Ground segment · Advisory only

The anomaly co-pilot that explains — and never commands.

VELA turns a telemetry deviation into a cited root-cause narrative and a drafted recovery procedure — every claim traceable to the spacecraft's own manuals and knowledge graph1, and held from release until an operator signs off.

Cited or blocked Never commands Air-gap deployable
Telemetry · EPS.BATT.V VELA-REF-1
Warning Held for approval

Battery cell degradation — string 3 undervoltage

Deviation follows no related telecommand; cell-imbalance signature matches the FMECA degradation mode for the EPS battery.

confidence HIGH 3 citations resolved

The loop

Edge detects. Ground explains. A human decides.

VELA sits in the ground segment and does the investigation a mission-assurance engineer would do — faster, and with its working shown at every step.

A satellite flags a telemetry deviation with a glowing anomaly pulse
01 / DETECT

Edge detects

A deviation is flagged — by onboard FDIR, or by VELA's own detectors over the downlink. Command-response noise is filtered out first.

A knowledge graph resolves into a cited report
02 / EXPLAIN

Ground explains

A deterministic agent graph walks the anomaly, reaching data only through an audited boundary, and writes a root-cause narrative where every claim carries a citation.

An operator authorizes the drafted recovery procedure
03 / APPROVE

A human decides

The drafted recovery pauses at a real release gate. Nothing leaves VELA until an operator reviews the evidence and signs off. VELA never executes it.

Why teams trust it on a live fleet

Built to be believed, not just fast.

Six properties that make an AI safe to put in front of a spacecraft operator.

Cited or blocked2

Every narrative and procedure claim resolves to the spacecraft's own manuals and graph — or it is emitted as UNGROUNDED and held from release. A hallucinated reference is a sev-1.

Advisory-only — never commands

VELA reads telemetry and drafts recovery steps for a human to authorize. It never constructs, formats, or transmits a telecommand — enforced by a grep guardrail in CI.

Air-gap & sovereign

Runs fully offline with in-memory stores, or against your own Neo4j and Qdrant. No external calls, no CDN, no data leaving the ground segment.

Standards-universal ingest

Telemetry enters through one swappable source — CCSDS / PUS, XTCE, Yamcs, OpenC3, MQTT, or seeded replay. The reasoning above it never changes.

Deterministic & reproducible

Graph traversal, event forming, and citation checks are deterministic and unit-tested; replay is seeded, so an investigation reproduces exactly — every time.

Human-in-the-loop gate

The drafted procedure pauses at a real approval interrupt. The operator's decision — and the evidence behind it — is captured in an append-only audit trail.

For the room the fleet depends on

Your operators keep authority. VELA does the reading.

Mission-assurance teams, insurers, and defence programmes can trust an AI on a live fleet precisely because it advises and cites — it never touches the commanding chain. That boundary is the product.

The boundary is the moat

Advisory only. It never commands.

Most tools bolt an AI onto the command path and ask you to trust it. VELA does the opposite: it stays on the read-only side, shows its evidence, and hands a human the pen. That is what lets it near a real spacecraft.

Plug into every tier — one swappable telemetry source

CCSDS Space PacketPUS servicesXTCE dictionaries YamcsOpenC3 / COSMOSMQTTAWS Ground Station Onboard-AI eventsSeeded replay

See it investigate

Watch VELA turn a deviation into a cited verdict.

A guided walkthrough on the VELA-REF-1 reference spacecraft — no live mission data required. Run it in your own air-gapped environment.