Skip to content
CHINOOKRequest early access

Is your cooling plant telling the truth?

CHINOOK checks every sensor, meter and status point in a liquid-cooled AI data hall against physics and against each other. It proves the plant follows its sequence of operations, and it attaches the evidence to every finding. It reads your systems. It doesn't control them.

Illustration: a cold aisle in a liquid-cooled data hall. CHINOOK flags coolant distribution unit CDU-02, whose flow meter reads 22 percent low according to the heat balance.

Demo site kol-dc1, CDU-02 simulated, updating live

Supply
32.0 °C
Return
42.2 °C
Flow, as metered
1,330 L/min
IT load
1.14 MW
Flow truth score
41 / 100

Two questions every commissioning lead has to answer

Liquid cooling puts thousands of new sensors between your IT load and your plant. Before you hand a hall over, and every day after, you need to know they're right and that the plant responds the way the design says it will.

Flow meter1,331 L/min, reads 22 % lowSupply RTD32.0 °C, trustedReturn RTD42.3 °C, trusted

Is the plant telling the truth?

Sensors freeze, drift, get scaled wrong and get mapped to the wrong pump, and the BMS still shows green. CHINOOK runs sixteen checks on every point and gives every instrument a truth score you can defend in front of an owner.

Pump A, leadtripped at 12:04:06Pump B, lagrunning 3.2 s later, pass

Does the plant do what the sequence says?

Turn the sequence of operations into test specs. On test day, grade every expectation against live data as pass, fail or inconclusive, with the trend plot and the action log attached.

Watch a flow meter get caught

Heat removed has to equal heat produced. CHINOOK computes Q = ṁ·cp·ΔT from the loop's own flow and temperature sensors, compares it with the IT load from the power meters, then fits every explanation for the gap and keeps the one the data supports. Inject a fault and watch it work.

7008009001,0001,1001,2001,3001,40000:0006:0012:0018:0024:00
IT load from power metersHeat removed, from flow × ΔTkW, CDU-02, last 24 h (simulated)
Mean IT load
1,163 kW
Mean sensor heat
908 kW
Balance gap
-22.0 %
Competing explanations, best fit first
ExplanationResidual
Flow meter scalingreads 22 % low3 kW
Supply RTD offset+2.86 K19 kW
Points belong to CDU-03follows CDU-03 at 1.10×71 kW
Sensors are rightno correction256 kW

Most likely the flow meter's scaling: it reads 22 % low. Correcting the scale factor closes the balance to within 3 kW.

Evidence: rule C07 heat balance, 24 h window at 10-minute resolution, 4 hypotheses fitted

Sixteen checks on every point

The results roll up into a truth score for every instrument, laid out by equipment so a bad sensor is obvious at a glance. On live sites the checks rerun every 15 minutes. Every cell carries a number and a symbol, never colour alone. Select one.

Signal checks

Is each sensor behaving like a working instrument?

C01 Flatline
Stuck sensors, using a coupling test so a held setpoint isn't flagged
C02 Spike
Impulsive outliers
C03 Range
Values outside engineering limits
C04 Noise
Abnormal noise and dead-band chatter
C05 Redundancy
Disagreement between redundant sensors
C06 Drift
Slow calibration drift
C14 Unit plausibility
Wrong units or magnitude

Physics checks

Do the readings obey conservation of energy and the pump laws?

C07 Heat balance
Q = ṁ·cp·ΔT against IT load, with the cause attributed
C08 HX balance
Heat exchanger primary against secondary energy
C09 Pump affinity
Flow, head and power against the affinity laws
C10 System curve
Operating point against the system curve, such as a clogging strainer
C11 Dew point
Supply temperature margin above the dew point

Control checks

Does the control system do what it is told?

C12 Loop performance
Oscillating or poorly tracking loops
C13 Valve stiction
Position against command
C15 Command and status
Commanded on, reported off
C16 Alarm routing
Alarms that never fire or never reach anyone
Truth score for every point, by equipment and point type. Select a cell for detail.
Supply tempReturn tempFlowDiff. pressureValve positionPump status
CDU-01
CDU-02
CDU-03
CDU-04
HX-1–
Pump P-2A–––
Pump P-2B–––

CDU-02 flowtruth score 41, finding

C07 heat balance. Flow × ΔT is 22 % below the IT load all day. Flow-meter scaling explains it far better than an RTD offset or a mapping error.

Test day, with a record nobody argues about

The sequence of operations becomes a short spec that your Cx lead approves. A technician performs the stimulus and logs it on a tablet, offline if needed. CHINOOK never actuates anything. It reads the response and grades each expectation, and missing data is graded inconclusive, never a silent pass.

test: cdu_lead_pump_failover
dsl: "1.0"
bind:
  cdu:   "$equipment"
  pumpA: "$cdu/hasPart[Pump][role=lead]"
  pumpB: "$cdu/hasPart[Pump][role=lag]"
  flow:  "$cdu/feeds[TCS_Loop]/hasPoint[Water_Flow_Sensor]"
preconditions:
  - pumpA.status == RUN
  - pumpB.status == STANDBY
stimulus: {text: "Open Pump A breaker", action: manual_trip}
expect:
  - id: lag_start
    within: 5s
    that: pumpB.status == RUN
  - id: flow_recovery
    within: 15s
    that: flow >= 0.9 * design(flow)
    measure: time_to_true
  - id: alarm_routed
    within: 10s
    that: alarm(pumpA.fault).state == ALARM
evidence: [trend_plot, alarm_excerpt, action_log]

Run on CDU-02, live

Stimulus logged on the tablet by the commissioning engineer

Pump APump BFlowAlarm90 % of design flowStimulus: open Pump A breaker0s10s20s30s40s
  • PassLag pump runs within 5 sran 3.2 s after the stimulus
  • PassFlow back to 90 % of design within 15 s13 s ± 1 s (1 Hz sampling)
  • InconclusivePump A fault alarm within 10 sno alarm data from 2 s to 30 s after the stimulus

2 pass, 1 inconclusive. The alarm path gets re-tested before sign-off. A gap in the data is never graded as a pass.

One spec, every CDU

Specs bind to the approved equipment graph, not to point names, so the same failover test runs on CDU-01 through CDU-40.

It keeps checking after handover

Every 15 minutes, CHINOOK reruns the checks against a baseline frozen at handover and flags drift with both values side by side.

Real events become tests

When a pump really trips at 3 a.m., CHINOOK grades the response against the handover spec and opens a finding if the plant has regressed.

Live data that survives a bad uplink

A small edge agent sits on your plant network and only makes outbound connections. Alarm rules run on the edge itself, so a critical alert doesn't wait for the cloud. Cut the uplink and see what happens.

  1. Plant systems

    BMS, CDU controllers, power meters and historians, over Modbus, BACnet/SC, OPC UA or MQTT. Read requests only.

  2. Edge agent on site

    Polls each device under a signed polling plan, runs tier-0 alarm rules locally, and buffers to disk when the uplink drops.

    Buffered on the edge: 0 samples

  3. CHINOOK cloud

    Stream workers, all sixteen checks every 15 minutes against a frozen baseline, findings, tests and reports.

  4. Your tools

    PagerDuty, Opsgenie, ServiceNow, Maximo, Slack or Teams, and signed webhooks. Only CHINOOK's own records.

Uplink connected

  • Uplink connected. Samples reach the cloud about a second after they are read.

Reads the systems you already run

Every connector version is certified against a simulator of the vendor's documented interface before an edge agent will load it. The certification includes a test that the vendor system saw no write.

Building management

  • BACnet Secure ConnectHub client, TLS 1.3 mutual auth, ReadProperty onlyreads
  • Johnson Controls MetasysREST APIreads
  • Schneider EcoStruxure Building OperationWeb servicesreads
  • Niagara and Project HaystackHaystack RESTreads

PLCs and industrial

  • Modbus TCPFunction codes 01 to 04 onlyreads
  • OPC UABrowse, read, subscribe; Basic256Sha256, sign and encryptreads
  • OPC UA virtual pointsDerived points from server-side calculationsreads
  • MQTT Sparkplug B 3.0Subscriber; a DEATH message marks the data as lostreads

Cooling and IT

  • RedfishRack and CDU cooling telemetryreads
  • Prometheus and NVIDIA DCGMGPU power and temperaturereads
  • SlurmREST API, job and queue statereads
  • KubernetesAPI, workload and node statereads

DCIM

  • Sunbird dcTrackAssets, power chains, rack layoutreads
  • NlyteAssets and capacityreads

Electrical and grid

  • COMTRADEDisturbance records from protection relaysreads
  • OpenADRDemand-response events, listen onlyreads
  • Weather and grid signalsAmbient conditions and grid signalsreads

Design and commissioning

  • IFC modelsEquipment and topology from BIMreads
  • Design collaborationProject documents for sequence extractionreads
  • Cx platformsIssues and checklists; CHINOOK edits only its own recordssends

Maintenance and ticketing

  • IBM MaximoWork orders from findingssends
  • SAP PMNotifications from findingssends
  • ServiceNowIncidents and changessends

Paging and chat

  • PagerDutyAlerts with de-duplication keyssends
  • OpsgenieAlertssends
  • Slack and Microsoft TeamsAlert and finding messagessends
  • SMS webhookHMAC-signedsends
  • EmailSMTPsends

Data platforms

  • MQTT publishFindings and verified data to your brokersends
  • Kafka RESTFindings and verified data to your topicssends

Product names belong to their owners. Listing shows interface compatibility, not a partnership.

Read-only by default. Writes only when you've earned them.

Most sites never go past recommendations. For those that want CHINOOK to adjust setpoints, autonomy is earned one level at a time, per site, and each gate records who signed it off and when.

  1. L0

    Observe

    Findings, truth scores and tests. Nothing leaves CHINOOK but reports and alerts.

    Requires The default for every site.

  2. L1

    Recommend

    A suggested change, with its evidence and the expected effect.

    Requires Available once findings have a track record.

  3. L2

    Hand off

    A pre-filled change lands in your BMS or CMMS workflow. Your team makes it. CHINOOK writes nothing.

    Requires Your opt-in.

  4. L3

    Supervised write

    One bounded setpoint after a named approval, two people for critical points. Signed, expires in 60 minutes, reverts on its own if the plant misbehaves. For the first 90 days: supply temperature within 1.0 K and pump ΔP within 5 % only.

    Requires Operations and insurer sign-off, an independent IEC 62443-4-2 assessment of the on-site Actuator, kill switch and auto-revert tested on site.

  5. L4

    Bounded autonomy

    Moves pre-approved setpoints inside an agreed envelope, only when the digital twin gives at least 95 % confidence that every limit holds.

    Requires Six months at L3 with zero incidents, and a contract change.

Never in scope, at any level

  • Life safety
  • Fire
  • Emergency power off
  • Breakers
  • Transfer switches
  • Leak-isolation valves
  • Interlocks
  • Protection settings

Rejected by the cloud before a request is created, and again by the Actuator on site when it reads its policy.

AI that has to show its work

In critical infrastructure, a confident wrong answer is worse than no answer. CHINOOK is built so that everything it tells you can be traced, checked and audited.

  • Code decides, language models explain

    Deterministic checks decide what is true. Language models draft explanations and answer questions, and every claim they make must cite evidence or it isn't shown.

  • Evidence on every finding

    The rule and its version, the data window, the competing explanations with their residuals, a plot, and a SHA-256 hash over all of it.

  • Read-only by construction

    Inbound connectors get an HTTP client that only allows reads, and the protocol drivers contain no write encoders. Static scans and runtime guards check both.

  • Tenant isolation in the database

    PostgreSQL row-level security sits beneath the application, so a bug in the app can't show one customer another's data.

  • Your identity provider

    Single sign-on through Okta, Entra ID or Google, SCIM 2.0 provisioning, and scoped API tokens that always expire.

  • Signed all the way to the edge

    Connector certification reports, polling plans and alarm rule sets are signed. An edge agent refuses anything unsigned, and every action is audited.

Start with the data you already have

Early-access sites start with a trend audit on an export. Live data and on-site testing come after, once you've seen what CHINOOK finds.

  1. 1

    Send a historian export

    CSV, Excel or Parquet from your BMS or historian. No hardware and no network access to your site.

  2. 2

    Review the mapping

    CHINOOK proposes what every point is, in Brick, and says why. Your engineers approve from the keyboard.

  3. 3

    Get the trend audit

    Sixteen checks across every point, a truth score for each instrument, and a report with the evidence attached.

  4. 4

    Go live

    Add the edge agent for live data, run integrated systems tests on site, and keep checking after handover.

Commissioning leads

Defensible IST records, faster punch lists, and sensors you can sign off on.

Operations teams

Fewer nuisance alarms, faults found before they cost uptime, and alerts that still fire offline.

Owners and MEP engineers

Proof that the hall performs as designed, with evidence an auditor or insurer can follow.

Join early access

We're working with a small group of commissioning teams and operators of liquid-cooled halls. Tell us about your site and we'll be in touch.

  • A trend audit on your own data
  • A direct line to the engineers building CHINOOK
  • A say in which connectors and checks come next

We use these details only to contact you about CHINOOK.

Questions

Does CHINOOK change anything in our BMS?

No. It reads. Writing is a separate, optional component that is off by default, and it can only reach levels L3 and L4 after the sign-offs listed above. Life-safety, fire, emergency power off, breakers, transfer switches, leak-isolation valves, interlocks and protection settings can never be written, at any level.

What do you need from us to start?

A trend export covering a few weeks of the cooling plant, and the point list if you have one. A trend audit needs no hardware on site.

Which plants does it understand?

It is built for liquid-cooled AI halls: CDUs, technology cooling loops, heat exchangers, pumps and the facility water that feeds them. The physics checks apply to any hydronic plant, so air-side and chiller-plant points can be checked too.

How does the AI avoid making things up?

It doesn't decide anything. Findings come from deterministic checks. The assistant can only say what it can cite: a finding, a data window, a document page. If it can't cite it, it doesn't answer.

Where does it run?

The platform runs in the cloud with each customer isolated in the database. Live data comes through a small edge agent on your network that only makes outbound connections. Ask us if you need it deployed in your own environment.

What does early access include?

A trend audit on your own data, a direct line to the engineers building CHINOOK, and a say in which connectors and checks come next.