Industrial Reliability
Hardware watchdogs. Immutable audit trails. Full backup/restore. Degraded-mode operation. Reliability that matters more than features as soon as your machine is in production.
Air-gapped · EU AI Act-aligned · Five-tier safety authorization · Full audit trail
Reliability is the Buying Filter
When your factory is in production, the question stops being “can the AI write better code?” and starts being “what happens when something goes wrong?” Brain is built for the second question first.
Hardware Watchdog
An IWDG hardware watchdog runs on every STM32F412 I/O board. 2-second timeout. If the firmware hangs, the board reboots and the controller is notified within 2 seconds. The PLC engine continues running on every other board.
Independent IWDG per board
2-second timeout
Hardware-level — cannot be disabled by firmware
Auto-recovery
Status reported via Modbus to controller
Software Watchdog
If the Brain AI agent stops responding, hangs, or starts behaving abnormally, the software watchdog isolates it via circuit breaker. The PLC engine, drivers, and alarm processing continue running. AI is restored when stable.
Circuit breaker opens after consecutive failures
AI service isolated, PLC unaffected
Auto-retry with exponential backoff
Operator notification
Manual reset available
What Keeps Running
Failure
AI service down
What still works
PLC engine, drivers, alarms, HMI ✓
Failure
Backend crash
What still works
PLC engine, drivers, alarms ✓
Failure
Network outage
What still works
PLC engine, drivers, local alarms ✓
Failure
Cabinet power loss
What still works
Restores last known state on power-on
Failure
I/O board failure
What still works
All other boards continue, alarm raised
Failure
Multiple board failures
What still works
Cabinet enters safe state, all outputs to safe defaults
Audit Trail
Every AI action, every operator action, every system event is logged to SQLite in WAL mode with hash-chain integrity. Cannot be modified after the fact. Exportable for compliance audits, forensic investigation, and regulatory submission.
SQLite WAL mode
Hash-chain immutability
NTP-synchronized timestamps
Per-event operator + agent identification
Export formats: JSON, CSV, PDF
Backup / Restore
Every PLC program version is stored with metadata: who deployed, when, with what reason. Roll back to any previous version with one click. Brain keeps 90 days of history by default, configurable up to forever.
Historian Durability
5-second sampling by default. 7-day retention out of the box. Deadband optimization to skip identical values. Configurable retention from days to years. Survives power cycles. Survives controller swaps. Exports to CSV, JSON, Parquet.
Reliability by the Numbers
2s
Hardware watchdog timeout
100ms
PLC scan cycle, independent of AI
WAL
Audit trail integrity mode
90 days
Default version retention
✓
Air-gapped runtime support
0
Unreviewed PLC changes ever reach production
Reliability: Shipped vs In Progress
Today
In Progress
Verify, Don't Trust