Know what's wrong with your satellite, and what to do about it.
Health monitoring and fault diagnosis for small-satellite operators — with a false-alarm budget you set, and an attributable reason attached to every alarm.
A drawing of one synthetic telemetry channel: a quiet noisy trace that develops a slow drift and then a sharp excursion, with the excursion marked. It is an illustration of the shape of the problem and carries no measured result.
01 The problem
Thresholds miss the failures that matter, and cry wolf about the ones that don't.
Most small-satellite teams monitor bus health with hand-written threshold rules and whoever is on console.
Thresholds miss slow drifts, stuck-at faults and cross-channel interactions. When they do fire, they fire constantly — and operators learn to ignore them.
Diagnosis — working out which subsystem is actually failing from a wall of correlated alarms — still happens in someone's head, usually hours after the pass.
02 Detection, at a budget you set
Same budget. 18% of events caught, or 81%.
Labelled anomaly events caught
ESA OPSSAT-AD · 529 expert-labelled segments · 113 eventsRoughly an eighth of the raw false-alarm rate
3.76 false alarms per hour observed, against 28.84 per hour uncalibrated — the same detector, a 7.7× reduction.
What travels with thisCalibration is what buys it, and it is the same dial an operator uses to trade sensitivity against console noise. It is a dial, not a package.
Both ends of that dial
Run uncalibrated and our most sensitive detector flags 112 of 113 labelled events at 0.5-second median latency.
The cost of that sensitivityThat operating point runs at 15.14 false alarms per hour, where three of every four alarms is false. Calibrated to a 10/hour budget, that same detector reaches 8% recall. Two ends of a dial, not a package — which is why we never quote them in one breath.
03 A budget that holds
Set “no more than N false alarms per week.” Pick one and see what it did.
Three budgets were tested against 447 days per channel of real ESA mission telemetry, on four channels. Twelve configurations. These are the committed results — the only three that exist.
What travels with these numbers 447 days per channel across four channels (4.9 channel-years) of real ESA Mission-1 telemetry, on the shipped default configuration. Each panel's observed figure is the range across the four channels at that budget; the ratio band below it spans all twelve configurations. All twelve sat inside a 95% Wilson interval and held to within 1.5% of target. This is coverage held over the long run, not a finite-sample proof — and only these three budgets were tested, so the panel offers only these three.
04 An explanation, not just an alarm
An alarm tells you something moved. This tells you what broke.
Fault diagnosis ranks hypotheses across subsystems and states its evidence in plain English. The shape of the answer:
Battery-cell fault, confidence 0.82 — power and pack temperature are both away from where they should be; comms symptoms are downstream of the EPS.
What travels with this That is a format illustration, not a measured case. The power and thermal evidence behind it is validated on our simulator only — OPSSAT's magnetometer and photodiode channels carry no power or thermal observables to test it against. We state it as design intent, and will not claim otherwise until it is demonstrated on real telemetry.
05 Safe by construction
Your operators stay in command.
Recommend-only by default
Nothing we suggest reaches your spacecraft without passing a safety gate first, and the default posture is to recommend rather than act.
The gate is the audited path
66 of 66 generated mutants killed. Property suite at 2048 cases per property. Exhaustive state-space enumeration. Model-checked with Kani on scheduled CI.
Model-checked on scheduled CI, not per-commit. We say which, because the difference matters.
06 The onboard path
It already fits on the flight computer.
The same code path is built for embedded flight computers. The ground tool is step one of an onboard autonomy roadmap, not a port of it.
What travels with these numbers Flash, RAM and instruction counts are measured exactly under emulation. Cycles-per-instruction is now measured on silicon — 1.65 to 1.95 on a Cortex-M7 devboard, in both cache configurations, with the emulation anchor reproduced bit for bit. CPU load remains strongly target-dependent. The 1.98–2.34% figure applies this board's measured CPI to a different part's clock — an extrapolation, and we label it as one. The 13–19% figure is still projected at an assumed CPI, because the on-silicon run covered the M7 class only. We state the FPU class with the number, and we do not call a projected figure measured.
07 Why believe any of it
The discipline is the product.
Anyone can put a number on a website. Here is the machinery that stops us putting the wrong one there.
Every number has a row
Each public figure has an entry in our claims-provenance file naming its source report, the command that produced it, whether it is measured, derived or projected, and the caveat that must travel with it. CI fails if any of them drifts from its source artifact.
A mission we have never looked at
A second ESA mission is held out of development entirely, behind a code-level guard that raises unless explicitly overridden at release time. It is not a promise; it is a function that throws.
We reproduce the published baseline
0.296 vs 0.295Our isolation-forest segment F1 is 0.296 against the benchmark paper's 0.295. Segment F1, not event F1 — a benchmark audience will check, and they should.
ESA's data, ESA's methodology
The harness pins ESA's expert-labelled OPSSAT-AD dataset by checksum and follows the ESA-ADB event-wise evaluation methodology, not point-wise F1.
Every figure on this page is measured on public data and traces to a committed report naming the command that produced it. Where a number is derived or projected rather than measured, this page says which, next to the number.
08 The pilot
A fixed-scope pilot, on your telemetry.
We're taking on a small number of fixed-scope pilot deployments.
- We run Orbital-AI against your historical telemetry, on terms you set — including entirely within your own boundary, with no data leaving your infrastructure.
- We review the findings with your operations team: every detection, every missed event, every false alarm.
- You keep the report either way. If it finds nothing your thresholds didn't, you'll know exactly what your current system is worth.
09 Contact
Worth 20 minutes?
If you operate a small satellite and your bus-health monitoring is a threshold file and a console, I'd like to show you what the same telemetry looks like through this.