Offline by default
Analyze exported projects and source files. The initial product does not connect to or modify a running controller.
SpringFur OT assesses PLC and automation software for maintainability, determinism, security and change risk — offline, evidence-led and connected to its technical context.
OT software affects equipment, production and people. The assessment must therefore be useful without claiming authority it does not have.
Analyze exported projects and source files. The initial product does not connect to or modify a running controller.
From rating to rule, logic element, dependency and source artifact — with coverage and limitations shown.
SpringFur supports qualified controls and safety engineers. It does not replace commissioning or safety validation.
The scan combines software structure with execution, I/O, vendor and operational context. The exact evidence depends on the platform and available export.
SpringFur’s quality graph connects software to the controllers, I/O, machines, networks and operational processes that depend on it. That makes change impact and technical ownership visible.
L4 PROCESSL3 OPERATIONSL2 CONTROLL1 FIELDL0 PHYSICALThe result always names the project version, evidence coverage, applicable rules and review status.
Structure, modularity, complexity, reuse and readability.
Execution order, scan-cycle exposure and time-sensitive behavior.
Potential influence on interlocks, protection and safety boundaries.
Change control, identity, integrity and communication exposure.
Simulation, test cases, traceability and regression evidence.
Toolchain, controller, library and proprietary-construct dependence.
Applicability is selected per system, lifecycle role and evidence scope. SpringFur reports what it assessed and what it did not.
SpringFur OT can map technical evidence to candidate obligations while keeping legal applicability and final conclusions with qualified professionals.
Vulnerability handling, dependency inventory, support information and technical security findings for products with digital elements where applicable.
Assets, dependencies, risk controls, suppliers, change governance and incident-related evidence for organizations within scope.
The scan marks evidenced, partial, manual and unassessed controls. A code finding alone never becomes a legal verdict.
We are looking for one bounded PLC ecosystem and experienced controls-engineering partners to validate the model on real exported projects.