Virtual PLC Safety Boundary
Control Seat's Virtual PLC is not a safety controller. It has no SIL or PL rating and must not replace a safety relay or safety PLC.
Keep safety independent
Safety functions must continue to work when the Virtual PLC is powered off, faulted, restarting, or being updated.
Safety devices → certified safety relay or safety PLC → contactor, STO, or power removal
│
└─ status only → Control Seat Virtual PLC
Use certified safety hardware for E-stops, guards, light curtains, two-hand controls, safe torque off, muting, and other protective functions. The Virtual PLC may read the safety system's status for indication and normal sequencing, but it must never be the only path that permits or stops hazardous motion.
Appropriate uses
The Virtual PLC is intended for ordinary, non-safety control such as:
- sequencing and interlocks that are not protective functions;
- process regulation and utility control;
- batching and material handling;
- data acquisition, alarming, and HMI coordination; and
- supervisory coordination with existing equipment.
Important operating limits
- Program changes require a planned stop. Publishing is a controlled stop-and-swap; true online editing is not available.
- Recent retained changes can be lost on sudden power removal. Allow for a window of up to five seconds.
- Connection-loss behavior must be selected and tested. Never assume that a disconnected output automatically moves to a safe value.
- Standard Ubuntu is soft real-time. Timing must be measured on the exact application and hardware being commissioned.
Commissioning checklist
Before the process is allowed to run:
- Prove the safety system operates with the Virtual PLC powered off.
- Prove it operates while the Virtual PLC is faulted or restarting.
- Confirm no Control Seat output is the sole safety permissive.
- Disconnect each I/O adapter and verify the configured response.
- Remove power and verify retained-state and restart behavior.
- Measure scan timing with normal communications, logging, and background workload active.
- Record the tested hardware, software version, wiring, and results.
The PLC Timing and Fault Behavior and Supported PLC I/O pages describe the current operational behavior in more detail.