Skip to content

They generate documents, we compute the certification case

A co-pilot drafts prose from whatever you upload. CertProve derives the answer from the rules, cites it, and abstains when the evidence is not there

Two different machines

An LLM co-pilotCertProve
Drafts documents from what you upload
Computes the safety chain: hazard, allocation, assurance level, consequence of change
Fluent, and different every time
Same input, same answer, always
Knows whatever the customer uploaded
Authored regulatory packs, verified against the published text
Reads documents
Reads the aircraft, with safety analysis derived from the geometry
The model is the engine
The engines run without a model. AI optional, off by default
Invents when it is unsure
Abstains when it is unsure

The last row is the one that matters. A fluent guess inside a certification case is worse than a blank, because a blank gets filled and a guess gets signed.

Cited to the clause, at the amendment in force

Every citation names its authority, its document and the amendment it was written against, and resolves against the published rule

EASAauthority
CS-25document
Amendment 27amendment
CS 25.1309clause
a clause that resolvesthe authority’s own published text
a standard that is soldnamed, never reproduced
a clause that cannot be citedsaid so, never paraphrased

One living model carries the whole programme

Requirements, hazards, architecture, tests and evidence are one graph, graded against the live rule, from the first hazard to the sealed case

A link is not proof

Most requirements tools only confirm a link is there, CertProve checks whether it holds, so a broken, orphaned or unverified trace cannot hide behind a green tick

Only a passed test is evidence

A requirement with a failing or unrun test is not verified, however many links it carries

Trace runs both ways

A test that verifies nothing and a component nothing allocates to are gaps too, not clutter to ignore

A broken link is not a link

A trace pointing at an artefact that no longer exists is flagged as broken, never counted as healthy

Assurance cannot silently weaken

DAL flow-down is checked against ARP4754B, so implementation never carries less assurance than the hazard demands

The authority asks this first

A certification basis clause that no requirement cites is flagged before the review, not discovered in it

The whole aircraft, one model

Requirements, geometry, analysis and evidence resolve to a single connected model, not a folder of files that drift apart

Everything certification needs, already connected

From requirement to proof, one thread

A requirement, the components that implement it and the test that closes it, connected as structure. Pull any node and the whole chain answers.

CERTPROVE / AV-01 / TRACE
Find anything⌘K
SMD
LIVE
Model
Overview
Requirements
Architecture
Prove
Trace
Lattice
Gaps
Safety
FHA
FTA
Margins
Deliver
Test
Docs
Evidence
Work
Engineering lead

Trace

GraphImpactOrphansCoverage
TRACE QUERY
dal = A AND link = VERIFIED_BY
NODE TYPES
Requirement
Component
Test
SYS-RQ-441
Independent power
HW-PDU-01
Primary PDU
SW-BMC-C
Battery controller
TP-PDU-NOM
Nominal load
TR-8812
Passed, 10 Oct
REV CBASIS SC-VTOL214 NODES · 337 EDGES SYNCED

Derived from the model, graded against the rule

Six analyses in one linked flow, every verdict graded against the 25.1309 ceiling, catastrophic ≤ 1e-9

FHA

Functional Hazard Assessment

FMEA

Failure Modes & Effects

PSSA

Preliminary System Safety

FTA

Fault Tree Analysis

CCA

Common Cause Analysis

SSA

System Safety Assessment

You do not page through it, you fly it

STAGE

Fly the model

A spatial canvas with semantic zoom, pull back to the whole programme constellation, push in to a single requirement’s trace

HELM

Command by intent

Type what you want done and the cockpit navigates and acts, the fast path through a dense programme

CREW

A crew that cites or abstains

Every drafted row, requirement and gap arrives with its sources attached, and it refuses to invent a number

PULSE

A cockpit that breathes

Readiness recomputes live as evidence lands, and a briefing greets you with exactly what changed overnight

Five rules, enforced in the product

In a safety discipline, honesty is the feature, these are not values on a poster, they are behaviour the code refuses to break

CITED

Cited or silent

A fact without a source is never stated, an unsupported claim becomes an honest abstention, not a guess

EXACT

Deterministic first

Extraction, classification and every verdict are exact, repeatable computations, the product works fully with AI switched off

ASSIST

AI suggests, never authors

An assistant claim must quote the document word for word or it is dropped, and the drop is counted where you can see it

NULL

Never fabricate engineering data

A missing failure rate stays missing and says so, the platform will not invent the number that makes a review pass

CONTRA

The case can contradict you

A safety claim your own evidence disproves comes back contradicted, with the citation, never quietly averaged into a score

Built the way assured software is built

A tool that carries certification evidence must hold itself to the standards it serves

TESTED

Over 2,800 automated tests

Run on every change, all green before anything reaches production, and the suite grows with every capability

AUDIT

A complete, signed history

Every create, edit and sign-off is an attributable, tamper-evident record, rendered as readable history

SEALED

Baselines anyone can verify

Each evidence baseline carries a hash a third party can confirm, authenticity is checked, never assumed

SPLIT

Independence by construction

A reviewer may approve but never author, the separation an authority expects is built into the model

Faster documents are not a safer case

A paperwork generator answers a different question. CertProve keeps one deterministic, cited case that stays true as the design changes

generated paperwork
Fast, fluent, unsourced
Written once, stale by the next change
The document is the deliverable
the case
Deterministic, cited to the clause
Recomputed as the design changes
The document is a printout of the case, never the case itself

What works today, said plainly

A claim you can test beats a promise you must trust, so the line between the two stays visible

TODAY

Working end to end now

The safety chain, requirements and trace, document reading with cited extraction, supplier compatibility verdicts, geometry checks and sealed evidence, live in production

NEXT

Shaped by design partners

What gets built next is decided by the first programmes on the platform, not by a roadmap slide, if a capability is not listed as working, we will say so before you ask

What it refuses to do

In a safety discipline the refusals are load bearing, so they are stated before the claims

NOIt will not approve anything. The engineer and the authority stay the authors
NOIt will not sign anything. Every sign off carries a human name, a time and a version
NOIt will not print a number without a denominator. Where nothing was chosen to measure against, it says so
NOIt will not fill a gap with a guess. A missing fact is reported as missing, with what would close it

You do not have to trust our AI, bring your own or none at all

Four settings, and a programme can sit on any of them. The engines are deterministic code, so the product works completely with the model turned off

TRIAL
Our evaluation key
Capped per month, for looking at it. Never the setting a programme runs on
YOUR KEY
Your own key and endpoint
Your account, your provider, your terms. The only setting assisted drafting will run on at all
YOUR GATEWAY
Your gateway, your region
One setting points generation and search alike at your EU, sovereign cloud or on premise gateway
OFF
Disabled by policy
No model call leaves the product. Every deterministic engine keeps running in full

“Assisted drafting runs only on your organisation's own key and endpoint (BYOK), because the fact pack leaves the deployment. Configure the AI profile in Settings, or draft by hand.”

The product refusing our own key on a drafting request. Not a setting an administrator has to remember

See the whole programme on one graph

Access is granted on request while the platform is in early release