One workspace for AFHA, PSSA, SSA, fault tree analysis, and DO-178C/DO-254 traceability. Built by an aerospace engineer for the people who actually have to certify aircraft.
Mac download is Apple Silicon · Intel Mac version · desktop apps auto-update
The complete ARP 4761A spine lives together, with every artifact connected to every other one. State stays consistent across the workflow without manual reconciliation between documents.
Plus Common Cause Analysis (PRA, ZSA, CMA) as a parallel track, the way ARP 4761A actually describes it.
The promise at the top of this page is a single model, not a bundle of tools. Every aircraft function flows down to a system, a failure condition, a fault tree, the common-cause analyses — PRA, ZSA, CMA — that test its independence, the safety requirement that controls it, and the verification that closes it. That unbroken line is the golden thread, and it’s what “integrated” actually buys you: move the design and the whole thread moves with it, because there is only one source of truth to drift from.
In the workspace the thread is live on your own project: click any node to lay out its ecosystem — every linked failure condition, analysis, requirement and verification — then generate its full trace report in one click. The same deterministic model the whole workspace runs on.
This is where the golden thread stops being a filing discipline and becomes an engine. One behavioral model of the aircraft — functions, systems, resources, zones, typed deviations, operating modes — compiles into the analyses, proves the safety claims, and answers what-if questions live. Built on the ARP4754A / 4761A methodology. No sampling, no heuristics, no AI in the loop: a deterministic MBSA core — same model in, same analyses and verdicts out, on any machine, every time.
Availability rules compile into fault trees — and every compile is proven equivalent to the model it came from, automatically. Hand-built trees stay first-class; compiled ones can never quietly disagree with the model.
No single failure reaches a Catastrophic condition. No single zonal event does either. Dispatch relief never stands alone. Model covers every Cat/Haz condition. Twenty-plus live checks prove these on the model itself — and every exception carries a signed engineering basis that reopens if the design moves.
Click a system, a shared resource, or a whole zone failed. The dependency cascade lights up, the availability arithmetic shows its work, and the tripped failure conditions appear with their severities — a read-only lens for design reviews and what-if sessions.
Every evaluation runs twice — clause arithmetic and compiled model logic — and the two are cross-checked on every run. Disagreement renders as a named finding. Corroboration isn’t a claim here; it’s a mechanism.
Loss, erroneous, and inadvertent behavior propagate as distinct lanes — every claimed monitor or blocking path becomes a claim the common-mode analysis must own. Fallback modes are first-class, and the switchover itself is a named failure mode, corroborated by seeded Monte Carlo. Functional FMEAs generate from the model and enter your analysis only with an engineer’s signature.
Model rules cite the assumptions that substantiate them. Invalidate one and every claim resting on it is named on the spot — analyses, dispatch limits, signed acceptances, gates. The model’s schema is versioned and enforced, so it can’t silently drift.
And the core plugs into the tools you already run: architecture in from your MBSE tool over SysML/XMI, requirements flowing both ways with Jama · Polarion · DOORS — live change tracking on Jama, verification status returning over ReqIF. See the integrations ↓
— a safety engineer
And the part nobody forgets is the golden thread — the interconnectedness, and the live flagging of obsolescence and compromised requirements the moment something upstream changes.
Very powerful and highly visual — better than some of the tools I’ve used with previous clients, including very large aeronautical companies. Its strongest points are document export and full traceability of the whole process, from requirements V&V through to the safety CCAs. Really impressed.
What people call out most
Function → hazard → fault tree → requirement → evidence, every link live and traceable.
When a part or standard goes stale, every artifact it touches lights up at once — no manual sweep.
An upstream change that undermines a requirement is flagged the moment it lands.
Every analysis engine is independently verified against textbook benchmarks. The math is exposed, the references are cited, and you can audit any computation back to the standard it implements.
Quantitative fault tree analysis with minimal cutsets, K-of-N voting gates, dynamic gates (PAND / SPARE / FDEP), and common-cause failure models (β-factor, α-factor, MGL).
200+ public-domain failure rates from MIL-HDBK-217F, NSWC-11, DOT-FAA-CT-83-49, with π_T (Arrhenius) stress prediction. Bring your own NPRD / EPRD via BYOL if your organization is licensed.
Every requirement maps to a 14 CFR / CS-25 / AMC paragraph with the method of compliance (analysis / test / demonstration / inspection / similarity). Filters by your project's cert basis automatically.
Snapshot the entire project at each milestone (PDR, CDR, submission) with a SHA-256 hash. Iterate freely in the live project; baselines stay immutable for the audit trail.
AFHA, PASA, SFHA, PSSA, SSA, ASA, PRA, ZSA, CMA — all nine ARP 4761A reports generated to Word or PDF, with your own org template if you have one.
Not a bolted-on calculator — the same failure rates that drive your fault trees drive prediction, spares, maintenance intervals and cost. A field finding on a rate a handed-off safety argument used shows up on the dashboard as a challenge to that gate.
Reliability prediction, MTTR/MDT ledgers, dispatch reliability, and FRACAS with statistical verdicts — a field MTBF is VERIFIED only when the chi-square lower confidence bound clears the prediction, never on a point estimate.
Exact k-of-N block diagrams with live fault-tree duals, plus seeded Monte Carlo for what product forms can't express: standby redundancy, imperfect switching, warm dormancy, phased missions. Same seed, same number — reproducible for the auditor.
Weibull by median-rank regression and maximum likelihood side by side, with Fisher confidence bounds. A wear-out claim needs the whole β interval above 1 — a point estimate alone is not evidence. Crow-AMSAA growth with goodness-of-fit.
Systems & powerplant analysis with the full logic cascade, plus structures (AD/ED/FD ratings → derived task sets), zonal derived from your ZSA register, and L/HIRF protection features — all pushing into one maintenance ledger with provenance.
Dispatch rulings from exact minimal cut sets — an item whose loss leaves order-1 protection is NO DISPATCH, mechanically. Quantitative exposure via transient recomputation, time-limited dispatch budgets from your safety targets.
Poisson spares at your fill rate, PM intervals reconciled against latent-failure not-to-exceed limits, testability rollups, level-of-repair, and life-cycle cost — priced from the λ and MTTR the safety case already carries, so design trades price themselves.
Polarion, Jama Connect, IBM DOORS — Safety Lab imports the standard ReqIF interchange every major requirements tool exports, so requirements and FHA content arrive with their identifiers, attributes, hierarchy and trace links intact. Not as text to re-type.
OMG-standard ReqIF import with a preview before anything touches your project. Works with Polarion's Round-trip export, Jama Connect Interchange, DOORS, Codebeamer — one importer, every tool.
Rows match on their source identifiers: unchanged rows skip, changed rows update in place and keep their safety traces, deleted rows are flagged for disposition — never silently removed while analyses still reference them.
Failure conditions import with severity, phases and effects — and a severity wording the importer can't map unambiguously arrives unclassified with a warning, because a misread classification is worse than a missing one.
SysML blocks become systems, activities become functions, internal-block connectors become the interfaces and resources the dependency and propagation models run on — imported over standard XMI (Cameo and friends), re-import diffing changes onto the thread. Pilot program: bring a sample export.
Your requirements team keeps working in their tool. The live bridge watches your Jama project and stages every change for signed import — nothing crosses the boundary without an engineer’s signature, and your API token never leaves your machine. Verification status, MoC state, and DAL flow back over ReqIF today; direct API write-back is next. Polarion rides the same connector.
Imports parse entirely in your browser — requirement data never transits our servers. Excel round-trip for tools without ReqIF; live API synchronization with status write-back available as a pilot.
Safety Lab doesn’t do safety engineering. It makes your safety engineering executable, checkable, and provable — and then gets out of the way.
Every hazard call, severity, independence claim, β, and acceptance carries your signature — the engine derives everything else from those decisions and re-derives it when they change. Computed output never overwrites an engineer’s word.
Every claim knows what it rests on. Assumptions bind to the analyses, model rules, dispatch limits and dispositions built on them — invalidate one, and every exposed claim is named on the spot. An assumption nothing rests on gets flagged too.
Analyses parse and compute in your browser. Imports never transit our servers. The engine self-test runs the 25 published-reference benchmarks on your hardware and stamps the result into every evidence package.
Requirements stay in Polarion, Jama, or DOORS; architecture stays in your MBSE tool. Safety Lab reads them, builds the safety argument on top, and reports status back. No migration, no lock-in, no second source of truth.
Deterministic end to end: same project file, same trees, same requirements, same verdicts — on any machine, including your DER’s. The hash-chained journal makes the history itself tamper-evident.
When the evidence package goes out, it is your engineering — every derivation traceable to your inputs, every acceptance carrying your basis, every gate signed by your team. The tool just made it impossible to lose the thread.
Anyone can add features. The reason a DER trusts a workspace is what it will not let slide. These guardrails are not a mode you switch on — they are the design.
The deterministic engine owns every computation. The AI drafts structure and accelerates the busywork — but it never does the math, and nothing it produces enters your analysis until a qualified engineer reviews and accepts it.
An approval is a re-authenticated signature bound to the exact analysis it signs. If the analysis changes after sign-off, the signature no longer matches that state — and the record says so.
Saves, sealed revisions, and sign-offs land in an append-only, hash-chained ledger. Any later edit or deletion of a past record is mathematically detectable — the audit trail a certification authority expects.
Every engine is independently verified against textbook benchmarks, the references are cited, and any computation traces back to the standard it implements. You can always check our work.
Aerospace buyers respect transparency. Every tier includes the full safety workspace; what changes is the scale and the support depth.
Pro and Pro+ are individual licenses, priced per seat and billed monthly — cancel anytime. Use by an organization on an active type-certification program requires an Enterprise license. Education is free for verified academic use.
Muhammad Waqas Nafees
Founder · Safety Lab Aero
I've spent years inside Part 25 and SC-VTOL programs — running FHAs, building fault trees, allocating DALs, and walking DERs through verification. The classical safety toolset has earned its place; its methods have been refined over decades of certified flight.
What I wanted was a single workspace where every artifact connects to every other one — where the FHAs, fault trees, requirements, and supporting analyses share state automatically, instead of living in separate documents that get reconciled by hand.
Safety Lab Aero is that workspace. It's designed to fit how safety teams already work — and to give them back the time currently spent reconciling.
Questions? waqas.nafees@safetylabaero.com
Spin up a free trial — full Pro tier, no credit card for 10 days.
Start free trial ⬇ Download for Mac ⬇ Download for WindowsIntel Mac version · desktop apps auto-update to the latest release