What the platform does today, and how
This page is the capability index. Everything on it is running in the build we would show you, described as the mechanism behind it rather than as an adjective. Nothing on this page is an ambition. If a claim here matters to your assessment, ask us to demonstrate the mechanism.
Duress and life safety
The heart of the platform
9 capabilities →Location and positioning
One canonical fix
9 capabilities →Device and tag supervision
The platform will tell you when it cannot see
5 capabilities →Escalation and delivery
Honest state, not optimistic state
6 capabilities →Operator surfaces
Built for people under pressure
10 capabilities →Isolation, identity and access
Enforced by the database, not promised by the application
7 capabilities →Audit, privacy and evidence
Built for the review that follows
9 capabilities →Resilience and release safety
Engineered for failure
9 capabilities →Licensing and environments
The commercial layer cannot reach the safety layer
6 capabilities →Interfaces
If the interface cannot do it, neither can the screen
5 capabilities →Duress and life safety
Everything in this area is load bearing. Each item below is a mechanism you can ask us to demonstrate on the running platform, not a description of intent.
Priority fixed at origination
An event classified as a life safety priority is stamped at the moment it is raised, in the same transaction that records it. Nothing downstream can reclassify it, downgrade it or reorder it behind something else.
An escalation ladder that survives a restart
Each tier's deadline is a row in the database, not a timer in a process. A sweep claims due deadlines conditionally, so a duress mid escalation keeps climbing across a process restart, a container reschedule or a failover, and two machines running at once cannot double escalate it.
A ladder no one can misconfigure into silence
Recipients, channels and timings are configured per site. The guarantee that an unacknowledged event keeps climbing is not configurable, because a ladder a customer can switch off is a hazard rather than a feature.
Acknowledge once, stands down everywhere
One acknowledgement propagates to every recipient and every surface, so two responders never both run to the same call and no one arrives at an event another person already closed.
A failsafe on a channel that did not just fail
If a ladder exhausts every tier without an acknowledgement, the platform raises that exhaustion as its own high severity event and drives an independent path, rather than retrying through the delivery route that has already proven itself unable to reach anyone.
Man down and no motion
A worn device that stops moving for longer than its configured window raises without anyone pressing anything, on the same immutable priority path as a deliberate press.
Lone worker check in
A worker on a timed check in who does not respond escalates on the ladder. The overdue condition is evaluated centrally, so a handset that has gone quiet is exactly the case it still covers.
Evacuation broadcast that ignores the location system
An evacuation reaches the roster, not the people the positioning system happens to be able to see. It is deliberately presence independent, because an evacuation that only reaches the tags currently reporting is not an evacuation.
Life safety is never gated by commercial state
An unlicensed, lapsed, over count or suspended site still raises, routes and escalates. This is enforced by a database constraint that refuses to store a policy gating the safety path, so it cannot be undone by a configuration mistake, and a licence check on a safety route fails the build rather than warning at runtime.
Location and positioning
The platform consumes resolved positions from the engines you already own and turns them into one operational model. It does not ask you to replace your hardware to make the software work.
The adapter seam
Every positioning technology attaches through an adapter and normalises to one canonical fix. Nothing above the seam knows which vendor produced a position, which is what makes a vendor change a configuration exercise rather than an application rewrite.
Proven across two incompatible dialects
Normalisation is verified against two deliberately different vendor dialects, an angle of arrival engine and an ultra wideband engine. The same physical point presented in either arrives as the identical canonical fix.
Confidence and staleness gating
Every fix carries accuracy, confidence, freshness and provenance. A position the engine graded as presence rather than a fix degrades to the zone instead of drawing a dot, and a fix older than its site's threshold is dropped rather than repainted as fresh. The platform would rather show the right room than a confidently wrong dot.
Age measured on the engine's own clock
Staleness is evaluated engine clock against engine clock, so a clock difference between the positioning system and the platform can never invent staleness that is not there.
Source arbitration that explains itself
Where more than one source can see the same subject, a candidate registry scores each on accuracy, freshness and continuity and picks one authority. Hysteresis and a dwell period damp flapping, so an operator never watches somebody teleport between rooms, and the platform can say which source it chose and why.
Identity first, not device first
The platform tracks the person or the asset, not the tag. An entity outlives every tag, battery and firmware version it passes through, and replacing a device changes one attribute rather than requiring a re binding ceremony. Operators are not shown hardware addresses.
Unregistered tags still produce a position
A device nobody has commissioned is positioned anonymously rather than discarded. Unknown is a state to show, not a record to throw away.
Live, historical and spatial queries
Where is this subject now, where has it been across a window, and who is inside this zone. All three answer from the same model, so a replay and a live view cannot disagree.
Co located subjects resolve to one place
Two fixes closer together than the engine can actually resolve are drawn as one marker with a count, positioned at what was reported and with the members named. The threshold is a real world distance converted through each plan's own calibration, never a number of pixels.
Device and tag supervision
A safety platform makes an implicit promise: if a tracked person or asset is inside the facility, the system can see it. The moment that stops being true and nobody is told, the platform is quietly lying.
Two thresholds, not one
Crossing a device's expected reporting interval marks it stale, which is a dashboard state and deliberately quiet so operators are not desensitised. Crossing the longer supervision timeout while the feed itself is healthy marks it lost, and that is the state that raises.
Technology aware intervals
A device that reports many times a second and one that reports every few hours cannot share a silence threshold. Intervals are set per device class and per deployment.
One infrastructure alarm, not a storm
When a whole feed goes silent the platform raises a single infrastructure event naming the feed, the site and how many devices are affected, and suppresses the individual device losses behind it. On recovery, devices that come back clear silently and only those that do not are raised.
Cause offered as context, never as a gate
A loss event carries the device, its bound entity, its last known position and confidence, how long it has been silent, and a classification of the likely cause. The classification is advisory context on the event and never changes whether it fires.
Derived from the report stream, not the vendor
Supervision is computed from the normalised feed rather than waiting for a positioning system to volunteer that a device has gone offline. A design that depended on the vendor saying so would be blind exactly where a customer runs their own network.
Escalation and delivery
Accepted and arrived are different claims, and the gap between them is a person not turning up.
Channels running today
The console, an outbound signed webhook, a facility relay for hardwired annunciation, and the two paging protocols in wide use across Australian health and custodial estates.
One function may say delivered
Delivered can be produced by exactly one code path, and only from a positive acknowledgement carrying a carrier reference. A transport that returns success with no reference is recorded as a failure, because an unverifiable success is worse than a recorded failure.
A transport that cannot express a state does not get to claim one
Where a channel is one way and structurally cannot confirm receipt, the record says so rather than inferring arrival from the absence of an error.
Ordered fallback per recipient
Each recipient carries an ordered list of routes. The platform works down it and records every attempt, so the chain of custody for a notification is reconstructable from one place afterwards rather than by stitching six logs together under time pressure.
Nearest responder dispatch
An event can be routed to the closest appropriate responders from live position rather than to a fixed list, with a human dispatcher in control of the outcome.
Exhaustion is an event
A ladder that runs out is never silent. Exhaustion is raised in its own right at high severity.
Operator surfaces
One data model behind every surface, so the handset and the desk always tell the same story.
One shell, three workspaces
Live operations, dashboards and administration are workspaces inside one adaptive surface rather than three applications to learn, install and keep in step.
The queue, the drawer and the map stay in sync
Selecting anything selects it everywhere. This single selection behaviour is the core interaction contract of the desk, and it is what removes window hopping from the middle of an incident.
Ranked by severity, then age
A life safety event pulses and holds the top of the queue regardless of how recently it arrived.
A command palette that never commits
Every action is a keystroke away, and the palette stages rather than executes. Its own footer states the rule: commands never commit, you confirm in the drawer.
Administration is draft, confirm, apply
Configuration changes are composed as a draft, shown as a diff of what will change, and applied only on explicit confirmation.
Live by subscription, never by polling
Surfaces subscribe to an event stream. A write on any node fans out to every open screen, and a surface that reconnects back fills the gap it missed rather than silently starting from now.
Dark by default
The primary theme is dark because a bright interface in a darkened room at three in the morning is a physical hazard rather than a style preference. A light theme is available and the viewer's choice persists.
Status never means two things
Tenant and partner branding can override brand and surface colours but cannot override status colours. The meaning of critical is fixed, and a brand colour that collides with a status colour is refused.
Colour is never the only signal
A critical state carries an icon and a word as well as a colour, so it survives a colour vision deficiency and a bad monitor.
A handset with one deliberate gesture to help
The mobile app carries Respond, Raise and Me, with a persistent duress affordance on every screen. It carries the responder's own position, so help knows where the responder is and not only where the alarm is, and actions taken with no signal queue with a visible pending state and reconcile on reconnection.
Isolation, identity and access
The site is the isolation boundary. Everything above it is oversight, and none of it sits in the path of an alarm.
Row level isolation on every request
Scope is applied by the database on every query rather than by a filter a developer has to remember. One tenant's credentials return none of another's data, and that is verified on every promotion rather than asserted.
Default deny
A permission that has not been granted is refused. Access is not the absence of a prohibition.
Context aware permissions
A grant can be bound to a place and a time window, so an entitlement that makes sense on a ward during a shift does not silently extend to the whole estate at midnight.
Revocation takes effect immediately
Disabling an account applies to credentials already issued, not only to the next sign in.
The last administrator cannot be removed
The platform refuses the operation that would lock an organisation out of itself.
Step up authentication, with one prohibition
Sensitive operations can require a second factor at the moment of use. A rule attempting to place that requirement on a life safety action is refused by the database, because a person in trouble cannot be asked to authenticate again.
Support access is visible and bounded
Entering a customer's system for support runs under a named identity, shows a banner while it is active, expires on a clock, and is recorded on both sides.
Audit, privacy and evidence
In healthcare and custodial settings the question is rarely what happened. It is whether you can prove it months later.
Tamper evident audit
The audit trail is append only and hash chained with periodic checkpoints, so an alteration is detectable and can be localised rather than merely suspected.
Unbroken across a recovery boundary
The chain continues across a failover or a restart. A gap in an evidence trail is itself a finding.
Incident replay
An incident can be replayed with the positions, the alarm states and the notification attempts as they actually were, against the plan version current at that time.
Keys held per tenant
Encryption keys are separated per tenant, with a documented destruction path so an erasure obligation can actually be met rather than approximated.
Break glass leaves a mark
Emergency elevated access requires a written reason, expires on a clock the database enforces, and is audited as an exception rather than existing as a standing privilege.
Purpose bound retention and residency
Data classes carry their own retention, and residency can be pinned so records stay in the jurisdiction that requires them.
Subject rights with a safety exception
Access and erasure requests are supported, with the life safety path exempt. Consent governs routine visibility and analytics, never emergency location.
Privacy configuration cannot reach the safety core
The life safety runtime does not read privacy settings, so no privacy configuration can accidentally suppress a safety response.
Logs that do not leak
Structured logging is filtered so operational diagnostics do not become an unmanaged copy of personal data.
Resilience and release safety
A backup that has never been restored is a hope, not a backup. The same standard applies to every other resilience claim on this site.
Automatic database failover, proven by drill
Failover is exercised by killing the primary, not only an application node, and an acknowledged event committed before the kill survives the promotion. Synchronous replication is the posture for safety data.
Restore tested backups
Backups are scheduled and encrypted, and the restore path has been exercised end to end, because a backup nobody has restored has not been shown to work.
Honest health
Liveness and readiness are separate signals, and readiness fails when the database is unreachable. A component that cannot do its job does not report itself healthy.
Unavailable rather than a plausible zero
A source the platform cannot read returns unavailable. A convincing invented figure is worse than a visible gap, because a gap prompts a question and a number prevents one.
A fixed shedding order under pressure
When resources are constrained the platform sheds in a declared order, starting with lab telemetry. Duress ingest and duress fan out are never shed.
A life safety gate on every release
A suite of life safety assurances runs against the running platform on every promotion, and a failure rolls the release back automatically. It has already refused a real release.
A boot gate that fails closed
An instance whose safety case is structurally unsound refuses to serve rather than starting up and reporting itself green. Failing closed on an unreadable safety core is deliberate, and it was added because failing open is how a system looks healthy for the wrong reason.
Connection pools are supervised and alarmed
A pool that exhausts and never re establishes leaves a link that looks configured, reports no error and delivers nothing. The platform alarms on that condition rather than logging it, because a silent dead link is an outage.
Self healing that still tells you
Recovery actions are recorded and surfaced. A platform that heals silently teaches its operators that nothing ever goes wrong, which is the wrong lesson.
Licensing and environments
Licensing exists to be administered, not to be a control surface over people's safety.
Capacity at the organisation, not the site
Capacity is licensed as a band at the client organisation, and tags move freely between that organisation's own sites as needs change. A small or rural site is not penalised for being small.
Forgiving by design
Crossing a band prompts to remove, replace or purchase, with a leeway margin and a grace period. It is never a hard cut off.
Signed entitlements, checked locally
Entitlements are cryptographically signed and cached by the services that check them, so an entitlement check adds no dependency on reaching a licence server.
Integrations are never metered
There is no per adapter charge. Our marginal cost for another adapter to an existing customer is close to nothing, and metering them would discourage exactly the ingestion breadth that makes the platform useful.
What is never a price lever
Locator counts, incident volume, and operator seats. Pricing locators would tax a customer for improving their own accuracy. Metering an incident is indefensible on any reading. Charging per seat would penalise putting the safety picture in front of more people.
A lab environment with every deployment
Every deployment includes a lab alongside its live environment, and it is included rather than priced separately. Lab events are structurally incapable of reaching a real outbound channel, so a full scenario can run end to end without a pager, handset or phone in the facility ever hearing about it.
Interfaces
Every capability is reachable through the same interface the product's own surfaces use. There are no privileged internal back channels.
One documented interface
The surfaces consume exactly the interface third parties consume, described by a published schema that the validation, the documentation and the client tooling are all generated from. Documentation and behaviour cannot drift apart when both come from one artefact.
A durable event log
Operational events are appended to a durable log that drives live updates and replay. Consumers subscribe and can rewind rather than poll.
Signed outbound webhooks
Egress is signed so a receiver can verify origin, with retry and a dead letter path so a failing endpoint neither loses events nor blocks the platform.
Validated at the edge
Inbound events are validated against their registered schema and rejected to a dead letter path rather than admitted, so the fabric never carries malformed operational data.
Adapters are a replaceable seam
An adapter is a first class component with its own lifecycle and health, not a patch inside the core. That is what keeps a vendor's data model on the vendor's side of the boundary.
Ask us to demonstrate any of it
Bring the capability that matters most to your assessment. We will show you the mechanism behind it on the running platform, or tell you plainly that it is not built yet.