Your systems, understood — at every depth
Two lines, and they are different things. The assessment is the work of understanding a system: grounded extraction, a coverage disclosure — what was analysed, what was not, and the open unknowns — an interactive model, and exports you own; the reviewed grades add a named engineer's review record. Continuity is keeping that model worth having as the plant and the people change. Both are scoped and quoted before you pay — you see the figure after the scoping preview, and nothing starts until you confirm.
- ✓System map & main components
- ✓Overall structure & data flow
- ✓The most visible risks
- ✓Coverage & unknowns disclosed
- ✓Interactive model + document exports
- ✓Everything in Orientation
- ✓Every claim grounded to its source
- ✓Dependencies & a risk picture
- ✓Named, accountable reviewer — a review record, not a signature
- ✓Everything in Full model
- ✓A deeper, sceptical review pass
- ✓Entailment & contradiction checks
- ✓Obsolescence assessment
- ✓Everything in Verified
- ✓Diff / equivalence vs a replacement
- ✓A specification to rebuild from
- ✓Runtime / dynamic corroboration
Grade × depth, explicitly
Two independent axes: how deep the assessment goes, and who has reviewed it. Any depth is available machine-only at machine price — same grounding discipline, honest label. Verified is Full model plus the adversarial column.
| Depth | Machine-generated | Engineer-reviewed | + Adversarial pass |
|---|---|---|---|
| Orientation | Structure & visible risks, honest label | Map-level review, named reviewer | Rarely warranted |
| Full model | Grounded, identified behaviours | Claim-by-claim evidence review, named reviewer within scope | = Verified: evidence support, contradictions, obsolescence challenged across the model |
| Advanced | Replacement comparison, runtime data | Scoped engineering review record | Independent verification programme |
Two lanes, one discipline
Every deliverable carries its grade — machine-generated or engineer-reviewed — and the label is never blurred. The scopes above are the engineer-reviewed lane: a named reviewer works through the model and records what they found — what holds, and what they could not settle. A fast, AI-only lane covers breadth and everyday questions at machine speed and machine price, always labelled machine-generated; during early access it is available on request as part of a scoped engagement.
What each grade asserts, in writing — the Assessment Standard →
Assessing a whole line, not one controller?
A system assessment composes multiple units into one model and adds an Interface Control Document (ICD) covering every connection inside the system and outward to SCADA, field I/O, and neighbouring systems. Each unit is scoped at the depth it needs — a full model where it matters, a lighter map where it doesn't.
Optional IP protection
For sensitive systems, an automated obfuscation layer replaces your proprietary tag and equipment names with neutral identifiers before anyone reviews the code, then restores them in the delivered model — your logic is verified, your names never leave your environment. You preview and approve exactly what is exposed — in a searchable diff view, with AI suggestions — before anything reaches a reviewer. Obfuscate the code alone, or the code and its documentation together so the cross-references stay intact. Available on Verified and Advanced; because it makes the human review more demanding, it carries a premium.
Then keep it — the continuity line
A consultancy report is finished the day it arrives. An assessment buys you the model; continuity is what keeps it worth having. Quoted per live system alongside the assessment — the same way the scopes are.
It earns its keep on your worst days, not your busiest ones. An alarm nobody recognises at 02:00. A machine that fails in a way the manual does not describe. The engineer who knew this line leaving in March. None of that waits for you to be modifying the code — which is exactly why this is worth holding on a system nobody has touched in three years.
Ask about an alarm, an interlock, a mode nobody recognises — answers come from your assessed system and cite the evidence behind them, scoped to that machine.
Each assessment is kept as a baseline. Re-ingest after a modification and you get a diff: which findings still hold, which were invalidated, and what needs re-review — scoped to what moved.
An authenticated read API, and MCP so an AI copilot can query the verified model directly — read-only, scoped to your organisation by your own key.
Every analysed state is archived whole and content-addressed. Download the pack for any baseline and verify it independently — it opens with plain tar, and the identity re-derives from the sources inside it.
The living part: re-ingesting after a change, drift against your last baseline, the Advisor, and the hosted API and MCP endpoints.
Everything already delivered: the document exports, the structured model export, the offline single-file viewer, and the archived pack of every baseline you paid for. Nothing you hold is ever withdrawn for non-payment — it works without us, and it keeps working.
Common questions
Not sure which scope fits? Talk to us first.
Get a free scoping consultationOr see the output before you spend anything — try the Apollo 11 demo on real public-domain flight code, every citation checkable.