Fault Tree Analysis (FTA) is the quantitative backbone of an aircraft safety assessment. For each failure condition identified in the Functional Hazard Assessment, you build a top-down logic model of how component, system and environmental failures combine to cause it — then quantify the probability and compare it against the certification target for that severity.
Safety Lab Aero gives you a full FTA environment that does not stop at drawing the tree. Every tree links to its failure condition, carries the certification-basis target, and stays connected to the FMEA evidence, component library and requirements underneath it.
Build the tree
- Static gates — AND, OR, INHIBIT, VOTING / k-of-n, XOR — and dynamic gates PAND, SPARE and FDEP for time-ordered behavior.
- Event types — basic, undeveloped, conditioning and house events.
- Link the top event to its failure condition, so the tree inherits the severity classification and quantitative target.
- Span large analyses across multiple pages with TRANSFER gates; the combined cross-page tree is evaluated as one model.
Quantify it rigorously
Safety Lab Aero computes the top-event probability directly, not just a minimal-cut-set upper-bound approximation. That matters whenever a basic event repeats across cutsets or when common-cause coupling is present — the cases where the simple upper bound quietly over- or under-states the result.
- Top-event probability with the minimal-cut-set upper bound shown alongside for reference.
- Minimal cutsets, including common-cause-expanded cutsets where an order-1 common-cause term can dominate.
- Importance measures per basic event — Birnbaum, Fussell-Vesely, Risk Achievement Worth and Risk Reduction Worth.
- Uncertainty propagation via Monte Carlo over lognormal failure-rate distributions.
Set basic-event data the way your evidence actually exists
A basic event can take its rate from a direct failure rate, an MTBF, a fixed probability, a component-library entry (with environment, quality and temperature factors applied), or a Markov model for repairable, multi-state items. Repeated logical events are treated as one physical event so the quantification does not double-count them.
Allocate DAL top-down
Development Assurance Levels flow from the failure-condition severity down through the tree, honoring gate logic, with support for the ARP 4754B allocation options on AND gates. See ARP 4754B & DAL allocation for how that fits the development-assurance flow.
Frequently asked questions
Does Safety Lab Aero compute exact top-event probability or just the cut-set upper bound?
It computes the top-event probability directly and shows the minimal-cut-set upper bound alongside it for reference. The direct result is what you need when basic events repeat across cutsets or when common-cause coupling is present, where the upper bound is no longer a good approximation.
Can it handle dynamic fault trees?
Yes. PAND, SPARE and FDEP gates are supported, with a Monte Carlo simulator that samples failure times and honors time-ordered semantics for dynamic behavior.
Does the fault tree connect to FMEA and requirements?
Yes. Piece-part FMEA modes feed basic-event rates, the component library sources failure data, and safety requirements derive from the tree — all kept in one connected model so a change in one place flags what it affects elsewhere.
See it on your own analysis
Safety Lab Aero keeps functions, hazards, fault trees, FMEA, common-cause, requirements and verification in one connected model — from FHA to a certification-ready evidence package.