They generate documents, we compute the certification case
A co-pilot drafts prose from whatever you upload. CertProve derives the answer from the rules, cites it, and abstains when the evidence is not there
Two different machines
The last row is the one that matters. A fluent guess inside a certification case is worse than a blank, because a blank gets filled and a guess gets signed.
Cited to the clause, at the amendment in force
Every citation names its authority, its document and the amendment it was written against, and resolves against the published rule
One living model carries the whole programme
Requirements, hazards, architecture, tests and evidence are one graph, graded against the live rule, from the first hazard to the sealed case
A link is not proof
Most requirements tools only confirm a link is there, CertProve checks whether it holds, so a broken, orphaned or unverified trace cannot hide behind a green tick
Only a passed test is evidence
A requirement with a failing or unrun test is not verified, however many links it carries
Trace runs both ways
A test that verifies nothing and a component nothing allocates to are gaps too, not clutter to ignore
A broken link is not a link
A trace pointing at an artefact that no longer exists is flagged as broken, never counted as healthy
Assurance cannot silently weaken
DAL flow-down is checked against ARP4754B, so implementation never carries less assurance than the hazard demands
The authority asks this first
A certification basis clause that no requirement cites is flagged before the review, not discovered in it
The whole aircraft, one model
Requirements, geometry, analysis and evidence resolve to a single connected model, not a folder of files that drift apart
Everything certification needs, already connected
From requirement to proof, one thread
A requirement, the components that implement it and the test that closes it, connected as structure. Pull any node and the whole chain answers.
Derived from the model, graded against the rule
Six analyses in one linked flow, every verdict graded against the 25.1309 ceiling, catastrophic ≤ 1e-9
Functional Hazard Assessment
Failure Modes & Effects
Preliminary System Safety
Fault Tree Analysis
Common Cause Analysis
System Safety Assessment
You do not page through it, you fly it
Fly the model
A spatial canvas with semantic zoom, pull back to the whole programme constellation, push in to a single requirement’s trace
Command by intent
Type what you want done and the cockpit navigates and acts, the fast path through a dense programme
A crew that cites or abstains
Every drafted row, requirement and gap arrives with its sources attached, and it refuses to invent a number
A cockpit that breathes
Readiness recomputes live as evidence lands, and a briefing greets you with exactly what changed overnight
Five rules, enforced in the product
In a safety discipline, honesty is the feature, these are not values on a poster, they are behaviour the code refuses to break
Cited or silent
A fact without a source is never stated, an unsupported claim becomes an honest abstention, not a guess
Deterministic first
Extraction, classification and every verdict are exact, repeatable computations, the product works fully with AI switched off
AI suggests, never authors
An assistant claim must quote the document word for word or it is dropped, and the drop is counted where you can see it
Never fabricate engineering data
A missing failure rate stays missing and says so, the platform will not invent the number that makes a review pass
The case can contradict you
A safety claim your own evidence disproves comes back contradicted, with the citation, never quietly averaged into a score
Built the way assured software is built
A tool that carries certification evidence must hold itself to the standards it serves
Over 2,800 automated tests
Run on every change, all green before anything reaches production, and the suite grows with every capability
A complete, signed history
Every create, edit and sign-off is an attributable, tamper-evident record, rendered as readable history
Baselines anyone can verify
Each evidence baseline carries a hash a third party can confirm, authenticity is checked, never assumed
Independence by construction
A reviewer may approve but never author, the separation an authority expects is built into the model
Faster documents are not a safer case
A paperwork generator answers a different question. CertProve keeps one deterministic, cited case that stays true as the design changes
What works today, said plainly
A claim you can test beats a promise you must trust, so the line between the two stays visible
Working end to end now
The safety chain, requirements and trace, document reading with cited extraction, supplier compatibility verdicts, geometry checks and sealed evidence, live in production
Shaped by design partners
What gets built next is decided by the first programmes on the platform, not by a roadmap slide, if a capability is not listed as working, we will say so before you ask
What it refuses to do
In a safety discipline the refusals are load bearing, so they are stated before the claims
You do not have to trust our AI, bring your own or none at all
Four settings, and a programme can sit on any of them. The engines are deterministic code, so the product works completely with the model turned off
“Assisted drafting runs only on your organisation's own key and endpoint (BYOK), because the fact pack leaves the deployment. Configure the AI profile in Settings, or draft by hand.”













