Available for pilots
One AI-native platform for the renewable grid
Ozari brings real-time control, grid intelligence, cyber defence and open data into one hardened system. You run it on your own servers, even with no internet connection.
What is in the platform
Four capabilities, one system
Each capability uses the same safety gate, the same identity and the same audit trail. You license the modules you need.
Available for pilots
Ozari Grid
The AI-native control room for DER-heavy networks: real-time control, outage restoration and DER orchestration.
In AI-EMS
ozari+
Self-improving grid intelligence: forecasts, anomalies, asset health and advice with reasons. It never operates.
Built in · Defend early access
Cyber defence
Identity, authenticated reads and tamper-evident audit in every deployment, plus Ozari Defend for the wider OT estate.
Available
Data Exchange
One open data layer: six field protocols through a fault-isolated gateway, CIM/CGMES models, historians and security analytics.
How it works
One loop, from the field to a decision and back
Each part of Ozari has one job in the loop. The step in the middle, the decision, always belongs to your people.
What is different
Built differently from a traditional control system
How control-room software is often built and bought, and what Ozari does instead.
| Often today | With Ozari | |
|---|---|---|
| AI | A separate analytics tool, or automation that is hard to explain. | Built in and advisory. Every output shows its confidence and reasons, and the AI has no command path. |
| Getting better | New features arrive with the next vendor release. | ozari+ recalibrates to your network as it runs. New model generations are proven in shadow and promoted by people In development |
| Automation | On or off for a whole function. | Earned in stages: off, advise, confirm, auto. Set per action class and zone, with rate limits and a kill switch. |
| Footprint | Many servers, databases and third-party packages to patch. | One binary of about 6 MB, with zero third-party Go packages in the core. |
| Where it runs | A large on-premise stack, or a vendor cloud. | Your servers, air-gapped if you choose. Offline licence and no call-home. |
| Security | Added around the system after it is built. | Built in: multi-factor sign-in, single sign-on, authenticated reads, a tamper-evident audit and fail-closed behaviour. |
| Adoption | Replace the old system in one large cutover. | A read-only shadow pilot first, then a staged cutover, area by area. |
| Proof | Claims in a datasheet. | Test results and known limits, published on this site. |
Design principles
Principles we will not trade away
They decide how Ozari behaves when something goes wrong, not just when everything goes right.
Advisory-only AI
ozari+ has no command field and no route to the field. It explains and proposes.
Two people per command
Operator commands need two different people. The approval is bound to the exact command.
One writer at a time
A single-writer control lease and crew safety tags are checked again just before a device moves.
A record you can check
Every action lands on a SHA-256 hash-chained, write-once log. It is tamper-evident.
Fail-closed
If the licence, audit chain, disk or data is not right, Ozari stops and says why. It never guesses.
Small and self-contained
One binary of about 6 MB, with zero third-party Go dependencies in the core.
Sovereign by default
No call-home. Features that reach the internet are off until you turn them on.
Prove before control
Every engagement starts with a read-only shadow pilot beside your current system.
How a command moves
ozari+ proposes. People and interlocks decide
Closed-loop functions such as self-healing and volt/VAR control stay off until an administrator arms them. Once armed they can act without a per-action approval, but never without the interlocks, the control lease and the audit.
When things go wrong
Safe when something fails, and clear about why
A control system matters most on the day something breaks. This is what Ozari does.
| If this happens | Ozari does this |
|---|---|
| The primary server fails | The standby takes control. In our lab test it took 5.7 seconds. A standby never operates until it holds the control lease. |
| Data goes stale or bad | Every value carries its quality. Ozari stops and says why, rather than act on data it cannot trust. |
| The audit chain breaks, or the disk fills | Ozari stops and says why, so no action can happen without a record. |
| The licence is missing or invalid | Ozari stops and says why. The licence is offline and signed, so checking it needs no internet link. |
| A crew has tagged a device | Commands to that device are blocked. Tags are checked again just before anything moves. |
| Only one operator is on shift | Commands that need approval wait for a second person. Automation armed in advance keeps working in its zone, with interlocks and audit. |
| ozari+ is wrong, or switched off | Nothing moves because of it. ozari+ has no command path, and the control room runs normally without it. |
| A field protocol stack crashes | The fault stays in its gateway process. The control plane keeps running. |
| Someone reads data without signing in | The answer is 401. Every read needs a valid session, including the live stream. |
Deployment
Runs where your control room runs
| Item | Detail |
|---|---|
| Form | One self-contained binary of about 6 MB, with the operator console built in. |
| Where it runs | On-premise or fully air-gapped. Linux and macOS bundles. Windows through Docker. |
| High availability | Primary and standby with a shared control lease, on one host or across several. In our lab test the standby took control 5.7 seconds after the primary crashed. |
| Licensing | Offline and signed. No call-home. |
| Identity | Role-based access, TOTP multi-factor authentication and OIDC single sign-on. |
| Audit | SHA-256 hash-chained, write-once audit, streamed to your security analytics platform as syslog or CEF. |
| Monitoring | Prometheus metrics, alert rules and a Grafana dashboard. |
| Integration | Six field protocols through a fault-isolated gateway, CIM/CGMES models and historian export. See protocol status. |
Editions
Start with SCADA. Grow into ADMS and AI
| Edition | What it includes |
|---|---|
| SCADA | The operations core: live single-line, alarms, commands with two-person approval, safety tags, switching, trends and historian export. |
| ADMS | Everything in SCADA, plus outage management, fault location and restoration (FLISR), volt/VAR optimisation, DER management, state estimation and analytics. |
| AI-EMS | Everything in ADMS, plus ozari+, branded reports, high availability, single sign-on and links to peer control centres (ICCP, lab-grade). |
Beyond power
One kernel, many industries
Ozari Base is industry-neutral. The safety gate, audit, identity and drivers are shared, and each industry is a module on top. Power distribution is available today. Generation and renewables is in the final stages of completion. Transmission, water, oil and gas, manufacturing and transport are on the roadmap.
- Power distribution · Available
- Generation and renewables · Final stages
- Transmission · Roadmap
- Water · Roadmap
- Oil and gas · Roadmap
- Manufacturing · Roadmap
- Transport · Roadmap
Start safely
Begin with a read-only shadow pilot
Ozari runs beside your current systems, sees the same data and issues no commands. You measure the value with your own data before anything changes.