Engineering evaluation
Test one AI-driven machine task against your existing controls.
Start with a free fit assessment. Continue one phase at a time. For integrators and equipment builders: compare completed work, unwanted refusals and engineering hours on one fixed-base robot task. Begin with recorded commands. Each paid phase has an agreed deliverable and stop condition.
Start the fit assessment → Open the two-page partner pack →
Pilot status: the core runs on the selected FPGA. In a PC-assisted rig, a program in its interpreter has moved a physical arm, and the arm held when the gate withheld its reply. Endstop is pre-product and not certified. Read the board test record →
The object
A small FPGA gate in the command path, without a general-purpose operating system or network stack.
| Interface | Pilot scope | Current maturity |
|---|---|---|
| Program input | Framed messages over a serial link | UART diagnostics, binary request/reply rehearsals and PC-assisted arm runs |
| Command output | PWM or step/direction regenerated after enforcement | Target architecture; integrated per partner machine |
| Machine feedback | Direct encoder or drive capture where required by the envelope | Arm encoder, goal and health feedback recorded in a PC-assisted rig; direct sensing is integrated per machine |
| Evidence output | Trusted-side verdict records for off-board replay | Bounded emulated journal with an on-request Ed25519 seal; the durable chain is a pilot deliverable |
| Independent stop | Machine-specific rated stop path around the gate | Required around the gate; provided by the partner’s rated stop path |
The trusted software is 1206 measured lines: a 667-line interpreter and a 539-line envelope monitor. The machine-specific risk assessment still determines the envelope and the appropriate safe state. See the complete architecture and claim boundary →
What integration looks like
The planner stays where it is. A suitable command path is routed through the gate.
Today, a model or planner emits commands that reach the drive stage. In the pilot, Endstop is inserted before a PWM or step/direction input that it can regenerate. The fast current and velocity loops remain inside the drive. The model, training stack and planner do not have to change.
Many serious machines use EtherCAT, CANopen or a proprietary servo bus. Those interfaces are not supported by the current gate. Free scoping looks for an earlier or narrower interception point—a joint, subsystem or test rig. If none exists, the conclusion is that this version of Endstop does not fit the machine.
Classic CAN 2.0B command links are in development. The gateway logic passes simulated closed-loop tests against a reference drive-by-wire protocol. If your machine is commanded over classic CAN, say so in the intake form.
Run the same task and failure cases against the customer's existing approach and Endstop. Agree the required output, refusal tolerance, response budget and engineering-hour target before testing. Include attempts to exceed limits, repeat refused commands and use stale feedback. Record every failure.
The buyer receives repeatable tests, a comparison scorecard and a written recommendation to adopt, revise or stop. Useful work must meet the agreed floor; blocking everything cannot count as success. Physical stopping and bypass tests require a separate safe rig.
Read the test protocol and acceptance criteria →
Current software baseline →
How an engagement runs
Four separately scoped phases. The ranges below are planning ranges, not a schedule promise.
| Phase | Typical elapsed time | What you provide | What you receive | Exit criterion |
|---|---|---|---|---|
| 1 · Fit and envelope | 1–2 weeks; free | Command documentation, a recent failure or costly workaround, controls lead and budget owner | Written fit decision, comparison plan and draft limits | An accessible command interface and a problem worth paying to evaluate |
| 2 · Bench evidence | 2–4 weeks; paid | Recorded commands, representative limits and the existing approach to compare | Repeatable cases, results and hours by role | Agreed refusals, useful-output floor and engineering-effort comparison |
| 3 · In the loop | 2–6 weeks; paid | Non-production machine access and an integration engineer | Gate in the selected path, measured latency and a revised envelope | Timing and behavior meet the pilot acceptance criteria—or the constraint is documented |
| 4 · Evidence package | 1–3 weeks; paid | Final configuration review and incident-review requirements | Configuration record, replay results, test matrix, limitations and an assessor-facing evidence summary | Partner accepts the evidence package and named unresolved items |
Proposed evaluation pricing: $25,000–75,000 for agreed work. The quote names the included phases, comparison and decision date. Physical integration is separately agreed and is not automatically included.
Paid phases are quoted as fixed-scope statements of work after phase 1. Each can stop independently, and there is no commitment to the later phases when an earlier phase begins.
Read the Design Partner Pack → Eligibility, role-by-role effort, reference architecture, acceptance tests, indicative commercial terms, security posture and the path after a successful pilot.
What you bring
Required
A platform where a model genuinely participates in the control loop; someone who understands and can modify the command path; representative commands or traces; and a concrete statement of what the machine must never do.
Not required
A new model, retraining, a planner rewrite, belief in formal methods or a production deployment. Endstop's own board work is already underway; a pilot begins on recorded commands or a bench and reaches the partner's machine only when both teams agree it is ready.
A useful first conversation covers what you run, what the model decides and what you want bounded. Command-path documentation can follow once the likely interception point is clear.
Responsibilities and working terms
- The partner owns the risk assessment and envelope. Endstop helps translate them into an enforceable configuration; it does not decide what is safe for the application.
- Partner traces and architecture remain confidential. Nothing is published about the engagement without written approval.
- General product improvements may return to Endstop. Engagement terms distinguish them from partner-confidential material.
- Pricing follows the free fit phase. Later phases are separately scoped and priced for the platform and evidence work identified.
- Unsuitable machines receive an explicit no-fit result. Existing rated protection, an inaccessible fieldbus or a failure outside the configurable authority can all end the work.
Endstop is not certified and claims no performance level or SIL. It does not replace an emergency stop, rated drive function or machine-specific safe-state design.
Check the fit yourself
Four questions decide most of it, and you can answer all four without us.
The free fit assessment exists to reach a written yes or no. Most of that answer is already available to whoever knows the machine, so the questions are here rather than held back for a call. The last one settles more cases than the other three together.
| Question | A fit looks like | What the other answer means |
|---|---|---|
| Where does the model's proposed command last exist as something we could sit in front of? | A serial link, PWM or step/direction input carrying setpoints, which you can route through new hardware | EtherCAT, CANopen and proprietary servo buses are outside the current gate, and classic CAN is in development. Scoping looks for an earlier joint, subsystem or test rig; when there is none, that is the answer |
| What crosses that boundary, and what stays in the drive? | Setpoints or PWM at a machine-specific rate, validated during the evaluation. Current and velocity loops stay inside the drive | A gate sitting inside a torque or current loop is the wrong instrument for that machine |
| Can what the machine must never do be written as geometry? | Per-axis position and rate limits, plus keep-out regions as flat boundaries tested against tapped points on the chain | Force and torque envelopes, curved keep-outs and chains longer than six joints are each named work rather than configuration. Say which one you need |
| Can you produce a measured stopping table for each joint: travel at nine speed fractions, taken on the machine rather than in a jig? | You have one already, or you can measure it | This is the question that decides whole classes of machine. The reason is immediately below |
Why the stopping table decides it
The envelope monitor does not test the commanded position against a keep-out. It tests the position the machine would reach if the command were refused at that instant, which means every boundary carries a margin equal to the predicted stopping travel. That prediction comes from a per-joint table of measured worst-case travel at nine speed fractions, and the monitor validates the table before the machine moves: it must be non-decreasing in speed and convex, because those two properties are exactly what make reading between the entries an upper bound rather than a guess.
A machine whose travel after refusal is governed by its own momentum can fill that table. A machine that falls cannot. Its travel after refusal is set by gravity and whole-body dynamics rather than by the commanded speed of any one joint, so the honest table is dominated by a term that is already large at zero speed. The margin then swallows every keep-out worth having and the monitor refuses everywhere. The envelope is not wrong; it has no interior. This argument comes from the monitor's own load-time check, not from any legged platform's safety case; a team holding a measured stopping table for a balancing machine would falsify it, and that is a conversation worth starting.
Balancing legs and rotors need a fail-operational architecture, where the safety argument rests on continued correct actuation rather than on stopping. That is a different discipline from the one this gate is built for, and from the one ISO 13849 and IEC 61800-5-2 describe. Their whole vocabulary—safe torque off, safe stop 1, stop categories 0 and 1—names ways of reaching a de-energised state that such a machine does not have.
The productive move on those platforms is to qualify a subsystem instead. The arms and torso of a humanoid whose legs are parked, the manipulator on a mobile base, the implement on a field vehicle rather than its navigation: each of these comes to rest when power is removed, and each is a smaller integration and a faster answer than the whole machine.
Two things the answer to question four does not settle
A refusal is a verdict, not an actuator state. Electronic speed controllers hold the last commanded throttle for 320 to 500 milliseconds after the signal stops, and digital servo behaviour on signal loss is unspecified and varies between production batches of one part number. Reaching a safe state needs an energy-removal path separate from the command path—which is also what the standards mean, since stop category 0 is removal of power and ceasing to send a control signal is not.
And a refusal is terminal. The monitor latches it, a supervised reset is the one thing that clears it, and no control cycle can. On a fenced cell an operator presses a button. Where a reset would mean entering the hazard zone, or where the machine is unattended in a field, that is a constraint on the deployment and worth raising in the first conversation.
Frequently asked questions
What do we need for the free fit assessment?
Bring a machine or test platform, someone who understands its command path, representative commands or traces, and a concrete failure you want bounded. Command documentation, a controls lead and a budget owner help define a useful comparison. You do not need to retrain the model or commit to a production deployment. Describe the proposed task.
Which command interfaces can the current pilot evaluate?
Scoping looks for a serial command link or a PWM or step/direction input that the proposed gate can intercept. EtherCAT, CANopen and proprietary servo buses are outside the current gate’s support. Classic CAN 2.0B is in development and is not yet offered in a pilot. An earlier joint, subsystem or test rig may offer a suitable interception point; physical integration and complete timing still need validation. Review the interface and stopping requirements.
What would a paid evaluation cost?
The fit phase is free. Proposed evaluation pricing is $25,000–75,000 for agreed work. Each paid phase has a fixed scope, deliverable and stop condition. Physical integration is separately agreed and is not automatically included. Read the proposed commercial terms.
What counts as a successful evaluation?
Agree the task, existing controls, useful-output floor, refusal tolerance, response budget and engineering-effort comparison before testing. Record failures and compare the same cases. Blocking everything cannot count as success. Physical stopping and bypass tests require a separate safe rig; a successful pilot does not establish certification or production approval. Read the acceptance approach.
Free fit assessment
Describe the machine and the boundary you need.
The intake should take about five minutes. We review it directly and follow up with the appropriate next step, including a call when a technical fit conversation is useful.