Evidence updated June 2026

Measured, not asserted

How we build and test Ozari, what the tests found, and the limits we state openly. All results come from our own development and lab environment.

19.8M

Fuzzing executions across the IEC 104, DNP3, Modbus and gateway parsers. Zero crashes.

5.7 s

For the standby to take control after a simulated crash of the primary.

0

Third-party Go packages in the control plane, and zero data races under the race detector.

401

The answer to every read, including the live stream, without a valid session.

Internal verification results from the Ozari development environment (test report dated June 2026).

Evidence log

Break it on purpose, before the field does

Our tests assume the network, the devices and the operators will all do something unexpected. Each record says what we tested, how, and where the result is written down.

EV-01 · Quality

41/0

Test packages passing and failing

Unit and integration tests run on every package in every build of Ozari Grid.

Test report · June 2026

EV-02 · Quality

0

Data races

The race detector runs across the whole code base. It found three real races, which are now fixed.

Test report · June 2026

EV-03 · Protocols

19.8M

Fuzzing executions, zero crashes

Coverage-guided fuzzing of the IEC 104, DNP3, Modbus and gateway parsers, with a corpus replay for regressions.

Test report · June 2026

EV-04 · Resilience

40

Hostile connections at once

Malformed, oversized and truncated frames, then a 40-connection flood against a live gateway. No panic and no leaked connections.

Test report · June 2026

EV-05 · Resilience

5.7 s

Failover to the standby

We crash the primary server and time the takeover. The standby took control in 5,662 ms.

Test report · June 2026

EV-06 · Quality

59/59

Deployment validation checks

The deployment validation suite. All 59 checks pass and none fail.

Test report · June 2026

EV-07 · Protocols

18/18

IEC 60870-5-104 conformance tests

The conformance suite, run against the native IEC 104 driver.

Conformance report

EV-08 · Security

401

For every read without a session

A read-authentication matrix checks that every endpoint, including the live stream, rejects anonymous reads.

Test report · June 2026

EV-09 · Security

54 → 0

Open readiness findings

Our own readiness audit found 54 issues, 9 of them critical. All are fixed, with 18 new regression tests.

Readiness audit

EV-10 · Protocols

Live lab

Vendor reference servers

Certified IEC 104 and IEC 61850 gateways streamed data from vendor reference servers. A DNP3 control round-trip worked, and two-person control operated a reference IED.

Commissioning notes

EV-11 · Protocols

50/50

Field input and output operations

The Ozari Base regression suite over IEC 104 and IEC 61850, against simulated devices.

Regression report

EV-12 · Security

0

Third-party Go packages in the core

The control plane is one static binary, and it never speaks raw field protocols. Those stay behind the fault-isolated gateway.

Test report · June 2026

Ask for the evidence pack to see the reports behind each record. All records come from our development and lab environment.

Standards

Security standards and best practice

Ozari conforms to the requirements of ISA/IEC 62443 and follows recognised practice for securing operational technology. Each line says how.

StandardStatusWhy it matters
ISA/IEC 62443Conforms Conforms to the requirements of the ISA/IEC 62443 series, with zones, conduits and an evidence map for each requirement. Target security level SL 2.The main security standard for industrial automation and control systems. The evidence map saves your assessor time.
IEC 62351-3 and -4Built in Mutual TLS in the Ozari Base protocol drivers, following IEC 62351.Security for power-system protocols: encrypted, authenticated links to the field.
NIST SP 800-82 Rev. 3Followed Segmented zones, an OT DMZ, one-way data to the enterprise and fail-closed behaviour follow its guidance.The US guide to securing operational technology, used by utilities around the world.
Secure by designBuilt in Memory-safe Go, multi-factor authentication, role-based access, a tamper-evident audit and fail-closed behaviour are part of the product.Joint guidance from the Australian Cyber Security Centre, CISA and partner agencies: security is the vendor’s job, not an add-on.
Software supply chainPractised A software bill of materials, signed images, zero third-party Go packages in the control plane, fuzzing and race testing. SLSA level 1 to 2 practices in the build.Integrity of the software, from source code to the binary you run.
NIST Cybersecurity Framework 2.0Supports Ozari controls support its protect, detect, respond and recover functions.A common language for cyber risk across IT and OT.
AESCSFSupports Controls and evidence help energy operators reach their target maturity.The Australian Energy Sector Cyber Security Framework, used to assess and improve cyber maturity across the energy sector.
NERC CIPAligned to intent Aligned to the control intent. Whether it applies is the utility’s decision.North American security rules for the bulk power system. Most distribution networks are outside their scope.
ISA-18.2Built in Alarm performance metrics are built in. Alarm rationalisation remains the operator’s task.The alarm management standard. It helps keep alarm floods and standing alarms under control.
IEC 61970 / 61968 (CIM, CGMES)Tested Core-class import and export, round-trip tested.The common model for network data, so models move between tools without being typed in again.
OCSF and MITRE ATT&CK for ICSMapped Findings emitted in OCSF. Detections mapped to ATT&CK for ICS techniques. Mappings, not guarantees.Shared formats and terms, so your security team can use the findings in its own tools.
Field protocolsVaries See the protocol status table.Each protocol is labelled by how far it has been proven.

Known limits

What we want you to know up front

  • All figures on this page come from our development and lab environment.
  • The audit is tamper-evident. Anchoring the chain outside the server is part of go-live.
  • Automation that an administrator arms, such as self-healing, skips the per-action approval. It never skips the interlocks, the lease or the audit.
  • Some protocols are lab-grade or in development. The protocol table says which.
  • Screens on this site show simulated data from the Ozari lab network.

Security disclosure

Found a vulnerability? Tell us privately

Please report it through our contact form and choose “Something else”. Include enough detail for us to reproduce it. We will acknowledge your report and work with you on a fix and on disclosure.

Responsible AI

ozari+ advises and never operates, and it can never approve its own improvements. Read how it is designed around the December 2025 AI-in-OT principles, or get our free buyer’s checklist.

Start safely

Begin with a read-only shadow pilot

Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.

Secret Link