Solutions  /  Aerospace and safety-critical operations

Longer-term pathway

Should this action be allowed to execute at all?

Where a decision drives hardware, a permission boundary matters more than an explanation. The question is not whether the reasoning was good. It is whether the action was permitted, and whether the record of that permission existed before it ran.

The problem

Two responses, both unsatisfying

Trust the upstream system

Places the whole safety case on the component least able to explain itself.

Review after the fact

Useful for learning. Useless for prevention.

Autonomy is moving into operational paths faster than the assurance methods for it. A deterministic permission boundary is one of the few controls that does not depend on understanding the model that proposed the action.

Who is in the room

What each of them needs to see

RoleWhat they need before this proceeds
Safety and airworthinessWants fail-closed behaviour proved, not asserted.
OperationsWants the latency budget and the blast radius when the boundary is unavailable.
Assurance and certificationWants to know exactly what EcoKure claims and, more importantly, what it does not.
Behind this page

The gates that do the checking

This page exists because these implementations exist. We do not publish an industry page without gates behind it.

ExecutionGate

Open source

Fail-closed permission boundary for downstream use. The reference implementation of the DAX layer.

OrbitGate

Open source

Deterministic verification for orbital and satellite claims, with benchmark artefacts.

FlightGate

Research

Early work applying action permission to flight-envelope and operational constraints.

GridGate

Research

Early work applying action permission to energy and grid operational limits.

UnitGate

Interactive lab

Dimensional-analysis checker for physics equations. Catches equations that cannot be right regardless of the numbers.

Limits

What this is not

  • EcoKure is not a safety-instrumented system, carries no safety integrity level, and does not replace one.
  • It does not certify that any action is physically safe. It governs permission, not engineering.
  • FlightGate and GridGate are research scope. They must not be placed in any live control path.
  • This is a longer-term pathway. Procurement is long and the evidence bar is high, and both are stated plainly.

Start with one workflow

The useful first conversation is thirty minutes on a workflow where a change in rules or evidence has already cost you work. Both sides find out quickly whether this is worth pursuing.

Where it sits in what you already run

Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.

Your mission systems unchanged, never actuated by us Operator consoles and planning tools The AI or automation proposing actions Telemetry and reference data Procedure and limit documentation Existing safety-instrumented systems proposed action hold / allow + evidence no agent installed no data leaves your boundary EcoKure Assurance Runtime deployed in your account · 11 dependencies Domain rule pack, under your authority Checks against declared operating limits Verdicts computed with no network Signed evidence that replays offline Held actions with the reason recorded EcoKure never touches • Any actuation — DAX is disabled, no permission granted • Safety-instrumented systems — never replaced or bypassed • Dispatch, protection or switching decisions • Certification — no accreditation is held or claimed
Shadow mode, and the never list is the whole point. EcoKure checks a proposal against declared limits and preserves the record; it does not operate equipment, and physical action control would require a safety case that does not exist. Everything replays offline, which is what makes it usable in a disconnected environment.

What one decision actually does

The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.

air-gapped — no network, evidence replays offline In scope Operator or AI proposal EcoKure Limits, units and procedure version Decision ALLOW / BLOCK / ABSTAIN Your rules Domain rule pack — your authority binds version + hash entry 9041 ABSTAIN signed, append-only evidence chain signs every outcome outside declared envelope, Hold Held, never actuated Person Operator with domain authority entry 9042 BLOCK sign-off — commitment only, no identity references, never rewrites Evidence pack export Independent verifier no EcoKure code runs offline
Shadow mode. EcoKure does not actuate anything here and no action permission is granted: it checks a proposal against declared limits and preserves the record. Everything replays offline, which is the point in a disconnected environment — and physical action control would require a safety case that does not exist.
Next · See the assurance route Mission-critical