Claim-Specific Dependency Analysis

Backup paths are not independent if they can fail for the same reason.

Endoxa verifies whether the evidence and support paths behind a specific engineering Claim are actually independent. Where the evidence does not answer, we reconstruct only what the Claim needs and show you the few facts that can change the conclusion.

Pre-product, pre-pilot. Founding design partner program now open.

Fixed scope, fixed fee, one Claim at a time. No documents before an NDA and an Evidence Fit Check.

The problem

Separate paths. One hidden root.

Backup sensors, protection channels, alternate power paths, software channels and supplier parts look independent on paper. In practice they can share one measurement source, timing source, controller, network segment, power domain or supplier-controlled property. And that shared root is never written down in one place.

Illustrative example: mobile robotics

Three detection paths, one localization chain. For a global-position Claim the backup collapses. For local obstacle avoidance it may not matter. Independence is Claim-relative.

Illustrative example: process safety

The P&ID shows two transmitters. The instrument index and the cause-and-effect matrix name one tag for both the alarm and the shutdown. Until that conflict is resolved, independence cannot be supported.

Illustrative example: backup power

Separate UPS units, separate distribution, one transfer switch at the intake. Independent for a UPS fault. Not for a transfer-switch fault. The boundary decides which Claim holds.

All examples are constructed for illustration. They are not customer cases.

Found early
An engineering question.

One dependency to check while architecture and interfaces are still cheap to change.

Found late
A schedule problem.

Redesign, repeated validation, supplier escalation, field modification or downtime.

What Endoxa does

One Claim. One question. Answered from your own evidence.

A Claim is one specific engineering assertion: two protection channels are independent; a backup power path has no single point of failure up to the rack; obstacle detection survives the loss of one sensing path. Endoxa takes one such Claim and verifies what your existing evidence establishes about it.

Not a system of record

Works from the artifacts your requirements, FMEA and traceability tools already hold. Replaces none of them.

Not a certification

No safety verdicts. Every result is bounded to one Claim, one scenario, stated assumptions and an explicit Analysis Boundary.

Not a runtime system

Analyzes engineering evidence only. Never connects to your plant, your robots or your production environment.

The product

Claim Independence Audit

Fixed scope, fixed fee, one bounded case: one Claim or a tightly related group of Claims inside one subsystem.

1Bounded caseOne subsystem, one agreed boundary and configuration baseline.
1ClaimOr a tightly related family. You pay for the scope, not the Claim count.
0New documentsDrawings, requirements, FMEA, supplier and test records you already have.
2-4WeeksInitial format, after scope agreement and kickoff.

What you receive

DeliverableWhat it gives you
Evidence MapEvery relevant fact, tied to its exact source location.
Support PathsThe path sets that actually hold the Claim up.
Shared RootsDependencies that can defeat several paths at once.
High-impact Unknowns and ConflictsOpen or contradictory facts, ranked by impact on the conclusion.
Bounded resultThe conclusion, or the set of conclusions still possible.
Action ListEvidence to obtain, tests to run, supplier questions, decisions to confirm or change.
Supplier Evidence AnnexWhich supplier-controlled properties your conclusion rests on.
Versioned snapshotImmutable record of evidence, model and result as delivered.

An audit does not have to find a defect to succeed. You pay for the agreed analysis and a formally grounded result. Supported independence, a shared root, a consequential Unknown, a Conflict or an Assumption-dependent conclusion are all valid results.

What a result looks like

One constructed example from a generic braking subsystem. In a real report every line links to its source.

Result on one ClaimIllustrative, constructed example. Not a customer case.
Claim

The secondary brake path engages if the primary motion controller loses power.

Boundary

Braking subsystem, baseline B-07, single-fault scenario. Out of scope: mechanical wear, operator action, external power quality.

Path A: motion controller CONFIRMED Path B: safety relay K7 CONFIRMED Brake driver DRV-2 both paths act through it Brake coil 24 V SUPPLY TO DRV-2 behaviour on loss of supply: not in the manual UNKNOWN
UNKNOWN
Shared root

Does DRV-2 release the brake when its own 24 V supply is lost? The supplier manual does not say. This one fact decides the conclusion.

CONFLICT
Your evidence

Schematic rev C: DRV-2 on a separate 24 V supply. Wiring list rev D: on the controller supply. Both documents are current.

ASSUMPTION
Carried visibly

Relay K7 firmware matches the commissioning record. Not re-verified in this audit.

Bounded result

Independence is not established within the declared boundary. Two conclusions remain possible; one supplier fact and one as-built fact decide which.

01SUPPLIER
Written statement on DRV-2 behaviour on loss of its 24 V supply.
02EVIDENCE
Confirm which document reflects the as-built supply: schematic rev C or wiring list rev D.
03DECISION
Hold the dependent decision until both facts close. Then recalculate against the delivered snapshot.
How it works

Verification first. Reconstruction only where needed.

01

Ground

Every fact keeps its exact source. AI proposes candidates; it never writes trusted facts.

02

Verify

Which paths your evidence really establishes for this Claim, and what they share.

03

Reconstruct

Only the structure the Claim needs. Unresolved stays unresolved.

04

Qualify and close

Your engineers answer only the questions that can change the result. Closed on the evidence, inside an agreed window.

An engineer reviews every conclusion before it leaves Endoxa. Final engineering authority stays with your team.

Principles

Built to keep uncertainty visible

UNKNOWN

Unknown is not false.

What the evidence does not establish stays open. Never quietly treated as absent.

CONFLICT

Conflict is not false.

Contradicting sources are kept side by side, not averaged away.

CANDIDATE

A candidate is not a fact.

Machine-extracted relations enter the analysis only after an engineer qualifies them.

ASSUMPTION

An assumption is not evidence.

Stated explicitly, carried visibly into the result.

BOUNDARY

A missing link is not independence.

A dependency nobody modeled is not proof of independence. Every conclusion is bounded by a declared Analysis Boundary.

CLAIM-RELATIVE

Connected is not required.

A dependency can be real and still irrelevant to this Claim. What a path uses is not what the Claim requires.

AI reads and proposes. Conclusions come from formal analysis of engineer-qualified evidence.

Who it is for

Any system where a Claim rests on paths that must stay independent

The question is the same in every industry: can the paths behind one assertion fail for the same reason? Typical Claims:

Mobile and field roboticsObstacle detection survives the loss of one sensing path.
Energy and utilitiesMain and backup protection share no measurement source or DC supply.
Process and chemical plantsAlarm and safety shutdown use independent instruments.
Energy storage and power conversionBMS, converter and external shutdown do not hinge on one supplier property.
Data centers and critical facilitiesA and B feeds have no single point of failure up to the rack.
Rail and transit systemsDetection and interlocking channels share no power or timing source.
Industrial automation and machinerySafety PLC channels and emergency stop circuits are independent.
Automotive, off-highway and aerospace platformsRedundant braking or steering channels do not converge on one component.
Maritime and offshore systemsDynamic positioning references and shutdown paths are independent.
Medical and laboratory equipmentPrimary and backup alarm and power paths share no dependency.
Defence and dual-use systemsNavigation, command and termination paths do not converge on one link or module.
Space and satellite systemsRedundant power buses and command links share no upstream root.

Not listed? The method does not depend on the industry. For regulated or export-controlled programmes, handling mode and the legal basis for sharing evidence are settled before scope is discussed.

You are likely a good fit if

  • One concrete assertion that two or more paths are independent.
  • A subsystem that can be bounded, with a known configuration.
  • Evidence that exists but is spread across documents, teams and suppliers.
  • A real engineering decision depends on the answer.
  • A technical owner who can confirm consequential facts.

Probably not a fit if

  • One inspection or one supplier call would answer it in an afternoon.
  • The question is "is the whole plant safe" or "prove the system is compliant".
  • You need a certification, a HAZOP, a full FMEA or a protection study. Different services.

When teams usually come to us

before design or interface freezebefore a supplier commitment or purchase orderbefore a design review or assurance reviewbefore FAT, SAT or commissioningafter a major design changewhen supplier evidence contradicts the drawingswhen a shared dependency is suspected

Usual counterparts: Chief Engineer, Head of Systems, Functional Safety, Controls, Protection, Reliability or Integration Lead.

Your evidence

Your evidence stays bounded

Only what bears on the Claim

One subsystem, one Claim: we ask for the documents that matter to it, not for your repository.

NDA first, terms in writing

No document moves before an NDA. Transfer, storage, retention and deletion are agreed per engagement.

Plain handling terms

Initial format: analysis in an Endoxa-managed environment under engagement-specific controls, explained before you share anything.

Restricted evidence stays put

Critical-infrastructure or legally restricted material: whether it may be shared at all is settled with your security owner first. If not, we say so.

Founding design partner program

How an engagement starts

Pre-pilot. A founding design partner program for a few teams with one Claim worth examining. The first step costs nothing and involves no documents.

Discovery call

One Claim, the decision behind it, the evidence you already have. No documents.

Claim Charter and boundary

One testable assertion, one subsystem, one scenario, and what is out of scope.

Evidence Fit Check

Under NDA: formats, access, owners, handling. Fit, fit with conditions, or no fit. No fit means no engagement, not a cheaper one.

Fixed-fee proposal

Fee agreed once Claim, boundary, evidence scope and delivery are defined. Then the audit starts.

Request a discovery call
FAQ

Questions engineering leads ask first

Is this a certification or a safety verdict?

No. Endoxa does not certify systems or declare them safe. Every result is scoped to one Claim, one scenario, stated assumptions and a defined Analysis Boundary. It informs your decision; it does not replace your authority.

What if you do not find a hidden dependency?

Still a result, and a paid one. "Evidence supports independence within the declared boundary" is a statement your team can act on, as is a consequential Unknown, a Conflict or an Assumption-dependent conclusion. We say so before you sign.

What if our supplier never answers?

Qualification runs inside an agreed window. When it closes, open facts stay explicitly open, the result is recalculated on what is established, and the audit is delivered. An unanswered supplier question becomes a ranked Unknown and an action, not an endless engagement.

Does AI make the conclusion?

No. AI reads documents and proposes candidates. Only engineer-qualified evidence enters the formal analysis, and an engineer reviews every conclusion before delivery.

What documents do you need?

What you already have for the subsystem: architecture or single-line diagrams, protection or control logic, requirements, FMEA or HAZOP outputs, supplier manuals, configuration, test and commissioning records. Formats: PDF with a text layer, Markdown or plain text, CSV or XLSX. Scans, CAD or vendor-specific formats affect scope; tell us in the first conversation.

Do you need access to our systems?

No. The audit works from documents and exports. No access to your plant, robots, control systems or internal tools.

How long does it take, and what does it cost?

2-4 weeks after kickoff in the initial format. The fee is fixed and agreed once Claim, boundary, evidence scope and delivery are defined. The discovery call is free.

What about components from suppliers?

When a conclusion rests on a supplier property you cannot verify, the Supplier Evidence Annex records what the supplier asserted, where, and how much depends on it. We do not invent supplier internals. An unestablished property stays Unknown and becomes a precise supplier question.

Do you replace our requirements, FMEA or reliability tools?

No. Endoxa works from the evidence those tools hold and answers one question they are not built for: whether the paths behind a specific Claim are actually independent, and which open fact could change that.

What counts as a Claim?

One testable assertion about one subsystem under a stated scenario, where different answers lead to different decisions. "Main and backup protection do not share a DC supply" is a Claim. "The system is safe" is not. Turning a concern into a Claim is the first thing we do together.

Who sees our documents?

Only the Endoxa engineers on your engagement, under the NDA and the written handling terms. Documents serve your audit only: not used to train models, not shared with other clients, not kept beyond the agreed retention. Legally restricted evidence is cleared with your security owner before scope is agreed.

What happens when the design changes after the audit?

The delivered result is an immutable snapshot. When evidence changes, say a supplier answers or a revision ships, the result can be recalculated against that snapshot, so you see exactly what moved. Whether a refresh is included or ordered separately is agreed in the statement of work.

Get in touch

Request a discovery call

Tell us about one Claim you want examined. A founder replies within two business days. Please do not include confidential details at this stage.

One sentence is enough. Please do not include confidential details.
What happens next: a short written reply within two business days, usually with a few scoping questions. No sales deck, no document requests.

Prefer email? Write to info@endoxa.tech.