Private preview — enter access code
Proofwerk
The platform — what we are building

The AI-defined data center for machines that move.

Roadmap, stated plainly. Each element ships when its evidence does.

Zonal node · N:1

Resilience without dead weight.

A hyperconverged zonal node consolidates ECUs, HPCs, and controllers onto shared silicon. Today's 1:1 standby computer is dead weight — an N:1 cluster shares one standby across many workloads. The failover itself leaves evidence.

Diagram: a hyperconverged zonal node consolidating ECU, HPC and controller workloads
The zonal node
Diagram: N:1 failover — one standby node backing multiple active workloads
N:1 failover
Runtime assurance

The vote proposes. The monitor decides.

Diverse models vote — for availability, not for safety. A small assured monitor and an independent fallback carry the safety claim. Disagreement routes to the fallback, and every decision leaves a record.

Diagram: diverse models vote and feed their result to a monitor
Voting for availability
Diagram: runtime assurance — an assured monitor and an independent fallback beside the voting pool
Monitor and fallback
Diagram: three nodes on one time-synchronized fabric — one clock, MACsec at line rate, votes comparable by construction
One clock, one fabric
Cockpit

One silicon, two worlds.

An Android Automotive OS consumer plane and an assured plane share the cockpit — the assured plane owns the telltale path. Display-integrity attestation closes the loop: our claim stops at the display controller's output.

Diagram: one cockpit silicon partitioned into a consumer plane and an assured plane
Consumer plane · assured plane
Diagram: telltale rendering with integrity checks at the display controller output
Proven pixels
Diagram: the display path from rendering to display controller output, with attestation points
The display path

Android and Android Automotive OS are trademarks of Google LLC; references are nominative.

Updates

Rollback, not recall.

New software runs shadow-mode beside production until its evidence clears the gate. Then cutover takes a reboot — not a night.

Diagram comparing serial over-the-air updates across ECUs on low-capacity links with a hyperconverged cut-over migration: a pre-staged, shadow-tested version is activated by changing the boot order; the previous version stays warm for rollback
Serial OTA vs the cut-over migration
The problem today

In today's E/E architectures an update crawls box to box: dozens of ECUs fed over low-capacity serial links. Reported industry cases have run past ten hours — long enough to deplete the battery mid-update, strand the vehicle, and turn a software rollout into recall-class cost, up to and including battery swaps just to get the update installed.

Pre-staged, shadow-tested

On the hyperconverged node the new version is fully enrolled before anyone commits to it. Containers are staged, integration is complete, and the release has already run in shadow mode against live traffic — beside the fleet, holding no authority — until its evidence cleared the gate.

The swing migration

Cutover is a boot-order change. The node — or the individual VM guest — simply boots the new version. It is the cut-over–style migration that has carried data-center fleets for two decades, brought to the machine: update time collapses from hours of transfer to node-boot time, under a minute by design. That is what makes mass-scale, fleet-wide rollouts routine instead of an event.

Rollback in production

The previous version stays warm through its retention window. If the rare regression surfaces in production, rollback is the same move in reverse — one decision, boot time, no recall. Every stage, cutover and rollback is evidence-logged and attributable.

The headroom that makes this possible is the same N:1 argument as failover: spare capacity per ECU is expensive; consolidated overprovision is marginal — and it buys resilience and instant updates at once.

Contested connectivity

Built for contested links.

LEO, 5G-Advanced, 6G-ready — bonded paths that degrade gracefully. Dual use by design: the same platform serves civil fleets and defense programs. The platform goes further: it anticipates the network before the road — the Anticipation Layer →

Diagram: bonded bearers — LEO, cellular and mesh links converging on one vehicle node, rerouting under contested spectrum and degrading gracefully
Bonded bearers
Three parties, one record

The chain does not stop at the fleet.

An operator does not hold the whole story. An authority requires an action and asks, later, how much of the fleet it actually reached. The person who owns the vehicle decides when — or whether — it installs. Both answers have to survive being read back months later, which means both have to be recorded at the moment they happen, by the party that holds them.

The end user

Consent is recorded, and so is a deferral. A request from an owner's phone, a vehicle HMI, a fleet partner's API or a workshop tool enters through one governed door, gets a policy verdict, and leaves a record — including the refusals. The platform serves no consumer interface; it holds the evidence of what was asked and answered.

The operator

A deferred endpoint is counted as a cohort exception, never as converged. At fleet scale that is the largest single source of drift between the desired state and the actual one — a figure to be evidenced rather than smoothed. Fleet customers operate a narrower scope of the same ledger, not a copy of it.

The authority

Reach is reported with the owner-deferred share intact, and labelled with its sampling basis: exhaustive on metadata, sampled on full attestation per cohort, complete on exceptions. A corrected figure is a new attestation, not an edit.

Diagram: authority, operator and end user above a shared evidence ledger, each writing into it, with reach proven back to the authority
Authority → operator → end user

A deferral is a lawful answer. It still has to be counted.

The roadmap, honestly

The staircase, not the leap.

QM and lower-integrity workload pools come first. Hosting the highest-integrity workloads is the roadmap's north star — gated on assessor acceptance, not on our own confidence.

And further out, labeled clearly as roadmap: household vehicles sit parked roughly 95% of the day (FHWA 2022 NHTS). Partitioned idle capacity is an OEM TCO offset waiting for its evidence.

The operator console for all of this already has a face — Explore the Bridge — design prototype → (gated; every number illustrative).