[ TECHNOLOGY ]

From the radio to the assignment engine, one company owns the stack

RF communication

The RF communication module, the navigation stack, the perception stack and the command layer are built in house. We are not integrating a third-party autopilot with a third-party radio and calling the result a system.

System diagram

Three layers, two directions of flow

Tasking, downState and sensor return, up
Layer 01
Command
INTENT · ASSIGNMENT · AUTHORISATION
Intent parser
Capability match
Assignment engine
Authorisation gate
Mission record
↓ TaskingState
Layer 02
Network
RF MESH · LTE · SATCOM · FAILOVER
RF mesh
4G / 5G
SATCOM
Bearer select
Encryption
↓ TaskingSensor return
Layer 03
Agent
NAVIGATION · PERCEPTION · CONTROL
Navigation
Perception
Autonomy tier
Flight / drive control
Health monitor

Every section below is a zoom into one layer of this diagram. Interfaces between layers are named because the interfaces are where integration risk lives.

Layer 01

Command

The command layer takes a stated intent — jam this grid, hold eyes on this ridge, move this load — and resolves it into tasking for specific assets. It matches the capability the intent requires against what each asset is carrying, where it is, how much endurance it has left and whether it currently holds a link. The operator states what they want. The layer works out who can do it.

It proposes; it does not commit. Every assignment that results in an effect passes an authorisation gate held by the operator, and that gate is a property of the architecture rather than a setting.

Position in stack
Process — intent to execution
01
Intent received
Commander states an outcome, not a platform.
02
Capability match
Payload, position, endurance and link state per asset.
03
Assignment proposed
Best-fit asset, with the reason shown.
04Human
Authorisation
Operator gate. Required for any effect.
05
Execution
Tasking issued. State returns continuously.
State returns continuously — reassignment runs on every update
Step 04 — the authorisation gate

The one step the system cannot take for itself

An assignment reaches the operator with the reasoning that produced it. Approving is a person’s action, it expires rather than persists, and it is written to the mission record.

Embodiment · GCSMission 04-BOperator K. RaoLink mesh · 4 hopsAgents 12 / 1214:35:20
Assets
A-01EO/IRTASKED
A-02EW JAMMERTASKED
A-03EO/IRON STATION
A-07EFFECTORSTANDBY
A-08EFFECTORIDLE
A-11RELAYTASKED
G-01EO/IR · MASTMOVING
G-02CARGO 30KGIDLE
A-05COMINTNO LINK
Tasked 07 · idle 04 · lost 01
Span of control nominal
EO · zoom 4.0× · trk 3
Grid 43R FQ 8214 6390
Slant 1 480 m
Alt 620 m AGL
Feed · agent A-03 · EO/IR
Rec 14:35:20
Authorisation requiredT-00:42
Detection
Wheeled convoy, 3 vehicles
Class tracked / wheeled · conf 0.94
Bearing 041° · range 1 480 m
Speed 18 km/h · heading NE
First seen 14:31:08 · held 00:04:12
Proposed action
Assign A-07 to engage lead vehicle
01Payload matchEFFECTOR
02Time to target2 M 40 S
03Endurance remaining31 MIN
04Current taskingNONE
05Deconflicted withA-01, A-03
Operator authorisation is required for any effect. This decision is logged.
Approve
Cancel
Command
The ground station at the moment step 04 is reached. The system has proposed an assignment and shown its reasoning; nothing proceeds until a person presses approve, and the decision is written to the mission record. Screen shown for illustration — the station is not operable from this page.
When it fails — reassignment

An asset drops out mid-task

Losing an asset is the normal case, not the exception. The question worth asking is what the remaining assets do about it without being told.

Before · T+0

Four assets tasked. A-02 holds the track, A-03 holds the relay.

A-02
link lost
2.4 s
After · T+2.4 s

A-04 is retasked to the track and the relay repositions to close the gap. The operator is told what changed rather than asked to fix it.

Shown at block-diagram level. The allocation method itself is covered under NDA at briefing.

Assets per operator
12
Demonstrated in scenario simulation. Six flown concurrently to date.
Reassignment latency
2.4 s
Loss detected to replacement asset tasked, median over simulated runs.
Authorisation modes
3
Per-action, per-task with stated bounds, observe-only. No mode removes the gate for an effect.
Tasking input
Intent
Capability and area. Not waypoints, not a named platform.
Layer 02

Network

One module carries three bearers: an RF mesh between agents, terrestrial 4G/5G where a network exists, and SATCOM beyond it. Each asset holds whichever bearers its class can carry, and the module selects between them on link quality rather than on a fixed priority the operator has to manage.

The mesh is the layer that matters, because it is the only one that keeps working with no infrastructure at all. Agents relay for each other, so an asset beyond the ground station’s own range stays reachable through the assets between them.

Position in stack
Topology — bearers and relay paths
GROUND STATIONONE OPERATORSATCOM4G / 5GA-01MESHA-02MESHA-03MESH+SATA-04MESHG-01MESH+LTEA-05MESH
When it fails — automatic failover

A bearer drops

Failover happens without operator action. What matters to an evaluator is which assets keep a link and which do not.

SATCOM lost
10 of 12

Assets holding mesh or cellular keep a link. The two SATCOM-dependent assets fall back to mesh at reduced range.

Cellular lost
12 of 12

No asset depends on cellular alone. Cellular is a bearer of convenience, never the only path.

Ground link lost
0 of 12

Every asset executes its last authorised task and returns. None continues acting on stale tasking.

What degrades it

Mesh range is line of sight. In broken terrain a ridge between two agents costs the hop, and range falls well below the open-ground figure — which is why a relay asset is positioned from terrain rather than flown in a fixed pattern. Cellular depends on a network that may be absent, congested or hostile. SATCOM adds latency and costs mass and power that a light airframe cannot spare.

What we do not claim

We do not claim a jam-proof link. We claim that loss of any one bearer does not isolate an asset that holds another, that the mesh reforms without operator action, and that an asset which loses all bearers executes its last authorised task and returns rather than continuing to act on stale tasking.

Bearers
3
RF mesh, 4G/5G, SATCOM. Carried per class, mesh on every asset.
Mesh range
15 km
Open ground, agent to agent. Substantially less in broken terrain.
Failover
< 3 s
Bearer loss to traffic carried on an alternate path, measured on the bench.
Encryption
AES-256
In transit, with keys provisioned per mission. Key management under NDA.
Layer 03

Agent

An agent has to know where it is and what is around it without assuming a satellite fix. Three navigation techniques run on the asset, each suited to different conditions, and the estimator weights them on measured quality rather than on a fixed order. Position is always reported with its confidence, so a degraded fix is visible as degraded rather than presented as certain.

Perception runs onboard. Detection and tracking happen on the asset so that a link outage costs bandwidth, not the ability to see. What crosses the link is the resulting track, not the raw video.

Position in stack
Navigation — three techniques, measured drift
VIOSTEREO + IMU
Visual-inertial odometry

The default in daylight over textured ground. Cheap in mass and power, and available on every tier.

Drift0.8 % of distance
Fails onFeatureless ground, darkness, heavy dust
LIO3D LIDAR + IMU
LiDAR-inertial odometry

Tier 3 and above. Works in darkness and holds geometry where vision has nothing to lock onto.

Drift0.3 % of distance
Fails onOpen water, heavy rain, no structure
TRNDOWNWARD EO + DEM
Terrain-relative navigation

Bounds the drift of the other two by matching what is seen below against stored terrain.

DriftBounded, no growth
Fails onTerrain not in the reference set

Drift figures are measured over closed-loop runs on our own airframes and are stated as observed, not as specification. How the estimator weights the three is covered at briefing.

When it fails — GNSS denial

The fix is jammed or spoofed

Jamming denies the fix. Spoofing is worse: it supplies a false one that looks valid. Both are assumed.

Jamming
The fix is denied

The estimator drops GNSS and continues on VIO, LIO and terrain matching. Position confidence is reported honestly as it degrades rather than being held at a false certainty.

Spoofing
The fix is false

A GNSS solution that disagrees with the inertial and visual solution beyond a bound is rejected, not averaged in. Disagreement is surfaced to the operator as a condition of the area.

Operator view
Degradation is visible

The ground station shows which navigation sources each asset is currently using and the confidence of its position. A degraded asset looks degraded on the screen.

Autonomy tiers

Tiers are defined by sensor set, because that is what actually determines capability

A tier named after a behaviour is unfalsifiable. A tier named after its sensors tells you what it can and cannot do, and what it costs in mass and power.

Tier
Capability
Sensor set that defines it
Mass
Power
Typical use
Tier 1
Forward obstacle avoidance
Stereo depth camera, downward rangefinder
0.18 kg
6 W
Open ground, transit
Tier 2
Forward and rear avoidance
Dual stereo pair, rear ToF array
0.42 kg
14 W
Cluttered approach
Tier 3
Full autonomy with SLAM
3D LiDAR, stereo pair, tactical-grade IMU
0.95 kg
38 W
GNSS-denied, indoor
Tier 4
Night-capable autonomy
LiDAR-led, optional cooled thermal
1.30 kg
46 W
Darkness, low contrast
Each tier maps to a selectable option in the platform configurator.Open the configurator →
Navigation techniques
3
VIO, LIO and terrain-relative, weighted on measured quality.
Perception
Onboard
Detection and tracking run on the asset. Tracks cross the link, not raw video.
Autonomy tiers
4
Defined by sensor set, selectable per configuration.
Software licence
None
Permissive open stack. No per-unit software licence fee, ever.
[ Cross-cutting ]

Three things that sit across every layer

Assurance, validation and indigenisation are not features of one layer. They are properties of how the whole thing is built, and each is a named line in a procurement evaluation.

A

Assurance and security

Stated as posture, not as certification we do not hold.

Encryption and key management

AES-256 in transit across every bearer, with keys provisioned per mission and no static key shared across a fleet. The provisioning mechanism is covered at briefing.

Secure boot

Flight computers verify a signed image at boot and refuse to run an unsigned one. A recovered airframe cannot be reflashed into a working asset without our signing key.

Supply-chain attestation

Every board carries a recorded origin, and the build record ties a serial number to the components in it. We can state where each part of a delivered unit came from.

No unsolicited callhome

Nothing in the stack contacts us. There is no telemetry channel to a vendor server, no update that arrives unasked, and no dependency on our infrastructure for a mission to run.

Certification posture

We are building to the documentation and test standards Indian procurement applies, and we will say plainly which we hold and which we do not rather than implying coverage we have not earned.

B

How we validate

Most of what we prove, we prove before an airframe exists.

See the simulator →
01
SITL
In software.
02
Scenario simulation
In software.
03
Hardware in the loop
In software.
04On a range
Flight and range
On a range.
01 · SITL

Flight and drive control run against a simulated airframe. Control laws, failsafes and mode transitions are exercised before hardware exists.

02 · Scenario simulation

Multiple agents, a terrain model and degraded links. Assignment, reassignment and mesh behaviour are exercised at fleet scale.

03 · Hardware in the loop

Real flight computer, real communication module, simulated world. Timing and compute limits show up here, not on a range.

04 · Flight and range

What cannot be proven in software: aerodynamics, propulsion, RF propagation over real terrain, and the integration of all of it.

C

How we build

Indigenisation as an engineering decision, not a paperwork exercise.

72–82%
Indigenous content by BOM value

Range across the platform classes. The figure moves with powerplant and link set — an Indian-made engine raises it, SATCOM lowers it — and the configurator computes it per configuration rather than quoting a single number.

Made in house

Airframe structures, the communication module, flight and drive control, the navigation and perception stack, and the ground station. These are the parts where a dependency would be strategic rather than commercial.

Sourced in India

The IC engine on the 20 kg class, machined and composite components, wiring and connectors, and assembly. Domestic supply where a domestic supplier exists at the quality required.

Sourced abroad

Compute modules, imaging sensors, certain RF front-end components and SATCOM terminals. Stated openly, from named non-Chinese sources, with a documented second source where one exists.

Origin verification

Component origin is verified at goods-in against supplier declarations and recorded per serial number, not accepted on a distributor's word. Indigenous content is computed from that record as a share of BOM value.

Everything below block level is a conversation

Architecture, interfaces and trial data are released under NDA. Bring your evaluation criteria and we will walk the stack against them.