DDETERMINOVAEngineering Generator
BrowserAlpha 0.1

Deterministic industrial intelligence

One verified model.
Every control target.

Define the process once. Oliver OS builds the authoritative engineering model, validates every physical channel and generates reviewable PLC projects without giving AI direct control authority.

  1. LeoAIreasons
  2. Oliver OSmodels
  3. Digital twinverifies
  4. Policy gateauthorises
  5. FPGA runtimeexecutes deterministically

Architecture overview

DCS, PLC and SCADA — unified by Determinova.

The Browser operates. Leo AI reasons. Oliver OS models. The digital twin verifies. Policy authorises. Redundant FPGA pipelines execute deterministically at the edge.

Open Determinova BrowserExisting validated control and safety boundaries remain independent.

Determinova control architecture

OperateDeterminova BrowserReasonLeo AIVerifyOliver OS + digital twinAuthoriseOT Broker + policyExecuteRedundant FPGA pipelinesControlEdge + remote I/O
InputComplete
Typed modelComplete
ValidateComplete
4
Human reviewRequired
5
GenerateLocked

Project DEG-0001 · revision 03

Data centre cooling pump cell

Canonical model is internally consistent
1Project2Outputs3Review
01

Project definition

Authoritative source data

Validated
Advanced settings20 ms · Basic engineering
Signals82 AI · 5 DI · 1 DO
Hardware objects6Typed & allocated
Rule setv0.4.0SHA-256 pinned
Next stepChoose program outputs
02

Program outputs

4 targets selected

03

Assurance gate

Deployment authority

Human review
Schema validationAll objects typed
Physical allocationNo channel conflicts
Semantic constraintsSignal direction verified
4Engineering review recordReviewer acknowledgement required
5Independent policy approvalLocked until target evidence exists

Safety is a separate lifecycle. AI cannot assign SIL or generate an approved F-program without SRS, HAZOP/LOPA and verification evidence.

Object-backed hardware configuration

Devices & network

3 devices · 3 I/O modules · 0 conflicts
HWHardware configurationDEG-0001 · DC cooling pump cell
Swipe diagram horizontally
PN/IE_1 · PROFINET · VLAN 110
MRP ring · recovery ≤ 200 ms
PROFINET24 VDC A+BValidated
Topology internally consistentPROFINET IO system_1Revision 3

Physical hardware compiler

I/O allocation preview

0 errors · 1 review notes
Engineering tagTypeIEC addressPhysical bindingValidation
PUMP_101_RUNNING_FBDI%I0.0ET200SP-01 · S1 · Ch0Valid
PUMP_101_FAULT_FBDI%I0.1ET200SP-01 · S1 · Ch1Valid
CONTROL_ENABLEDI%I0.2ET200SP-01 · S1 · Ch2Valid
PUMP_101_START_REQDI%I0.3ET200SP-01 · S1 · Ch3Valid
PUMP_101_STOP_REQDI%I0.4ET200SP-01 · S1 · Ch4Valid
PUMP_101_START_CMDDO%Q0.0ET200SP-01 · S2 · Ch0Valid
PUMP_101_CURRENTAI%IW64ET200SP-01 · S3 · Ch0Valid
PT_101_PRESSUREAI%IW66ET200SP-01 · S3 · Ch1Valid
Generation is reproducible.Ready for deterministic validation
warningHIL_REQUIRED

Generated control logic has not been executed against physical hardware.

Run target compilation, simulation, HIL and fault-injection tests.
infoDRAFT_ONLY

Generation is limited to a reviewable draft package.

Complete independent review, target compiler checks and policy approval before deployment.

Forge Assure regression guardrail

8/8 known failure modes blocked

All passing

RV-01Start command incorrectly modelled as an inputCOMMAND_DIRECTION

RV-02Digital input represented in a word areaADDRESS_AREA_INVALID

RV-03Analog input starts at an odd byteADDRESS_AREA_INVALID

RV-04Analog input placed in an output wordADDRESS_AREA_INVALID

RV-05Channel number exceeds module capacityCHANNEL_OUT_OF_RANGE

RV-06Two signals share the same physical channelDUPLICATE_CHANNEL

RV-07Safety classification has no lifecycle evidenceSAFETY_EVIDENCE_REQUIRED

RV-08Ring network lacks a redundancy protocolRING_PROTOCOL_MISSING

Explicit engineering domains

Network, redundancy and provenance

A

Port-level network

Every cable terminates at an explicit managed port. The sample uses VLAN 110, PROFINET and an engineered MRP ring.

Nodes
3
Links
3
Recovery
200 ms
B

Structured redundancy

Redundancy is a typed set of controller, network, I/O and power failure domains—not a free-text label.

Controller
none
Network
MRP
Power
A+B
C

Provenance chain

The model, ruleset, targets and derived files receive stable identifiers. Changed engineering input produces a new build ID.

Revision
3
Status
validated
Authority
draft only