Skip to content
AI-NATIVE SCADA · DIGITAL REPLICA · UNLIMITED PER-SITE LICENSING

Nothing reaches the plantuntil it has been proven.

DjiniousCC is a complete SCADA system — acquisition, historian, HMI, alarms and commands — with a physics twin of your plant built into it. Which means a change can be proven on the twin before it touches the field. One licence per site. Everything unlimited.

  1. Observe
  2. Author
  3. Prove
  4. Act
The DjiniousCC copilot showing a proposed high-wind curtailment procedure, its dry-run on an isolated twin with all four assertions passing, six intercepted field commands, and an approve-and-execute gate labelled C4 operational action.The DjiniousCC copilot showing a proposed high-wind curtailment procedure, its dry-run on an isolated twin with all four assertions passing, six intercepted field commands, and an approve-and-execute gate labelled C4 operational action.
The copilot's proposal, dry-run on an isolated twin: assertions held, six field commands intercepted, and a C4 approval gate before anything is issued.DjiniousCC copilot · Provence Hybrid Plant
WHAT YOU GET

A complete SCADA system, not a component of one

Everything a supervisory system has to do, in one product with one data model — so there is no integration seam between the tag you acquire, the alarm it raises and the command you send back.

  • Acquisition

    OPC-UA · MODBUS TCP · SPARKPLUG B

    Genuine protocol stacks polling at 1 Hz. A tag in LIVE mode takes its value from a device read or reports not-connected — there is no silent fall-back to a model.

  • Historian and trends

    TIMESCALEDB

    Every tag historised and queried back through the same API that serves the live value. If the historian is down, a trend says so rather than drawing an empty chart.

  • HMI, built and run

    ISA-101

    Draw a mimic in the Builder and the Runner renders the same components from the same screen record. 2D synoptics and orbitable 3D scenes, with no second drawing set to drift.

  • Alarms

    ISA-18.2

    Priority, shelving, suppression, out-of-service and second-person acknowledgement — the management lifecycle, not just a red list.

  • Commands and interlocks

    READ-BACK VERIFIED

    Every write passes the asset's interlocks and a policy gate, then confirms against an independent applied-setpoint echo rather than the register it just wrote.

  • Procedures

    BPMN 2.0

    Operating procedures as versioned, statically validated artefacts executed by a token runtime — with a validation report and a record of who or what authored them.

5
sites running
energy, water, gas, discrete, district heat
693
live tags
95 writable · 212 alarmable
3
field protocols
OPC-UA · Modbus · Sparkplug
C0–C6
authority classes
L0–L4 autonomy
LICENSING

One licence. One site. Nothing metered.

DjiniousCC is licensed per site — one physical plant — not per tag, per client or per screen. Add operators, grow the tag count, build more screens, connect more devices: the licence does not change. Nobody should be deciding which signals are worth historising because of a licence.

  • TagsUnlimited
  • Clients and usersUnlimited
  • ScreensUnlimited
  • Device connectionsUnlimited
  • Concurrent designersUnlimited
  • Digital ReplicaIncluded
WHY NOT THE ONE YOU HAVE

What a conventional SCADA leaves you to solve

We do not name vendors, and we do not claim every system has every one of these problems. These are the properties of the category as most plants run it today.

Axis of comparisonConventional SCADADjiniousCC
LicensingPer tag, per client, per screen — the estate is metered as it growsPer site, everything unlimited, the Digital Replica included
Digital twinA separate product with its own data model, or nothing at allThe same assets, the same tags, the same historian — one model
Testing a changeOn the running plant, or on a spare PLC on a bench, or not at allOn an isolated twin, with assertions, and the baseline must fail first
AIBolted on through an external API the control room cannot depend onIn the loop, with a deterministic core that needs no external model
Who may actA role and a passwordAn authority class and an autonomy level, granted with a justification and an expiry
When a driver dropsThe last value, held — or a lamp that stays greenThe tag reports not-connected and the lamp goes grey

The last row is the one worth arguing about. A system that holds the last value when a driver drops is telling the operator something it does not know.

THE DIFFERENCE

A Digital Replica, not a diagram

A conventional SCADA shows you what the plant is doing. DjiniousCC also runs a physics model of that plant, bound to the same tags — so a change can be posed as a question and answered before it becomes a command. This is what a standard SCADA does not give you, and it is why the rest of the loop is possible at all.

  • Behavioural physics per equipment family, bound to the tags the live plant already writes
  • Runs beside a live plant, not instead of one — per-asset SIM or LIVE, switchable, and badged on the asset register, the twin and the asset detail
  • Structurally isolated: every command a dry-run issues is intercepted before a connector sees it
  • Reproducible by construction — virtual clock, seeded RNG, bit-exact on replay
The DjiniousCC simulation page with baseline and with-process dry-run panels and a run history showing pass and fail verdicts.The DjiniousCC simulation page with baseline and with-process dry-run panels and a run history showing pass and fail verdicts.
A baseline run and a with-procedure run of the same scenario, on the isolated twin.
THE LOOP

Four stages, and a gate between intent and the field

This is the whole product. Everything else — the historian, the alarm engine, the drivers, the twin — exists to make one of these four stages true.

  1. 01

    The plant, and its twin, in one place

    Real-time supervision on ISA-101 high-performance screens, backed by a continuously synced digital twin. Neutral grey is the resting state; colour means something is wrong.

    • 1 Hz acquisition over OPC-UA, Modbus TCP and MQTT Sparkplug B — real drivers, not adapters-in-name
    • Every tag historised to TimescaleDB and queryable back through the same API
    • ISA-18.2 alarm management: priority, shelving, out-of-service, second-person acknowledgement
    • Mimics you draw in the Builder are the same graphics the Runner shows — no parallel drawing set
  2. 02

    Intent becomes a procedure you can read

    An operator states what they want. The copilot grounds it in the live twin and emits a Process Intent Representation, which compiles to executable BPMN and is statically validated before anyone sees it.

    • Grounding first: the copilot resolves the intent against real assets, tags and limits
    • PIR → BPMN with a validation report — required capabilities, authority class, blast radius
    • Human-readable procedure: capability steps, decisions, human tasks, notifications
    • Deterministic. The closed loop needs no external LLM; one can be attached, never depended on
  3. 03

    Run it against a twin that cannot touch the field

    The procedure is dry-run on an isolated simulation twin with a virtual clock and a seeded RNG. Field commands are intercepted. Assertions are evaluated against what the twin actually measured.

    • Structurally isolated: every command the procedure issues is caught before a connector sees it
    • Reproducible: same seed, same trajectory, bit-exact on replay
    • Run the scenario without the procedure first — the baseline must fail for the proof to mean anything
    • Both the scenario's assertions and the procedure's own acceptance criteria are checked
  4. 04

    Execution a regulator could follow

    Approval issues real commands through interlocks, policy and read-back. Authority classes bound what an agent may ever request; autonomy levels bound whether it may execute at all.

    • Authority C0–C6 and autonomy L0–L4, granted per agent, per scope, with an expiry
    • Interlocks evaluated before every write; a failed check is an incident, not a retry
    • Read-back from an independent applied-setpoint echo — never the register just written
    • Kill switch, second-person approval, and a timestamped, attributed audit trail
THE PROOF STEP

A dry-run only counts if the baseline fails

Every procedure below ships with the scenario that proves it. The same scenario is run twice — once without the procedure, once with it. If the baseline passes, the procedure has proven nothing, and DjiniousCC shows you that.

Dry-run results for each plant: the measured baseline, the measured result with the procedure, and the limit each is checked against.
PlantScenarioMeasuredBaselineWith procedure
AQUAUF-03 fouling excursionTransmembrane pressurelimit 1.35 bar1.62 bar — fail0.56 bar — pass
CAMGCMP-01 suction restrictionAnti-surge marginlimit 12 %−32.3 % — fail+16.6 % — pass
BLN3Filler overspeed pushReject ratelimit 3.5 %9.40 % — fail1.90 % — pass
PROVHigh-wind gust frontWind-field powerlimit 1.3 MW3.60 MW — fail1.08 MW — pass
MEDICold snap capacity shortfallSupply headerlimit 67 °C61.63 °C — fail72.50 °C — pass

Read off the isolated simulation twin. Baseline and mitigated runs use the same scenario, the same seed and the same virtual clock.

ONE PLATFORM, FIVE SITES

The loop does not care what the plant makes

The same acquisition, twin, alarm and policy machinery runs a wind farm, a drinking-water works, a gas processing skid, a bottling line and a city district-heating network. Each is a real configuration in the platform — assets, tags, mimics, alarms and a proven procedure.

AI, ON A LEASH

An agent with a budget of authority

The copilot reads the plant, authors a procedure and asks for it to be run. What it cannot do is decide how far it is allowed to go: authority bounds what it may ever request, autonomy bounds whether it may act alone, and both are checked server-side on every command. The closed loop is deterministic — attach a language model to widen what the copilot understands, but nothing load-bearing sits behind it.

  • Authority C0–C6 and autonomy L0–L4, granted per agent and scope, with a justification and an expiry
  • Interlocks before every write; a failed check raises an incident rather than a retry
  • Second-person approval on safety-classified actions — the requester cannot self-approve
  • One kill switch halts agent-originated execution without taking supervision down with it
WHAT WE WILL NOT DO

This is control software. It does not pretend.

DjiniousCC runs against real plant. So the product refuses to fake: a tag in LIVE mode takes its value from a device read or reports no data; simulation is labelled SIM on every asset that carries it; an unimplemented capability is shown as unimplemented rather than mocked; and a lost connection turns a lamp grey, never green.

  • A LIVE tag with no fresh device read reports not-connected — it never falls back to the model
  • Command read-back reads an independent echo, so an acknowledgement cannot be tautological
  • The simulation twin is labelled, isolated, and its intercepted commands are listed
  • Where a protocol adapter is a stand-in, the connectivity page says so on the card

Bring us your plant.

We will stand DjiniousCC up against your tags, your alarm philosophy and one procedure you actually run — and dry-run it in front of you.