Backup paths are not independent if they can fail for the same reason.
Endoxa verifies whether the evidence and support paths behind a specific engineering Claim are actually independent. Where the evidence does not answer, we reconstruct only what the Claim needs and show you the few facts that can change the conclusion.
Fixed scope, fixed fee, one Claim at a time. No documents before an NDA and an Evidence Fit Check.
Separate paths. One hidden root.
Backup sensors, protection channels, alternate power paths, software channels and supplier parts look independent on paper. In practice they can share one measurement source, timing source, controller, network segment, power domain or supplier-controlled property. And that shared root is never written down in one place.
Three detection paths, one localization chain. For a global-position Claim the backup collapses. For local obstacle avoidance it may not matter. Independence is Claim-relative.
The P&ID shows two transmitters. The instrument index and the cause-and-effect matrix name one tag for both the alarm and the shutdown. Until that conflict is resolved, independence cannot be supported.
Separate UPS units, separate distribution, one transfer switch at the intake. Independent for a UPS fault. Not for a transfer-switch fault. The boundary decides which Claim holds.
All examples are constructed for illustration. They are not customer cases.
One dependency to check while architecture and interfaces are still cheap to change.
Redesign, repeated validation, supplier escalation, field modification or downtime.
One Claim. One question. Answered from your own evidence.
A Claim is one specific engineering assertion: two protection channels are independent; a backup power path has no single point of failure up to the rack; obstacle detection survives the loss of one sensing path. Endoxa takes one such Claim and verifies what your existing evidence establishes about it.
Not a system of record
Works from the artifacts your requirements, FMEA and traceability tools already hold. Replaces none of them.
Not a certification
No safety verdicts. Every result is bounded to one Claim, one scenario, stated assumptions and an explicit Analysis Boundary.
Not a runtime system
Analyzes engineering evidence only. Never connects to your plant, your robots or your production environment.
Claim Independence Audit
Fixed scope, fixed fee, one bounded case: one Claim or a tightly related group of Claims inside one subsystem.
What you receive
| Deliverable | What it gives you |
|---|---|
| Evidence Map | Every relevant fact, tied to its exact source location. |
| Support Paths | The path sets that actually hold the Claim up. |
| Shared Roots | Dependencies that can defeat several paths at once. |
| High-impact Unknowns and Conflicts | Open or contradictory facts, ranked by impact on the conclusion. |
| Bounded result | The conclusion, or the set of conclusions still possible. |
| Action List | Evidence to obtain, tests to run, supplier questions, decisions to confirm or change. |
| Supplier Evidence Annex | Which supplier-controlled properties your conclusion rests on. |
| Versioned snapshot | Immutable record of evidence, model and result as delivered. |
An audit does not have to find a defect to succeed. You pay for the agreed analysis and a formally grounded result. Supported independence, a shared root, a consequential Unknown, a Conflict or an Assumption-dependent conclusion are all valid results.
What a result looks like
One constructed example from a generic braking subsystem. In a real report every line links to its source.
The secondary brake path engages if the primary motion controller loses power.
Braking subsystem, baseline B-07, single-fault scenario. Out of scope: mechanical wear, operator action, external power quality.
Does DRV-2 release the brake when its own 24 V supply is lost? The supplier manual does not say. This one fact decides the conclusion.
Schematic rev C: DRV-2 on a separate 24 V supply. Wiring list rev D: on the controller supply. Both documents are current.
Relay K7 firmware matches the commissioning record. Not re-verified in this audit.
Independence is not established within the declared boundary. Two conclusions remain possible; one supplier fact and one as-built fact decide which.
Verification first. Reconstruction only where needed.
Ground
Every fact keeps its exact source. AI proposes candidates; it never writes trusted facts.
Verify
Which paths your evidence really establishes for this Claim, and what they share.
Reconstruct
Only the structure the Claim needs. Unresolved stays unresolved.
Qualify and close
Your engineers answer only the questions that can change the result. Closed on the evidence, inside an agreed window.
An engineer reviews every conclusion before it leaves Endoxa. Final engineering authority stays with your team.
Built to keep uncertainty visible
Unknown is not false.
What the evidence does not establish stays open. Never quietly treated as absent.
Conflict is not false.
Contradicting sources are kept side by side, not averaged away.
A candidate is not a fact.
Machine-extracted relations enter the analysis only after an engineer qualifies them.
An assumption is not evidence.
Stated explicitly, carried visibly into the result.
A missing link is not independence.
A dependency nobody modeled is not proof of independence. Every conclusion is bounded by a declared Analysis Boundary.
Connected is not required.
A dependency can be real and still irrelevant to this Claim. What a path uses is not what the Claim requires.
AI reads and proposes. Conclusions come from formal analysis of engineer-qualified evidence.
Any system where a Claim rests on paths that must stay independent
The question is the same in every industry: can the paths behind one assertion fail for the same reason? Typical Claims:
Not listed? The method does not depend on the industry. For regulated or export-controlled programmes, handling mode and the legal basis for sharing evidence are settled before scope is discussed.
You are likely a good fit if
- One concrete assertion that two or more paths are independent.
- A subsystem that can be bounded, with a known configuration.
- Evidence that exists but is spread across documents, teams and suppliers.
- A real engineering decision depends on the answer.
- A technical owner who can confirm consequential facts.
Probably not a fit if
- One inspection or one supplier call would answer it in an afternoon.
- The question is "is the whole plant safe" or "prove the system is compliant".
- You need a certification, a HAZOP, a full FMEA or a protection study. Different services.
When teams usually come to us
Usual counterparts: Chief Engineer, Head of Systems, Functional Safety, Controls, Protection, Reliability or Integration Lead.
Your evidence stays bounded
One subsystem, one Claim: we ask for the documents that matter to it, not for your repository.
No document moves before an NDA. Transfer, storage, retention and deletion are agreed per engagement.
Initial format: analysis in an Endoxa-managed environment under engagement-specific controls, explained before you share anything.
Critical-infrastructure or legally restricted material: whether it may be shared at all is settled with your security owner first. If not, we say so.
How an engagement starts
Pre-pilot. A founding design partner program for a few teams with one Claim worth examining. The first step costs nothing and involves no documents.
One Claim, the decision behind it, the evidence you already have. No documents.
One testable assertion, one subsystem, one scenario, and what is out of scope.
Under NDA: formats, access, owners, handling. Fit, fit with conditions, or no fit. No fit means no engagement, not a cheaper one.
Fee agreed once Claim, boundary, evidence scope and delivery are defined. Then the audit starts.
Questions engineering leads ask first
Is this a certification or a safety verdict?
No. Endoxa does not certify systems or declare them safe. Every result is scoped to one Claim, one scenario, stated assumptions and a defined Analysis Boundary. It informs your decision; it does not replace your authority.
What if you do not find a hidden dependency?
Still a result, and a paid one. "Evidence supports independence within the declared boundary" is a statement your team can act on, as is a consequential Unknown, a Conflict or an Assumption-dependent conclusion. We say so before you sign.
What if our supplier never answers?
Qualification runs inside an agreed window. When it closes, open facts stay explicitly open, the result is recalculated on what is established, and the audit is delivered. An unanswered supplier question becomes a ranked Unknown and an action, not an endless engagement.
Does AI make the conclusion?
No. AI reads documents and proposes candidates. Only engineer-qualified evidence enters the formal analysis, and an engineer reviews every conclusion before delivery.
What documents do you need?
What you already have for the subsystem: architecture or single-line diagrams, protection or control logic, requirements, FMEA or HAZOP outputs, supplier manuals, configuration, test and commissioning records. Formats: PDF with a text layer, Markdown or plain text, CSV or XLSX. Scans, CAD or vendor-specific formats affect scope; tell us in the first conversation.
Do you need access to our systems?
No. The audit works from documents and exports. No access to your plant, robots, control systems or internal tools.
How long does it take, and what does it cost?
2-4 weeks after kickoff in the initial format. The fee is fixed and agreed once Claim, boundary, evidence scope and delivery are defined. The discovery call is free.
What about components from suppliers?
When a conclusion rests on a supplier property you cannot verify, the Supplier Evidence Annex records what the supplier asserted, where, and how much depends on it. We do not invent supplier internals. An unestablished property stays Unknown and becomes a precise supplier question.
Do you replace our requirements, FMEA or reliability tools?
No. Endoxa works from the evidence those tools hold and answers one question they are not built for: whether the paths behind a specific Claim are actually independent, and which open fact could change that.
What counts as a Claim?
One testable assertion about one subsystem under a stated scenario, where different answers lead to different decisions. "Main and backup protection do not share a DC supply" is a Claim. "The system is safe" is not. Turning a concern into a Claim is the first thing we do together.
Who sees our documents?
Only the Endoxa engineers on your engagement, under the NDA and the written handling terms. Documents serve your audit only: not used to train models, not shared with other clients, not kept beyond the agreed retention. Legally restricted evidence is cleared with your security owner before scope is agreed.
What happens when the design changes after the audit?
The delivered result is an immutable snapshot. When evidence changes, say a supplier answers or a revision ships, the result can be recalculated against that snapshot, so you see exactly what moved. Whether a refresh is included or ordered separately is agreed in the statement of work.
Request a discovery call
Tell us about one Claim you want examined. A founder replies within two business days. Please do not include confidential details at this stage.
Prefer email? Write to info@endoxa.tech.