Certification is earned by verifiable evidence, not by assertion. An AI that silently authors safety claims is a liability, not a feature. So the part you must trust here is not the AI — a deterministic engine owns every number, and the model is confined to proposing drafts a qualified engineer explicitly accepts.
The AI proposes, the deterministic engine computes, the qualified human decides — and every layer in between is grounded in the standards and the live project, routed through one governed gateway, citing its sources, calibrating its confidence, checking its own consistency, hard-gated, independently verified, recorded as evidence, and continuously red-teamed. The tool stands on its own: every analysis can be performed end to end on the deterministic core, and the AI is an optional accelerator, never a dependency.
A candidate fault-tree shape. A failure condition. A requirement. Narrative and justification prose. Structure and organisation — reversible, attributable, and inert until a human accepts it.
Exact top-event probability via Binary Decision Diagrams (repeated-event-correct). Common-cause failure by β / Multiple-Greek-Letter. Exposure-aware top-down DAL allocation. Component data from a curated reliability library.
| Risk | Guardrail | Where it acts |
|---|---|---|
| The AI does the math | Deterministic engine owns all quantification | Every probability / allocation |
| Wrong backend for controlled data | AI gateway policy router | Every AI request |
| Fabrication without inputs | Insufficiency guard; depth bounded by architecture | All drafting features |
| Ungrounded claims | Source-span citation + calibrated confidence | Every proposed item |
| Stale / wrong-config evidence | Approved-and-applicable evidence filter | Every retrieval |
| Approximate diagram reads | Vision flag + verify-to-accept gate | Decompose, FTA synthesis, chat |
| Silent inconsistency | Golden-thread consistency engine | After every AI write |
| Wrong severity / gate logic | Hard gates + independent verifier (generator ≠ judge) | Safety-critical drafts |
| Format / standards drift | Deterministic validators + scorecard | All AI artifacts |
| Unattributed change | Provenance stamp + AI Evidence Record + human accept | On acceptance |
| Regression over time | Eval harness, red-team suite, deploy gate, correction dataset | Continuous |
We’re glad to walk your safety, software and airworthiness teams through the guardrail architecture, answer a questionnaire, or share the full white paper (SLA-WP-002) and supporting evidence under NDA.