Acquisition
Genuine protocol stacks polling at 1 Hz. A tag in LIVE mode takes its value from a device read or reports not-connected — there is no silent fall-back to a model.
OPC-UA · Modbus TCP · Sparkplug B
DjiniousCCOperations & SCADADjiniousCC is a complete SCADA system — acquisition, historian, HMI, alarms and commands — with a physics twin of your plant built into it. Which means a change can be proven on the twin before it touches the field. One licence per site. Everything unlimited.

What it is
Everything a supervisory system has to do, in one product with one data model — so there is no integration seam between the tag you acquire, the alarm it raises and the command you send back.
Genuine protocol stacks polling at 1 Hz. A tag in LIVE mode takes its value from a device read or reports not-connected — there is no silent fall-back to a model.
OPC-UA · Modbus TCP · Sparkplug BEvery tag historised and queried back through the same API that serves the live value. If the historian is down, a trend says so rather than drawing an empty chart.
TimescaleDBDraw a mimic in the Builder and the Runner renders the same components from the same screen record. 2D synoptics and orbitable 3D scenes, with no second drawing set to drift.
ISA-101Priority, shelving, suppression, out-of-service and second-person acknowledgement — the management lifecycle, not just a red list.
ISA-18.2Every write passes the asset’s interlocks and a policy gate, then confirms against an independent applied-setpoint echo rather than the register it just wrote.
Read-back verifiedOperating procedures as versioned, statically validated artefacts executed by a token runtime — with a validation report and a record of who or what authored them.
BPMN 2.0Inside the product
Every capture below is the running product.
01 · Digital Replica
Every DjiniousCC deployment runs a physics model of the plant it supervises, bound to the same tags, driven by the same configuration. Each equipment family — turbine, inverter, battery, pump, exchanger, compressor, filler — carries a behavioural model that computes its state from its inputs. The replica is not a parallel drawing of the plant: it is the plant’s own asset register and tag namespace, computed instead of measured.

02 · On a live plant
The replica is not a sandbox you go to when the plant is down. It runs on the deployment that is supervising your plant right now. Each asset independently carries a data-source mode — a real device read, or the model — and whichever it is, it says so on the screen. A plant can be fully live with a replica running alongside it.

03 · The proof step
An operating procedure is dry-run against the replica before anyone approves it. The same scenario is run twice — once without the procedure, once with it. If the baseline passes, the procedure has proven nothing, and DjiniousCC shows you that. The commands it would issue are intercepted and listed, its assertions are evaluated against what the replica actually measured, and the verdict is recorded against that version of the procedure.

04 · Isolation
A dry-run cannot reach the field because there is no path from it to a connector — not because a flag says it should not. The run maintains its own setpoint and state maps, and every command a procedure under test issues is caught and recorded before any driver sees it. Approval is what would make those commands real.
05 · Surfaces
A district network is not a P&ID — it is streets. When the plant is a district, the replica is the district: the geo-twin extrudes real IGN BD TOPO® building footprints over live IGN orthophoto imagery and binds the instrumented ones to their substation assets. It runs entirely on France’s open Géoplateforme: no Cesium ion account, no token, nothing calling home.

06 · What it does not do
This is control software, so the limits are stated rather than hidden. If either of these is what you need, say so on a call and we will tell you plainly where we are.
AI & agents
The copilot can read the plant, author a procedure and ask for it to be run. What it cannot do is decide how far it is allowed to go — that is granted to it, in writing, with a ceiling and an expiry, and enforced server-side on every request. AI is an accelerant, never a dependency: grounding, authoring, compilation, validation, dry-run and execution all run with no external model in the path, so the plant does not stop when an API does. A language model can be attached to widen what the copilot understands. Nothing load-bearing sits behind it.
The intent is resolved against the live twin: which assets, which tags, which limits, what is currently true. An intent that cannot be grounded is rejected here, not halfway through execution.
A Process Intent Representation is emitted and compiled to BPMN. Static validation reports the required capabilities, the authority class the procedure would need, and its blast radius.
The procedure is dry-run on an isolated twin. Commands are intercepted. The scenario’s assertions and the procedure’s own acceptance criteria are both evaluated against measured aggregates.
A human sees the proposal, the proof and the authority class it needs, then approves or rejects. Approval is what turns intercepted commands into real ones.
C0 read configuration · C1 read data · C2 propose · C3 reversible configuration change · C4 operational action · C5 high-consequence action · C6 safety-relevant action. Checked on the server on every command — a client cannot talk its way past it.
L0 advisory only · L1 propose, a human executes · L2 execute on approval · L3 autonomous, notify · L4 autonomous, review after. The bundled grid copilot is granted C4 / L1, with a justification and an expiry.
Each command is checked against the asset’s interlock set before it is issued. A failed check raises an incident; it is never retried around.
Confirmation reads an applied-setpoint echo written by the plant model or device, not the register the command just wrote. A tautological acknowledgement is not an acknowledgement.
Safety-classified actions require a different person to approve than the one who requested. The requester cannot self-approve.
One control halts agent-originated execution across the deployment, without taking supervision or acquisition down with it.

Capabilities
Acquisition, historian, HMI, twin, process automation and policy are not six integrations here — they are one system with one data model. Which is why a procedure can be grounded in the twin, proven against it, and executed through the same tag it was written for.
Real-time supervision on ISA-101 high-performance screens, backed by a continuously synced digital twin. Neutral grey is the resting state; colour means something is wrong.
An operator states what they want. The copilot grounds it in the live twin and emits a Process Intent Representation, which compiles to executable BPMN and is statically validated before anyone sees it.
The procedure is dry-run on an isolated simulation twin with a virtual clock and a seeded RNG. Field commands are intercepted. Assertions are evaluated against what the twin actually measured.
Approval issues real commands through interlocks, policy and read-back. Authority classes bound what an agent may ever request; autonomy levels bound whether it may execute at all.
A node-opcua client, a Modbus TCP master and an MQTT Sparkplug B subscriber southbound; northbound, an OPC-UA server with 693 AnalogItems, historical access from TimescaleDB and Alarms & Conditions. An external OPC-UA write passes the same interlocks and read-back as an operator’s.
Site, areas and assets carry an ontology type, aspects, a criticality and a safety classification. Twin nodes bind to the specific tags that express their state, with binding confidence — which is what lets a procedure be grounded rather than guessed.
Real building footprints over open orthophoto imagery, bound to their substation assets. Same tags, same alarms, same historian as every other surface — the scrubber replays the district from TimescaleDB.
A palette and a canvas with a tag-binding inspector. Equipment symbols per family, animated pipes and feeders, 2D and 3D from one screen record, and imported CAD tessellated in a worker and normalised to glTF-binary.
Authored as intent, compiled to BPMN, statically validated, published and executed by a token runtime. A step does not complete until its command’s read-back settles; a mismatch is a step failure.
PLY, PCD, XYZ and PTS point clouds rendered in the browser, coloured by scan or by height, with equipment annotations placed by click. Useful when the as-built and the drawing disagree.
Assets, tags, screens, alarm definitions, connections and processes snapshot into a signed, versioned project with a deployment mode of production, simulation or mixed. Export it, import it elsewhere, activate it to restore.
OPC-UA · Modbus TCP · MQTT Sparkplug B
1 Hz tick, per-connection scan rate
TimescaleDB (PostgreSQL 16), continuous aggregates
OPC-UA server — AnalogItems, HA, Alarms & Conditions, methods, audit events
ISA-101 high-performance, 2D and 3D, authored in-product
ISA-18.2 — priority, shelve, suppress, out-of-service, second-person ack
Interlocks, policy gate, independent read-back echo
English, French, German, Italian, Romanian
PIR → BPMN 2.0, statically validated, token runtime
Isolated twin, virtual clock, seeded RNG, intercepted commands
C0–C6 classes, granted per agent and scope with an expiry
L0 advisory → L4 autonomous with review
Bun · React 19 · TypeScript
SurrealDB 3.x (graph, vectors, full-text) + TimescaleDB
JWT (HMAC-SHA256) + Argon2id, server-side role gates
MCP server + REST, API-key scoped
Trust
DjiniousCC is API-first and self-hosted. It speaks the protocols your estate already speaks, stores its configuration as a signed artefact, and records who did what to which tag, when, and on whose authority. And because it runs against real plant, it refuses to fake.
A tag in LIVE mode takes its value from a device read or reports no data; simulation is labelled SIM on every asset that carries it; an unimplemented capability is shown as unimplemented rather than mocked; and a lost connection turns a lamp grey, never green.
HonestyYour SCADA, historian or MES connects to DjiniousCC as an OPC-UA server: AnalogItem nodes with engineering units and EU range, historical access served from TimescaleDB, and Alarms & Conditions with an acknowledgement round-trip.
InteropDjiniousCC roles map to OPC-UA well-known roles. Writable nodes carry explicit write permissions, so an anonymous session is read-only and an operator session is not an engineer’s.
InteropA write arriving over OPC-UA becomes a command: interlocks, policy and read-back, attributed to the session’s user. External systems get the same guarantees as the operator at the console.
InteropAn embedded MCP server exposes the platform to AI agents over API-key-scoped JSON-RPC, alongside the same REST API the product’s own front end uses.
InteropEvery command carries its requester, prior value, requested value, interlock result, approval record and read-back — including commands that originated from an agent or an external session.
GovernA published procedure records its authorship mode, its generation record, its validation report and its version — so ‘who wrote this and what was it checked against’ has an answer.
GovernGoverned writes and method calls raise OPC-UA audit events carrying the client user id, so an existing SIEM or historian can subscribe rather than scrape logs.
GovernA Docker Swarm stack: the Bun application, SurrealDB and TimescaleDB, behind your reverse proxy. Data stays on your infrastructure.
OperateThe server refuses to start with a default JWT secret or default database credentials, will not reflect arbitrary CORS origins, and has no seeded default admin password outside development.
OperateIf the historian is unavailable, trend views say so instead of drawing an empty chart. If a connection drops, its tags report not-connected and the lamps go grey.
OperateEnglish, French, German, Italian and Romanian, including data-driven labels such as asset kinds and operational statuses.
OperateIn the digital thread
DjiniousCC does its part of the engineering loop and passes its evidence along — and it works just as well on its own.
DjiniousCCOperations & SCADADjiniousCC is a complete SCADA system on its own: acquisition, historian, HMI, alarms, commands and the Digital Replica, self-hosted and licensed per site against the protocols your plant already speaks.
Commercial model
DjiniousCC is licensed per site — one physical plant — with nothing inside that site metered. No per-tag charge, no client seats, no screen count, no charge for the Digital Replica. There is no price list, because the number depends on your plant: tell us about it and we will quote it.
One site means one physical plant. Everything that plant needs to be supervised, historised, alarmed, drawn, automated and replicated is inside the licence.
Several plants under one operator are quoted as a group, not as the arithmetic of separate licences. One deployment can run every site in it — a single asset register, one tag namespace and one alarm list across the estate.
Three things are not in the per-site price, and we would rather say so here than in month three of a procurement.
Pricing is worked out on the call where we stand DjiniousCC up against your own tags — bring the site count, a rough tag count, the protocols in the field and what you need supported.
Use cases
5 worked cases.
District energyEuroméditerranée District Energy NetworkA seawater-source district-heating network: two intake pumps and two seawater exchangers feeding three heat pumps, two backup boilers and a stratified thermal store, distributing through two network pumps and a differential-pressure valve to thirty consumer substations. The network is simulated; the city under it is not — every substation sits on its real IGN BD TOPO® building footprint in the Euroméditerranée quarter. It is a demonstration network on open data, not any operator's plant.
Water & wastewaterVaucluse Water Treatment WorksA 42 Ml/d municipal drinking-water works: raw-water intake, coagulation, three ultrafiltration skids, UV and chlorine disinfection, clearwell storage and pressure-managed distribution.
Oil & gas midstreamCamargue Gas Processing SkidA midstream conditioning and export skid: emergency shutdown valve, two three-phase production separators, pressure control, two export compressors, interstage and export cooling, condensate export and a flare/relief system.
Food & beverage manufacturingBellini Foods — Aseptic Bottling Line 3A 24 000 bottles/hour aseptic PET line: blow moulding, aseptic filling, capping, labelling, case packing and palletising, with live OEE on every machine and its own utilities and CIP block.
Renewable generationProvence Hybrid PlantA 120 MW hybrid plant: six wind turbines, four PV inverter blocks, two battery racks, the main 33/225 kV transformer, the grid connection point and a meteorological mast.Book a demo
A working session, not a slide deck. Ninety minutes. Bring a tag list and one procedure you actually run. We will stand it up and prove it — or tell you plainly which part DjiniousCC does not do yet.
Along the thread