WeEngineerBetter Ignition gateway analysis

How it works

Four steps. About two hours of your time.

Fifteen minutes to scope, a file transfer, and an hour on the walkthrough call. The rest happens without you in the room.

  1. Scoping message — 15 minutes of your time

    Tell us the Ignition version, roughly how big the system is, and what is bothering you. We confirm which gateway tier applies, count the PLCs and database connections, and give you the total. If your legal team needs an NDA signed first, we sign it before you send anything. No charge for this step, and if we are not the right fit we will say so here.

    How we know the tier before you pay. The installed-module list is readable straight from the gateway backup header. That tells us whether Sepasoft, Cirrus Link, or a custom module is in play, so you are quoted once and never upgraded mid-engagement.

  2. You send a sanitized backup

    Strip the following before the file leaves your building. The safest way to protect a secret is to never send it:

    • Recipes, setpoint libraries, and formulation data
    • Process parameters that constitute trade secrets
    • Customer names, order data, and production records
    • Serial numbers, license keys, and stored credentials
    • Historian values — we need the configuration, not the data
    • Anything your legal team would not want sitting in an email

    Transfer happens however your IT department prefers — your SFTP, your file share, your cloud link. We never connect to your live gateway and we never ask for VPN access.

    Never taken a gateway backup, or want a second pair of eyes while you sanitize it? We will get on Teams or Google Meet and walk through it with you. Twenty minutes, no charge, and it happens before any money changes hands.

  3. We analyze — AI reads it, an engineer verifies it

    Anyone can point an AI at a gateway backup and get back forty pages of output. That part is not the service, and it is not what you are paying for.

    What you are paying for is the pass that comes after: every finding checked line by line against your actual configuration, with the wrong ones deleted before you ever see them. Raw output on a system this complex always contains findings that read beautifully and are simply not true. Those are the expensive ones — the ones that send an engineer down a two-day dead end.

    That review is done by an Ignition Gold Certified engineer who has built and maintained these systems in production, not by a second AI pass.

    Turnaround is 3–5 business days from the moment the files land. Rush turnaround of 48 hours is available. We do not work weekends or holidays, so those are not counted — we would rather quote honestly than promise a Sunday.

  4. Packet delivered, then a month of questions

    You get the packet, plus a one-hour walkthrough call scheduled whenever suits your team. After that, thirty days of email questions are included — if your engineers hit something in the plan that is not clear, they ask, we answer, and there is no clock running.

    Your own team does the remediation work, on your schedule and inside your own downtime windows. We are not onsite for it, we are not billing hourly while it happens, and there is nothing further to buy.

    The walkthrough call and the 30-day window are per engagement, not per item — one call covers the gateway, every PLC, and every database in the same job.

The review

What we commit to — and what we don't

Written plainly so that both sides know where they stand before anything is signed.

What we commit to

  • An Ignition Gold Certified engineer personally reviews every finding against your files
  • Findings that are wrong, irrelevant, or unsafe to act on are removed before delivery
  • What remains is re-ranked by real-world risk, not by what a model found interesting
  • Every finding points at a specific object in your system, so you can verify it yourself
  • Anything we could not fully inspect is labelled as such rather than glossed over
  • If you find an error, we correct the packet at no charge

What we do not claim

  • That the analysis is exhaustive. It is thorough and careful; it is not a guarantee that nothing was missed.
  • That it is a certification, an audit, or a safety review, and it should not be presented as one to a regulator or an insurer.
  • That it replaces your own engineering judgment on a live system.
  • That we understand your process better than the people who run it every day.

Everything we deliver is advisory. You and your engineers decide what changes and when, and you remain responsible for those changes. Our liability on any engagement is limited to the fees paid for it.

Why you can check our work. Every finding names a specific project, tag, script, routine, table, or connection in your own system. Open the backup and look. That is a deliberate design choice, and it is what makes this arrangement worth trusting at this price.

Data handling & paperwork

Your private data stays out of scope entirely

We do not want your recipes and we do not need them. The strip-list in step 2 exists so the sensitive material never reaches us in the first place.

How your files are handled

  • Encrypted storage, access limited to the engineer on your engagement
  • Never used to train any model, ours or anyone else's
  • Never shared outside the engagement
  • Deleted 90 days after delivery — or immediately, if you ask
  • Transferred however your IT department prefers, on their systems

If something proprietary reaches us anyway, we flag it, we do not analyze it, and we destroy it on request.

NDAs and what we never do

We sign your NDA — yours, not ours — before you transfer a single file. If you need a mutual NDA and do not have one, we provide a straightforward one you can mark up. Certificates of insurance, W-9, and vendor onboarding forms on request.

  • Connect to your live gateway
  • Ask for VPN or remote access to your network
  • Make changes to your system
  • Name you or reference your system publicly without written permission
  • Add you to a mailing list

Which AI reads your files, and why that one

The analysis runs on Claude, from Anthropic, through their commercial API. Two reasons, and neither one is brand preference.

The data commitment is in writing, and you can check it without trusting us. Anthropic's commercial terms state that customer inputs and outputs are not used to train their models. The one documented route by which commercial API content can reach training is the customer explicitly submitting it as model feedback — we never do that with your files. That is what stands behind the “never used to train any model” line above; it is a term you can read yourself, not a promise we invented.

The failure mode that costs you money is confident wrongness. On a system this size, a fabricated finding is more expensive than a missed one — a missed finding leaves you where you already were, while an invented one sends an engineer down a two-day dead end. Anthropic publishes the principles its models are trained against, and those principles put honesty and saying “I am not sure” ahead of sounding useful. On a gateway backup, that is the property worth buying.

None of which makes it correct every time, and we will not pretend otherwise. That is exactly why an Ignition Gold Certified engineer checks every finding against your actual configuration before you see it. The tooling choice reduces how much there is to catch. It does not replace the catching, and it never will.

That is the whole process.

Fifteen minutes of scoping tells you whether this is worth doing on your system. If it is not, we will say so and it will have cost you nothing.

Start a conversation