Scoped & quoted before you pay

Your systems, understood — at every depth

Two lines, and they are different things. The assessment is the work of understanding a system: grounded extraction, a coverage disclosure — what was analysed, what was not, and the open unknowns — an interactive model, and exports you own; the reviewed grades add a named engineer's review record. Continuity is keeping that model worth having as the plant and the people change. Both are scoped and quoted before you pay — you see the figure after the scoping preview, and nothing starts until you confirm.

Orientation
A high-level map of one system.
Priced per system at scoping
Review: Map-level engineer review — structure and risk calls checked and signed by a named engineer (not claim-by-claim). Machine-only grade on request.
  • System map & main components
  • Overall structure & data flow
  • The most visible risks
  • Coverage & unknowns disclosed
  • Interactive model + document exports
Request an Orientation
Most popular
Full model
Every identified behaviour, grounded and reviewed.
Priced per system at scoping
Review: Claim-by-claim evidence review across included claims; a named engineer signs within the stated scope. Machine-only grade at machine price.
  • Everything in Orientation
  • Every claim grounded to its source
  • Dependencies & a risk picture
  • Named, accountable reviewer — a review record, not a signature
Request a Full model
Most thorough
Verified
A full model, stress-tested.
Priced per system at scoping
Review: Everything in Full model, plus an adversarial pass over the whole model — does the evidence truly support each claim, do claims contradict, what is obsolete.
  • Everything in Full model
  • A deeper, sceptical review pass
  • Entailment & contradiction checks
  • Obsolescence assessment
Request a Verified model
Advanced
Replacement, modernisation & verification.
Priced per system at scoping
Review: Review programme defined in the agreement — a scoped engineering review record; independent verification where the programme requires it.
  • Everything in Verified
  • Diff / equivalence vs a replacement
  • A specification to rebuild from
  • Runtime / dynamic corroboration
Talk to us

Grade × depth, explicitly

Two independent axes: how deep the assessment goes, and who has reviewed it. Any depth is available machine-only at machine price — same grounding discipline, honest label. Verified is Full model plus the adversarial column.

DepthMachine-generatedEngineer-reviewed+ Adversarial pass
OrientationStructure & visible risks, honest labelMap-level review, named reviewerRarely warranted
Full modelGrounded, identified behavioursClaim-by-claim evidence review, named reviewer within scope= Verified: evidence support, contradictions, obsolescence challenged across the model
AdvancedReplacement comparison, runtime dataScoped engineering review recordIndependent verification programme
⚖️

Two lanes, one discipline

Every deliverable carries its grade — machine-generated or engineer-reviewed — and the label is never blurred. The scopes above are the engineer-reviewed lane: a named reviewer works through the model and records what they found — what holds, and what they could not settle. A fast, AI-only lane covers breadth and everyday questions at machine speed and machine price, always labelled machine-generated; during early access it is available on request as part of a scoped engagement.

What each grade asserts, in writing — the Assessment Standard →

🏭

Assessing a whole line, not one controller?

A system assessment composes multiple units into one model and adds an Interface Control Document (ICD) covering every connection inside the system and outward to SCADA, field I/O, and neighbouring systems. Each unit is scoped at the depth it needs — a full model where it matters, a lighter map where it doesn't.

🔒

Optional IP protection

For sensitive systems, an automated obfuscation layer replaces your proprietary tag and equipment names with neutral identifiers before anyone reviews the code, then restores them in the delivered model — your logic is verified, your names never leave your environment. You preview and approve exactly what is exposed — in a searchable diff view, with AI suggestions — before anything reaches a reviewer. Obfuscate the code alone, or the code and its documentation together so the cross-references stay intact. Available on Verified and Advanced; because it makes the human review more demanding, it carries a premium.

Then keep it — the continuity line

A consultancy report is finished the day it arrives. An assessment buys you the model; continuity is what keeps it worth having. Quoted per live system alongside the assessment — the same way the scopes are.

It earns its keep on your worst days, not your busiest ones. An alarm nobody recognises at 02:00. A machine that fails in a way the manual does not describe. The engineer who knew this line leaving in March. None of that waits for you to be modifying the code — which is exactly why this is worth holding on a system nobody has touched in three years.

Ask it questions

Ask about an alarm, an interlock, a mode nobody recognises — answers come from your assessed system and cite the evidence behind them, scoped to that machine.

See what changed

Each assessment is kept as a baseline. Re-ingest after a modification and you get a diff: which findings still hold, which were invalidated, and what needs re-review — scoped to what moved.

Read it from your own tools

An authenticated read API, and MCP so an AI copilot can query the verified model directly — read-only, scoped to your organisation by your own key.

Check any baseline yourself

Every analysed state is archived whole and content-addressed. Download the pack for any baseline and verify it independently — it opens with plain tar, and the identity re-derives from the sources inside it.

If you stop, this stops

The living part: re-ingesting after a change, drift against your last baseline, the Advisor, and the hosted API and MCP endpoints.

This stays yours, permanently

Everything already delivered: the document exports, the structured model export, the offline single-file viewer, and the archived pack of every baseline you paid for. Nothing you hold is ever withdrawn for non-payment — it works without us, and it keeps working.

Common questions

What platforms do you support?
Vendor-neutral — we read the logic itself across controller families, IEC 61131-3 languages, and embedded control code. We prioritise vendor-neutral formats like PLCopen XML and add vendor formats on demand. Support depth varies by format, and every assessment states what was fully parsed and what was read at reduced depth — disclosed, never assumed.
What if the answer isn’t in the code?
Then we ask. Where the sources cannot settle a behaviour, the assessment raises it as an open question — the line that prompted it, and who is likely to know — for you and your team to answer, instead of filling the gap with a guess. Answers are recorded against the claim they explain, attributed to who said it and when, and kept as testimony rather than merged into what the code proves. Anything still unanswered ships as a stated unknown.
Can I go deeper later?
Yes — each scope builds on the one below. Start with an Orientation or Full model and deepen, or add more systems, whenever you like.
Do I own the output?
Fully, and permanently. You receive the interactive model, document exports, a structured export in an open, documented format, and the archived pack of every baseline — no licensing restrictions. None of it depends on a live subscription, and none of it is ever withdrawn: what the continuity line pays for is the model staying current, never your right to what you already hold.
What if I stop the continuity line?
You keep everything delivered up to that point — exports, the offline viewer that needs no server, and the full archived pack of each baseline you paid for, which you can verify yourself without us. What stops is the living part: re-ingesting after a change, drift against your last baseline, the Advisor, and the hosted API and MCP endpoints. Restart later and the model picks up from the last baseline you have.
Is my code confidential?
Yes. Your code and data are never shared, and we sign NDAs on request. For maximum protection, the optional obfuscation add-on replaces your proprietary names before review and restores them in the delivered model.

Not sure which scope fits? Talk to us first.

Get a free scoping consultation

Or see the output before you spend anything — try the Apollo 11 demo on real public-domain flight code, every citation checkable.