Skip to content
Technology How it works Breeder — Hyperion Burner — Aegis Burner — MetroVolt AI-Native Architecture Magnets Fuel cycle Safety Roadmap
Solutions AI & Data Centers Defense & Government Grid & Baseload Neutron Detection Quantum
Learn Technical Library
Proof Publications Whitepapers Technical Library Open Science & Reproducibility The Honest Gates
Company About / Mission Leadership Environment Health & Safety Investors Careers Press Contact
3D Model
AI Architecture › Security & Zero-Trust
Security & Zero-Trust

Safety-Instrumented System Isolation

The safety-instrumented system is physically and logically independent of the control network, with a one-way status feed out and no command path in.

STRATEGY / SLOW ▲ ▼ MICROSECOND REAL-TIMEL7Ecosystem & Strategytelemetry ▲ control ▼open ▸L6Experience & Visualizationtelemetry ▲ control ▼open ▸L5Applications & Copilotstelemetry ▲ control ▼open ▸L4Orchestrationtelemetry ▲ control ▼open ▸L3Twin Modeling & AItelemetry ▲ control ▼open ▸L2Data Fabrictelemetry ▲ control ▼open ▸L1Control Planetelemetry ▲ control ▼open ▸L0Foundationtelemetry ▲ control ▼open ▸PHYSICAL S.M.A.R.T. GENERATOR PLANTBREEDER · HYPERION1R0 1.2 m · A 2.5 · 16.84 T · δ −0.30BURNER · TANDEM MIRROR2317 T throat · 26.49 T plug · fₙ 5.44% · DEC1 center stack + plasma · 2 high-field plug · 3 expander → direct converterCOLOR GRAMMAR strategy AI-workflow infra/data models reactor/DECLINE SEMANTICStelemetry (µs)controlKRONOS FUSION ENERGYAI-NATIVE S.M.A.R.T. GENERATORMASTER BLUEPRINTSHEET 01REV. 2026-08L0-L7 · 2 MACHINES
The AI-Native S.M.A.R.T. Generator Master Blueprint — eight layers (L0→L7), one control stack, wired to both machines. Telemetry rises in microseconds; control descends the same path.

A shutdown that cannot be talked out of it

The safety-instrumented system (SIS) exists to place the machine in a safe state when defined limits are crossed. Its assurance comes from independence: it must not share failure modes, networks, or authority with the control system it protects. Kronos runs the SIS on separate hardware, separate networks, and separate power, with logic simple enough to verify exhaustively. Nothing on the control plane can disable or reprogram it during operation.

One-way relationship with control

Why sensor independence matters

If the SIS trusted the same diagnostics an attacker could spoof to fool the control loop, a single spoof could defeat both control and safety. Independent instrument channels mean an attacker would have to compromise two physically separate sensing chains to hide a limit violation from safety - a much higher bar.

Simplicity as a security property

The SIS logic is intentionally not an ML model or a general-purpose computer. It is small, deterministic, and formally analyzable, so its behavior under all inputs can be reasoned about. Complexity is where vulnerabilities hide; the safety layer minimizes it deliberately, in contrast to the model-rich control stack it guards.

Design status: the isolation architecture and one-way status feed are validated in the twin and bench rigs. The physically independent SIS hardware and its dedicated actuation are FOAK build scope; not yet operating on a reactor.

Content reviewed August 2026 · design-and-simulation stage