Skip to main content
Open the slide deck

The briefing, as text

Wildfire Ahead · platform briefing

The whole briefing, in writing

Everything the slide deck says, in order, in whichever reading level you choose — all 27 slides across 7 acts, with the detail behind each one and the questions audiences ask about it.

Act I — The ground

Wildfire Ahead

One platform that gathers every wildfire signal a continent produces, works out what it means, and puts it in front of the people who decide — without ever taking their decision away.

A wildfire agency already has satellites, weather models, camera networks and its own records. What it does not have is one place where all of that arrives together, is made comparable, is checked, and is turned into an answer to a question somebody actually asked.

  • Wildfire Ahead sits on top of authoritative public science rather than replacing it. Government agencies run the satellites, the weather models and the fire danger systems; the platform integrates them.
  • Everything the platform produces carries its working: sources, times, ages, uncertainty and what disagreed.
  • Every consequential act — issuing an alert, ordering a resource, tasking an aircraft — stays with the authority that holds it, and the platform's build refuses to contain the code that would do it.
  • It runs as independent jurisdiction cells, so one province or state is not exposed to another's outage, breach or policy.

Is this replacing what we already run?

No. It integrates with your systems of record and reads from them. Your fire records, your dispatch, your alerting stay exactly where they are.

What makes it different from a dashboard?

A dashboard shows you a number. This shows you the number, where every input came from, how old each one is, what disagreed, and what evidence would resolve it.

Takeaway Satellites and cameras tell you a fire exists. This platform tells you what it means, for your ground, with the working shown.

What this actually is, in one minute

Skip the jargon. Four things, and if you remember only these, you have the shape of it.

When a fire starts, nobody has the whole picture. A satellite sees a hot patch of ground. A camera on a ridge sees smoke. Somebody phones it in. The weather service says the wind turns at four. Each holds one piece, in its own format, with its own idea of how sure it is.

  • Somebody has to turn all of that into one answer — is this real, what is at risk, what should we look at first — fast enough to matter.
  • Today that person does it by hand, cross-referencing four or five systems, often at three in the morning in a bad week.
  • This platform does that assembly, continuously, and shows its working so the answer can be challenged.

Is this artificial intelligence?

Partly. Models estimate things like how likely a hot spot is to be a real fire. But the models are one part of a much larger system, and they only ever estimate — a person always decides.

Who is it for?

Fire agencies first. Also utilities, forestry, mining, railways and municipalities who own things a fire could reach — and researchers who need the underlying data.

Takeaway Gather everything, work out what it means, show the working, hand it to the people who decide.

A continent-sized problem, measured a piece at a time

Canada averages about 7,000 wildfires and 2.7 million hectares burned a year over 1994–2023. The 2026 season alone reached 5,248 fires and 4.49 million hectares by 31 August.

Wildfire is a heavy-tailed problem. Most seasons are ordinary and a few are catastrophic, and the catastrophic ones are not the average multiplied by a factor — they behave differently.

  • A model tuned on ordinary seasons is least reliable exactly when it matters most, which is why evaluation here is stratified by region, season, fuel and drought regime rather than pooled.
  • The same reasoning drives the platform's refusal to report one continental accuracy number: it would be dominated by the easy cases.
  • Lightning causes about 46 percent of fires in Canada but about 83 percent of the area burned. The two figures belong together — that gap is where the remote, hard, fast-growing fires live.

Where do these figures come from?

The Canadian Wildland Fire Information System fire history record, and the Government of Canada's 2026 season updates. Both are public.

Why does the lightning split matter so much?

Because it says the fires that burn the most area start where nobody is watching. That is a detection and verification problem, and it is the one the platform is built around.

Takeaway The variance is the point. A plan built for the average year fails in the year that matters.

Four honest difficulties

Anyone can promise prediction. These are the four things that make wildfire prediction hard, and how the platform handles each one.

Of the four, the third one — the difference between not seeing a fire and not looking — is the one that most reliably tells a fire scientist whether the people who built a system have understood the problem.

  • A detection stream tells you where fires were seen. It cannot tell you where fires were not, because it does not know where anybody looked.
  • The platform computes coverage from sensor geometry: orbital tracks and overpass schedules, the satellite product's own cloud mask, camera viewsheds, station distance and observation age.
  • Where coverage is unknown, the answer is unknown. Confident absence is not expressible without a mask, by construction rather than by policy.
  • This is what turns 'we looked at that ridge' into 'we would have seen a fire on that ridge' — and only the second one is worth acting on.

Could you not just infer coverage from the detections themselves?

No, and that is the trap. If you infer where you were looking from where you saw things, a blind spot looks like a quiet area. The mask has to be computed from the sensors' own geometry.

What does an operator actually see?

A layer on the map showing where the platform could not have seen a fire, and for how long, with its own legend distinct from every observed and official class.

Takeaway Teaching an audience to read uncertainty correctly is public-safety work in itself.

Act II — The seam

Every capable system in this field owns one layer

The wildfire technology field is strong, well funded and specialised. Each part of it does one thing very well. None of them owns the joins.

A ground platform whose headline is 'we detect fires early' is competing with two funded constellations, one of them backed by Google, that will find a five-metre fire anywhere on Earth on a tightening revisit. That is not a market to enter.

  • FireSat launched its first three operational satellites in July 2026 with a six-channel multispectral infrared payload and onboard machine learning comparing each scene against roughly a thousand prior images of the same location.
  • OroraTech operates in 22 countries with hotspot detection to four metres and alerts within three minutes.
  • Both are complementary inputs to this platform, not competitors to it. The platform ingests detections and improves what an agency can do with them.
  • What neither can do is measure the vertical dimension of the fire environment, the time derivative at metre scale, or anything at all when smoke defeats optical sensing.

So what is the competitive claim?

The seam between the layers, and an instrument nobody else has. A hardware vendor cannot copy the model plane, and a model company cannot copy the instrument.

Does this platform work without those satellites?

Yes, but it is better with them. It is designed to consume every detection source available and weight each one by measured evidence rather than vendor assertion.

Takeaway In February 2026 two of these companies partnered to wire two layers together. That is the market conceding where the value is.

Five questions, and where each one is answered today

These are the questions duty officers actually ask. Most of them have no single home, so a person assembles the answer by hand, under time pressure.

The twelve capabilities in Act IV are not a technology roadmap. Each one exists because a named person, in a named role, currently answers that question by hand.

  • 'What changed since I last looked' is the cheapest large usability win in the whole platform, and it needs no new science — only a per-person watermark and a typed change vocabulary.
  • 'What should someone look at first' is decision support at its most literal: the platform ranks, explains the rank, and names the evidence that would resolve the item. A person disposes of it.
  • The asset question is where the commercial value concentrates, because a utility, a railway or a mine already knows what it owns and has no way to connect that to a fire picture.

How do you avoid building a feature list?

Every capability has to name the question, the role that asks it, and what they do today instead. If it cannot, it stays in discovery.

Which of these lands first for an agency?

Usually the change digest and the verification queue, because they need no new data — only a better use of what the agency already has.

Takeaway Each of these is a real workflow that a person currently does by hand, at three in the morning, in a bad week.

Leverage the public science. Do not rebuild it.

Governments have already funded the satellites, the weather models, the fire danger science and the historical records. Rebuilding any of that would be a waste of public money and would produce something worse.

It is a build decision that shows up in the code. The platform contains no fire weather index of its own invention, no competing satellite product, and no attempt to be an alternative record of what happened.

  • Fire danger comes from the published Canadian and United States systems, in their published editions, with the edition recorded.
  • Detections come from the agencies that fly the sensors, and each one keeps its own stated resolution, latency and confidence semantics.
  • Historical records stay distinct: the Canadian national database, the burned-area composite, the United States occurrence record and the severity archive are never silently merged into one number.
  • What the platform adds is the fusion, the provenance, the explanation, the ranking, and the measurement instrument.

Does this make you dependent on public data?

It makes the platform an amplifier of public investment, which is the argument that wins a government room. It also means every source is replaceable behind an adapter.

Where does proprietary value accumulate?

In the harmonisation and crosswalk work, the evidence model, the fusion mathematics, the model plane, and the instrument — none of which a data provider supplies.

Takeaway The advantage is integration, speed, usability and cross-domain reasoning. Not recreating authoritative inputs.

Act III — How it works

How it works, in five steps

Everything the platform does fits in this shape. The rest of this act is detail underneath it.

“Keep the original and never edit it” sounds like housekeeping. It is the decision the whole platform rests on.

  • If you can quietly change what arrived, nobody can ever prove what was actually known at the time.
  • Because nothing is edited, a briefing given at 07:02 can be reproduced exactly — including the parts later found to be wrong.
  • That is what an after-action review needs, what an auditor needs, and what a court would need.

Does keeping everything not get enormous?

Large files live in cheap bulk storage with rules about how long they stay. The database keeps the records and the trail between them, and an index makes it all findable.

Takeaway Collect, check, compare, work out, show. Everything else in this presentation sits underneath one of those five words.

Four separated planes, and a governance plane across them

The platform is not one big system. It is four deliberately separated zones with different rules, and a governance layer that spans all of them.

A layered architecture describes what calls what. A plane describes who is allowed in and what they may take out. The distinction matters when the failure you are designing against is a breach or a surge rather than a bug.

  • The public plane is served from separate artefacts with separate hostnames, content security policy, cookies and release pipeline. The public build carries no protected route at all — not lazily loaded, absent.
  • The research plane can read governed data and produce model releases. It cannot write into operations; a release has to pass qualification first.
  • The aviation plane exchanges evidence in one direction. The build fails if a control verb appears anywhere near it.
  • Above all four, jurisdiction cells: each agency's deployment has its own identity, keys, database, audit stream and release authority. There is no continental administrator.

Does the cell model mean data cannot be shared?

No. It means sharing is explicit, minimal, revocable and auditable, through a signed exchange package with its own agreement, purpose, retention and expiry.

What happens if one cell is compromised?

It has its own keys, credentials and network. A compromise there does not confer access anywhere else, and imported records never silently become another cell's official truth.

Takeaway A public traffic surge cannot reach operations. A research result cannot reach operations without qualification. Neither can reach an aircraft.

Fourteen stages from a satellite pass to a screen

This is the whole path. Click any stage to see what arrives, what leaves, which part of the system owns it and what rule it enforces.

Almost everything else in this diagram follows from two decisions taken at the start: never edit what arrived, and record two clocks.

  • The first clock is when something was true in the world. The second is when the platform found out. Keeping them apart is what makes replay honest.
  • A correction does not overwrite. It creates a new assertion linked to the old one, with the reason and the authority, and the old one stays readable.
  • That means a briefing given at 07:02 can be reproduced exactly, including the things that were later found to be wrong, which is what an after-action review and an audit both need.
  • It also means the platform can never quietly improve its own history, which is the single most important property for a government buyer.

Does keeping everything not become unmanageable?

Bulk data lives in object storage with lifecycle rules; the database holds the records and the lineage. The catalogue is what makes the volume navigable.

What happens when a source changes its schema without telling you?

It fails at the contract stage and quarantines, with the specific change named. A silent schema drift is exactly what the quarantine gate exists to catch.

Takeaway Nothing that arrives is ever edited. Everything after it is a copy with its own history, so you can always get back to what was actually said.

Ten modules. Each owns something, and is forbidden something.

The second column is the interesting one. A module that is not allowed to own something cannot quietly grow into it.

Every system that has ever quietly become something it should not have, did so one reasonable-looking feature at a time. Writing down what a module may not own is how you stop that.

  • Drone and remote sensing owns mission references and collected imagery. It does not own aircraft control — and the build fails if a control verb, field, route or network destination token appears anywhere in it.
  • Model and prediction owns releases and envelopes. It does not own approval, so a model cannot promote itself by being useful.
  • Publication owns the release package. It does not own alert origination, so the platform cannot become an alerting authority by adding a button.
  • These are checked on every build by named scripts, not reviewed at design time and forgotten.

Who decides the prohibitions?

They come from the architecture baseline and from each domain's own plan, and they are reviewed as architecture decisions with a recorded rationale.

What if a customer asks for one of the forbidden things?

Then it belongs in their system of record, and the platform integrates with it. That is a better answer commercially as well as legally — it is a shorter sale.

Takeaway Ownership plus prohibition, enforced by build checks, is what keeps a support system from becoming a command system by accident.

Every number has a Why

A risk score with no working is a black box, and a black box does not get adopted by an agency. Every consequential figure opens into its inputs.

The Why panel is not a rendering trick. It is a contract that every consequential response carries, so the explanation is generated by the thing that produced the number rather than reconstructed afterwards.

  • Contributing factors with their weight and direction, so a reader can see what moved the number and by how much.
  • The identity and age of every source, so the reader knows whether they are looking at something fresh.
  • Conflicts, preserved as conflicts. Where two sources disagree, the disagreement is shown rather than averaged away.
  • The uncertainty method and its intervals, the model release identifier, and the exact data releases the model consumed.
  • Assumptions and contraindications: what the model was assuming, and the conditions under which it should not be trusted.

Does this slow the interface down?

No. The pack is assembled with the response, so the panel opens instantly. What it costs is discipline in the services that produce numbers.

Can a person disagree with it?

Yes, and that is the point. A ranked item can be disposed of by a named human with a reason, and that disposition becomes a calibration observation that feeds back into the model's evaluation.

Takeaway An agency adopts a number it can argue with. It does not adopt one it cannot see inside.

Act IV — What it does

Twelve capabilities, one platform

Each one exists because a person in a named role currently answers that question by hand. Click any capability for what goes in, what comes out, and what makes it different.

They are not twelve products. They are one chain, and each capability consumes the one before it.

  • Lightning intelligence and holdover intelligence say where a fire is likely to be. The coverage map says where the platform could not have seen one.
  • The fusion engine turns detections into candidates with a confidence trend. The verification queue ranks those candidates against asset consequence and names the evidence that would resolve each one.
  • Risk-directed patrol turns that ranking into a draft sensing need for a named human. The asset twin and time-to-asset say what is at stake and when.
  • What changed and the copilot are how a person consumes all of it under time pressure. Wildfire memory is how the whole chain learns.
  • The cross-border graph is what keeps one physical fire from becoming five unrelated records.

Which capability do you lead a pilot with?

Fusion, the asset twin and the verification queue. Together they demonstrate the whole thesis on real data in one session.

Are these separately licensable?

The platform is one system with four surfaces. Commercially the asset twin and time-to-asset are what an enterprise buys; agencies buy the operating picture and the queue.

Takeaway Twelve answers to twelve real questions, each one showing its working.

“No fire observed” and “not observed” are different answers

Most systems cannot tell you the difference. This one refuses to express a confident absence without first computing where it could actually see.

Every wildfire scientist has been burned by a system that presented an absence of detections as an absence of fire. Showing that you have modelled the difference is the fastest credibility you can buy in that room.

  • The mask is computed from the sensors' own geometry and the providers' own declarations, never inferred from the detection stream — because inferring it from detections makes a blind spot look like a quiet area.
  • A cell with no observation returns unknown. The module has no way to express confident absence without a mask.
  • This feeds directly into patrol prioritisation: the cells worth looking at are the ones where uncertainty is high and consequence is high, not the ones where something was already seen.
  • It also feeds honest evaluation. A model cannot be credited for a correct negative in a cell nobody was watching.

How is this different from a coverage map a satellite operator publishes?

An operator publishes where their sensor passed. This composes every sensor available to the cell, including cameras and ground observers, and expresses it as usable observation quality rather than passes.

What turns coverage into probability of detection?

Field measurement against known sources at known ranges over real diurnal cycles. That is one of the things the tethered station in Act VI produces.

Takeaway Coverage says a cell was looked at. Only a measured probability of detection turns that into 'we would have seen it'.

Act V — Who uses it

Four surfaces, one platform

The same governed truth, delivered four ways — because a resident, a duty officer, a professor and a utility's operations lead need genuinely different things.

A single application with role-based hiding is the design that fails a security review, and it also fails the public. The four surfaces have different threat models, different performance budgets and different promises.

  • The public surface must survive a traffic surge on the worst day of the season, on a slow rural connection, on a five-year-old phone. It is served from static artefacts behind a content delivery network and carries no protected route at all.
  • The agency portal assumes an authenticated, trained user in a jurisdiction, and every route declares both a permission and a purpose.
  • The research workbench assumes a scientist who needs reproducibility more than speed, and distinguishes durable, computed and reference evidence rather than blending them.
  • The enterprise workspace assumes an organisation that owns assets and wants precise geometry about its own property, which is exactly what the public surface must never show.

Does a person need four logins?

No. One identity, with memberships that determine which workspaces are available. The public surface needs no account at all.

What does the field app do without signal?

Everything that matters: the assignment, cached map layers, observation and task capture with attachments, and an outbox that reconciles on reconnect with typed conflicts rather than last-write-wins.

Takeaway Two mobile apps as well: one for households with no account and no location tracking, one for responders that works fully offline.

Forty-six roles, eight families

Authority is per action. An aviation role cannot confirm an incident, and an incident commander cannot issue an evacuation. Pick a family to see what those people actually do.

Most systems have an administrator who can do everything. This one does not, and the absence is deliberate.

  • A permission is checked together with a declared purpose and a jurisdiction cell. Holding a role in one cell grants nothing in another.
  • The nine consequential actions — confirming an incident, approving objectives, ordering a resource, setting priority between incidents, publishing an alert, issuing an evacuation, approving a flight, accepting safety risk, transferring command — each require a named human in an approved external process.
  • Separation of duties is enforced where it matters: a reviewer cannot have authored the draft, and a model's developer cannot be its independent validator.
  • None of this is enforced by hiding buttons. The interface follows the server's decision, and the server is the authority.

Can a platform administrator read incident data?

No. Platform administration and operational data are different authorities. There is no administrator bypass into incident records.

How does an agency map its own structure onto this?

Roles are assigned per membership per cell, so an agency's own command structure determines who holds what. The platform supplies the vocabulary, not the org chart.

Takeaway Every route declares a permission and a purpose, and a build check fails when a route needs a permission that no role grants.

Nine things this platform will not do — and what stops it

This is the slide that matters most to a government room. Each row names who does perform the action, and what in the build refuses to let the platform do it.

Take the aviation boundary, because it is the sharpest. The claim is that the platform contains no path by which a person could command an aircraft. Here is what makes that true rather than asserted.

  • A build script scans the aviation contracts and source. If any member named like a control verb appears — takeoff, land, return to home, waypoints, set waypoint, gimbal command, upload geofence, ground control station credential, command-and-control endpoint — the build fails.
  • It also scans for network destination tokens: mavlink, gcs, autopilot, c2-link, payload actuation, telemetry command. A destination is as dangerous as a verb.
  • At runtime, a boundary policy walks records to depth twelve and throws on a match, so a control-shaped payload cannot arrive by data either.
  • The most permissive output the preflight assessment can produce is 'ready for human release'. It is a recommendation to a person, never an authorisation, and the receipt records that no launch was authorised and no flight command was issued.

What if an agency wants the platform to task their drone?

Then it belongs in their ground control station, and the platform exchanges evidence with it in one direction. That boundary is also what makes the platform sellable to agencies that will never permit an outside system near their aircraft.

Does this limit what you can build later?

It limits what this platform can be. A control product would be a separate, separately certified product line — which is exactly how the tethered station's flight software is structured.

Takeaway A boundary that is only written down erodes one reasonable feature at a time. These are checked on every build.

Data sovereignty is a boundary in the software, not a policy page

Participation, consent, knowledge, access, benefit and withdrawal are determined by the applicable Nation's or Tribe's own laws and representatives — and the platform is built so those terms can actually be enforced and reversed.

A commitment that cannot be enforced or reversed in software is a commitment that will be broken by an ordinary feature change. These are the properties that make it hold.

  • A benefit and commitment ledger records what was promised and its delivery status, visible to the partner.
  • Independent relationship review is partner-selected, with confidential feedback and a remediation plan the partner accepts.
  • Participation capacity is funded work — governance, technical and legal advice chosen by the partner — not consultation overhead.
  • The partnership lifecycle allows a partner to stop before agreement without adverse consequence, and immediate pause is mandatory on consent lapse or unauthorised use.

Has a Nation or Tribe been engaged?

Engagement is a relationship, not a build task, and it belongs to named people rather than to software. What the platform has done is build the enforcement so that when terms are set, they can be kept and reversed.

Where is the line on cultural fire knowledge?

It originates with partner Nations on their terms or it does not exist in the platform. Nothing about cultural fire is authored by the programme.

Takeaway Indigenous knowledge is not presumed open, digitisable or model-training material. Consent is never inferred from public availability.

Act VI — Eyes that stay

A vendor-neutral aerial platform port

Drone procurement is a moving target and manufacturers come and go. The platform talks to aircraft through a port with a fail-closed registry, and no part of the domain names a vendor.

The port declares a small, stable surface: capability declaration, telemetry, mission or session state, and evidence handoff. Everything vendor-specific lives inside the adapter.

  • A platform declares a versioned capability profile — what it is, what it carries, what it can and cannot do — and the registry refuses anything it does not recognise.
  • Telemetry normalises onto an existing open vocabulary rather than a private one, so a partner's ground station can already read it.
  • Evidence leaves the aircraft with its calibration state attached. An uncalibrated thermal product is quarantined rather than scored, which protects the manufacturer as much as the platform.
  • The seam is one-directional by construction, which means integrating does not expose a manufacturer's control plane to anything.

What does a manufacturer get out of this?

A named integration into a platform that agencies use, field validation of their sensor products against a governed evidence plane, and a reference architecture they can point at.

Is there an exclusivity requirement?

No. Neutrality is the point, and a port with one adapter is not a port.

Takeaway For a manufacturer, that means integration is bounded work against a published contract — not a bet on a partnership.

What a tether actually buys, and it is not endurance

Vendors sell endurance. Endurance is the by-product. A conductor and a fibre running to the ground change which instruments can fly at all — and move the computer off the aircraft.

A tethered station sold as a persistent camera is a worse camera tower that you have to drive to and that comes down in wind. That is not the product.

  • Detection from orbit is being won by funded constellations. Wide-area smoke from towers is being won by camera networks. Both are complementary inputs.
  • What neither can measure: the vertical dimension of the fire environment — the lowest 150 metres of atmosphere where the wind that drives the fire actually is; the time derivative at metre scale; absolute radiometric quantities at metre resolution; or anything at all when the smoke column defeats optical sensing.
  • Those four are the white space, and every one is a measurement problem rather than a surveillance problem.
  • The claim: satellites and camera networks tell you a fire exists. The tethered aerial station is a measurement instrument for the fire environment — and this is the only party that both builds the instrument and owns the model plane its measurements feed.

Why can nobody else do this?

A hardware vendor can copy the airframe. They cannot copy the model plane the data feeds. A model company cannot copy the instrument. The vertical is the advantage.

What is the operating envelope?

The derived wind envelope is 15 metres per second sustained, which sets siting and scheduling. The station is sited rather than roaming, so placement is computed against the predicted front, and it complements mobile assets rather than replacing them.

Takeaway One qualification path, one model card, one evaluation — because the same model artefact runs at the incident and in the cloud.

The station, in section

Every figure here is derived from first principles with its assumptions stated, or taken from a cited vendor datasheet, or set by a regulation. Select any part to see the working.

The commanded-altitude ceiling is the minimum of five separate limits, and the operator is told which one is binding rather than just being given a number.

  • The regulatory ceiling for the regime currently in force.
  • The marker configuration ceiling — what is physically fitted, attested by a person, never inferred. A crew that fitted markers for 90 metres cannot command 120 by typing a number.
  • The tether's usable length minus its reserve, which is never paid out.
  • The site obstacle assessment for this specific anchor point.
  • Any active flight restriction or fire-area restriction arriving from the evidence path.
  • And separately, the buffer battery: the station refuses to ascend further when the measured contingency descent energy no longer supports the height it is at.

What happens if the tether separates?

The aircraft is programmed to initiate a controlled landing, and the buffer battery is sized for exactly that descent from the session's maximum commanded altitude, with margin.

Is the tether a consumable?

It is a life-limited structural component with a serial number, a cycle count, a retirement limit and an inspection record — the same way a helicopter's lifting sling is.

Takeaway Endurance stops being the constraint. Delivered power, wind, and regulatory status become the three that bind.

The rules that apply are a function of how it is being flown

In Canada, the same aircraft on the same tether at the same height is either an obstacle or a remotely piloted aircraft, depending on whether a pilot is navigating it right now. The platform models that as state.

Without it, the honest answer to 'can we operate here?' is a paragraph of prose a crew cannot act on and an auditor cannot check. With it, the answer is a state the console displays and a set of gates the software enforces.

  • Every observation session carries a time-ordered series of regime assertions. A session that ran nine hours in one regime and four minutes in another records both, with the exact transition instants and the evidence completeness evaluated for each.
  • The distinction is defined mechanically: whether any horizontal position setpoint originates outside the disturbance rejection loop. Wind pushes and the controller pushes back — that is holding position. An operator moving the aircraft thirty metres east is navigating.
  • The firmware knows which is happening because they enter the controller through different paths, and it reports it as a telemetry field rather than letting the ground infer it.
  • Air operations get a live presence projection: position, current altitude, the composed ceiling, a positive tether-engaged state sourced from measured tension rather than intent, the marker configuration a pilot will see, a contact frequency and callsign, and a freshness bound.

Why does the economics follow from this?

In the station-keeping regimes one operator can be responsible for several stations, where a free-flying drone programme needs one certificated pilot per aircraft. The regime engine is the control that makes that true rather than assumed.

What about wildfire airspace specifically?

A station inside a fire traffic area is a persistent obstacle in airspace that airtankers and helicopters use at low level. So the presence projection is continuous and first-class, and an immediate ground order exists: one operator action that commands descent and reports completion with a receipt.

Takeaway A repositioning command is refused unless the evidence for that regime is complete, and the refusal names the missing items.

Six measurements nothing else makes

Each one is a real gap in operational wildfire science, not a feature. This is the slide a professor reads twice.

If the goal were scientific contribution rather than product breadth, this is the capability to build first, because it has the clearest line to a model input everybody already uses.

  • Operational fire spread modelling needs wind at flame height. Weather stations measure at 6 metres and standards use 10 metres; the value the model needs is obtained by multiplying by a modelled coefficient carrying assumptions about canopy shape and sheltering — and implementations of that coefficient differ between the major tools.
  • So the most sensitive input to the most-used model in the business is a modelled multiple of a measurement taken somewhere else.
  • Above the surface it is worse: radiosondes are twice daily at airports and instrumented towers are fixed and rare. The boundary layer literature says plainly that current observing systems cannot provide adequately detailed profiles of temperature, moisture and wind in this layer.
  • A station profiles it on every ascent, at the fire, for the whole diurnal cycle. Several stations are a three-dimensional weather network at the incident.
  • One honest design rule that comes with it: profiles are taken on ascent only. During descent the aircraft flies inside its own downwash and the estimate is unreliable, so descent data is recorded but never published as a profile.

Who would use this data?

Fire behaviour analysts operationally, and the fire science community for validation. It is the strongest research-partnership offer in the whole platform.

What would it take to prove?

Field measurement against reference instruments over real diurnal cycles. That is a research programme with a university partner, and it is the natural first joint publication.

Takeaway The data that trains the models that make the platform valuable comes from the instrument the platform builds.

Cost per observation-hour, with a low operator-to-station ratio

The station's argument is not that the hardware is cheap. A complete tethered system runs roughly $15,000 to $250,000 depending on capability. It is what an hour of continuous observation costs.

The station is a sited instrument. Understanding where that is an advantage and where it is not is what makes the deployment model work.

  • Fixed overwatch above an incident command post, helibase or camp, with electro-optical and infrared to the fireline.
  • A detection picket over a ridge or gap where lookout and camera coverage is poor, running persistent baseline smoke detection.
  • A communications relay restoring or extending incident connectivity — the profile with the clearest demonstrated demand, since incident connectivity fails exactly when it is needed.
  • Night illumination over a ground work area from a controllable height and angle.
  • And where it does not fit: a fire moves and a station does not, so placement is computed against the predicted front with the prediction's uncertainty attached, and the station complements mobile assets rather than replacing them.

Who operates it?

The agency or operator, under their own authority. The platform proposes where observation would reduce uncertainty most; a named human decides whether a station is deployed.

What is the first commercial configuration?

The observation profile with a measurement payload, sited against the priority grid. The relay profile is the one with the clearest existing demand and the least ambiguous regulatory position.

Takeaway In the United States the public-safety relief reaches volunteer departments, which are roughly 65 percent of the firefighting workforce and largely cannot staff a certificated drone programme at all.

Act VII — The position

Twelve dimensions, named products

Each column is a real, capable product. Ratings are drawn from public sources and the dimensions are buying questions, not features we happen to have.

A rating of adjacent means the product does a neighbouring thing well. It is often the truthful answer, and including it is what makes the rest of the grid credible.

  • Detection is deliberately not the row where this platform claims the win. Two funded constellations own it, and the platform's job is to consume their output well.
  • The rows where the platform is alone — coverage modelling, cross-border resolution, machine-checked authority boundary, in-situ measurement — are the rows that define the position.
  • Every strength row is mandatory. A column without one does not render.
  • Sources and read dates travel with the grid, so any figure can be checked.

Are these companies competitors or partners?

Mostly partners. Satellite detection and camera confirmation both feed this platform, and the February 2026 partnership between two of them shows the market already paying to cross the seam.

What would change this grid?

Any of them building the integration layer. The moat is not any single row — it is the combination of the integration, the governance and the instrument, and the last one takes hardware.

Takeaway The named players are strong and mostly complementary. Each occupies one layer; the position is the seam between them plus the instrument.

Where we connect rather than compete

Satellite detection feeds in. Camera networks feed in. Predictive analytics interoperate. Evacuation platforms receive. The platform is the connective tissue and the measurement layer.

Three things compound, and no single competitor holds all three.

  • The integration and the governance model: 46 sources with preserved semantics, provenance that survives correction, an evidence pack behind every number, and an authority boundary enforced by the build. That is years of unglamorous work that nobody can shortcut.
  • The model plane: point-in-time feature assembly, stratified evaluation, a qualification vector rather than a badge, and a monitoring path that treats delayed labels honestly.
  • The instrument: a tethered station that produces the calibrated, continuous, georeferenced ground truth this field does not have — the data that trains the models that make the platform valuable.
  • A hardware vendor can copy the airframe but not the model plane. A model company can copy an algorithm but not the instrument. The vertical is the advantage.

What is the fastest path to a reference customer?

An agency or utility pilot on the fusion, asset twin and verification queue, using data they already have, with the change digest as the daily habit that makes it stick.

What does a research partner get?

Governed data, reproducible evaluation, and access to a measurement programme that produces genuinely novel observations of fire behaviour and the surface layer.

Takeaway Nothing here asks an agency to replace what works. It asks them to stop assembling the answer by hand.

What we are asking of you

Four audiences, four different next steps. All of them start with a working session on your own ground rather than a demonstration of ours.

A pilot is bounded on purpose: one region, one season, a named capability set, named roles and a pre-agreed way to tell whether it worked.

  • It starts with the sources the agency already trusts, connected through adapters, so nothing new has to be believed on day one.
  • It runs beside the existing workflow rather than replacing it, so the comparison is against what people do today, not an idealised baseline.
  • The success measures are agreed before it starts: time to verify a candidate, time to brief, quality of the change digest, and whether the queue ranked the things that mattered.
  • It ends with a decision, an after-action review and a benefit reconciliation, and either it continues or it stops.

What does an agency have to commit?

A region, a named operational sponsor, and access to the sources they already use. Not a procurement, and not a migration.

How long?

One season is the natural unit, with the off-season before it for configuration, integration and training, and the off-season after it for the review.

Takeaway Every one of these starts the same way: your data, your ground, your question.

Open the slide deckWalk the data journeyThe short briefingWildfire Ahead home