Foundation
Accounts, projects, invite-only authentication.
Releases
Every claim on this site resolves to one of three states. Shipped items appear in the present tense anywhere. In-build items carry an amber chip and a sentence on what exists today. Roadmap items carry a grey chip, the future tense, and no dates — ever.
Accounts, projects, invite-only authentication.
Functions, items, failure conditions, configurable classifications, spreadsheet import.
Tree editor, MOCUS + ROBDD solvers, four unavailability models, five importance measures, beta-factor CCF.
23-column worksheets, modes linked to fault-tree basic events.
Control structures, unsafe control actions, loss scenarios, FHA links.
Quantified reliability logic per failure condition, synchronised with the FHA.
CMA, ZSA and PRA as structured checklist records.
Argument editor with evidence freshness computed on read.
FDAL, verification status, validation records, FHA links.
Compliance matrix with derived status — INCOMPLETE / NOT ASSESSED today; COMPLIANT and NON-COMPLIANT reserved for a typed per-flight-hour result — and an append-only audit trail with before/after state.
DOCX reports, XLSX workbooks with the audit log as its own sheet, demonstration marking on every demo export.
Background solves in isolated child processes with tested cross-worker cancellation.
The audit, computation-run and model-import ledgers are append-only beneath the application — UPDATE is refused by the database itself on all three, DELETE on all but a parent-cascade; the least-privilege runtime role that completes the guard is a named open item.
Every quantitative comparison path reports INDETERMINATE or INCOMPLETE with its reason; no dimensionless unavailability is compared with a per-flight-hour objective anywhere.
Multi-user collaboration, project hierarchy and baselines. What's built today is per-account projects with no sharing between accounts, plus isolated background computation — the collaboration layer is ratified and in progress.
Element-level anchoring and drift reporting, gated behind the completeness checks that catch never-assessed imported functions. What's built today is the ingestion engine on the standard serialisation — library-level, no import screen yet. Full plan →
Some roadmap entries publish their gates as well as their intent — for example, model import ships together with the completeness checks that catch never-assessed imported functions, and completeness cannot read green while that count is non-zero.