Engineering responsibility
DA Synergie software is intended to assist qualified industrial professionals in building automation and visualization systems. It does not eliminate the need for competent design, risk assessment, rigorous validation, testing, and independent safety systems.
DA Synergie is responsible for PLCMaker and PLCRuntime according to the products’ documented specifications, contractual terms and applicable law.
DA Synergie does not control and therefore cannot warrant: arbitrary customer operating-system configurations; arbitrary customer hardware; customer network engineering; third-party remote-I/O configuration; third-party device firmware; machine electrical design; machine safety architecture; customer PLC application logic; or independently configured third-party fail-state behavior.
Qualified platform responsibility
PLCRuntime is designed for deployment on a DA Synergie-qualified real-time operating-system platform. Deterministic execution and timing characteristics apply only to operating-system, hardware and runtime configurations specifically qualified and documented by DA Synergie.
General-purpose operating systems and non-real-time configurations may allow PLCRuntime to execute for development, evaluation, simulation or other appropriate uses, but they are not considered deterministic PLCRuntime production platforms. See PLCRuntime — Real-Time Platform.
Customer and integrator duties
- Validate software behavior in the intended application before production use.
- Implement independent safety measures, including emergency stops, interlocks, guarding, and protective relays where required.
- Document application logic, operator procedures, and maintenance activities.
- Use the software in accordance with applicable codes, standards, and regulatory requirements.
- Configure and validate communication-loss and remote-I/O fail-state behavior for the actual devices and topology used.
- Select hardware, networks and configurations appropriate to the machine or process risk assessment.
See the Safety Notice for fail-safe system design, HMI supervisory boundaries, and independent safety-function principles.
HMI supervisory boundary
HMIMaker and HMIViewer are supervisory/operator interfaces, not machine safety systems. Required emergency stopping and safety functions must not depend solely on the HMI. Loss of HMI, communications, or process-data availability must be considered in system design and commissioning. See the Safety Notice — HMI supervisory software.
Industrial networks and remote I/O
PLCRuntime may communicate with industrial devices and remote I/O using technologies such as EtherNet/IP and Modbus.
The behavior of the complete control system depends not only on PLCRuntime but also on infrastructure and equipment outside DA Synergie’s control, including:
- Network switches
- Cabling
- Network topology
- Power supplies
- Remote I/O hardware
- Third-party device firmware
- Device configuration
- Communication timeout settings
- Network loading and performance
Industrial communications may be interrupted, delayed or unavailable. The system designer or integrator is responsible for designing, configuring and validating the network and control architecture appropriate to the application.
Remote I/O fail-state configuration
Remote I/O devices may implement their own communication-loss and fallback behavior independently of PLCRuntime.
Depending on the device and its configuration, an output may:
- De-energize
- Retain its last state
- Assume a configured fallback state
- Or behave according to another manufacturer-defined failure mode
Some remote I/O products store this configuration within the I/O device itself using manufacturer configuration software.
PLCRuntime cannot override or guarantee independently configured fail-state behavior of third-party hardware after communication with that hardware has been lost.
The system designer or integrator is responsible for configuring and validating the required communication-loss behavior of each remote I/O device. Where the machine risk assessment requires a device to assume a particular state following communication loss, the remote I/O hardware and its configuration must be selected and commissioned accordingly.
Communication-loss behavior of Modbus and other remote I/O families can depend on the specific device and configuration and must be verified during commissioning. Do not assume that remote outputs automatically go to zero for every device or setup.
Communication and failure testing
As part of commissioning, the machine builder or system integrator should validate the behavior of the actual installed system under foreseeable failure conditions appropriate to the application.
This should include, where applicable:
- Controller / runtime interruption
- Loss of control power
- Loss of network communication
- Loss of a remote I/O island
- Communication timeout
- Remote-I/O fail-state
- Stale or invalid input data
- Restoration of communication
- Runtime restart
- Host-system restart
- Power cycle
- Independent safety-system operation
The objective is to verify that the selected hardware, configuration and system architecture produce the intended machine or process response. DA Synergie cannot define the safe state of every customer’s machine; that determination belongs to the machine or system designer.
Scope of software
The software provides visualization, communications, automation runtime, and data acquisition capabilities. It is not a substitute for certified safety controllers, functional safety systems, or machine-specific safety hardware.
Change management
Any changes to the control application, hardware, or operational procedures must be reviewed and validated before being deployed in production.
Risk awareness
Systems using DA Synergie software should be treated as part of a safety-critical environment when they control or monitor equipment that can cause injury, property damage, or environmental harm.
Failures of the runtime, host computer, network, switches, remote I/O, third-party hardware, power, or ordinary control logic must be considered in the machine or system risk assessment.