Industrial Reliability

When AI fails, the PLC keeps running.

Hardware watchdogs. Immutable audit trails. Full backup/restore. Degraded-mode operation. Reliability that matters more than features as soon as your machine is in production.

Air-gapped · EU AI Act-aligned · Five-tier safety authorization · Full audit trail

Reliability is the Buying Filter

The market is shifting from “best AI” to “trustworthy AI”.

When your factory is in production, the question stops being “can the AI write better code?” and starts being “what happens when something goes wrong?” Brain is built for the second question first.

Hardware Watchdog

Every I/O board independently watches itself.

An IWDG hardware watchdog runs on every STM32F412 I/O board. 2-second timeout. If the firmware hangs, the board reboots and the controller is notified within 2 seconds. The PLC engine continues running on every other board.

spec

Independent IWDG per board

spec

2-second timeout

spec

Hardware-level — cannot be disabled by firmware

spec

Auto-recovery

spec

Status reported via Modbus to controller

Software Watchdog

The controller watches the AI.

If the Brain AI agent stops responding, hangs, or starts behaving abnormally, the software watchdog isolates it via circuit breaker. The PLC engine, drivers, and alarm processing continue running. AI is restored when stable.

behavior

Circuit breaker opens after consecutive failures

behavior

AI service isolated, PLC unaffected

behavior

Auto-retry with exponential backoff

behavior

Operator notification

behavior

Manual reset available

What Keeps Running

PLC, drivers, alarms — independent of everything.

Failure

AI service down

What still works

PLC engine, drivers, alarms, HMI ✓

Failure

Backend crash

What still works

PLC engine, drivers, alarms ✓

Failure

Network outage

What still works

PLC engine, drivers, local alarms ✓

Failure

Cabinet power loss

What still works

Restores last known state on power-on

Failure

I/O board failure

What still works

All other boards continue, alarm raised

Failure

Multiple board failures

What still works

Cabinet enters safe state, all outputs to safe defaults

Audit Trail

Immutable. Complete. Exportable.

Every AI action, every operator action, every system event is logged to SQLite in WAL mode with hash-chain integrity. Cannot be modified after the fact. Exportable for compliance audits, forensic investigation, and regulatory submission.

SQLite WAL mode

Hash-chain immutability

NTP-synchronized timestamps

Per-event operator + agent identification

Export formats: JSON, CSV, PDF

Backup / Restore

One-click rollback. Full project snapshots.

Every PLC program version is stored with metadata: who deployed, when, with what reason. Roll back to any previous version with one click. Brain keeps 90 days of history by default, configurable up to forever.

Historian Durability

BadgerDB time-series storage. Built to outlast hardware.

5-second sampling by default. 7-day retention out of the box. Deadband optimization to skip identical values. Configurable retention from days to years. Survives power cycles. Survives controller swaps. Exports to CSV, JSON, Parquet.

Reliability by the Numbers

2s

Hardware watchdog timeout

100ms

PLC scan cycle, independent of AI

WAL

Audit trail integrity mode

90 days

Default version retention

Air-gapped runtime support

0

Unreviewed PLC changes ever reach production

Reliability: Shipped vs In Progress

What ships today. What's on the roadmap.

Today

  • Hardware watchdog on every I/O board
  • Software watchdog with circuit breaker
  • SQLite WAL audit trail
  • Project versioning and rollback
  • BadgerDB historian
  • Degraded-mode PLC operation
  • Air-gapped runtime

In Progress

  • IEC 61508 SIL 2 functional safety (target 2027)
  • IEC 62443 industrial cybersecurity (Q4 2026)
  • Hot-standby controller pairing (2027)
  • N+1 cabinet redundancy templates (2027)

Verify, Don't Trust

Test it yourself.

Reliability you can prove. Not just promise.

SEE BRAIN PRO PRICING →