ISO 10218
Carried as a standard the recipe honours for this class.
A six-axis robotic work cell modelled end to end in ELANG as an audited reference — roughly a thousand lines carrying a functional-safety design to ISO 13849-1 Performance Level d, with every safeguard traced to the hazard it mitigates.

On a machine that can injure, the hard part is not drawing the guarding — it is proving that every hazard has a safeguard, every safeguard a means of detection, a responsible actor and a lifecycle gate.
The Kronos model is the reference for that closure: the WHY pillar’s hazards and safeguards are wired to the HOW pillar’s tests and the WHO/WHEN pillar’s gates.
Driven by the production machine / manipulator recipe.
Carried as a standard the recipe honours for this class.
The functional-safety design the reference model carries.
Carried as a standard the recipe honours for this class.
Model a work cell whose functional-safety case is complete and traceable, to ISO 13849-1 PL d, with the safety chain checkable rather than asserted.
Frame the cell’s capabilities and the environment it operates in.
Enumerate hazards and the safeguards that mitigate them.
Tie each safeguard to a detection means, a responsible actor and a gate.
WFR-9Allocate the safety functions onto components and interfaces.
Close the verification matrix and reach L2 conformance.
Before test, the safety case and the models have to line up.
The digital replica correlates with the analytical models.
Abort criteria and safety cases are agreed.
Every hazard has a safeguard with an assigned verification.
Test procedures exist for every safety function.
ELANG’s well-formedness rules refuse to call the model complete while an obligation lacks an implementation, a test, an actor or a gate.
Keep exploring