Independent verification of physical assets

A picture shows you a site. A record shows you what it is doing.

CZDTS reads the whole satellite record held for an asset, not the latest scene, and issues a dated statement of what it measured, with the uncertainty carried through, and a plain list of what it could not measure. It runs on free data by default, buys a capture only when a specific asset raises a specific question, and takes your own instrumentation into the same record.

One site, as the report renders it: eight tailings facilities at a working copper mine in Arizona, watched for 3.7 years.

Record read 22,108state rows Across eight facilities, from free radar and optical plus 106 interferograms.
Alarms raised 4in 3.7 yr In January, January, February and March, on downstream faces and a toe.
Alarm rate 0.14per facility, per year Over 29.6 facility-years. Nothing failed here in the window, so all four count as false alarms.
Detectability, simulated 11of 12, 19 d median Best of four injected signatures; the others score 10, 8 and 8 of 12. The 19 days runs forward from the injected onset, not back from a failure.
01 — What we read

The answer comes from the whole record, not the latest pass

Draw an area and the platform pulls the archives it has indexed for it, then keeps appending, and the statement prints which archives it read. At the Arizona site that came to 22,108 state rows across eight facilities in 3.7 years. Normal is defined by each facility’s own history, so the detector needs no failures to run.

WHAT ONE ANSWER IS BUILT FROMONE ARIZONA COPPER MINE · JAN 2023 TO SEP 2026A single imageone scene1Sentinel-2 optical10–60 m, 13 bands≤ 891Sentinel-1 radarall weather≤ 282PlanetScope3 m, validation only≤ 147Interferograms12-day chain, site-wide106202320242025202622,108 state rows across 8 facilities255 SERIES FITTED · 109 WITH r² AT OR ABOVE 0.5
Fig. 1  Ticks are drawn at even cadence, so no row should be read as continuous coverage. Counts are the highest per-facility totals in this build, not one facility’s tally, and they count archive records rather than distinct acquisitions. Coverage is uneven: one impoundment has no high-resolution scenes at all, and PlanetScope is research-licensed, so it feeds validation rather than the product.

Coverage differs by site and the statement prints the window it read. The earliest data anywhere in the platform is June 2018; the median area begins in 2024. An area with no usable imagery is reported as unobserved. We do not report it as unchanged.

A self-referenced check says a facility has changed. It does not say it was ever safe. A facility that has been degrading slowly since before its record begins carries that degradation inside its own baseline. So every invariant is marked in the statement as learned from history or taken from a design value, and where you supply a site plan the check runs against the design value instead.

02 — What we check

A short list of conditions that hold while a facility behaves normally

Each kind of asset carries its own list. For a tailings impoundment: the crest displacement rate in line of sight is not increasing, the pond is not growing beyond this facility’s own seasonal range, the minimum beach width is not reducing, no new wet area appears on the downstream face, and no new or expanding seepage appears at the toe beyond what the drains discharge by design. Each is tested separately against that facility’s own record, and the statement names the ones that could not be tested.

IMPOUNDMENT IN SECTIONTOE DRAINPHREATIC SURFACENOT OBSERVABLE FROM ORBIT12345PONDBEACHCRESTDOWNSTREAM FACETOE1Crest displacementrate not increasing,line of sight2Pond growthwithin this facility'sown seasonal range3Downstream faceno new wet area4Toeno new orexpanding seepage5Minimum beach widthnot reducing
Fig. 2  Each is checked on its own, which is what lets the report say which checks ran and which did not, rather than returning one score. Note what is drawn and not measured. The phreatic surface governs both toe seepage and liquefaction, and no satellite reads it at any resolution. Beach width is a planimetric distance measured at 10 m; it is not freeboard, which is a vertical distance the platform does not measure. Pond area is judged against this facility’s own seasonal history: there is no site water balance behind it, and pond depth and stored volume are not observable at any resolution. Crest displacement is line of sight from a twelve-day interferogram chain, so vertical and downstream components are not separated. The phreatic surface is drawn intercepted by a toe drain, as a facility of this type is designed to be. Section not to scale.
03 — What comes back

A dated statement, and what it could not measure

Every check returns one of four states. The last two are different problems with different answers.

Observed, within expectation

The check ran on this asset in this window and the state sits inside what the asset’s own history predicts. This is the only state in which an empty report means something.

Observed, outside expectation

Outside expectation past a stated threshold, held for a stated length of time. You get the alarm, the before and after, the series, and the run it came from.

Unobserved

The archive could not support the question this time: no scene, an incoherent interferogram network, no named control. A later pass or a tasked capture can fix it. No claim is made meanwhile.

Not observable

Outside the method at any resolution: the phreatic surface, pore pressure, internal erosion, drain condition, pond depth and stored volume, and the state of the tailings themselves. No satellite capture will answer these; an instrument will.

The distinction between the last two is the one that decides what to do next. The first is a gap you can close by spending money. The second is a gap you close by installing an instrument. Freeboard as an elevation sits between the two: it is not in the free layer, but a tasked stereo capture can return it, and the statement says which was used.

The numbers on the statement

A detection on its own cannot be underwritten, because nothing in it says how often the system is wrong. So each statement carries the state with its uncertainty, the alarm count with the exposure it was measured over, and the share of checks that could not be run. Uncertainty is propagated from each input stream; calibration against held-out ground truth is not yet demonstrated and is not claimed.

At the Arizona site the alarm rate is 0.14 per facility-year over 29.6 facility-years, with a 95% interval from 0.04 to 0.35. All four alarms fell in one winter window across different facilities, so they may be one weather event counted four times. We publish the interval because the point estimate on four events is not a precise number.

At a site with no recorded failure the statement reports detectability against injected onsets, and labels it as such. No lead time has yet been measured against a real failure.

04 — Escalation

Free by default. Sharper only when a question needs it.

The free layer is wide, continuous and coarse, and it carries the screening. When it raises something, a sharper capture or an independent one is a single order away. Where the sky cannot settle it at all, your own instrumentation joins the same record.

THE ESCALATION LADDER1 · Free archiveAlways on, every passSentinel-2, Sentinel-1, Landsat.NISAR and EMIT where they pass.under USD 0.01data cost per km², per year2 · Tasked captureOnly when a trigger firesa sharper picture, or an independentone the finding did not come fromfrom USD 16 for an archive lookUSD 675 to 4,830tasked, for the box as drawn3 · Your instrumentationWhen the sky cannot settle itpiezometers, prisms, drone orthos,operator records, ground truthno satellite costjoins the same recordEvery rung writes into the same asset record, on the same grid, with the licence and the cost recorded on the order.Nothing on rung 2 is bought without a person approving it: the auto-approve cap is USD 0 by default, including for free scenes.
Fig. 3  Rung one is cheap enough to run continuously across a portfolio, which is what makes rung two defensible: you buy a capture to answer a question the record has already raised. The order path is built and tested against both vendor APIs, but every run so far has been read-only and no capture has been purchased.

Choosing a capture means knowing who images the wavelengths in question, what they publish as a rate, and what minimum order they will bill you for. We keep that survey current and public: the Earth observation procurement reference covers the operating providers we have found across optical, radar, hyperspectral and thermal, alongside the free public missions and the zero-cost routes open to researchers, and it names the operators who publish no rates at all.

Customer observations are ingested against the same asset and the same run lineage, and are used for calibration and validation. Combining them with satellite evidence inside the state estimate is the open research problem, not a build task: no forward model of how facility state evolves transfers between sites, and when streams disagree those regimes carry no labels.

05 — Who buys it

Built for the adviser who has to sign it

Lenders, auditors and their technical advisers buy a single dated artefact on a named asset. The rows below that one are who else it serves.

BuyerWhat they buy
Lenders, auditors
and their advisers
A dated verification statement on one named asset. It says what was measured, over what window, with what uncertainty, and lists what could not be measured and why. Your adviser can reproduce any trigger in it from the API alone. Facility outlines are proposed from imagery unless you supply a site plan, and the statement says which it used. On a covenant date where a check comes back unobserved, the statement says so rather than reporting the asset as unchanged.
Operators and
Engineers of Record
An independent read alongside instrumentation, and the evidence trail conformance work needs. A statement issued against an outline proposed from imagery is a screening product and is labelled as one. Supply a surveyed outline and the statement records that it used it.
Registries
and regulators
A check on a declared value that does not depend on the declarer, with the observability limit stated beside every number.
Insurers Not yet. A parametric trigger needs a frozen index definition, a stated rule for what happens when a displacement epoch is unobserved, and a lead time measured against real events. We have the first, are working on the second, and do not have the third.
06 — Where the work is

Where the work has actually been done

Thirty-three invariants are declared in the specification, twenty-nine are implemented in code, and eight have been measured on a real asset. The engine can run the rest. It has not.

Asset familyExamplesMeasured on a real site
ImpoundmentTailings dams, ash ponds, evaporation and leach ponds8 of 8
ConveyanceCanals, pipelines, levees, diversion channels0 of 5
Field surfaceIrrigated land, plantations, managed rangeland0 of 5
ClosureCapped landfills, closed mine sites, remediated ground0 of 4
EarthworksEmbankments, cuttings, stockpiles, haul roads0 of 4
Managed systemWellfields, water networks, subsurface programmes0 of 4
Terminal and plantRefineries, tank farms, concentrators, data centre campusesdeclared only

A methane and emissions overlay is declared once and binds into subsurface risk and closure, rather than being an asset family of its own. Measured means a rule with a stated threshold produced a result on a real asset from real data.

07 — Provenance

Every number can be traced back to the run that produced it

Each statement records the data it used, the code version and the settings it ran under. Your own analyst can pull the same number back from the API and get the same value, whether or not it raised an alarm, for as long as your report is live.

Corrections are issued as new versions with their own identifier, and the original stays readable, so a figure quoted in a meeting last quarter can still be looked up.

Licence terms follow the data a run actually consumed rather than a label attached by hand, so a product inherits the most restrictive licence among its inputs, and where an input cannot be redistributed the statement says so.

08 — Contact

Name one asset. We will tell you what we can and cannot see.

Give us an area and the sentence you need to be able to write about it. We will come back with what the free archive actually holds for that ground and from when, which checks would run, which would come back unobserved, and which parts of your question are outside the method entirely. If the answer is that we cannot help, we will say so.

A centre point is enough to start. If you have something more exact, paste it: a bounding box as west, south, east, north, a GeoJSON polygon, or a WKT string. If the outline came from a site plan rather than from imagery, say so, because it changes what we can put our name to.
This opens your own mail client with the details filled in. Nothing is sent from this page and nothing is stored here.

Prefer to write it yourself? Email us directly. CZDTS LLC, Tempe, Arizona.