it is and why it sits there. Dashed boxes are third-party platforms already common in the estate (identity providers, etc.) — not part of the Yellow Cube portfolio.

**From the PLC to the cloud** — Yellow Cube secures every level of the Purdue model with one specialist vendor per domain, so your network architecture decides where the controls belong, not a vendor’s product catalogue.

### FAQ

#### Where does each Yellow Cube product sit in the Purdue model?

Yellow Cube places its portfolio across the whole stack, read bottom-up: Purdue L1–L0 is the OT bus, carrying PLCs, RTUs, drives and sensors; L3–L2 is the OT control network with SCADA, historians, HMIs and engineering workstations; L3.5 is the air gap; L4 covers the office network and the IT DMZ; L5 is cloud, SaaS and the mobile fleet. Firewall boundaries sit between them — internet perimeter, internal segmentation and cell segmentation.

Every network is drawn as a single L2 segment with its hosts hanging off it, so what you are reading is a network position, not a product category.

#### How does Yellow Cube protect Purdue L0–L1 devices that cannot run a security agent?

Protection for PLCs, RTUs, drives and sensors that cannot run a security agent is placed in the network, upstream of those devices.

In practice that means an industrial firewall in front of the cell, the machine or the individual PLC: OPSWAT's Industrial Firewall, which learns the normal traffic pattern and then enforces it with protocol-specific inspection for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet, or Stormshield's ruggedised SNi range on DIN rail with hardware bypass. That is exactly why the firewall in front of the cell carries so much of the weight at this level.

#### How does telemetry cross the air gap without opening a route back into OT?

At Purdue L3.5 the path is deliberately one-way. The primary option is OPSWAT's NetWall Unidirectional Gateway, a paired-appliance gateway with protocol emulation so historians, OPC servers and file shares replicate northbound as if the link were bidirectional — telemetry leaves OT, and nothing routes back in.

Waterfall Security's Unidirectional Security Gateway appears as an equivalent where a regulator already expects it, though that is the customer's own platform rather than part of the Yellow Cube portfolio. Removable media and contractor laptops take a different route entirely: a MetaDefender Kiosk acts as the airlock door, scanning and sanitising every USB stick and file before it is released into the OT side.

#### Do we have to replace the customer's existing identity provider or firewalls?

No. The dashed boxes in this architecture are third-party platforms most estates already run — Microsoft Entra ID or Google Workspace as the identity provider, for example — and they are explicitly not supplied by Yellow Cube. Yellow Cube's identity products layer on top of the provider the customer already has rather than replacing it, because that platform issues the tokens everything else trusts.

Where two products are joined by “or”, they are equivalent options for the same position: choose one, do not stack both.

#### What in the portfolio covers the whole stack rather than one Purdue level?

Three things are cross-cutting rather than tied to a single level. Yellow Cube's own 24×7 Managed SOC watches IT and OT out of hours, working from the telemetry that the agents and sensors in this architecture produce. Cymulate Exposure Validation safely attacks the deployed controls to prove each zone blocks what it claims, including the OT boundary.

CYBER RANGES adds live-fire exercises on realistic IT and OT scenarios, so a blue team learns this architecture under pressure rather than during an incident.

### Let’s Build Smarter Cyber Defenses Together

Partnerships are the foundation of everything we do — built on trust, expertise, and shared success. Whether you’re looking to grow your business, strengthen your cybersecurity offerings, or bring innovative solutions to new markets, Yellow Cube is ready to be your committed, long-term ally.

[Get in touch with Yellow Cube](<mailto:hello@yellowcube.eu?subject=Partnership>)

### Purdue L5 · Cloud & Internet

SaaS tenants, public cloud and the mobile fleet that never touches the office LAN.

**Cloud posture (CSPM)**

[WithSecure Elements Cloud Security](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_cloud>) or [Cynet AutoXDR CSPM](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet_cspm>) or [Stellar Cyber Cloud Sensors](<https://yellowcube.eu/purdue-model-architecture/#reference-sc_cloud>) or [OPSWAT MetaDefender Cloud](<https://yellowcube.eu/purdue-model-architecture/#reference-md_cloud>)

**Identity & MFA**

[Imprivata SSO + MFA](<https://yellowcube.eu/purdue-model-architecture/#reference-imprivata_mfa>) or [Microsoft Entra ID](<https://yellowcube.eu/purdue-model-architecture/#reference-ms_entra>) or [Google Workspace identity](<https://yellowcube.eu/purdue-model-architecture/#reference-google_ws>)

**Supply chain integrity**

[OPSWAT Software Supply Chain](<https://yellowcube.eu/purdue-model-architecture/#reference-md_ssc>) or [Cymulate Exposure Validation](<https://yellowcube.eu/purdue-model-architecture/#reference-cymulate>) or [Group-IB Attack Surface Management](<https://yellowcube.eu/purdue-model-architecture/#reference-gib_asm>)

**Mobile devices**

[iVerify Mobile EDR](<https://yellowcube.eu/purdue-model-architecture/#reference-iverify>) or [WithSecure Elements Mobile Protection](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_mobile>)

**Cloud mailbox**

[IronScales Email detection & response](<https://yellowcube.eu/purdue-model-architecture/#reference-ironscales>) + [MailStore Email archive](<https://yellowcube.eu/purdue-model-architecture/#reference-mailstore>)

### Boundary · Internet perimeter

**DDoS & edge**

[A10 Networks Thunder TPS](<https://yellowcube.eu/purdue-model-architecture/#reference-a10_tps>)

**Perimeter firewall**

[Stormshield SNS firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-sns>)

**DNS security**

[Whalebone DNS security](<https://yellowcube.eu/purdue-model-architecture/#reference-whalebone>)

### Purdue L4 · DMZ · IT DMZ

Published, internet-facing services. The office endpoint stack plus edge and identity controls.

**WAF + load balancer**

[A10 Networks Thunder ADC + WAF](<https://yellowcube.eu/purdue-model-architecture/#reference-a10_adc>)

**Identity security (ITDR)**

[Varonis ITDR](<https://yellowcube.eu/purdue-model-architecture/#reference-varonis_itdr>) or [Imprivata PAM](<https://yellowcube.eu/purdue-model-architecture/#reference-imprivata_pam>)

**Agent on published servers**

[Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>) or [WithSecure Elements EDR](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_edr>) or [Group-IB Managed XDR](<https://yellowcube.eu/purdue-model-architecture/#reference-gib_xdr>) or [Stellar Cyber Server Sensor](<https://yellowcube.eu/purdue-model-architecture/#reference-sc_server>)

**File uploads in**

[OPSWAT MetaDefender ICAP Server](<https://yellowcube.eu/purdue-model-architecture/#reference-md_icap>) or [OPSWAT MetaDefender Core](<https://yellowcube.eu/purdue-model-architecture/#reference-md_core>)

### Boundary · Internal segmentation

**DMZ ↔ office firewall**

[Stormshield SNS firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-sns>)

**DNS security**

[Whalebone DNS security](<https://yellowcube.eu/purdue-model-architecture/#reference-whalebone>)

### Purdue L4 · Office network

One L2 office network: servers, workstations, the SPAN port and the log path out to the SOC.

**Endpoint agent — servers & workstations**

[Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>) or [WithSecure Elements EDR](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_edr>) or [Group-IB Managed XDR](<https://yellowcube.eu/purdue-model-architecture/#reference-gib_xdr>)

**NDR sensor on SPAN / TAP**

[Stellar Cyber NDR sensor](<https://yellowcube.eu/purdue-model-architecture/#reference-sc_ndr>) or [Group-IB Network Traffic Analysis](<https://yellowcube.eu/purdue-model-architecture/#reference-gib_nta>) or [OPSWAT MetaDefender NDR](<https://yellowcube.eu/purdue-model-architecture/#reference-md_ndr>)

**Log collection → SOC**

[Stellar Cyber Open XDR platform](<https://yellowcube.eu/purdue-model-architecture/#reference-sc_xdr>) or [Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>)

**Patch & vulnerability management**

[WithSecure Elements](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_elements>) or [Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>)

**Endpoint security posture (ESPM)**

[WithSecure Elements](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_elements>) or [Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>)

**Data & insider risk**

[Varonis Data Detection & Response](<https://yellowcube.eu/purdue-model-architecture/#reference-varonis_ddr>) or [Teramind Insider threat management](<https://yellowcube.eu/purdue-model-architecture/#reference-teramind>)

### Purdue L3.5 · Air gap

Electronic or optical separation. Telemetry leaves OT northbound; nothing routes back in.

**One-way transfer**

[OPSWAT NetWall Unidirectional Gateway](<https://yellowcube.eu/purdue-model-architecture/#reference-md_usg>) or [Waterfall Security Unidirectional Security Gateway](<https://yellowcube.eu/purdue-model-architecture/#reference-waterfall>)

**Media & contractor laptops**

[OPSWAT MetaDefender Kiosk](<https://yellowcube.eu/purdue-model-architecture/#reference-md_kiosk>) + [OPSWAT MetaDefender Drive](<https://yellowcube.eu/purdue-model-architecture/#reference-md_drive>) or [OPSWAT Managed File Transfer](<https://yellowcube.eu/purdue-model-architecture/#reference-md_mft>)

### Purdue L3–L2 · OT control network

SCADA, historians, HMIs and engineering workstations. Windows hosts here still take an agent — where the OEM allows it.

**Industrial firewall — zone control**

[Stormshield SNS industrial firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-sni40>) or [OPSWAT Industrial Firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-md_if>)

**Agent on HMI / engineering WS**

[Cynet AutoXDR agent](<https://yellowcube.eu/purdue-model-architecture/#reference-cynet>) or [WithSecure Elements EDR](<https://yellowcube.eu/purdue-model-architecture/#reference-ws_edr>) or [OPSWAT MetaDefender Endpoint](<https://yellowcube.eu/purdue-model-architecture/#reference-md_endpoint>)

**OT asset visibility**

[OPSWAT MetaDefender OT Security](<https://yellowcube.eu/purdue-model-architecture/#reference-md_ot>) or [OPSWAT MetaDefender NDR](<https://yellowcube.eu/purdue-model-architecture/#reference-md_ndr>)

**Vendor remote access**

[OPSWAT MetaDefender OT Access](<https://yellowcube.eu/purdue-model-architecture/#reference-md_ot_access>) or [Imprivata PAM](<https://yellowcube.eu/purdue-model-architecture/#reference-imprivata_pam>)

### Boundary · Cell segmentation

**Control ↔ bus**

[Stormshield SNS industrial firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-sni40>)

### Purdue L1–L0 · OT bus / PLC network

Fieldbus and controllers. Nothing is installed down here — protection is in-line and transparent.

**In front of the PLC**

[OPSWAT Industrial Firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-md_if>) or [Stormshield SNS industrial firewall](<https://yellowcube.eu/purdue-model-architecture/#reference-sni40>)

**Field devices**

[By design No agent possible](<https://yellowcube.eu/purdue-model-architecture/#reference-none_field>)

### Cross-cutting

[Yellow Cube 24×7 Managed SOC](<https://yellowcube.eu/purdue-model-architecture/#reference-yc_soc>) + [Cymulate Exposure Validation](<https://yellowcube.eu/purdue-model-architecture/#reference-cymulate>) + [CYBER RANGES Cyber range training](<https://yellowcube.eu/purdue-model-architecture/#reference-cyber_ranges>)

### [WithSecure Elements Cloud Security](<https://withsecure.com/>)

CSPM

Continuous posture and misconfiguration checks across M365, Entra, Azure and AWS — in the same console as the endpoint agents below.

SaaS. No in-network component.

### [OPSWAT MetaDefender Cloud](<https://www.opswat.com/products/metadefender/cloud>)

Cloud file analysis

Multiscanning, Deep CDR and sandboxing offered as a cloud API for files entering the organisation.

SaaS API, called by apps and gateways.

### [Stellar Cyber Cloud Sensors](<https://stellarcyber.ai/>)

Cloud telemetry

Pulls cloud audit, identity and SaaS logs into the Open XDR data lake so cloud events correlate with network and endpoint events.

Cloud tenant + on-prem collector.

### [Stellar Cyber Server Sensor](<https://stellarcyber.ai/>)

Host telemetry sensor

Software sensor for supported Windows and Linux servers, forwarding system events and host telemetry as Interflow so Open XDR can correlate activity with the rest of the stack.

Agent on each published server in the IT DMZ.

### [Imprivata SSO + MFA](<https://imprivata.com/>)

Identity & access

Single sign-on, badge tap and MFA built for shared workstations and shift work — clinical, shopfloor and control-room patterns included.

Cloud identity service + endpoint client.

### [OPSWAT Software Supply Chain](<https://www.opswat.com/solutions/software-supply-chain-security>)

Supply chain integrity

SBOM generation, vendor package scanning and sanitisation before third-party software, updates or firmware are accepted into the estate.

Release gate / CI pipeline.

### [Cymulate Exposure Validation](<https://cymulate.com/>)

Security validation

Safely attacks your own controls to prove the stack blocks what it claims — per zone, including the OT boundary.

Light agents across zones.

### [Group-IB Attack Surface Management](<https://group-ib.com/>)

External exposure & supply chain

Continuously maps what you expose to the internet — shadow assets, exposed services, leaked credentials and the third parties in your supply chain — and scores what to fix first.

External, nothing to install.

### [Microsoft Entra ID](<https://www.microsoft.com/security/business/identity-access/microsoft-entra-id>)

Identity provider

The identity platform most customers already run. It issues the tokens everything above trusts — our identity products layer on top of it, they do not replace it.

Cloud identity provider.

**The customer's own platform — not supplied by Yellow Cube.**

### [Google Workspace identity](<https://workspace.google.com/>)

Identity provider

The Google-side equivalent: the directory and token issuer the rest of the stack authenticates against.

Cloud identity provider.

**The customer's own platform — not supplied by Yellow Cube.**

### [iVerify Mobile EDR](<https://iverify.io/>)

Mobile defence

Detects mercenary spyware, jailbreaks, malicious profiles and configuration drift on iOS and Android — real detection, not just MDM compliance.

App on the device. No network position.

### [WithSecure Elements Mobile Protection](<https://withsecure.com/>)

Mobile AV

Malware, phishing and browsing protection for managed phones and tablets, reported in the same Elements console as the desktops.

App on the device.

### [Whalebone DNS security](<https://www.whalebone.io/>)

DNS filtering

Resolver-level blocking of phishing, malware and C2 domains. Covers guests, IoT and anything you cannot install software on.

Network resolver, or roaming client on mobiles.

### [IronScales Email detection & response](<https://ironscales.com/>)

Email security

Post-delivery phishing detection and one-click remediation inside M365 or Google, with user reporting that trains the model.

API-integrated with the mailbox — no MX change.

### [MailStore Email archive](<https://mailstore.com/>)

Retention & evidence

Tamper-proof journal archive of every mail — legal hold, e-discovery and the evidence trail auditors ask for.

Server in the office network.

### [A10 Networks Thunder ADC + WAF](<https://www.a10networks.com/>)

Load balancer + web app firewall

Terminates TLS and balances published services, then enforces OWASP-class protection, bot defence and API guardrails on the same appliance — one insertion point for the WAF policy and for full-visibility decryption.

DMZ, in-line in front of the web tier.

### [A10 Networks Thunder TPS](<https://www.a10networks.com/>)

DDoS mitigation

Volumetric and application-layer DDoS scrubbing at the internet edge, before the firewall's state table becomes the bottleneck.

Internet perimeter, in-line or on-demand.

### [Stormshield SNS firewall](<https://stormshield.com/>)

NGFW

Perimeter and internal segmentation with IPS and application control — the same policy engine as the industrial SNi40 further down, managed together.

Internet perimeter and between internal zones.

### [Varonis ITDR](<https://varonis.com/>)

Identity threat detection

Watches Active Directory and Entra for privilege abuse, Kerberos attacks, stale admin paths and the blast radius each account carries.

Collector in the DMZ or office network.

### [Imprivata PAM](<https://imprivata.com/>)

PAM

Vaults credentials and records privileged sessions to servers, jump hosts and OT assets — the audit trail for who did what.

Jump host in the DMZ.

### [Cynet AutoXDR agent](<https://www.cynet.com/>)

EDR / XDR agent

One agent covering NGAV, EDR, deception and automated response, with a 24×7 MDR team behind it. The pragmatic default where the security team is small.

Installed on every Windows, Linux and macOS host.

### [WithSecure Elements EDR](<https://withsecure.com/>)

EDR agent

Endpoint detection and response with Elevate-to-expert escalation. Same agent family as the mobile and cloud modules — one vendor across three layers.

Installed on every server and workstation.

### [Group-IB Managed XDR](<https://group-ib.com/>)

Managed XDR

Agent plus network sensors driven by Group-IB's own threat intelligence and incident-response practice. Strong where attribution and IR matter.

Agent on hosts + sensor on the network.

### [OPSWAT MetaDefender ICAP Server](<https://www.opswat.com/products/metadefender/icap>)

Upload inspection

Every file uploaded through the reverse proxy is multiscanned and sanitised with Deep CDR before it reaches the application.

DMZ, beside the load balancer.

### [OPSWAT MetaDefender Core](<https://www.opswat.com/products/metadefender/core>)

File sanitisation engine

The scanning and Deep CDR engine that ICAP, managed file transfer and the Kiosks all call. Deploy once, reuse at every file entry point.

Server in the DMZ or office network.

### [Stellar Cyber NDR sensor](<https://stellarcyber.ai/>)

NDR

Passive sensor on a SPAN or TAP: east-west traffic, lateral movement and the unmanaged assets no agent will ever report.

SPAN/TAP port on the core switch.

### [Group-IB Network Traffic Analysis](<https://group-ib.com/>)

NDR

Traffic analysis with in-line file detonation, tied to Group-IB intelligence on the actors targeting your sector.

SPAN/TAP, plus a copy of mail flow.

### [OPSWAT MetaDefender NDR](<https://www.opswat.com/products/metadefender/ndr>)

NDR

Network detection tuned for converged IT/OT traffic — understands industrial protocols as well as enterprise ones.

SPAN/TAP on either side of the boundary.

### [Stellar Cyber Open XDR platform](<https://stellarcyber.ai/>)

Log collection & correlation

Collects logs from every layer of this diagram, normalises them and does the correlation the SOC actually works from — vendor-agnostic by design.

Collector on-prem, platform in the cloud.

### [Varonis Data Detection & Response](<https://varonis.com/>)

Data security

Finds the sensitive data, fixes over-broad permissions, and alerts on abnormal access to file shares, SharePoint and mail.

Collector next to the file and mail servers.

### [Teramind Insider threat management](<https://teramind.co/>)

Insider risk & DLP

User activity monitoring, session recording and DLP for the accounts that already hold legitimate access.

Agent on workstations and terminal servers.

### [Stormshield SNS industrial firewall](<https://stormshield.com/>)

OT firewall

The SNi range of ruggedised industrial firewalls — DIN-rail and rack models with protocol IPS and hardware bypass, sized to the cell rather than to one fixed appliance.

Between control zones, cells and machines.

### [OPSWAT Industrial Firewall](<https://www.opswat.com/products/metadefender/industrial-firewall-ips>)

OT firewall / IPS

Learning mode records the normal traffic pattern, then enforces it — protocol-specific DPI for Modbus TCP, S7, DNP3, EtherNet/IP and BACnet. Designed to sit between Purdue L2 and L3.5.

In front of a cell, a machine or a single PLC.

### [OPSWAT MetaDefender OT Security](<https://www.opswat.com/products/metadefender/ot-security>)

OT asset visibility

Passive and safe active discovery of every OT asset, its firmware level and its known vulnerabilities — the inventory the risk assessment needs.

Sensor in the control network.

### [OPSWAT MetaDefender OT Access](<https://www.opswat.com/products/metadefender/ot-access>)

Secure remote access

Brokered, time-boxed and session-recorded vendor access to OT assets — without a VPN tunnel into the control network.

Broker at the IT/OT edge.

### [OPSWAT MetaDefender Endpoint](<https://www.opswat.com/products/metadefender/endpoint>)

Posture & AV for OT hosts

Lightweight posture, patch and malware checks for hosts where the OEM will not certify a full EDR agent.

HMI and engineering workstations.

### [OPSWAT NetWall Unidirectional Gateway](<https://www.opswat.com/products/metadefender/netwall>)

Unidirectional gateway

One-way gateway with protocol emulation, so historians, OPC servers and file shares replicate northbound as if the link were bidirectional.

L3.5, paired appliances.

### [Waterfall Security Unidirectional Security Gateway](<https://waterfall-security.com/>)

Unidirectional gateway

Hardware-enforced one-way replication with a long track record in energy and water, and the regulator familiarity that comes with it.

L3.5, paired appliances.

**The customer's own platform — not supplied by Yellow Cube.**

### [OPSWAT MetaDefender Kiosk](<https://www.opswat.com/products/metadefender/kiosk>)

Removable media control

The airlock door: every USB stick and contractor file is scanned and sanitised at the kiosk before it is released into the OT side.

Physically at the entrance to the OT area.

### [OPSWAT Managed File Transfer](<https://www.opswat.com/products/metadefender/managed-file-transfer>)

Controlled file entry

The supervised path for files that must cross the boundary — scanned, sanitised, approved and logged, with no shared drive in between.

Either side of the air gap.

### [OPSWAT MetaDefender Drive](<https://www.opswat.com/products/metadefender/drive>)

Offline device inspection

Boots a contractor laptop or commissioning machine from a trusted drive and scans it offline, before it ever joins the OT network.

Portable, used at the air gap.

### [CYBER RANGES Cyber range training](<https://cyberranges.com/>)

Skills & exercises

Live-fire exercises on realistic IT and OT scenarios — the way a blue team learns this diagram under pressure.

Hosted platform.

### [Yellow Cube 24×7 Managed SOC](<https://yellowcube.eu/soc/>)

Managed detection & response

The team that watches everything above out of hours, across IT and OT, on the telemetry the agents and sensors here produce.

Yellow Cube SOC, fed by the collectors.

### [Cynet AutoXDR CSPM](<https://www.cynet.com/>)

Cloud posture

Cloud security posture management inside the same AutoXDR console as the endpoint agents — misconfigurations, exposed storage and identity drift in one place.

Agentless, connected to the cloud tenant.

### [WithSecure Elements](<https://withsecure.com/>)

Endpoint posture, patching & vulnerability management

One agent and one console for endpoint protection, third-party patching and vulnerability management, with posture scoring across the estate.

Servers and workstations on the office network.

### [By design No agent possible](<https://yellowcube.eu/cybersecurity-for-critical-infrastructure/>)

Field devices

PLCs, RTUs, drives and sensors cannot run security agents. Everything protecting them is in-line, transparent and upstream — which is why the firewall in front of the cell matters so much.

Purdue L0–L1.

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

