Operational technology quality intelligence

Know the software behind the machine.

SpringFur OT assesses PLC and automation software for maintainability, determinism, security and change risk — offline, evidence-led and connected to its technical context.

OFFLINE ANALYSIS FIRSTNO LIVE PLC CONNECTIONENGINEER-VALIDATED
CONTROL CONTEXT / LINE 04ASSESSMENT 017
HMIOperator Panel 04
PLC PROGRAMPackagingControl
SAFETY PLCGuarding & E-stop
DRIVEConveyor VFD
I/ORemote rack 4B
PROCESSPackaging line
QUALITY RATING 3.7 / 52 CHANGE RISKS
Operating principles

Designed for engineering reality.

OT software affects equipment, production and people. The assessment must therefore be useful without claiming authority it does not have.

01 / SAFE ENTRY

Offline by default

Analyze exported projects and source files. The initial product does not connect to or modify a running controller.

02 / VISIBLE EVIDENCE

Every finding is traceable

From rating to rule, logic element, dependency and source artifact — with coverage and limitations shown.

03 / ACCOUNTABLE REVIEW

Engineers remain responsible

SpringFur supports qualified controls and safety engineers. It does not replace commissioning or safety validation.

Assessment scope

More than a syntax check.

The scan combines software structure with execution, I/O, vendor and operational context. The exact evidence depends on the platform and available export.

Program structureMAINTAINABILITYPrograms, function blocks, functions, tasks, globals, libraries, calls, duplication and complexity.
Control behaviorDETERMINISMExecution order, states, timers, latches, initialization, restart and fault-handling patterns.
Data and I/OTRACEABILITYSignal mapping, ranges, scaling, units, unused points, absolute addresses and force-sensitive variables.
Safety boundariesCHANGE RISKSeparation of standard and safety logic, protected blocks, interlocks and evidence gaps.
OT securityDEFENCEAccounts, remote access, communication, credentials, integrity and unauthorized-change exposure.
Vendor lifecyclePORTABILITYController, firmware, toolchain, library versions, obsolete instructions and migration risk.
Software in context

From a logic block to the production line.

SpringFur’s quality graph connects software to the controllers, I/O, machines, networks and operational processes that depend on it. That makes change impact and technical ownership visible.

L4 PROCESS
PackagingBatch handling
L3 OPERATIONS
SCADAHistorianMES
L2 CONTROL
PLCSafety PLCHMI
L1 FIELD
I/ODrivesRobots
L0 PHYSICAL
SensorsActuatorsMachine
OT quality rating

Seven dimensions. One declared scope.

The result always names the project version, evidence coverage, applicable rules and review status.

Control software maintainability

4.1

Structure, modularity, complexity, reuse and readability.

Determinism and timing

3.6

Execution order, scan-cycle exposure and time-sensitive behavior.

Safety change risk

3.2

Potential influence on interlocks, protection and safety boundaries.

OT security

3.8

Change control, identity, integrity and communication exposure.

Test and verification

3.4

Simulation, test cases, traceability and regression evidence.

Hardware and vendor portability

2.9

Toolchain, controller, library and proprietary-construct dependence.

Reference framework

Standards inform the method. They are not marketing badges.

Applicability is selected per system, lifecycle role and evidence scope. SpringFur reports what it assessed and what it did not.

IEC 61131-3Programming-language syntax and semantics for programmable controllers.LANGUAGE MODEL
IEC 61131-10XML-based exchange format for IEC 61131-3 projects where supported.PROJECT EXCHANGE
PLCopenCoding guidance and software-quality metric practices for industrial control software.QUALITY GUIDANCE
IEC 62443Applicable cybersecurity requirements for industrial automation and control systems.CONTEXT SELECTED
European by design

OT evidence for European security and product context.

SpringFur OT can map technical evidence to candidate obligations while keeping legal applicability and final conclusions with qualified professionals.

CRA / PRODUCT SECURITY

Secure lifecycle evidence

Vulnerability handling, dependency inventory, support information and technical security findings for products with digital elements where applicable.

NIS2 / CYBERBEVEILIGINGSWET

Operational resilience evidence

Assets, dependencies, risk controls, suppliers, change governance and incident-related evidence for organizations within scope.

ACCOUNTABLE INTERPRETATION

No one-click compliance

The scan marks evidenced, partial, manual and unassessed controls. A code finding alone never becomes a legal verdict.

A quality assessment is not a functional-safety certificate.

  • No autonomous changes to control software.
  • No connection to live PLCs in the first product generations.
  • No safety conclusion without qualified human review.
  • No generic “IEC 62443 compliant” claim from a source scan.
  • Every report includes coverage, limitations and accountable reviewers.

Build the first SpringFur OT pilot with us.

We are looking for one bounded PLC ecosystem and experienced controls-engineering partners to validate the model on real exported projects.

Discuss a pilot →