Infusion-pump configuration
Can startup and control logic reach a declared over-delivery state under a reviewed configuration and environmental model?
Use cases
These examples show evaluation targets, not certified product claims. Each requires a reviewed model, assumptions, property and horizon.
Can startup and control logic reach a declared over-delivery state under a reviewed configuration and environmental model?
Can an illegal actuator command survive a bounded fault, watchdog and reset sequence?
Can motion enable remain asserted while a modelled guard, limit or emergency-stop condition is active?
Do structurally repeated channels preserve the declared property under exact composition and independent replay?