NADIR / Technology / 04 of 04
What the system will not do is the reason it can be deployed.
NADIR reads, scores and reports. It does not steer, brake, calibrate, or write to an ECU. That boundary is what lets a monitoring layer go onto a working fleet without entering the functional-safety path.
Safety boundary
The write boundary.
An actuating system takes telemetry, runs control logic, writes to an ECU, and the vehicle moves. Every one of those arrows is a functional-safety obligation: ASIL decomposition, hazard analysis, a validation campaign measured in vehicle-years.
NADIR's chain stops one box earlier. Telemetry and CAN come in, residual scoring runs, a tier and an evidence bundle come out, and a work order lands in front of a human. The write boundary is not a configuration flag that a sufficiently privileged operator could switch on later. There is no actuation path in the product to enable.
That constraint is the feature. It is why a fleet can run NADIR in shadow alongside whatever it already operates without opening a safety case, and why the only honest description of the output is advisory. A human and a calibration bay do the rest.
Evidence
Lineage that survives an audit.
A score nobody can check is an opinion. Every flag NADIR raises compiles into an evidence bundle carrying the repair event it is anchored to, the residual score with its sample count and sigma, the exact model version and pinned weight hash that produced it, and an HMAC-SHA256 signature over the payload.
The chain is append-only. You cannot revise a score after the fact without breaking the digest, which is the property that matters when a bundle is handed to an insurer, a safety board, or a customer's own QA team eighteen months later. Canonical JSON keeps serialisation stable, so the same facts always hash to the same value.
Nothing in the bundle requires interpretation by NADIR. That is the point. It should be checkable by someone who does not trust us.
Operations
What an operator actually sees.
Fleet state is a grid, not a number. Fourteen weeks across eleven vehicles shows which assets are drifting, which repaired and recovered, and which repaired and did not. The cells marked with a repair event that stay hot afterwards are the entire product in one view.
The funnel is the honest accounting. 1,244 repair events came in, all 1,244 were scored, 202 crossed CAUTION or above, 171 were routed to a bay, and 158 closed with a signed bundle. The drop-offs are real and worth arguing about: 31 flags never got dispatched and 13 dispatched vehicles never closed signed. A dashboard that hides those two numbers is marketing rather than instrumentation.
Outcome
Whether it was worth doing.
Detection only matters if the queue clears. Dispatch is capacity-bound — 84 open flags against 54 bay slots across three bays, one already at its limit — so routing has to account for where the vehicle is and which bay can actually take it this week.
The burndown is the operational contract. Against a 21-day SLA the open-CRITICAL count has to reach zero, and the inflow arriving between days seven and eleven is the real test of whether the process holds when work turns up faster than it clears. On this window it stayed inside the envelope and closed at zero.
The financial case follows from that, and not before it. Cumulative avoided incident cost crosses programme cost at month seven and reaches 2.4 times return by month eighteen. That curve is only credible because the three charts before it are measured rather than assumed.
NADIR emits evidence and work orders. A human and a calibration bay do the rest.
If any part of this page reads as though the software fixes the vehicle, that is a writing failure on our part rather than a roadmap.
Want this pointed at your fleet?
We are onboarding fleets and repair networks a few at a time. Tell us what you run and we will reach out.