DatumProof

About DatumProof

Give equipment design
grounds to be called correct.

DatumProof verifies automation-equipment designs before the machine exists. This page covers why this problem, what principles we work by, and what we do not do.

The starting question

If the physical system being controlled is not that complex, why does the control software become so hard to understand, so hard to change, and so hard to verify?

The answer is not that the machine is complex. It is that requirements, system behaviour, abnormal handling, verification conditions and past design decisions are not expressed in any explicit, executable form. What is not expressed cannot be checked. What cannot be checked is not known until the machine runs — which is why verification of equipment software is deferred to the very end.

Principles

We have settled on three

01

Put the design in a form where correctness can be asked about

The reference for equipment software is the design. Yet that design usually lives in natural language and in the heads of senior engineers — in a form where the question "is this right?" cannot even be posed. That is where we start.

02

Return results in the engineer’s own language

"The tool says so" does not carry on a factory floor. Findings come back as event sequences you can walk through in a design review. If a person cannot read it and judge it, we do not consider it a finished deliverable.

03

State the limits first

Design verification is not a universal answer. It verifies the design, not the assembled machine. Models are abstractions, and choosing an abstraction has real limits. We explain what this cannot do before what it can.

What we do not do

Keeping the scope narrow is what keeps adoption cheap

The first worry about any new method is: does this mean changing everything we already do? The answer is no.

Replace your control software

We do not touch how your PLC development or control software is written. Verification runs alongside the development you already have.

Make testing unnecessary

Wiring, assembly, the actual response of a motor — everything that only the real machine can settle stays testing’s job. Verification and testing answer different questions.

Generate production code

What we return is the result of verification, not code. The scope is deliberately narrow: confirming whether the design is right, at low commitment.

Where we sit

Not creating demand — adding one rung to a ladder already being climbed

The world has already moved toward designing with models. On top of that, building a model and proving the model is correct remain two different jobs — and only one of them is being done.

DatumProof does not compete with the tools that build models. It is the verification layer above them. That layer does not yet exist for the equipment industry, and that is the reason this company exists.

Principle

Equipment software should be understandable, verifiable and changeable from an explicit model and documented design intent.

Current status

DatumProof is in formation. Registration details will be published on this page once incorporation completes.

Enquiries are welcome at this stage.

Tell us what hurts.

Which machine, and what is the most painful part right now.

Contact us