AeroBrain by SkyDynamics
High-assurance, real-time and hard real-time AI. The AeroBrain set of auditable technologies for aerospace, defence and safety-critical fields.
AeroBrain is a set of AI technologies developed by SkyDynamics: the LLiDA real-time database, the Contextual Composition Protocol, a secured RAG engine written in Rust and an auditable Assurance Small Language Model. Together they read live data from the aircraft's avionics, understand a problem as it appears and propose solutions that people can verify and audit.
Aircraft avionicsLive
IllustrativeEngine 2 vibration
Rising
The crew decides. Everything is recorded.
LLiDA
Detects
Trend found
Protocol
Understands
Climb, icing
RAG
Retrieves
4 sources
SLM
Proposes
3 options
Possible solutions
- Apply the high engine vibration procedureSource: Operator QRH
- Reduce thrust on engine 2 within limits and monitorSource: FCOM limits, live data
- Review diversion options if the trend continuesSource: Operations manual
Audit record written: data, sources, model version, decision
- High assurance
- Developed to MISRA C and the objectives of DO-178C, with requirements, code, tests and evidence traceable in both directions.
- Auditable
- Every input, source, model version, output and decision is recorded, so any answer can be replayed and examined afterwards.
- Real time
- Works on live data from the avionics and answers while the event is still unfolding, not after the flight.
- Hard real time
- For functions where a late answer counts as a failure: each stage runs to a fixed deadline, so the response time is designed in, not hoped for.
Use case: real-time decision support on the aircraft
The same event, stage by stage. Four technologies working together, and a crew that decides.
The event
In the climb, in icing conditions, the vibration of one engine starts to rise.
- Phase
- Climb
- Signal
- Engine 2 vibration
- Source
- Avionics, live
- Conditions
- Icing
LLiDA captures the trend
Engine parameters arrive from the avionics in real time and are sampled into memory at a fixed rate, on the aircraft. The rise is seen as it happens, not after the flight.
Vibration above the normal band and rising
Contextual Composition Protocol holds the situation
Phase of flight and aircraft configuration from the avionics, open MEL items and weather are already in memory. The event is read against them.
Climb, icing conditions, no open engine items
Secured RAG engine retrieves the evidence
The live readings and the passages of the operator's approved manuals that apply to this situation are retrieved deterministically, each with its source and time.
Live readings, procedure, limits and MEL reference
Assurance Small Language Model proposes the solutions
A compact, auditable model composes the possible solutions from that evidence only. Each one keeps its source.
Three possible solutions, each with its source
Governed layer the crew decides
The solutions are offered, never executed. The decision and its evidence are recorded and synchronised to the ground over a secured link.
Decision recorded, ground informed
Time budget
Every stage inside its deadline
Each stage runs to a fixed time budget, which is what makes the chain usable in real time and hard real time.
On the flight deck
Evidence
- Vibration trend above the normal bandSource: Live avionics data, in LLiDA
- Icing conditions in the current phaseSource: Held context, from the avionics
- High engine vibration procedureSource: Operator QRH, current revision
Possible solutions
- Apply the high engine vibration procedureSource: Operator QRH
- Reduce thrust on engine 2 within limits and monitorSource: FCOM limits, live data
- Review diversion options if the trend continuesSource: Operations manual
Decision
Chosen by the crew. Recorded with its evidence and sent to maintenance control.
Illustrative use case with invented values. It shows how the technologies combine; it is not a certified airborne function or an operator procedure.
What AeroBrain is
Four technologies. One governed stack, from the processor to the decision.
Each technology does one job and can be used on its own. Combined, they take real-time data from the aircraft's avionics, read it against approved manuals and records, and produce an advisory that a person can check, with every step recorded.
Every layer is built to the same requirements: high assurance, auditability, real time and hard real time. The whole set was developed in-house by SkyDynamics over 15 years of research and development, and proven in research before being offered to industry.
Processor
RISC-V, ARM and others
Live data
From the aircraft's avionics
AeroBrain
Four technologies, one after another
- LLiDA
- Protocol
- RAG
- Model
Instructor, crew or engineer
Sees the options and their evidence
Decision
Taken by a person, and recorded
- Governed decision layerPeople decide. Every recommendation, source and override is recorded.
- Assurance Small Language ModelWords the answer from the evidence it is given, and can be audited.
- Secured RAG engineRetrieves live readings and approved passages, the same way every time.
- Contextual Composition ProtocolHolds the task and its context in memory and correlates each event with it.
- LLiDA real-time databaseCaptures real-time avionics data as time series and keeps every node synchronised.
Runs on RISC-V, ARM and other processors, in RAM and on disk, from a microcontroller to a data centre, connected or air-gapped.
Developed in-house
Every technology in the set is designed and written by SkyDynamics.
15 years of research and development
The set grew out of long-running research into AI for safety and mission-critical fields.
Proven in research
Demonstrated in research settings and ready to be taken into next-generation avionics and other assured products.
Secured RAG engine
Retrieval you can replay. A secured RAG engine written in Rust, for real-time and edge AI.
RAG (retrieval-augmented generation) grounds an AI answer in sources you approve. In AeroBrain those sources are not only manuals and records: the engine also retrieves over real-time data from the aircraft's avionics, held as time series in LLiDA. An answer can cite a live reading and the procedure that applies to it.
The engine is deterministic: the same question, on the same document snapshot and the same recorded data, returns the same evidence, in the same order, with its source and time. An auditor can replay an answer, not just read it.
The question
Asked by a person, or raised by an event.
High engine vibration in icing conditions
Two kinds of source
Live data from the avionics and your approved documents, each identified.
- Live avionics data
- Time series in LLiDA, time-stamped
- Approved documents
- Manuals and records, one revision set
Ordered fusion and ranking
Candidates are fused and ranked in a defined order. Nothing is left to chance.
The evidence set
Readings and passages, each with its source, time or revision.
- LLiDAEngine 2 vibration: live trend, time-stamped
- QRHAbnormal procedures: high engine vibration
- FCOMPower plant: limitations
- MELPower plant: dispatch conditions
Audit replay
- First run: evidence fingerprint
- 7c41 9be2 05af
- Replayed later: evidence fingerprint
- 7c41 9be2 05af
Identical evidence set
Live avionics data and documents
Retrieves over real-time data from the aircraft's avionics, held in LLiDA, together with approved manuals and records. Each piece of evidence keeps its source, and its time or revision.
Written in Rust
The engine is written in Rust for memory safety without a garbage collector. Safety-critical components use Ada SPARK and C written to MISRA C.
Deterministic paths
Ordered fusion, reproducible ranking and explicit provenance, so the same query, corpus snapshot and recorded data yield the same evidence set for audit replay.
Edge, on-premises and air-gapped
Runs on the device, behind your perimeter or in a disconnected enclave. Inference and corpora stay under your data residency and access policies.
Real time and hard real time
Built to answer inside a fixed time budget. On our reference stack, retrieval through ranking is ~12 ms-class; with LPU-class accelerators the target is ~3 ms-class. Your figure depends on hardware, index size and network path.
Operator-grade observability
Usage, model routing and safety classifications are exposed for enterprise monitoring, so the engine can be operated and evidenced like any other critical system.
Contextual Composition Protocol, developed by SkyDynamics
Context held, not rebuilt. The Contextual Composition Protocol keeps the whole task in memory.
The Contextual Composition Protocol holds all the data relevant to a specific task or workflow in memory, behind the scenes, and correlates it with whatever arrives at that moment: a reading, a question, a message.
So when an event occurs, nothing has to be looked up or entered again. The system already holds the phase of flight and the aircraft state from the avionics, and the procedure in progress, and the event is read in that context.
In service today: EBT and CBTA training
The protocol already works behind every AeroEBT application.
- In the EBT Scenario Builder it holds the specification, the competency framework and the aircraft type while a scenario is composed
- In the instructor app it holds the scenario and the event in play during recording and assessment
- It supports the instructor and never makes the grading decision
Next: real-time decision support
The same mechanism carries into operations and avionics.
- An alert is read against the phase of flight and the live aircraft state
- Retrieval is narrowed to the procedures that apply to that situation
- The advisory is short, because the context is already known
The protocol does not decide. It makes sure that whatever is decided, by a person or a model, is decided with the full context in view.
Low Level integrated Database Architecture, developed by SkyDynamics
LLiDA. A real-time time-series database for RAM, disk and the processor itself.
LLiDA captures real-time data, such as the data of an aircraft's avionics, as time series. It works in RAM, on disk and at processor level, on RISC-V, ARM and other architectures, from a low-level microprocessor computer to a server.
It keeps every connected node synchronised live, over secured or common networks, and it is written to safety-critical rules such as MISRA C and the objectives of DO-178C, for high-reliability and high-assurance systems.
Sampled at a fixed rate
Each avionics channel is read on a fixed period, so timing is known in advance.
Held in RAM and on disk
The newest samples sit in memory for the layers above, and the record is kept on disk.
- Latest sample
- 4128
Synchronised live
Every node sees the same record, as it is written.
Microcontroller
RISC-V, low-level computer
4128In sync
- Secured network
Avionics computer
ARM, on the aircraft
4128In sync
- Common network
Ground system
Server, operations and maintenance
4128In sync
Real-time time series
Avionics and sensor values are captured as they are produced and are available to the layers above without a round trip to a server.
RAM, disk and processor
LLiDA works in RAM, on disk and at processor level, so one architecture covers the working data and the stored record.
RISC-V, ARM and others
The same architecture across processor families, from low-level microprocessor computers to avionics computers and servers.
Live synchronisation
Nodes exchange data live over secured networks or common networks, so the aircraft, the edge device and the ground hold the same record.
High reliability and assurance
Developed to the rules used for flight software, including MISRA C and the objectives of DO-178C, for high-reliability and high-assurance systems.
Assurance Small Language Model
A small model you can audit. The Assurance Small Language Model, built for real-time AI in safety-critical use.
Large general-purpose models are hard to bound and hard to inspect. The Assurance Small Language Model is custom developed by SkyDynamics to be the opposite: compact enough to run at the edge in real time, and designed so that each statement it produces can be traced to the evidence it was given.
Evidence in
- E1Live reading: vibration trend above the normal band
- E2Held context: icing conditions in the current phase
- E3Manual: high engine vibration procedure
Assurance Small Language Model
Compact. Fixed version. Runs on the device.
Statements out
- Engine 2 vibration is rising.Source E1
- Icing conditions are present.Source E2
- The high engine vibration procedure applies.Source E3
- A statement about the probable cause.Withheld: no supporting evidence
Audit record
- Input
- Event and held context
- Evidence
- E1, E2, E3 with time or revision
- Model
- Version identified
- Output
- Three statements, one withheld
Auditable
Input, evidence, model version and output are recorded together, so a result can be examined after the fact.
High assurance
Developed under the same assurance discipline as the rest of the set, for work where an unsupported answer is not acceptable.
Real time at the edge
Small enough to run on the device, without a connection, inside a fixed time budget.
Standards, assurance and auditability
Built to the rules of flight software. Assurance and auditability are designed in, not added afterwards.
The technologies are developed to high-assurance practice: MISRA C for C code, Rust for memory safety, Ada SPARK where proof is required, and the objectives of DO-178C for airborne software. Requirements, code, tests and evidence are traceable in both directions.
Requirement
Each function starts as an identified requirement.
Design
The design states how the requirement is met.
Code
Written to MISRA C, in Rust or in Ada SPARK.
Test
Each requirement has tests that exercise it.
Evidence
Results are kept with the release they belong to.
Forward: every requirement reaches a test.
Back: every line of code answers a requirement.
Auditable by design
High assurance needs more than careful development. Every answer the system gives in service must be open to examination afterwards, by the operator, the manufacturer or the authority.
Recorded
The input data and its time, the evidence with its source and revision, the model version, the output and the human decision are kept together.
Replayable
Retrieval is deterministic, so the same question on the same data returns the same evidence when an auditor runs it again.
Traceable
Each statement the model produces is designed to point to the evidence behind it, and each requirement to its code and tests.
Accountable
A person takes the decision. What was proposed, accepted or overridden is recorded with it.
Standards that frame the engineering
MISRA C and the objectives of DO-178C are followed in development. The related standards below frame how the technologies are taken into an assured or certified product with the customer.
Languages and coding rules
- MISRA CCoding rules for C in critical systemsHere: C code in the set, including LLiDA
- RustMemory and thread safety enforced by the compilerHere: The RAG engine
- Ada SPARKA subset of Ada whose properties can be provedHere: Safety-critical components
Airborne and ground software
- DO-178C / ED-12CSoftware considerations in airborne systems and equipment certificationHere: The development objectives the engineering follows
- DO-330 / ED-215Software tool qualificationHere: Tools whose output is relied on without further verification
- DO-333 / ED-216Formal methods supplement to DO-178CHere: Where SPARK proof stands in for testing
- DO-278A / ED-109ASoftware for ground-based CNS/ATM systemsHere: Ground systems the aircraft synchronises with
Systems, hardware and security
- ARP4754B / ED-79BDevelopment of civil aircraft and systemsHere: Allocating functions and assurance levels with the integrator
- ARP4761A / ED-135Safety assessment processHere: The failure conditions that set the assurance level
- DO-254 / ED-80Design assurance for airborne electronic hardwareHere: The hardware that hosts the software
- DO-326A / ED-202AAirworthiness security processHere: Synchronisation over secured and common networks
AI and other safety-critical fields
- EASA AI Roadmap and concept paperGuidance for Level 1 and 2 machine learning applicationsHere: AI trustworthiness, explainability and human oversight
- EU AI ActRegulation (EU) 2024/1689 on artificial intelligenceHere: High-risk AI obligations
- IEC 62304Medical device software life cycleHere: Medical applications
- IEC 61508Functional safety of electronic systemsHere: Other safety-critical industries
Developing to a standard is not a certificate. AeroBrain is a set of technologies, not an airworthiness approval. Certification is granted for a specific product and installation, with the authority, and the engineering is organised so that the evidence can be produced.
Where it applies
Combine what the task needs. From next-generation avionics to medicine.
The same technologies serve any field where a wrong answer has consequences. They are specialised in aerospace and defence, and apply equally to medical and other safety-critical systems. Each can be used alone; the task decides the combination.
Next-generation avionics
Real-time decision support from live avionics data
LLiDA + Protocol + RAG + Model
Operations and maintenance control
Live fleet data, procedures and recovery options
LLiDA + Protocol + RAG
EBT and CBTA training
Scenario design, recording and assessment in AeroEBT
Protocol + RAG
Defence and mission systems
Disconnected and air-gapped operation
LLiDA + Protocol + RAG + Model
Medical and other safety-critical devices
Monitoring and advice at the point of use
LLiDA + RAG + Model
Typical combinations, not a fixed configuration. Each deployment is specified with the customer and its assurance level.
Already at work in SkyDynamics products
- AeroEBT and the EBT Scenario Builder
Evidence-Based Training and CBTA, with the Contextual Composition Protocol behind every application.
- OpsEye
Airline operations control: disruption monitoring and costed recovery options.
- Wingman
Briefings, manual retrieval and decision support for front-line crew.
- AeroTechLog
The digital technical log, with defect context for maintenance control.
- AeroBrain platform
The enterprise deployment for airlines: one governed AI layer across departments.
Questions. Asked by engineers, operators and authorities.
What is AeroBrain?
AeroBrain is a set of AI technologies developed by SkyDynamics for safety and mission-critical fields, specialised in aerospace and defence. It combines a secured RAG engine written in Rust, the Contextual Composition Protocol, the LLiDA real-time time-series database and an auditable Assurance Small Language Model to turn real-time avionics data and approved documents into decision support that people can verify.
What is LLiDA?
LLiDA (Low Level integrated Database Architecture) is a real-time time-series database developed by SkyDynamics for high-reliability and high-assurance systems. It works in RAM, on disk and at processor level, on RISC-V, ARM and other architectures, synchronises live over secured or common networks, and is developed to safety-critical rules such as MISRA C and the objectives of DO-178C.
What data does AeroBrain work from?
Two kinds. Real-time data from the aircraft's avionics, captured as time series by LLiDA, and the operator's approved manuals and records. The RAG engine retrieves over both, and each piece of evidence keeps its source, and its time or revision.
What is the Contextual Composition Protocol?
The Contextual Composition Protocol is SkyDynamics technology that holds all the data relevant to a specific task or workflow in memory, behind the scenes, and correlates it with each event as it arrives. It already works behind every AeroEBT application, including the EBT Scenario Builder, and carries the same mechanism into real-time decision support.
Does AeroBrain support real-time and hard real-time applications?
Yes. The set is built for high-assurance, real-time and hard real-time safety and mission-critical applications. It works on live data and answers while the event is still unfolding, and for hard real-time functions, where a late answer counts as a failure, each stage runs to a fixed deadline. The actual figures depend on the hardware and are set with the customer.
Is AeroBrain auditable?
Yes. Auditability is part of its high-assurance design. For every answer, the input data and its time, the evidence with its source and revision, the model version, the output and the human decision are recorded together. Retrieval is deterministic, so an auditor can replay the same question on the same data and obtain the same evidence.
Is AeroBrain certified to DO-178C?
No certificate is claimed. The technologies are developed to high-assurance practice, including MISRA C and the objectives of DO-178C, so that certification evidence can be produced. Certification itself is granted for a specific product and installation, with the authority.
Can AeroBrain run without an internet connection?
Yes. The RAG engine and the Assurance Small Language Model can run on the device or on-premises, including in air-gapped environments, and LLiDA keeps nodes synchronised over whichever secured or common network is available.
Does AeroBrain make the decision?
No. AeroBrain supports the decision. It proposes, shows its evidence and records what was accepted or overridden. The accountable person decides.
Bring high-assurance AI into your programme.
Tell us the function, the hardware and the assurance level. We will show which technologies apply and what evidence comes with them.
