Skip to content

An evidence-led approach to proving that uncrewed systems behave predictably when communications, sensors and assumptions fail.

Zantasy Defence Systems · 2026 · 6 MIN READ

Hardware-in-the-loop evaluation bench with sensor rig wired to a rugged edge computer — concept imagery
FIG. 01 — Hardware-in-the-loop evaluation bench · concept imagery

Claiming that a system degrades gracefully is easy. Demonstrating it, repeatably and on the record, is the actual work. This explainer describes how Zantasy thinks about testing the three failure behaviours that matter most for uncrewed defence systems: lost link, sensor conflict and safe-state entry.

Definitions

01

Define the behaviour before the test

Every test starts from an authorised behaviour, not from a scenario script. For each degradation — lost communications, conflicting sensors, a navigation source dropping out — the programme defines what the system is permitted to do, within what bounds, and what evidence would show that it did so. The test then measures the system against that definition.

02

Simulation before hardware, hardware before field

Simulation explores the space cheaply: link loss at different mission phases, injected sensor disagreement, timing edge cases. Hardware-in-the-loop testing then exercises the real compute, the real interfaces and the real timing against the same fault cases. Only after both does field testing confirm behaviour in the operating environment.

Each stage produces evidence in the same structure, so results accumulate into a single assurance case rather than a pile of disconnected reports.

Test every assumption — in simulation, on the bench, then in the field.

03

Evidence programme teams can assess

A test that cannot be reviewed is a demonstration, not evidence. Recorded inputs, logged confidence-state transitions, timestamps and configuration identifiers let programme teams replay exactly what the system saw and why it acted. That record is what turns “it worked on the day” into an assurance argument.

Conclusion

Lost-link, sensor-conflict and safe-state behaviour are not edge cases to be discovered in service. They are design commitments to be tested in stages — simulated, bench-proven and field-confirmed — with evidence that stands up to review. That is the operating model of Zantasy AssureLab.