Trust & security

Your data, your AI, your certification basis

Safety Lab Aero is built so the AI accelerates the work without ever becoming part of the safety argument. The deterministic engine owns every safety‑significant number, the AI is advisory and gated, and controlled documents are routed only where you allow them.

How it's built

The deterministic core owns the numbers

Failure rates, probabilities, cut‑sets, and DAL allocation are computed by explicit, repeatable logic — never by the AI. The AI may draft structure, but it never sets λ, DAL, or severity as fact.

Advisory and gated AI

Every AI edit is proposed, not applied: you see a before‑to‑after diff, accept what you want, and undo any turn. Nothing the AI does is silent or irreversible.

Your model stays yours

The project model and the deterministic engine run in your browser or desktop app; your projects are your own files. Only an explicit AI request sends anything to your configured AI backend.

AI backend & controlled data

You choose where AI requests are processed, to match your programme's data‑handling posture. Documents you mark controlled (ITAR or proprietary) are hard‑routed: while one is in the project, every cloud AI path is blocked — server‑side — unless the backend is on‑premise.

BackendWhat it isControlled docs
Hosted proxyClaude via the Pro+ hosted proxy.Not permitted
Bring‑your‑own keyYour provider key, used directly.Not permitted
ITAR (US‑sovereign cloud)Planned: hosted proxy routed to Azure Government. Until live, the proxy refuses ITAR traffic server‑side rather than routing it to any public‑cloud model.Planned
On‑premiseSelf‑hosted / local backend.Permitted

Controlled‑document routing is enforced in the application: a controlled document on file blocks every AI call — chat and batch alike — unless an on‑premise backend is configured (US‑sovereign cloud routing is planned), and where each controlled document was processed is recorded. The block is enforced server‑side at the proxy, not only in the browser. This is a routing control, not a claim of formal accreditation; talk to us about your specific ITAR/EAR or programme‑security requirements.

Frequently asked

Does the AI decide λ, DAL, or severity?

No. Those are owned by the deterministic engine and the engineer. The AI may propose a severity with rationale for you to confirm, and may build fault‑tree structure with rates left blank — but it never establishes a safety number as fact.

Is the AI part of the certification argument?

No — by design. The AI drafts, traces, and connects; the deterministic engine and the engineer own the numbers, the allocation, and the safety case. Requirements are allocated by interpreting the fault‑tree logic, not by the AI.

Where does my data go?

The model and engine run locally in your browser or desktop app. Only an explicit AI request sends the relevant context to your configured backend — hosted proxy, your own key, or on‑premise. For ITAR projects, cloud backends are blocked server‑side (US‑sovereign cloud routing is planned).

Can I use it on ITAR or controlled programmes?

Mark the relevant documents controlled; the AI is then restricted to an on‑premise backend and blocked from every cloud path, enforced server‑side (a US‑sovereign cloud option is planned). For fully air‑gapped work, the on‑premise backend keeps everything inside your boundary.

Does it replace my DER or my engineers?

No. It is a tool your engineers and DER use; the human owns every judgement and signs the safety case. The platform's job is to make the work faster and the golden thread complete and traceable.

What standards does it follow?

ARP 4754B and ARP 4761A, the means of compliance for your cert basis (AC 23.1309 / AC 25.1309 / AC 27 / AC 29 / SC‑VTOL, ASTM F3230), and DO‑178C / DO‑254 development assurance.

Built to be trusted on a certification programme.

Advisory AI above a deterministic, engineer‑owned core — with the data‑handling controls a controlled programme needs. Questions about your specific security posture? We're happy to talk.

Open the app →