Engineering evidence

Demonstrated behaviour, with its boundary.

Three kinds of truth appear on this site, always labeled: Measured numbers with a method, Simulation demos that reproduce behaviour without being it, and Tuned profile figures from real but non-default configurations. This page is where the measured ones live.

No customer claims, no availability percentages
Field demonstration

HEMUS 2026: eight nodes, six link types, four days.

A mixed fleet — two laptops, five single-board relay nodes, one airborne node — carried MAVLink command-and-control, H.265 video and live gimbal control continuously, over up to six dissimilar underlay types bonded per node: two serial telemetry radios, Bluetooth-PPP, Wi-Fi ad-hoc, 802.11s mesh and Ethernet.

Links were killed and degraded live throughout — power cuts, cable pulls, USB-hub kills, and packet-level impairment injection — while visitors operated the ground station unaided. These were controlled link-degradation trials: no live RF jamming was performed, and nothing here is an availability or SLA claim.

4 daysof continuous public demonstration
8 nodes2 laptops · 5 SBC relays · 1 UAV
6 typesof dissimilar links bonded on one node
2 rolesMAVLink C2 + H.265 video, simultaneously
Measured numbers

Each number, its meaning, its method.

If a number on this site doesn’t appear in this table, it’s a simulation or a labeled tuned profile — by policy.

NumberWhat it meansHow it was measured
0.1–0.75 sTraffic-reweighting cadence under degradation — a response cadence, not a recovery guaranteeTypical configured scheduler cadence; observed continuously in the decision log
p50 0.18 / p95 0.42 msBonding tax: latency the pipeline itself adds over the raw linksThe daemon’s own always-on ledger — five sampled one-way series, reproducible from /api/stats on any node
0 loss across rekeyMake-before-break key rotation costs nothingEnd-to-end suite pings continuously through forced rekeys under load
3×30% → ~2.7%Broadcast redundancy under severe lossScripted namespace demo: three links each forced to 30% loss with netem, end-to-end loss measured
3×2% → 0.0008%Independent-loss multiplication in broadcast modeArithmetic (0.02³), stated as arithmetic
C2 wait 0.0 ms @ 20k pkt/sStrict priority holds under a two-thousand-fold floodScripted QoS run: C2 max queue wait at 200/1k/5k/20k pkt/s offered video; AQM drops 0 → 1,046 → 9,042 → 39,027
0% over 123 s, both relays deadRelays are warm standbys to a punched direct pathHardware verification of relay election: both hosted relays blocked while a punched path carried; loss counted
32 / 125 msLive gateway RTTs (DE / CA) from SofiaMeasured by the Android client’s STUN prober against the live hosted gateways
< 1 sRelay path bring-up behind CGNAT, outbound-onlyNamespace traversal harness with stateful NAT + latency; also the live gateway connect path
Units

Every crate, deterministically

Core, protocol, traffic classes, erasure coding, the bundle store, relay, STUN, terrain, the daemon and the telemetry crates each carry their own suites. The class, coding and store crates are deliberately pure — injected clocks, no I/O — so their tests are deterministic rather than timing-dependent.

Data path

Two real daemons over two virtual links: handshake, bidirectional traffic, link-kill failover and restore, endpoint roaming via live re-addressing, lossless rekey under load, status CLI. ~50 seconds, no root.

IPv6 underlay

The same flow over an IPv6-only underlay — proving the v6 endpoint support end to end.

Traversal

Two daemons each behind its own stateful CGNAT with real latency: relay bring-up, NAT classification, hole punching, traffic held across the relay→direct transition.

Config apply

Three commit-confirmed apply cycles through the daemon’s outbox: peers-auto-confirm across an in-place restart, a deadline revert, and a fatal config rejected with the live file untouched. “Can I brick a remote node?” is answered by CI.

Fleet epochs

Signed config epochs over encrypted gossip between two mesh daemons: propagate, apply, tamper-reject, rollback-reject, recover with the next good epoch.

Class escalation

Per-class adaptive escalation under 30% injected loss: enter, exit after dwell, and the budget guard refusing amplification.

CI

Build, the full test estate and the namespace end-to-end suites run on every push, with a dependency audit — advisories, licences, provenance — as a merge gate. Further loopback suites cover STUN, relay links and hole punching without namespaces.

Known boundaries

What this evidence does not say.

The limits, in the same font size as the claims.

No production claims

Demonstrations and test harnesses, not customer deployments. There are no reference customers named on this site, and no availability percentages anywhere — deliberately.

No jamming claim

Link kills were physical and impairment was packet-level. Behaviour under live RF attack is exactly what a controlled pilot with your RF environment would establish.

Configuration-specific numbers

Every measurement is a property of its configuration and environment. That’s why each row above names its method — and why the evaluation harness exists.

Request an evaluation

Reproduce us.

Every measured number here comes with its method. An evaluation gives you the harness to run them against your own links — and to catch us if one doesn’t hold.