A qualifiable stack, pixels to firmware.
Slint SC is the qualifiable UI. Rust is memory-safe by construction. Ferrocene is the qualified toolchain beneath.
Together they carry the two hardest pieces of a functional-safety case.
The stack
Qualifiable, top to bottom
The toolchain under a qualifiable UI is qualified too — not a gap you have to argue around.
Standards
The programmes it's built for
Slint SC targets industrial, automotive and rail; the Ferrocene toolchain beneath adds qualified support for medical, and Rust is certifiable for aerospace.
IEC 61508
Industrial functional safety — the base standard many others derive from.
Ferrocene · SIL 3
ISO 26262
Road-vehicle functional safety, from clusters to ADAS displays.
Ferrocene · ASIL D
EN 50128
Railway control and protection software.
Slint SC · target programme
IEC 62304
Medical-device software lifecycle.
Ferrocene · Class C
DO-178C
Airborne systems and equipment.
Rust · certifiable
Honest scoping
What the toolkit covers — and what your product owns
Slint SC gives you
- A qualifiable UI subset of the Slint language
- A documented safety manual
- Traceable requirements
- Memory-safe rendering, no garbage collector
Ferrocene gives you
- A TÜV SÜD-qualified Rust compiler
- Qualification evidence for the toolchain itself
- The same Rust you already build with
- No "unqualified compiler" hole in your case
Your product still owns
- The system-level safety case
- Hazard analysis and risk assessment
- Your control logic and its verification
- Final certification with your assessor
No certification theatre — we tell you plainly where the boundary sits.
Building a safety case?
Let's scope it with you.
Tell us your target standard and hardware. We'll map what Slint SC and Ferrocene cover, and what stays yours.