Platform Platform OverviewArchitecture
Jurisdictions Thermal InspectionPrecision MappingFire MonitoringISR Operations
Papers Partner with us

One platform.
Three components.
Governed BVLOS.

Flightworks Sentinel sits between your AI layer and your autopilot. It does not replace your GCS or flight controller — it governs what AI is permitted to propose, issues typed verdicts, and preserves replayable evidence of every decision.

3 
Verdict Types
0 
Unsigned Decisions
Replayable Missions
Sentinel Platform Architecture
Works alongside existing GCS and autopilot stacks · MAVLink-native
Governance Active
YOUR STACK YOUR STACK FLIGHTWORKS SENTINEL GCS QGroundControl AI module Proposes Autopilot PX4 / ArduPilot Flightworks Control Auth / Evidence / Replay SENTINEL CORE Authority Gate ALLOW DENY ESCALATE EDGE RELAY / Capture / Replay proposals allowed only CRYPTOGRAPHIC AUDIT CHAIN / CONTINUOUS
01 · Before flight
Mission Auth
Flightworks Control
02 · During flight
Authority Gating
Sentinel Core + Edge Relay
03 · After flight
Evidence Review
Flightworks Control
What It Is

Not a GCS.
The governance layer.

Flightworks Sentinel is the governed flight platform built on the SwiftVector and RustVector enforcement kernels. It does not compete with QGroundControl or any flight controller — it governs what any GCS executes.

Architecture

Constitutional
infrastructure

Every state mutation flows through typed Actions, deterministic Law evaluation, pure-function Reducers, and an append-only SHA256 hash chain. The laws cannot be bypassed because they are the architecture.

Separation

Governs, does
not execute

Watch Station handles pre-flight authorization and post-flight evidence review. The GCS handles execution. This separation is intentional — governance runs before and after the flight, not during it.

Enforcement

Safety by
construction

Safety is not bolted on after the fact. FlightLaw’s nine laws (0–8) are evaluated before every state transition. Violations are not warnings — they are architectural constraints that prevent the transition from occurring.

Edge Infrastructure

Four crates.
One mission.

Sentinel is four Rust crates composed in strict layers. Each crate has a single responsibility and cannot reach into a layer it does not own. The kernel enforces governance at the edge with zero cloud dependency.

Sentinel Governance Engine · RustVector Architecture
RUSTVECTOR-CORE State / Action / Reducer / Audit PURE · NO DEPS · DETERMINISTIC SENTINEL-CORE GovernancePolicy / Laws / AuthorityGate DOMAIN RULES · VERDICT ENGINE SENTINEL-RELAY MAVLink Proxy / Decoder / Allowlist UDP FORWARDING · ZERO-COPY PARSING SENTINEL-CLI relay / replay / verify via clap OPERATOR INTERFACE · SUBCOMMANDS UDP MAVLINK V2 PX4 / ARDUPILOT (SITL OR HW)
Verdicts

Three outcomes.
No ambiguity.

Every evaluation produces exactly one of three verdicts. There is no fourth option. There is no grey area.

AUTO_ALLOW
Permitted

Action within all rule boundaries. Permitted without operator intervention. Frame forwarded to autopilot. Verdict logged with full evaluation trace.

AUTO_DENY
Denied

Action violates one or more rules. Denied immediately. Frame blocked from reaching autopilot. Logged with violation detail and rule identifiers.

ESCALATE_TO_OPERATOR
Escalated

Action within boundaries but exceeds auto-approve threshold. Frame held pending explicit principal decision. Timeout enforced by risk tier.

FlightLaw

Nine laws.
One kernel.

Every jurisdiction inherits FlightLaw. These nine laws (0–8) are evaluated before every state transition. FlightLaw violations always take precedence over jurisdiction-specific laws.

0
Containment

System boundary enforcement. Defines the operational envelope. EMCON boundary in ISR jurisdictions.

1
Identity

Principal authentication. Verifies the authorized human decision-maker before any mission state transition.

2
Weather

WeatherKit environmental pre-flight gate. Operational thresholds evaluated deterministically. No override without principal authorization.

3
Observation

Telemetry quality, GPS lock, IMU calibration. The system must observe itself accurately before it can act.

4
Resource

Battery, compute, and link budget enforcement. Operations cannot exceed available resources. RTH reserve enforced.

5
Classification

Data classification at the state level. Active in ISRLaw jurisdictions. Determines handling, storage, and transmission constraints.

6
Degraded Mode

Authority contracts when comms degrade. Autonomy envelope contracts — never expands. Deterministic fallback chain.

7
Spatial

Geofence, altitude ceiling, and no-fly zone enforcement. Corridor locked at mission authorization. Violations trigger immediate response.

8
Authority

Risk-tiered principal approval gate. The final law. Low risk auto-approved. Medium risk with timeout. High risk requires explicit principal authorization — no timeout, no default. The system waits.

Performance

Edge speed.
Full audit.

Governance at wire speed means zero compromise between safety and latency. Every frame evaluated, every verdict logged, every session replayable.

<5ms
Target Relay Latency

Transparent MAVLink v2 forwarding with zero-copy parsing. Governance enforcement at wire speed.

<1ms
Target Audit Write

Append-only log with SHA256 hash chain. Every frame logged without blocking the relay pipeline.

100%
Design Goal: Replay Fidelity

Deterministic replay of any audit log produces identical state transitions. Every time.

100%
Design Goal: Frame Audit

Every MAVLink frame logged and hashed. No sampling. No gaps. Complete chain of custody.

Interface

Three commands.

Sentinel exposes three subcommands. Each maps to a core capability of the governance engine.

sentinel relay
Governance Relay

Start the MAVLink proxy with governance enforcement. Binds to a UDP port, evaluates every frame against the active rule set, forwards permitted frames to the autopilot.

sentinel replay
Deterministic Replay

Replay an audit log file deterministically. Reproduce the exact sequence of evaluations and verdicts from a previous session.

sentinel verify
Chain Verification

Verify hash chain integrity of an audit log. Walk the chain from first entry to last. Any break in the hash sequence indicates tampering.

Regulatory

Built for
emerging standards.

Sentinel’s architecture aligns with the direction of emerging regulatory and procurement requirements for autonomous drone operations. Deterministic enforcement and tamper-evident audit trails are designed as architectural primitives.

FAA
BVLOS Rulemaking Direction

Proposed BVLOS frameworks point toward requirements for machine-enforceable geofencing and auditable decision trails. Sentinel provides both as architectural primitives.

NDAA
Machine-Readable Geofencing

Growing legislative emphasis on machine-readable, enforceable geofence boundaries. Sentinel evaluates polygon containment on every telemetry frame with full audit trail.

DoD
Trusted Autonomy Requirements

Defense procurement increasingly emphasizes deterministic, auditable governance for autonomous systems. Sentinel’s replay capability enables post-mission verification of every decision.

Explore the
architecture.

Sentinel is one layer of the Flightworks governance stack. Understand how the SwiftVector kernel, RustVector edge relay, FlightLaw, and the Watch Station principal interface compose into a complete mission governance platform.