Features

What the platform does today, and how

This page is the capability index. Everything on it is running in the build we would show you, described as the mechanism behind it rather than as an adjective. Nothing on this page is an ambition. If a claim here matters to your assessment, ask us to demonstrate the mechanism.

The heart of the platform

Duress and life safety

Everything in this area is load bearing. Each item below is a mechanism you can ask us to demonstrate on the running platform, not a description of intent.

Priority fixed at origination

An event classified as a life safety priority is stamped at the moment it is raised, in the same transaction that records it. Nothing downstream can reclassify it, downgrade it or reorder it behind something else.

An escalation ladder that survives a restart

Each tier's deadline is a row in the database, not a timer in a process. A sweep claims due deadlines conditionally, so a duress mid escalation keeps climbing across a process restart, a container reschedule or a failover, and two machines running at once cannot double escalate it.

A ladder no one can misconfigure into silence

Recipients, channels and timings are configured per site. The guarantee that an unacknowledged event keeps climbing is not configurable, because a ladder a customer can switch off is a hazard rather than a feature.

Acknowledge once, stands down everywhere

One acknowledgement propagates to every recipient and every surface, so two responders never both run to the same call and no one arrives at an event another person already closed.

A failsafe on a channel that did not just fail

If a ladder exhausts every tier without an acknowledgement, the platform raises that exhaustion as its own high severity event and drives an independent path, rather than retrying through the delivery route that has already proven itself unable to reach anyone.

Man down and no motion

A worn device that stops moving for longer than its configured window raises without anyone pressing anything, on the same immutable priority path as a deliberate press.

Lone worker check in

A worker on a timed check in who does not respond escalates on the ladder. The overdue condition is evaluated centrally, so a handset that has gone quiet is exactly the case it still covers.

Evacuation broadcast that ignores the location system

An evacuation reaches the roster, not the people the positioning system happens to be able to see. It is deliberately presence independent, because an evacuation that only reaches the tags currently reporting is not an evacuation.

Life safety is never gated by commercial state

An unlicensed, lapsed, over count or suspended site still raises, routes and escalates. This is enforced by a database constraint that refuses to store a policy gating the safety path, so it cannot be undone by a configuration mistake, and a licence check on a safety route fails the build rather than warning at runtime.

One canonical fix

Location and positioning

The platform consumes resolved positions from the engines you already own and turns them into one operational model. It does not ask you to replace your hardware to make the software work.

The adapter seam

Every positioning technology attaches through an adapter and normalises to one canonical fix. Nothing above the seam knows which vendor produced a position, which is what makes a vendor change a configuration exercise rather than an application rewrite.

Proven across two incompatible dialects

Normalisation is verified against two deliberately different vendor dialects, an angle of arrival engine and an ultra wideband engine. The same physical point presented in either arrives as the identical canonical fix.

Confidence and staleness gating

Every fix carries accuracy, confidence, freshness and provenance. A position the engine graded as presence rather than a fix degrades to the zone instead of drawing a dot, and a fix older than its site's threshold is dropped rather than repainted as fresh. The platform would rather show the right room than a confidently wrong dot.

Age measured on the engine's own clock

Staleness is evaluated engine clock against engine clock, so a clock difference between the positioning system and the platform can never invent staleness that is not there.

Source arbitration that explains itself

Where more than one source can see the same subject, a candidate registry scores each on accuracy, freshness and continuity and picks one authority. Hysteresis and a dwell period damp flapping, so an operator never watches somebody teleport between rooms, and the platform can say which source it chose and why.

Identity first, not device first

The platform tracks the person or the asset, not the tag. An entity outlives every tag, battery and firmware version it passes through, and replacing a device changes one attribute rather than requiring a re binding ceremony. Operators are not shown hardware addresses.

Unregistered tags still produce a position

A device nobody has commissioned is positioned anonymously rather than discarded. Unknown is a state to show, not a record to throw away.

Live, historical and spatial queries

Where is this subject now, where has it been across a window, and who is inside this zone. All three answer from the same model, so a replay and a live view cannot disagree.

Co located subjects resolve to one place

Two fixes closer together than the engine can actually resolve are drawn as one marker with a count, positioned at what was reported and with the members named. The threshold is a real world distance converted through each plan's own calibration, never a number of pixels.

The platform will tell you when it cannot see

Device and tag supervision

A safety platform makes an implicit promise: if a tracked person or asset is inside the facility, the system can see it. The moment that stops being true and nobody is told, the platform is quietly lying.

Two thresholds, not one

Crossing a device's expected reporting interval marks it stale, which is a dashboard state and deliberately quiet so operators are not desensitised. Crossing the longer supervision timeout while the feed itself is healthy marks it lost, and that is the state that raises.

Technology aware intervals

A device that reports many times a second and one that reports every few hours cannot share a silence threshold. Intervals are set per device class and per deployment.

One infrastructure alarm, not a storm

When a whole feed goes silent the platform raises a single infrastructure event naming the feed, the site and how many devices are affected, and suppresses the individual device losses behind it. On recovery, devices that come back clear silently and only those that do not are raised.

Cause offered as context, never as a gate

A loss event carries the device, its bound entity, its last known position and confidence, how long it has been silent, and a classification of the likely cause. The classification is advisory context on the event and never changes whether it fires.

Derived from the report stream, not the vendor

Supervision is computed from the normalised feed rather than waiting for a positioning system to volunteer that a device has gone offline. A design that depended on the vendor saying so would be blind exactly where a customer runs their own network.

Honest state, not optimistic state

Escalation and delivery

Accepted and arrived are different claims, and the gap between them is a person not turning up.

Channels running today

The console, an outbound signed webhook, a facility relay for hardwired annunciation, and the two paging protocols in wide use across Australian health and custodial estates.

One function may say delivered

Delivered can be produced by exactly one code path, and only from a positive acknowledgement carrying a carrier reference. A transport that returns success with no reference is recorded as a failure, because an unverifiable success is worse than a recorded failure.

A transport that cannot express a state does not get to claim one

Where a channel is one way and structurally cannot confirm receipt, the record says so rather than inferring arrival from the absence of an error.

Ordered fallback per recipient

Each recipient carries an ordered list of routes. The platform works down it and records every attempt, so the chain of custody for a notification is reconstructable from one place afterwards rather than by stitching six logs together under time pressure.

Nearest responder dispatch

An event can be routed to the closest appropriate responders from live position rather than to a fixed list, with a human dispatcher in control of the outcome.

Exhaustion is an event

A ladder that runs out is never silent. Exhaustion is raised in its own right at high severity.

Built for people under pressure

Operator surfaces

One data model behind every surface, so the handset and the desk always tell the same story.

One shell, three workspaces

Live operations, dashboards and administration are workspaces inside one adaptive surface rather than three applications to learn, install and keep in step.

The queue, the drawer and the map stay in sync

Selecting anything selects it everywhere. This single selection behaviour is the core interaction contract of the desk, and it is what removes window hopping from the middle of an incident.

Ranked by severity, then age

A life safety event pulses and holds the top of the queue regardless of how recently it arrived.

A command palette that never commits

Every action is a keystroke away, and the palette stages rather than executes. Its own footer states the rule: commands never commit, you confirm in the drawer.

Administration is draft, confirm, apply

Configuration changes are composed as a draft, shown as a diff of what will change, and applied only on explicit confirmation.

Live by subscription, never by polling

Surfaces subscribe to an event stream. A write on any node fans out to every open screen, and a surface that reconnects back fills the gap it missed rather than silently starting from now.

Dark by default

The primary theme is dark because a bright interface in a darkened room at three in the morning is a physical hazard rather than a style preference. A light theme is available and the viewer's choice persists.

Status never means two things

Tenant and partner branding can override brand and surface colours but cannot override status colours. The meaning of critical is fixed, and a brand colour that collides with a status colour is refused.

Colour is never the only signal

A critical state carries an icon and a word as well as a colour, so it survives a colour vision deficiency and a bad monitor.

A handset with one deliberate gesture to help

The mobile app carries Respond, Raise and Me, with a persistent duress affordance on every screen. It carries the responder's own position, so help knows where the responder is and not only where the alarm is, and actions taken with no signal queue with a visible pending state and reconcile on reconnection.

Enforced by the database, not promised by the application

Isolation, identity and access

The site is the isolation boundary. Everything above it is oversight, and none of it sits in the path of an alarm.

Row level isolation on every request

Scope is applied by the database on every query rather than by a filter a developer has to remember. One tenant's credentials return none of another's data, and that is verified on every promotion rather than asserted.

Default deny

A permission that has not been granted is refused. Access is not the absence of a prohibition.

Context aware permissions

A grant can be bound to a place and a time window, so an entitlement that makes sense on a ward during a shift does not silently extend to the whole estate at midnight.

Revocation takes effect immediately

Disabling an account applies to credentials already issued, not only to the next sign in.

The last administrator cannot be removed

The platform refuses the operation that would lock an organisation out of itself.

Step up authentication, with one prohibition

Sensitive operations can require a second factor at the moment of use. A rule attempting to place that requirement on a life safety action is refused by the database, because a person in trouble cannot be asked to authenticate again.

Support access is visible and bounded

Entering a customer's system for support runs under a named identity, shows a banner while it is active, expires on a clock, and is recorded on both sides.

Built for the review that follows

Audit, privacy and evidence

In healthcare and custodial settings the question is rarely what happened. It is whether you can prove it months later.

Tamper evident audit

The audit trail is append only and hash chained with periodic checkpoints, so an alteration is detectable and can be localised rather than merely suspected.

Unbroken across a recovery boundary

The chain continues across a failover or a restart. A gap in an evidence trail is itself a finding.

Incident replay

An incident can be replayed with the positions, the alarm states and the notification attempts as they actually were, against the plan version current at that time.

Keys held per tenant

Encryption keys are separated per tenant, with a documented destruction path so an erasure obligation can actually be met rather than approximated.

Break glass leaves a mark

Emergency elevated access requires a written reason, expires on a clock the database enforces, and is audited as an exception rather than existing as a standing privilege.

Purpose bound retention and residency

Data classes carry their own retention, and residency can be pinned so records stay in the jurisdiction that requires them.

Subject rights with a safety exception

Access and erasure requests are supported, with the life safety path exempt. Consent governs routine visibility and analytics, never emergency location.

Privacy configuration cannot reach the safety core

The life safety runtime does not read privacy settings, so no privacy configuration can accidentally suppress a safety response.

Logs that do not leak

Structured logging is filtered so operational diagnostics do not become an unmanaged copy of personal data.

Engineered for failure

Resilience and release safety

A backup that has never been restored is a hope, not a backup. The same standard applies to every other resilience claim on this site.

Automatic database failover, proven by drill

Failover is exercised by killing the primary, not only an application node, and an acknowledged event committed before the kill survives the promotion. Synchronous replication is the posture for safety data.

Restore tested backups

Backups are scheduled and encrypted, and the restore path has been exercised end to end, because a backup nobody has restored has not been shown to work.

Honest health

Liveness and readiness are separate signals, and readiness fails when the database is unreachable. A component that cannot do its job does not report itself healthy.

Unavailable rather than a plausible zero

A source the platform cannot read returns unavailable. A convincing invented figure is worse than a visible gap, because a gap prompts a question and a number prevents one.

A fixed shedding order under pressure

When resources are constrained the platform sheds in a declared order, starting with lab telemetry. Duress ingest and duress fan out are never shed.

A life safety gate on every release

A suite of life safety assurances runs against the running platform on every promotion, and a failure rolls the release back automatically. It has already refused a real release.

A boot gate that fails closed

An instance whose safety case is structurally unsound refuses to serve rather than starting up and reporting itself green. Failing closed on an unreadable safety core is deliberate, and it was added because failing open is how a system looks healthy for the wrong reason.

Connection pools are supervised and alarmed

A pool that exhausts and never re establishes leaves a link that looks configured, reports no error and delivers nothing. The platform alarms on that condition rather than logging it, because a silent dead link is an outage.

Self healing that still tells you

Recovery actions are recorded and surfaced. A platform that heals silently teaches its operators that nothing ever goes wrong, which is the wrong lesson.

The commercial layer cannot reach the safety layer

Licensing and environments

Licensing exists to be administered, not to be a control surface over people's safety.

Capacity at the organisation, not the site

Capacity is licensed as a band at the client organisation, and tags move freely between that organisation's own sites as needs change. A small or rural site is not penalised for being small.

Forgiving by design

Crossing a band prompts to remove, replace or purchase, with a leeway margin and a grace period. It is never a hard cut off.

Signed entitlements, checked locally

Entitlements are cryptographically signed and cached by the services that check them, so an entitlement check adds no dependency on reaching a licence server.

Integrations are never metered

There is no per adapter charge. Our marginal cost for another adapter to an existing customer is close to nothing, and metering them would discourage exactly the ingestion breadth that makes the platform useful.

What is never a price lever

Locator counts, incident volume, and operator seats. Pricing locators would tax a customer for improving their own accuracy. Metering an incident is indefensible on any reading. Charging per seat would penalise putting the safety picture in front of more people.

A lab environment with every deployment

Every deployment includes a lab alongside its live environment, and it is included rather than priced separately. Lab events are structurally incapable of reaching a real outbound channel, so a full scenario can run end to end without a pager, handset or phone in the facility ever hearing about it.

If the interface cannot do it, neither can the screen

Interfaces

Every capability is reachable through the same interface the product's own surfaces use. There are no privileged internal back channels.

One documented interface

The surfaces consume exactly the interface third parties consume, described by a published schema that the validation, the documentation and the client tooling are all generated from. Documentation and behaviour cannot drift apart when both come from one artefact.

A durable event log

Operational events are appended to a durable log that drives live updates and replay. Consumers subscribe and can rewind rather than poll.

Signed outbound webhooks

Egress is signed so a receiver can verify origin, with retry and a dead letter path so a failing endpoint neither loses events nor blocks the platform.

Validated at the edge

Inbound events are validated against their registered schema and rejected to a dead letter path rather than admitted, so the fabric never carries malformed operational data.

Adapters are a replaceable seam

An adapter is a first class component with its own lifecycle and health, not a patch inside the core. That is what keeps a vendor's data model on the vendor's side of the boundary.

Ask us to demonstrate any of it

Bring the capability that matters most to your assessment. We will show you the mechanism behind it on the running platform, or tell you plainly that it is not built yet.