We build software for the places
the cloud can't reach.
We're a team of industrial automation and distributed systems engineers. We spent years building control systems and analytics for utilities and device software, and most of that work came back to the same problem — a network sitting between the process and the decision. So we build without one.
Why the round-trip is the problem.
OT used to be isolated by physics. Modern software ran in shared clouds. Neither habit survives contact with how these systems are deployed now. A grid, a pipeline manifold or a bedside monitor has to answer in real time. Send its raw data across someone else's network and you buy latency you can't bound, compliance exposure you didn't ask for, and a dependency on a link you don't own.
That's why RooTrust runs its control loops in a verified bare-metal Rust microkernel, and why SciBor embeds streaming columnar analytics inside the client application. Both give you the same thing: an answer that arrives now, and memory bounds you can check.
Four rules we don't bend.
A late command is a failed command
In protection and fluid transport, a command that arrives late is the same as one that never arrived. So we took dynamic heap allocation off the hot path. Control loops hold their timing jitter under 10 microseconds. We'd rather the loop miss an optimisation than miss a deadline, so the fast path is kept small enough that its worst case can be reasoned about on paper.
We show you the raw signal
A console should show what the transducer actually reported. We don't smooth the trace and we don't interpolate the gaps to make a graph look tidy. If a packet is late or lost, the screen says so, right away.
Substations that survive a dead WAN
A substation or a valve manifold has to hold its safe state through a long outage. When the WAN is up, the nodes talk over open protocols — IEC 61850, OPC UA, DNP3 — not a vendor's private silo.
Some limits shouldn't be software
Logic and credentials can be stolen. Safety can't rest on them. So the last line is physical: pressure relief valves, bimetallic thermal trips, actuator stroke governors — parts that stop a hazardous command whether or not the software agrees.
Six things that hold when the network doesn't.
Every buffer and register table is allocated at boot time. Nothing fragments later, and there's no allocator pause sitting on an actuation path.
Live event streams are evaluated incrementally, so only the delta between updates gets computed. Query response stays under a microsecond, and nothing re-scans a table.
Physical limits live in the controller firmware. Actuator slew rates are clamped to prevent hydraulic shock in a pipeline, and chemical pumps can't exceed their dosage cap.
The edge RTUs hold their safe state on their own through a continuous WAN outage, and they're writing every state transition to non-volatile storage.
Native parsers for IEC 61850 GOOSE, Modbus TCP and OPC UA read frames straight into local memory. No translation proxy in the middle.
Patient diagnostics and industrial sensor readings are processed on the client hardware itself. Only authorized summary metrics ever leave it.
Where we work
Vaduz Engineering Center
Vaduz, Principality of Liechtenstein
Operating Hours: 08:00 – 17:00 CET (UTC+1)
What happens here: microkernel development, formal verification, and integration work with European utilities.
Panama Operations & Field Support
Panama City, Republic of Panama
Operating Hours: 08:00 – 17:00 EST (UTC-5)
What happens here: field engineering, SCADA commissioning, and pipeline telemetry support across the region.