PARAGON REFLEX

A reflex layer for autonomous machines.

Your perception network’s backup
should not be another perception network.

A second detection channel that shares no model, no training pipeline, and no inference runtime with your perception stack.

In most autonomy stacks one network decides whether there is a hazard, and nothing downstream can tell when that decision is wrong. We run a second channel on the same lidar and camera input. It reaches its own answer by a different route and flags the frames where the two disagree.

The budget
A safety-island budget, not an AI-accelerator budget
2 KB
Of state
None
Floating-point inference
0
Network inference
Kilobytes of pattern state, plus a distilled encoder of about 144 kilobytes · No dynamic allocation · Fixed execution cost

A product line of Univault Technologies. Patent-pending.

Beyond automotive

Built and measured on road autonomy. Now on NVIDIA Jetson, the compute those aircraft already carry.

An NVIDIA Jetson Orin Nano developer kit, the board the reflex layer runs on

The same second channel, on the compute those aircraft already carry. It reads the same input as the perception stack, reaches its own answer, and raises the frames where the two disagree. And because a fleet is many aircraft rather than one, what a single airframe catches then travels to the rest instead of being met again by each of them.

Reflex for uncrewed aircraft
Lidar and camera input | Own model | Own training pipeline | Own runtime | Safety-island budget | Automotive Safety Integrity Level D decomposition target | Patent-pending

Why this matters

The fleet finds it Tuesday.
The fleet gets the fix
two quarters later.

A vehicle meets something your perception stack does not flag. Turning that one event into fleet-wide behavior means a labelling cycle, a retrain, a full revalidation of a network that changed underneath you, and a software-update file that has to be re-opened.

Why it is always two more years

Autonomy is usually described as a perception problem. The bottleneck is the correction loop.

Label it, change the model, prove nothing else broke. Once the weights move, your existing evidence describes a system you no longer ship, so the safety case gets re-argued and, in type-approval markets, the update file gets re-opened.

Then the fleet finds four more.

Almost none of this is bounded by compute, and compute is the part you can buy more of. The bound is the people who write the safety argument and the independent assessors who sign it, and that capacity does not grow because you need it to.

The date moves because the loop that corrects a fault runs slower than the loop that finds one. You can tell where the industry thinks the constraint is by what it is paying for. Waymo is spending to compress the time it takes to open a new city. Mobileye built a map that updates itself off the fleet. Wayve is betting on not needing a map. None of that is a bet on better driving. All of it is a bet on making the next change cost less than the last one.

An independent monitor on your perception channel, built so that keeping it current costs less than rebuilding it.

When the backup is another network
  • Every fix is a retrain
    New weights mean your argued safety case describes a system you no longer ship, and your assessor has to form a view on the change.
  • Correlated failure modes
    Two networks trained on the same conventions tend to be wrong about the same scenes, and share the accelerator besides.
  • The scarce resource is people
    One retrain spends the same review capacity whether it fixes one scenario or forty, and that capacity is booked months out.
  • Couples you to a vendor's roadmap
    The backup constrains which detector you are allowed to choose next.
With a reflex layer
  • Updates stay small
    Keeping the channel current does not move your perception network’s weights, so the safety argument you already made for that network still describes what you ship.
  • Sized for the other processor
    Kilobytes of state and a fixed execution cost, so independence can be physical.
  • Not a network
    Its own model, its own training pipeline, its own inference runtime. Nothing it does depends on yours being correct.
  • Does not constrain your detector
    It does not touch your model or your choice of detector, so you keep choosing.

The evaluation

You set the bar.
Then we run it on your data.

The only quantity worth anything to you is how much of your own stack’s residual this channel recovers on your own fleet’s data. That number does not exist in a public benchmark and we are not going to manufacture a proxy for it. So we do not lead with numbers. We run the test you specify, on a bench, with your logs.

You write the criteria

Pass and fail are defined by your team, in writing, before we see any of your data. Including the scoring convention and the false-alarm budget you actually have to live inside.

Your logs, your labels

A replay on your recorded data against your own detector. No integration, no vehicle time, and nothing installed on anything that moves.

You keep the verdict

Your team scores it against the criteria your team wrote, and keeps the result either way. We see the same report you do.

How we release results. A result about a safety layer is only readable with its conditions attached: which detector it was measured against, the false-alarm rate both sides were held to, the distance band, and the definition of a miss. Those four travel with every number we release, under a mutual non-disclosure agreement.

Where it runs, and what it is for

Three things to check
before you talk to us.

None of these needs a benchmark to evaluate. Two of them you can check against hardware you already own.

01 — THE BOUNDARY

Model failure, not sensor failure

The reflex layer has its own model, its own training pipeline, and its own inference runtime. Nothing it does depends on the perception network being correct. It is not sensor-independent: both channels read the same sweep, so a blinded sensor takes both down together. The independence is from the perception software, and that is the failure family it is there for.

02 — THE BUDGET

Sized for the safety island

Two kilobytes of state and a fixed-cost comparison against it. No floating-point network inference, no dynamic allocation, and control flow that does not branch on the data. That is a budget we are targeting at the lockstep microcontroller already in the vehicle rather than the accelerator inside the main system-on-chip. The port to that microcontroller is in build.

03 — THE UPDATE PATH

The update path

When the fleet finds a hazard pattern the car did not have, updating the channel for it is designed to be a smaller thing to argue under an update-approval regime than shipping a different network. No assessor has given an opinion on that yet.

What this is, and is not, today. At its current false-alarm rate the reflex layer is a monitoring, arming, and event-capture channel. It is not a brake authority. The false-alarm rate is the gate, and closing it is the program we are running.

Talk to us if you ship
autonomy at scale.

Tier-1 supplier, OEM, robotics platform, eVTOL (electric vertical take-off and landing) program — if you have to argue independence for a perception channel, we should be talking.