It reads copies. It writes nothing to the plant. Nothing leaves.
The least invasive way to learn what a plant's data means is to never touch
the plant. Each answer below is a property of how the product is built, and
where it can be checked, the right hand column says how.
Your control system
Never connected and never touched. It reads copies of files that somebody exported.
There is no industrial protocol driver anywhere in the product: no code in it speaks to a PLC, a DCS or a SCADA server.
Writing to the plant
Never. An agent may propose a work order for a person. Writing a setpoint is refused, and the refusal is written down beside the proposal.
The site policy, enforced in code, and a role can only narrow it. python -m auge_plant.roles checks every role against it.
The network
Nothing leaves. The only address the product opens is the machine it runs on, where the language model is.
A sealed run blocks every other address, proves the block works, then runs a full working day on two plants inside it.
What gets installed
Nothing is installed. On Windows it is one folder, unpacked from a zip, with its own Python inside, and an optional local model. Nothing on the plant's own servers.
The whole product runs on numpy and the Python standard library. The Windows zip is built and started on a clean Windows machine for every change we make.
What it leaves behind
Two files in the export folder: the result, and a state file that lets the next run spot renames.
The state file keeps fingerprints of each tag and not the readings, and it is plain JSON, so it can never carry code.
Your security review
Still happens, and anyone who says it does not is wrong. It has much less to cover: no new conduit, no remote access, no data leaving.
In IEC 62443 terms there is no new zone crossing to assess.
Taking it out
Delete the program and the folder. There is nothing on the plant to roll back, because nothing on the plant was changed.
How current it is
As current as the last file in the folder. Point your historian's scheduled export at the folder and the console reads each new file as it lands, within half a minute. New readings on tags it already understands are added without working the plant out again, in milliseconds; it is worked out in full when the tags change and at least every hour. That is live enough for a shift, and it opens no connection. For plants that want live readings there is a read only OPC UA reader: it opens one outbound session to the server the plant already runs, writes into the same folder, and is the one part of this that needs a conduit review.
The watcher checks the folder every 30 seconds; files with the same columns are read as one system, however many of them arrive. The OPC UA reader can only read, by construction.