Failsafe

A resilience compiler for edge / Physical-AI systems.

200+
real-time experiments under injected failures
2 × 72
operating configurations measured under two failure conditions
4
search strategies compared, measured, losses included
0
LLM calls in the runtime decision loop

Cut the link. Watch what happens.

Same real video, two systems, same failures. Left: a normal system that needs the cloud. Right: Failsafe. Pick a domain to see it on a dashcam, a drone, or a robot.

Link healthy. Both systems are watching the zone.

Ordinary system
Failsafe
watching the zone
watching the zone
loading real footage…
0%
Ordinary system
100%
of the time the zone was occupied, it was watching. Modeled baseline.
Failsafe
100%
of the time the zone was occupied, it was watching, in a verified mode or its verified fallback.
0.0s

Both sides see the same real detections. The left side is a modeled baseline that needs the cloud. On the warehouse scene the right side runs the compiled policy; on the other domains its labels are illustrative. Footage: NVIDIA PhysicalAI-SmartSpaces (CC-BY 4.0), KITTI, VisDrone, JRDB, YCB-Video.

The main result

Drawn from the recorded experiments, with full provenance. Nothing here is a mock-up.

Per-alert latency by cloud condition against the 2-second limit
The headline result

Slow ≠ dead

Each dot is one real alert. When the cloud is dead (offline), all 57 arrive under the 2 second limit. When it is slow but alive, every one of 281 arrives too late, on the same configuration. Catching slow, not just down, is the whole point, and the fix is a verified on-device mode, not a smarter prompt.

Where it is verified, and where it isn't

Every condition the compiler looked at, one per row. Green passed on every clean run. The others say why there is no verified mode, so nothing is guessed.

Loading the compiled policy…