Know what's wrong with your satellite, and what to do about it.

Health monitoring and fault diagnosis for small-satellite operators — with a false-alarm budget you set, and an attributable reason attached to every alarm.

Validated on real ESA mission telemetry Every number published with its source Recommend-only by default
excursion
Illustrative signal, not mission data Single channel · synthetic · fixed seed, identical on every load

A drawing of one synthetic telemetry channel: a quiet noisy trace that develops a slow drift and then a sharp excursion, with the excursion marked. It is an illustration of the shape of the problem and carries no measured result.

01 The problem

Thresholds miss the failures that matter, and cry wolf about the ones that don't.

Most small-satellite teams monitor bus health with hand-written threshold rules and whoever is on console.

Thresholds miss slow drifts, stuck-at faults and cross-channel interactions. When they do fire, they fire constantly — and operators learn to ignore them.

Diagnosis — working out which subsystem is actually failing from a wall of correlated alarms — still happens in someone's head, usually hours after the pass.

02 Detection, at a budget you set

Same budget. 18% of events caught, or 81%.

Labelled anomaly events caught

ESA OPSSAT-AD · 529 expert-labelled segments · 113 events
18% z-score threshold baseline
81% Orbital-AI, calibrated
Axis condition · both bars false-alarm budget matched at 10 / hour / channel event-wise metrics, ESA-ADB methodology

Roughly an eighth of the raw false-alarm rate

3.76 false alarms per hour observed, against 28.84 per hour uncalibrated — the same detector, a 7.7× reduction.

What travels with thisCalibration is what buys it, and it is the same dial an operator uses to trade sensitivity against console noise. It is a dial, not a package.

Both ends of that dial

Run uncalibrated and our most sensitive detector flags 112 of 113 labelled events at 0.5-second median latency.

The cost of that sensitivityThat operating point runs at 15.14 false alarms per hour, where three of every four alarms is false. Calibrated to a 10/hour budget, that same detector reaches 8% recall. Two ends of a dial, not a package — which is why we never quote them in one breath.

03 A budget that holds

Set “no more than N false alarms per week.” Pick one and see what it did.

Three budgets were tested against 447 days per channel of real ESA mission telemetry, on four channels. Twelve configurations. These are the committed results — the only three that exist.

False alarms per channel, per week
Requested10 FA / channel / week
Observed, across the four channels9.92 – 10.01 FA / channel / week
Configurations at this budget4 — one per channel, 447 days each
Observed ÷ requested, all twelve configurations0.992 – 1.013
Inside the 95% Wilson intervalYes — 4 of 4

What travels with these numbers 447 days per channel across four channels (4.9 channel-years) of real ESA Mission-1 telemetry, on the shipped default configuration. Each panel's observed figure is the range across the four channels at that budget; the ratio band below it spans all twelve configurations. All twelve sat inside a 95% Wilson interval and held to within 1.5% of target. This is coverage held over the long run, not a finite-sample proof — and only these three budgets were tested, so the panel offers only these three.

04 An explanation, not just an alarm

An alarm tells you something moved. This tells you what broke.

Fault diagnosis ranks hypotheses across subsystems and states its evidence in plain English. The shape of the answer:

Format illustration — not a measured case

Battery-cell fault, confidence 0.82 — power and pack temperature are both away from where they should be; comms symptoms are downstream of the EPS.

What travels with this That is a format illustration, not a measured case. The power and thermal evidence behind it is validated on our simulator only — OPSSAT's magnetometer and photodiode channels carry no power or thermal observables to test it against. We state it as design intent, and will not claim otherwise until it is demonstrated on real telemetry.

05 Safe by construction

Your operators stay in command.

Recommend-only by default

Nothing we suggest reaches your spacecraft without passing a safety gate first, and the default posture is to recommend rather than act.

The gate is the audited path

66 of 66 generated mutants killed. Property suite at 2048 cases per property. Exhaustive state-space enumeration. Model-checked with Kani on scheduled CI.

Model-checked on scheduled CI, not per-commit. We say which, because the difference matters.

06 The onboard path

It already fits on the flight computer.

The same code path is built for embedded flight computers. The ground tool is step one of an onboard autonomy roadmap, not a port of it.

Flash, rad-tolerant-class Cortex-M7 hard-float 8.9KiB
RAM, image on the M7 target 4.1KB
RAM per additional monitored channel 3.25KiB
Heap none0 B arena · 0 alloc symbols
Output across ARM, AArch64, RISC-V and the x86-64 anchor bit-for-bit identical
Cycles per instruction, measured on silicon Measured 1.65 – 1.95
CPU load — 100 MHz Cortex-M7 with a double-precision FPU, 100 channels at 1 Hz Extrapolated 1.98 – 2.34%
CPU load — 100 MHz Cortex-M4 class without one Projected 13 – 19%

What travels with these numbers Flash, RAM and instruction counts are measured exactly under emulation. Cycles-per-instruction is now measured on silicon — 1.65 to 1.95 on a Cortex-M7 devboard, in both cache configurations, with the emulation anchor reproduced bit for bit. CPU load remains strongly target-dependent. The 1.98–2.34% figure applies this board's measured CPI to a different part's clock — an extrapolation, and we label it as one. The 13–19% figure is still projected at an assumed CPI, because the on-silicon run covered the M7 class only. We state the FPU class with the number, and we do not call a projected figure measured.

07 Why believe any of it

The discipline is the product.

Anyone can put a number on a website. Here is the machinery that stops us putting the wrong one there.

01 — Provenance

Every number has a row

Each public figure has an entry in our claims-provenance file naming its source report, the command that produced it, whether it is measured, derived or projected, and the caveat that must travel with it. CI fails if any of them drifts from its source artifact.

02 — Held out

A mission we have never looked at

A second ESA mission is held out of development entirely, behind a code-level guard that raises unless explicitly overridden at release time. It is not a promise; it is a function that throws.

03 — Reproduction

We reproduce the published baseline

0.296 vs 0.295

Our isolation-forest segment F1 is 0.296 against the benchmark paper's 0.295. Segment F1, not event F1 — a benchmark audience will check, and they should.

04 — Public data

ESA's data, ESA's methodology

The harness pins ESA's expert-labelled OPSSAT-AD dataset by checksum and follows the ESA-ADB event-wise evaluation methodology, not point-wise F1.

Every figure on this page is measured on public data and traces to a committed report naming the command that produced it. Where a number is derived or projected rather than measured, this page says which, next to the number.

08 The pilot

A fixed-scope pilot, on your telemetry.

We're taking on a small number of fixed-scope pilot deployments.

  1. We run Orbital-AI against your historical telemetry, on terms you set — including entirely within your own boundary, with no data leaving your infrastructure.
  2. We review the findings with your operations team: every detection, every missed event, every false alarm.
  3. You keep the report either way. If it finds nothing your thresholds didn't, you'll know exactly what your current system is worth.

09 Contact

Worth 20 minutes?

If you operate a small satellite and your bus-health monitoring is a threshold file and a console, I'd like to show you what the same telemetry looks like through this.

ankit@orbital-ai.uk

Company
Orbital AI Space Limited
Company number
SC896657 — registered in Scotland
Registered office
Clyde Offices, Glasgow
Contact
Ankit Pawar, Founder & Director