Aerospace safety analysis,
integrated.

One workspace for AFHA, PSSA, SSA, fault tree analysis, and DO-178C/DO-254 traceability. Built by an aerospace engineer for the people who actually have to certify aircraft.

Mac download is Apple Silicon · Intel Mac version · desktop apps auto-update

The full safety spine

AFHA → PASA → SFHA → PSSA → SSA → ASA, in one workspace.

The complete ARP 4761A spine lives together, with every artifact connected to every other one. State stays consistent across the workflow without manual reconciliation between documents.

AFHAAircraft FHA
PASAPrelim. AC Safety
SFHASystem FHAs
PSSAPrelim. System Safety
SSASystem Safety Assess.
ASAAircraft Safety Assess.

Plus Common Cause Analysis (PRA, ZSA, CMA) as a parallel track, the way ARP 4761A actually describes it.

The golden thread

“Integrated” isn’t a layout. It’s one connected thread.

The promise at the top of this page is a single model, not a bundle of tools. Every aircraft function flows down to a system, a failure condition, a fault tree, the common-cause analyses — PRA, ZSA, CMA — that test its independence, the safety requirement that controls it, and the verification that closes it. That unbroken line is the golden thread, and it’s what “integrated” actually buys you: move the design and the whole thread moves with it, because there is only one source of truth to drift from.

Click a function in the left column to open its live trace.
FunctionSystemFailure conditionFault treeCommon causeRequirementV&V evidenceAF-01 Lift & thrustAF-02 Flight pathAF-03 Crew awarenessPropulsionFlight controlElectrical powerAvionicsLoss of thrustLoss of controlMisleading displayLoss of all powerAsymmetric thrustFT · thrustFT · asym thrustFT · controlFT · powerFT · displayCMA shared powerPRA rotor burstPRA batteryZSA power zoneZSA aft bayZSA fwd bayCMA FCS swRedundant powerIndependent lanesThrust monitoringDisplay integrityPower routingPower redund. testLane dissimilarityThrust isolationDisplay integ. test

In the workspace the thread is live on your own project: click any node to lay out its ecosystem — every linked failure condition, analysis, requirement and verification — then generate its full trace report in one click. The same deterministic model the whole workspace runs on.

The deterministic MBSA core

The model doesn’t illustrate the analyses. It produces them.

This is where the golden thread stops being a filing discipline and becomes an engine. One behavioral model of the aircraft — functions, systems, resources, zones, typed deviations, operating modes — compiles into the analyses, proves the safety claims, and answers what-if questions live. Built on the ARP4754A / 4761A methodology. No sampling, no heuristics, no AI in the loop: a deterministic MBSA core — same model in, same analyses and verdicts out, on any machine, every time.

⚙️

The model compiles the analyses

Availability rules compile into fault trees — and every compile is proven equivalent to the model it came from, automatically. Hand-built trees stay first-class; compiled ones can never quietly disagree with the model.

Safety claims, machine-checked

No single failure reaches a Catastrophic condition. No single zonal event does either. Dispatch relief never stands alone. Model covers every Cat/Haz condition. Twenty-plus live checks prove these on the model itself — and every exception carries a signed engineering basis that reopens if the design moves.

Fault injection you can watch

Click a system, a shared resource, or a whole zone failed. The dependency cascade lights up, the availability arithmetic shows its work, and the tripped failure conditions appear with their severities — a read-only lens for design reviews and what-if sessions.

⚖️

Two engines, forced to agree

Every evaluation runs twice — clause arithmetic and compiled model logic — and the two are cross-checked on every run. Disagreement renders as a named finding. Corroboration isn’t a claim here; it’s a mechanism.

🔀

Failures are typed. Reconfiguration is real.

Loss, erroneous, and inadvertent behavior propagate as distinct lanes — every claimed monitor or blocking path becomes a claim the common-mode analysis must own. Fallback modes are first-class, and the switchover itself is a named failure mode, corroborated by seeded Monte Carlo. Functional FMEAs generate from the model and enter your analysis only with an engineer’s signature.

📌

Standing on named assumptions

Model rules cite the assumptions that substantiate them. Invalidate one and every claim resting on it is named on the spot — analyses, dispatch limits, signed acceptances, gates. The model’s schema is versioned and enforced, so it can’t silently drift.

And the core plugs into the tools you already run: architecture in from your MBSE tool over SysML/XMI, requirements flowing both ways with Jama · Polarion · DOORS — live change tracking on Jama, verification status returning over ReqIF. See the integrations ↓

From the field

“The most complete safety analysis tool I’ve used.”

— a safety engineer

And the part nobody forgets is the golden thread — the interconnectedness, and the live flagging of obsolescence and compromised requirements the moment something upstream changes.

Used by DERs on active certification programs
Validated across multiple eVTOL beta programs
Loved by industry veterans
Very powerful and highly visual — better than some of the tools I’ve used with previous clients, including very large aeronautical companies. Its strongest points are document export and full traceability of the whole process, from requirements V&V through to the safety CCAs. Really impressed.

What people call out most

One connected thread

Function → hazard → fault tree → requirement → evidence, every link live and traceable.

Obsolescence, in real time

When a part or standard goes stale, every artifact it touches lights up at once — no manual sweep.

Compromised requirements, surfaced live

An upstream change that undermines a requirement is flagged the moment it lands.

What's inside

Where the math is first-class.

Every analysis engine is independently verified against textbook benchmarks. The math is exposed, the references are cited, and you can audit any computation back to the standard it implements.

🌳

Fault Tree Analysis

Quantitative fault tree analysis with minimal cutsets, K-of-N voting gates, dynamic gates (PAND / SPARE / FDEP), and common-cause failure models (β-factor, α-factor, MGL).

📚

Component reliability library

200+ public-domain failure rates from MIL-HDBK-217F, NSWC-11, DOT-FAA-CT-83-49, with π_T (Arrhenius) stress prediction. Bring your own NPRD / EPRD via BYOL if your organization is licensed.

📋

Means of Compliance matrix

Every requirement maps to a 14 CFR / CS-25 / AMC paragraph with the method of compliance (analysis / test / demonstration / inspection / similarity). Filters by your project's cert basis automatically.

📦

Configuration baselines

Snapshot the entire project at each milestone (PDR, CDR, submission) with a SHA-256 hash. Iterate freely in the live project; baselines stay immutable for the audit trail.

📝

Reports your DER actually reads

AFHA, PASA, SFHA, PSSA, SSA, ASA, PRA, ZSA, CMA — all nine ARP 4761A reports generated to Word or PDF, with your own org template if you have one.

Reliability & Maintainability · Pro+

A complete R&M program, on the same golden thread.

Not a bolted-on calculator — the same failure rates that drive your fault trees drive prediction, spares, maintenance intervals and cost. A field finding on a rate a handed-off safety argument used shows up on the dashboard as a challenge to that gate.

📈

Prediction to field data, closed loop

Reliability prediction, MTTR/MDT ledgers, dispatch reliability, and FRACAS with statistical verdicts — a field MTBF is VERIFIED only when the chi-square lower confidence bound clears the prediction, never on a point estimate.

🎲

RBD — exact and Monte Carlo

Exact k-of-N block diagrams with live fault-tree duals, plus seeded Monte Carlo for what product forms can't express: standby redundancy, imperfect switching, warm dormancy, phased missions. Same seed, same number — reproducible for the auditor.

📐

Life data, honestly bounded

Weibull by median-rank regression and maximum likelihood side by side, with Fisher confidence bounds. A wear-out claim needs the whole β interval above 1 — a point estimate alone is not evidence. Crow-AMSAA growth with goodness-of-fit.

🛠

MSG-3, all four programs

Systems & powerplant analysis with the full logic cascade, plus structures (AD/ED/FD ratings → derived task sets), zonal derived from your ZSA register, and L/HIRF protection features — all pushing into one maintenance ledger with provenance.

✈️

MMEL & dispatch, computed

Dispatch rulings from exact minimal cut sets — an item whose loss leaves order-1 protection is NO DISPATCH, mechanically. Quantitative exposure via transient recomputation, time-limited dispatch budgets from your safety targets.

💰

Spares, intervals, cost

Poisson spares at your fill rate, PM intervals reconciled against latent-failure not-to-exceed limits, testability rollups, level-of-repair, and life-cycle cost — priced from the λ and MTTR the safety case already carries, so design trades price themselves.

Connectivity

Your requirements live in an ALM. Ours plug into it.

Polarion, Jama Connect, IBM DOORS — Safety Lab imports the standard ReqIF interchange every major requirements tool exports, so requirements and FHA content arrive with their identifiers, attributes, hierarchy and trace links intact. Not as text to re-type.

🔗

ReqIF from any ALM

OMG-standard ReqIF import with a preview before anything touches your project. Works with Polarion's Round-trip export, Jama Connect Interchange, DOORS, Codebeamer — one importer, every tool.

🔁

Re-import is a sync, not a paste

Rows match on their source identifiers: unchanged rows skip, changed rows update in place and keep their safety traces, deleted rows are flagged for disposition — never silently removed while analyses still reference them.

🛡️

FHA import that refuses to guess

Failure conditions import with severity, phases and effects — and a severity wording the importer can't map unambiguously arrives unclassified with a warning, because a misread classification is worse than a missing one.

📐

Architecture from your MBSE tool

SysML blocks become systems, activities become functions, internal-block connectors become the interfaces and resources the dependency and propagation models run on — imported over standard XMI (Cameo and friends), re-import diffing changes onto the thread. Pilot program: bring a sample export.

📡

Status flows back, live

Your requirements team keeps working in their tool. The live bridge watches your Jama project and stages every change for signed import — nothing crosses the boundary without an engineer’s signature, and your API token never leaves your machine. Verification status, MoC state, and DAL flow back over ReqIF today; direct API write-back is next. Polarion rides the same connector.

🔒

Your data stays yours

Imports parse entirely in your browser — requirement data never transits our servers. Excel round-trip for tools without ReqIF; live API synchronization with status write-back available as a pilot.

The story

It’s not us. It’s you.

Safety Lab doesn’t do safety engineering. It makes your safety engineering executable, checkable, and provable — and then gets out of the way.

🧠

Your judgment

Every hazard call, severity, independence claim, β, and acceptance carries your signature — the engine derives everything else from those decisions and re-derives it when they change. Computed output never overwrites an engineer’s word.

📌

Your assumptions, load-bearing

Every claim knows what it rests on. Assumptions bind to the analyses, model rules, dispatch limits and dispositions built on them — invalidate one, and every exposed claim is named on the spot. An assumption nothing rests on gets flagged too.

🖥

Your machine, your data

Analyses parse and compute in your browser. Imports never transit our servers. The engine self-test runs the 25 published-reference benchmarks on your hardware and stamps the result into every evidence package.

🔁

Your tools, not ours

Requirements stay in Polarion, Jama, or DOORS; architecture stays in your MBSE tool. Safety Lab reads them, builds the safety argument on top, and reports status back. No migration, no lock-in, no second source of truth.

🔍

Your proof, re-runnable by anyone

Deterministic end to end: same project file, same trees, same requirements, same verdicts — on any machine, including your DER’s. The hash-chained journal makes the history itself tamper-evident.

✍️

Your name on it, deservedly

When the evidence package goes out, it is your engineering — every derivation traceable to your inputs, every acceptance carrying your basis, every gate signed by your team. The tool just made it impossible to lose the thread.

The discipline

What the tool refuses to do.

Anyone can add features. The reason a DER trusts a workspace is what it will not let slide. These guardrails are not a mode you switch on — they are the design.

🧮

The AI never does the math

The deterministic engine owns every computation. The AI drafts structure and accelerates the busywork — but it never does the math, and nothing it produces enters your analysis until a qualified engineer reviews and accepts it.

✍️

Nothing is approved on trust

An approval is a re-authenticated signature bound to the exact analysis it signs. If the analysis changes after sign-off, the signature no longer matches that state — and the record says so.

⛓️

The record can’t be quietly changed

Saves, sealed revisions, and sign-offs land in an append-only, hash-chained ledger. Any later edit or deletion of a past record is mathematically detectable — the audit trail a certification authority expects.

🔍

The math is never a black box

Every engine is independently verified against textbook benchmarks, the references are cited, and any computation traces back to the standard it implements. You can always check our work.

Pricing

Real numbers. No "contact us" for the basics.

Aerospace buyers respect transparency. Every tier includes the full safety workspace; what changes is the scale and the support depth.

Education
Free / forever
Verified .edu or academic — for individual coursework, thesis work, and research.
  • Full FTA / FMEA / FHA tools
  • Component library
  • Reports in Word and PDF
  • Email support
Sign up free
Pro
$500 / seat · month
Working safety engineers — the full classical toolset, no AI assist.
  • Everything in Education
  • End-to-end requirements workflow
  • Verification evidence tracking
  • Configuration baselines
  • Means of Compliance matrix
  • 10-day free trial
Start 10-day trial
Enterprise
Custom
Organizations running certification programs — teams, controlled environments, qualification support.
  • Everything in Pro+, multi-seat
  • Independent review & sign-off chains, gates & evidence packages
  • RM integration — Jama live + ReqIF (DOORS / Polarion / Codebeamer)
  • SSO & user provisioning
  • On-prem / air-gap deployment (ITAR & non-US regimes)
  • DO-330 tool-qualification support · support SLA
Contact sales

Pro and Pro+ are individual licenses, priced per seat and billed monthly — cancel anytime. Use by an organization on an active type-certification program requires an Enterprise license. Education is free for verified academic use.

About

For safety engineers, by a safety engineer.

Muhammad Waqas Nafees

Founder · Safety Lab Aero

I've spent years inside Part 25 and SC-VTOL programs — running FHAs, building fault trees, allocating DALs, and walking DERs through verification. The classical safety toolset has earned its place; its methods have been refined over decades of certified flight.

What I wanted was a single workspace where every artifact connects to every other one — where the FHAs, fault trees, requirements, and supporting analyses share state automatically, instead of living in separate documents that get reconciled by hand.

Safety Lab Aero is that workspace. It's designed to fit how safety teams already work — and to give them back the time currently spent reconciling.

Questions? waqas.nafees@safetylabaero.com

Stop reconciling. Start certifying.

Spin up a free trial — full Pro tier, no credit card for 10 days.

Start free trial ⬇ Download for Mac ⬇ Download for Windows

Intel Mac version · desktop apps auto-update to the latest release