Command that survives uncertainty
OperationalAutonomy
Navigation, decision and doctrine, built as one system.
Built for the environments autonomy will actually face, where position degrades, links disappear, and every action still needs a reason.
Karta, written across Indian scripts.
Name / the one who acts
Karta - the one who acts, and answers for it.
The machine acts; a human answers. The record is designed to show why.
One sortie / plan to proof
When the plan breaks, intent must still hold.
A clear corridor can become a denied environment in minutes. GPS disappears. The command link drops. Other aircraft enter the route.
Operational autonomy must keep the system oriented, limit every next action to approved intent, and preserve a record of what happened.

01 / The brief
A route, an objective, and an operating envelope. Every condition appears knowable.

02 / Contact with the field
Conditions change. The system must stay useful without inventing authority it was never given.
- 01
Position source lost
Estimate pose with calibrated uncertainty, then expose the confidence downstream.
- 02
Command link lost
Continue only inside the intent and constraints approved before the link disappeared.
- 03
Airspace congested
Resolve the next safe action and preserve the reason in the flight record.
The operating requirement
Position with uncertainty. Decisions within bounds. Doctrine visible in the flight record. All three must work as one system.
Product / operational stack
One stack. Three responsibilities.
Position with uncertainty. Adapt decisions within approved intent. Return a record that shows why. Each layer is useful alone and stronger as part of one accountable system.
L1 / Edge layer
SkyAnchor
It knows where it is, and how sure it is.
SkyAnchor runs as a single deterministic process on-vehicle. There is no cloud, no model download, no online learning. The fusion is exposed as a service with explicit confidence intervals, so downstream consumers can reason about pose uncertainty instead of pretending it doesn't exist.
Capabilities
- Visual-inertial odometry with multi-camera support
- Terrain-relative navigation against on-board map tiles
- Bounded drift on terrain-relative fix
- Bounded behaviour as confidence degrades
- Deterministic - no online learning in the flight loop

Positioning designed for GNSS denial. Terrain-relative, visual-inertial, sealed.
01L2 / Command layer
TENERE
It knows what to do next, within approved intent.
TENERE is a constraint solver wrapped in an editor. Operators express what they want as bounded intent; TENERE deconflicts, plans, and runs the sortie graph. Every action is reversible. Every decision the operator did not see was provably out-of-scope of what they asked.
Capabilities
- Mission graph composition with explicit bounds
- Multi-vehicle deconfliction at composition time
- After-action telemetry and decision audit
- Doctrine-aware planning surface operators can read and edit
- Designed for multi-vehicle command within approved bounds

Mission composer. Prioritises the next action across vehicles.
02L3 / Theatre layer
Kiksuya
It remembers why an action was allowed.
Kiksuya is a runtime that takes operator intent and a published doctrine, and produces an executable plan annotated with which doctrine clauses authorise which step. The annotation is logged alongside the telemetry stream, federated across echelons, and survives the sortie. Doctrine becomes a property of the running plan, not a checkbox on a slide.
Capabilities
- Doctrine encoded as versioned, signed policy
- Per-action authority audit trail
- Plan-level dry-run with explicit clause attribution
- Federated memory across echelons and bases
- Traceability designed to reach from authorization to flight record

The memory layer. Doctrine, audit and cross-echelon coordination.
03Intent goes down. Situation and record come back.
The autonomy loop is a four-step circuit. It begins when an operator expresses intent. SkyAnchor surfaces the situation. TENERE adapts the mission. Kiksuya records why each action was allowed. Then, audit becomes the next intent - the loop runs again.
The loop is not closed until the record returns.
T+01:20:00 / THE MISSION
Autonomous systems are arriving. They must be bounded.
Karta exists because the autonomous future is arriving whether we participate or not. The choice is not whether autonomous systems fly. It is whether they fly under doctrine that is auditable, constrained, and built for the field they will see.
We are not building one category-leading vehicle. We are building the operational autonomy layer underneath autonomous systems, the navigation, decision and integration stack that turns hardware into a safe, auditable teammate.
Bounded autonomy
Every autonomous action is constrained by an operator-approved doctrine. The system surfaces what it cannot do as clearly as what it can.
Integration discipline
Hardware, software, doctrine and sustainment are one product. We do not ship anything we cannot maintain in the envelope it will fly.
Audit by design
Every decision the system makes is logged at telemetry-frame granularity. After-action review is not a feature - it is the substrate.
Allied-export discipline
Engineered for the doctrines we ship under, with export pathways consistent with allied use only.

Built close to the work.
Engineered, integrated and flown from Hyderabad. The team that builds the code is the team that deploys it, close to the aerospace, semiconductor and defence-software expertise we draw from, and close to the fields where the systems will operate.
T+01:42:00 / WHEELS DOWN / SORTIE COMPLETE / RECORD SEALED / READY FOR REVIEW
Operational autonomy: command that survives uncertainty - and returns a record you can review.