Releases

What shipped, what's in build, what's queued.

Every claim on this site resolves to one of three states. Shipped items appear in the present tense anywhere. In-build items carry an amber chip and a sentence on what exists today. Roadmap items carry a grey chip, the future tense, and no dates — ever.

Shipped

Foundation

Accounts, projects, invite-only authentication.

System model & FHA

Functions, items, failure conditions, configurable classifications, spreadsheet import.

FTA builder & math engine

Tree editor, MOCUS + ROBDD solvers, four unavailability models, five importance measures, beta-factor CCF.

FMEA

23-column worksheets, modes linked to fault-tree basic events.

STPA

Control structures, unsafe control actions, loss scenarios, FHA links.

Dependence diagrams

Quantified reliability logic per failure condition, synchronised with the FHA.

Common cause analysis

CMA, ZSA and PRA as structured checklist records.

GSN safety case

Argument editor with evidence freshness computed on read.

Requirements & assumptions

FDAL, verification status, validation records, FHA links.

Compliance & audit

Compliance matrix with derived status — INCOMPLETE / NOT ASSESSED today; COMPLIANT and NON-COMPLIANT reserved for a typed per-flight-hour result — and an append-only audit trail with before/after state.

Document generation

DOCX reports, XLSX workbooks with the audit log as its own sheet, demonstration marking on every demo export.

Solver process isolation

Background solves in isolated child processes with tested cross-worker cancellation.

Ledger guards at the database level

The audit, computation-run and model-import ledgers are append-only beneath the application — UPDATE is refused by the database itself on all three, DELETE on all but a parent-cascade; the least-privilege runtime role that completes the guard is a named open item.

Fail-closed quantity semantics

Every quantitative comparison path reports INDETERMINATE or INCOMPLETE with its reason; no dimensionless unavailability is compared with a per-flight-hour objective anywhere.

In build

Amber

The platform phase

Multi-user collaboration, project hierarchy and baselines. What's built today is per-account projects with no sharing between accounts, plus isolated background computation — the collaboration layer is ratified and in progress.

SysML v2 model import

Element-level anchoring and drift reporting, gated behind the completeness checks that catch never-assessed imported functions. What's built today is the ingestion engine on the standard serialisation — library-level, no import screen yet. Full plan →

Roadmap

Grey · no dates
  • Seven further methodsPHA, HAZOP, Bow-Tie, ETA, Markov, RBD, ALARP — specified in the architecture.
  • Audit export for IV&VA standalone, filterable audit deliverable.
  • Deliverable issue controlIssue numbers and a report registry behind every generated cover.
  • Per-account lockoutAlongside the existing per-IP rate limiting.
  • Offline install & syncAn air-gap bundle, and reconnection sync for disconnected working.
  • Publish back to the modelDerived requirements written to a SysML branch through your review gate.
  • Protective markingMarkings across every document producer and a fail-closed instance ceiling — specified, awaiting ratification.
  • Typed per-flight-hour quantities and verdictsThe mathematics specification's release gates, reached through a proposed conformance arc; verdicts return only when a typed quantity exists.

Some roadmap entries publish their gates as well as their intent — for example, model import ships together with the completeness checks that catch never-assessed imported functions, and completeness cannot read green while that count is non-zero.