# Y.E. Secure Connector
Outbound-only agent architecture:
Accounting/HR PC -> Connector Agent -> TLS -> Y.E. API.
Use a device certificate, short-lived access token, scoped operations, local encrypted queue, retry/backoff, and immutable transfer audit records.
