One pipeline. Physics as the source of truth.
Datasheets and CAD go in; a frozen parameter sheet comes out. Every scenario, replay, dataset and report downstream is computed from that sheet by one deterministic physics core. Renderers are viewers and sensor rigs on the same trajectory files — never a second simulation.
Record, then re-render. Batches run headless and cheap; only the runs you select pay for photoreal rendering or sensor capture.
Every value with its source. Missing data becomes a question.
Intake is the most defended stage of the pipeline: everything downstream trusts what leaves it. The extractor reads what a manufacturer actually publishes and never invents a value.
Documents
One or more datasheet or specification PDFs. Extraction runs against a versioned schema and returns a parameter sheet with a verbatim quote, page and confidence for every field.
Geometry
Meshes in .obj, .glb or .stl. Unit sniffing against the datasheet dimensions, a watertightness check, then mass properties, inertia and frontal area computed from the mesh and merged into the sheet, tagged by method.
Provenance per value
Value and source quote side by side at the confirmation gate. Your edits are recorded as operator values; re-extraction after new documents produces a diff, never a silent overwrite.
Open questions, never guesses
A gap becomes an open question resolved by you or by a flagged estimate. Nothing is silently filled in, and nothing runs until you approve the sheet.
Freeze
You confirm once. The sheet becomes immutable and hash-linked to its source documents; every batch references the frozen sheet id. New evidence produces a new sheet version.
- Documents
- PDF, up to 50 MB each · optional free-text test intent
- Geometry
- .obj · .glb · .stl
- STEP
- In development.step / .stp via OpenCascade conversion
- Per project
- 500 MB · content-type sniffing, not extension trust · AV scan · quarantine until conditioning passes
- Sheet
- schema-valid JSON · per field: value, unit, verbatim quote, page, confidence, methodMethod is extracted, mesh or operator, so you can always tell where a number came from.
- Freeze
- immutable · hash-linked to source documents · referenced by id from every batch
Calibrated six-degree-of-freedom physics. Batches in seconds.
A Python multirotor core with a full energy model, deterministic by construction. Same seed, byte-identical results — a CI gate, not a promise.
Vehicle model
Six-degree-of-freedom multirotor dynamics with a Glauert–Leishman rotor energy model. Mass, inertia and frontal area come from your mesh; motor, battery and aerodynamic parameters from the frozen sheet.
Available nowMissions
Hover endurance, a 1 km waypoint box and wind penetration, each with configurable contingency behaviours: return-to-home thresholds and loiter rules.
Available nowScenario matrices
Any leaf of the scenario file is a sweep axis — wind, payload, temperature, density altitude, site, time of day, threat placement. Thirty-six scenarios run in seconds; a 40-minute hover run costs about 40 ms of wall clock.
Available nowDeterminism
Multiprocessing batches with a fixed seed produce byte-identical results. Trajectories, scenarios and results land as versioned, content-addressed files that every later stage reads.
Available nowCalibration
+1.7% simulated versus claimed hover endurance against a reference airframe at zero wind. Face validity is CI-gated at ±25%. Results remain unvalidated design-iteration estimates until a validation programme says otherwise.
Available now- Airframe
- Available nowmultirotor · quad-nativeHexa- and octo-rotor airframes run as thrust-equivalent quads today; a generalised rotor model is in development.
- Fixed-wing
- In developmentJSBSim as an external process, same schema
- Missions
- hover_endurance · waypoint_box_1km · wind_penetration
- Batch
- 36 scenarios in seconds · 60-run budget under 5 min on a laptop
- Determinism
- same seed → byte-identical results.csv, checked in CI
- Realtime
- 30 Hz websocket state stream · position, velocity, attitude, state of charge, power, wind
- Calibration
- +1.7% vs claimed hover endurance · reference airframe, zero wind · CI gate ±25%Unvalidated design-iteration estimates. The disclaimer footer is non-removable in every report format.
Any run, re-rendered over real terrain.
Batches run headless and cheap. Only the runs you pick pay for photoreal rendering — and the renderer reads the trajectory file, it never steps physics, so the video matches the numbers.
Browser replay
A CesiumJS viewer replays any run today: follow, free and top-down cameras, a HUD, scrub and speed controls, over streamed world imagery.
Available nowUnreal Engine worker
A C++ Unreal Engine 5 project with Cesium for Unreal and photorealistic 3D tiles. A trajectory replay actor plays the recorded run over the terrain the physics sampled.
In developmentCameras
Chase, onboard and cinematic cameras, with a HUD driven by the same state stream as the physics. Switch to the onboard view at the moment of first detection.
In developmentVideo export
Movie Render Queue to mp4, one command from a batch directory. Selected renders ship inside the evidence bundle.
In development- Renderers
- CesiumJS in the browser · Unreal Engine 5 worker (in development)
- Input
- the trajectory file — the same one the report was scored from
- Cameras
- follow · free · top-down (browser) — chase · onboard · cinematic (Unreal)
- Output
- In developmentmp4 via Movie Render Queue · frames for datasets
- Budget
- a 30-minute trajectory loads in under 5 sEngineering target for the Unreal worker.
A report you can send to a programme office.
Go/no-go envelopes with the limiting factor named, claims against simulation, and a provenance appendix that ties every number back to a source document. The disclaimer footer is non-removable in every format.
Go/no-go envelopes
Heatmaps across the swept axes with the go-rate verdict, endurance envelopes against the manufacturer’s claims, and the limiting factor named on every run.
Available nowClaims versus simulation
The published figure beside the simulated one, with the delta, for every claim the datasheet made and the frozen sheet carried.
Available nowProvenance appendix
Every artifact — sheet, scenario, trajectory, frame set, report — is content-addressed and chained back to the hashes of the source documents.
Available nowLive telemetry strip-charts
Altitude, ground speed, power and state of charge beside the 3D view, with event markers for detection, denial-zone entry, RTH trigger and battery floor. Live view and replay are one component reading one schema.
In developmentBatch dashboard
Per-run status streaming from the registry as results land; aggregate tiles for go-rate, envelope edge and energy spread; pin two batches — design variants or a policy A/B — and diff their envelopes.
In developmentExports
A self-contained report.html today. PDF with cover block and provenance appendix, and a one-click evidence bundle — report, chart PNGs, results.csv, selected trajectories and photoreal mp4s — in development.
- Formats
- report.html (single file) · PDF · evidence bundle (.zip) · results.csv / JSON · labelled dataset with manifest
- Verdicts
- go-rate · envelope edge · limiting factor · claims-vs-sim delta
- Session stats
- In developmentdistance · energy used · average and peak power · max tilt · exposure timeAccumulate live and freeze at session end; the replay view re-renders the same panel from the trajectory file.
- Disclaimer
- non-removable footer in every format: unvalidated design-iteration estimates
- Budget
- report in under 30 s for 500 runsEngineering target.
Any coordinates. Terrain that is load-bearing, not scenery.
A site is an origin, a terrain source and a set of descriptors. The heightfield the viewer draws is the one the threat layer’s line-of-sight and the ground-collision check sample.
Streamed photogrammetry
The connected tier streams world terrain and imagery for any coordinates — Cesium World Terrain and photorealistic 3D tiles — so nothing is modelled by hand. The browser viewer replays over streamed world imagery today; photoreal tiles in the Unreal worker are in development.
Named site library
Each site is an origin latitude, longitude and altitude, a terrain source and preset descriptors: coastal, urban, mountain, desert, maritime. Scenarios reference sites by name and can sweep across them.
In developmentEnclave terrain packs
Photoreal tiles cannot be cached offline. Air-gapped installs use customer-supplied terrain and imagery packs or licensed offline tiles; the fallback ships with the on-premises package.
In developmentTerrain in the physics
Line-of-sight for detection and engagement checks, terrain masking and ground collision all sample the same heightfield the renderer draws.
In development- Sources
- Cesium World Terrain · photorealistic 3D tiles (connected tier) · customer terrain packs (enclave)
- Descriptors
- coastal · urban · mountain · desert · maritime
- Consumers
- rendering · threat line-of-sight · terrain masking · ground collision
- Caveat
- photoreal 3D tiles cannot be cached offlineThe connected tier is the photoreal tier. Air-gapped sites bring their own terrain.
Weather is a physics input, never a visual effect.
Every atmospheric parameter changes what the vehicle experiences and what sensors can see. Rendered weather mirrors the same scenario values, so the video matches the numbers.
- Wind
- Available nowsteady, uniform per scenario · sweepable like any other axis
- Turbulence
- In developmentgusting · Dryden or von Kármán turbulence by mean speed and intensity class · altitude shear
- Temperature
- Available nowcold-weather battery derate
- Density altitude
- Available nowthrust and power from local air density
- Visibility
- In developmentfog and precipitation as detection-range multipliers on the craft’s sensors and the threat layer’sOptional mass and drag accretion later.
- Time of day
- In developmentdrives the sun in rendering and an illuminance term degrading EO detection on both sides
- Rendering
- In developmentUnreal weather and sun set from the same scenario values
Environment models are pure functions injected into mission stepping. They change what the vehicle experiences — wind vector, nav error, link state — and what gets scored, never the integrator itself.
Generic, parameterised, sweepable like any other axis.
Four model classes measure your test article’s resilience — never a named system’s performance. Every shipped preset is fictional. Your real threat data stays in your enclave.
Detection sites
Position, sector field of view, maximum range, probability-of-detection curve against range, altitude band and target size class; terrain line-of-sight from the site.
Emits detection events along the trajectory. Visibility conditions scale the ranges.
Time to first detection, cumulative exposure, detected versus undetected route segments.
Navigation-denial zones
Polygon or circle; GNSS state (denied, degraded); datalink state (lost, degraded, latency).
Position-error growth while inside. Loss of link triggers the craft’s configured behaviour: return to home, loiter, or continue autonomous.
Nav drift at exit, mission completion under denial, behaviour-trigger log.
Engagement envelopes
Range and altitude band, sector, engagement probability as a pure function of geometry and exposure time.
Probabilistic mission-kill event that terminates the run with outcome negated.
Survival rate across the matrix, exposure time to negation.
Terrain masking
None to author. Heightfield line-of-sight from the same terrain the renderer draws.
Shadows detection and engagement checks behind terrain.
Masking utilisation over the route.
Threats are scenario furniture. Any placement is a sweep axis: the same ingress against nine positions of one detection site is a single batch.
In development"threats": [
{ "type": "detection_site",
"preset": "type_a_shortrange",
"pos": [51.529, -0.471],
"heading_deg": 90 },
{ "type": "nav_denial_zone",
"shape": "circle_r_800m",
"pos": [51.531, -0.468],
"gnss": "denied",
"datalink": "degraded" }
],
"axes": {
"threats[0].pos": ["grid_3x3_500m"]
}Parameters are generic capability classes, not real-system data. The platform measures the test article’s resilience and never optimises effector performance. Real threat parameters enter only inside a customer’s own enclave deployment.
In the report: exposure heatmaps along routes, survival envelopes across wind, route and placement, and A/B of guidance behaviours.
Labelled frames from every rendered run.
The render plane is a sensor rig as well as a viewer. Re-render a batch subset and every frame arrives pose-stamped, tied to its run and scenario.
RGB and depth
Scene-capture RGB and depth from onboard cameras, pose-stamped per frame. Semantic segmentation via custom stencils follows.
In developmentManifests
A manifest ties every frame to its run, pose and scenario. The dataset is packaged beside the trajectory it was rendered from and fetched from the same API.
In developmentSim-to-real caveats
Every dataset ships with written sim-to-real caveats. A train-on-synthetic, test-on-real harness with published deltas is on the roadmap.
In developmentOperator demonstrations
Manual sessions log schema-identical trajectories, so a controller-in-hand flight is an imitation-learning example in the same format as an autonomous run.
Available now- Modalities
- In developmentRGB · depth · semantic segmentation (next)
- Per frame
- pose · run id · scenario · camera
- Delivery
- In developmentGET /batches/{id}/dataset · GET /runs/{id}/traj
- Economics
- record → re-renderBatches stay headless; only the runs you select are rendered and captured.
Pick up a controller. Same craft, same physics, same scenario.
Any standard game controller, or the keyboard. The physics server steps the same model the batches use, at 30 Hz, with wind active — and the session is logged as an operator demonstration.
Live physics
Angle-mode manual control over the websocket at 30 Hz: sticks and configuration in, full state out. The browser viewer flies today; the Unreal client, on the same protocol, is in development.
Available nowController
Any standard game controller through the browser Gamepad API, or the keyboard. The Unreal client takes the same sticks through Enhanced Input.
Available nowSessions as data
Every manual session writes a schema-identical trajectory: the same file a batch run produces, replayable in the same viewer, packaged as an operator demonstration.
Available nowWind and threats active
Wind and flight mode are set in-session. Threat scoring applies to a manual flight exactly as it applies to a batch run.
In development- Rate
- 30 Hz state stream · jitter budget under 10 ms
- Input
- game controller (Gamepad API) · keyboard · Unreal Enhanced Input (in development)
- Mode
- angle mode
- Output
- schema-identical trajectory per session · replay and telemetry from the same file
Test your own guidance against the range.
Three tiers of autonomy under test, and a Test Director to run the campaign. The agent proposes; a human approves before any compute is spent.
Scripted
Waypoint missions with configurable contingency behaviours: return-to-home thresholds, loiter rules, continue-autonomous on link loss.
Available nowFirmware-in-loop
PX4 SITL via MAVSDK as the premium fidelity tier: the actual autopilot code flies the simulation.
In developmentPolicy API
A gym-style environment over the sim core. Observations: state, detection warnings, nav quality. Actions: velocity or attitude setpoints. Two baseline policies ship — naive direct route and a cost-map replanner that trades endurance for masking — so every report has a built-in A/B.
In developmentTest Director
In developmentInput: the confirmed sheet plus a requirements document or plain-text intent. Output: a proposed scenario matrix with rationale, reviewed and approved before any compute is spent.
During a campaign it bisects wind, payload and threat placement to find envelope edges — typically 5–10× fewer runs than a dense grid — and queues follow-up batches. Afterwards it drafts the report narrative with per-claim citations to specific runs.
It uses the same public API as any other client, and every action lands in the audit log like a human’s.
> why did run_014 fail?
GNSS-denied drift exceeded 40 m at t=312 s; RTH triggered into headwind; battery floor at 4.1 km out — see samples 9300–9600.
Every number traces to a quote. Every pixel traces to a number.
Design-partner access only. Results are unvalidated design-iteration estimates, not certified test evidence.