Independent verification of physical assets

A picture shows you a site. A record shows you what it is doing.

Most monitoring answers from one image, or from the latest pair. CZDTS answers from the whole archive: every usable pass since 2017, rebuilt into a per-asset history with calibrated uncertainty. It runs on free satellite data by default, buys a sharper or independent capture only when a specific asset raises a specific question, and takes your own ground instrumentation into the same record when the sky cannot settle it.

One site, exactly as the report renders it: eight tailings facilities at a working copper mine in Arizona, watched for nearly four years on free satellite data.

Record read 3.7years, 8 facilities Free radar and optical, plus 106 interferograms on a 12-day chain.
Alerts raised 4in 3.7 yr All wet-season events on downstream faces and a toe. The deposition cycling on the north impoundment never fires.
Alarm rate 0.14per facility, per year Two of those four alerts were on control facilities with nothing wrong with them. We count them.
Seepage onsets caught 11of 12, 19 d median From simulated onsets. Weaker signatures are mostly missed, and the report names which.
01 — What we read

The answer comes from the whole record, not the latest pass

Draw an area and the platform backfills the public satellite archive from 2017, then keeps appending. At one tailings site in Arizona that comes to 22,108 state rows across eight facilities in three and a half years, built from up to 891 optical passes, 282 radar passes and 147 high-resolution scenes per facility, plus 106 interferograms on a twelve-day chain. Nothing is answered from a single scene, because a single scene cannot tell you whether what you are looking at is unusual for this asset. Normal is defined by the asset’s own history, which means the detector needs no failures to run.

WHAT ONE ANSWER IS BUILT FROMJAN 2023 TO SEP 2026 · ≤ IS THE PER-FACILITY MAXIMUMA single image, or the latest pairwhat most tools read1Sentinel-2 optical10 m, 13 bands≤ 891Sentinel-1 radar10 m, all weather≤ 282PlanetScope3 m, validation only≤ 147Interferograms12-day chain, site-wide106202320242025202622,108 state rows across 8 facilities255 SERIES FITTED · 109 WITH r² AT OR ABOVE 0.5
Fig. 1  Ticks are drawn at even cadence. One tick is one pass, but the spacing is synthetic, so no row should be read as continuous coverage. Counts are the highest per-facility totals in the Pinto Valley build, not one facility’s tally — coverage is uneven, and one impoundment has no high-resolution scenes at all. PlanetScope is research-licensed and feeds validation rather than the product path, so the answer itself rests on the free streams. Window is January 2023 to September 2026. The point of the comparison is not that more data is better in the abstract. It is that a threshold on one image is a threshold against somebody else’s idea of normal, while a threshold on a record is one this facility earned.

One backbone, one engine, many verticals

A vertical is not a separate product. It is a trained model plus a trigger definition running on the same engine, over the same data backbone, producing the same four numbers. That is what makes a second vertical cheap and a claim about the first one checkable.

THE LOOP HOVER A STAGE A trigger that fires can carry a confirmation task — see §02 Draw an area any polygon, any asset backfill starts on creation Free archive S2 · S1 RTC · Landsat NISAR L-band · EMIT Engine features · assimilation state · calibrated uncertainty Vertical trained model + trigger definition Verification statement claim · evidence · confidence false alarm rate · manifest Matched controls assets that did not fail Your own data gauges · piezometers · polygons Hover or tab through a stage to see what happens there. Any polygon, any asset. The backfill starts the moment the area is saved, and a first time series appears within minutes. Sentinel-2 and Sentinel-1 from 2017, Landsat where the question needs it, NISAR L-band since 2026. Under one cent per km² per year. State and uncertainty against the expectation each asset’s own history defines — never against a global average or a neighbouring site. Thresholds, persistence requirements and error bars, trained once per family of assets and reused on every asset of that kind. Immutable, with the run identifier on every page. It states what could not be measured as plainly as what could. Assets of the same kind that did not fail. Running the identical detector over them is what produces the false alarm rate. A piezometer series or a patrol note is ingested as an observation on the same asset record, under the same run lineage.
Fig. 2  Chips land on a common 10 m grid in local UTM, so every asset in an area is measured the same way and a second vertical inherits the work of the first. Purchased and tasked data enter through the same contract as the free archive and are never fetched automatically. Customer observations are a source like any other: a piezometer series is ingested against the same asset, on the same run lineage, and is used for calibration and validation. Combining it with satellite evidence inside the state estimate is in build.
Free first
Sentinel-2, Sentinel-1 RTC, Landsat, NISAR L-band and EMIT carry the continuous layer. At 10 m, the data cost of watching a square kilometre for a year is under one cent. Commercial imagery is bought only when a question needs it.
One grid
Everything is chipped onto the area's own grid before anything is computed, so results are comparable across assets, across time and across verticals.
Lineage, not labels
Inputs arrive on different terms: free public archives, purchased scenes, and your own data. Every run records what it actually consumed, so what a result was built from is a query rather than a recollection. Most licences permit derived products, so this is rarely a constraint — it is there so the question can always be answered, and so customer data never ends up anywhere it should not.
One row, one number
Every figure a customer or an auditor sees traces to a single run record in one join, with input checksums, model version, code commit, image digest, parameters and seeds in the manifest.
02 — Escalation

Free by default. Sharper only when a question needs it.

The free layer is wide, continuous and coarse, and it carries the screening. When it raises something, two things make the answer firmer: a sharper picture of the same ground, and an independent capture that was not part of the record the finding came from. Both are one tasking order away. And where the sky cannot settle it at all, your own ground instrumentation joins the same record rather than living in a separate system. Three rungs, one lineage, and money spent only when a specific asset raises a specific question.

THE ESCALATION LADDER1 · Free archiveAlways on, every passSentinel-2, Sentinel-1, Landsat,NISAR L-band since 2026, EMITunder USD 0.01data cost per km², per year2 · Tasked captureOnly when a trigger firesa sharper picture, or an independentone the finding did not come fromfrom USD 16 for an archive lookUSD 675 to 4,830tasked, for the box as drawn3 · Your instrumentationWhen the sky cannot settle itpiezometers, prisms, drone orthos,operator records, ground truthno satellite costjoins the same recordEvery rung writes into the same asset record, on the same grid, with the licence and the cost recorded on the order.Nothing on rung 2 is bought without a person approving it: the auto-approve cap is USD 0 by default, including for free scenes.
Fig. 3  Most monitoring contracts start at rung two and bill for it continuously, whether or not anything is happening. Starting at rung one is what makes watching a thousand facilities affordable, and it is also what makes rung two defensible: you are buying a capture to answer a question the record already raised, not buying coverage in the hope that it raises one.
CONFIRMATION TASKING 1 · Free screening continuous, every pass data cost under USD 0.01 per km² · year 2 · Trigger fires one invariant, stated threshold and persistence requirement 3 · Alert and evidence chips before and after, series, manifest link, notification 4 · Quote attached live feasibility, and a price where the vendor publishes one 5 · A human approves auto-approve cap is USD 0 nothing is ever bought silently 6 · Task via SkyFi or UP42 Umbra · ICEYE · Capella · Vantor Satellogic · Airbus · Vexcel aerial 7 · Delivery chipped onto the same grid, licence recorded on the order 8 · Same evidence chain confirmation joins the run, the statement is reissued Two vendor contracts reach the constellations: SkyFi (Vantor, Planet SkySat, Satellogic, Umbra, ICEYE, SatVu, Constellr, OSK, Vexcel, GEOSAT) and UP42 (Airbus Pléiades Neo, Pléiades, SPOT, plus ICEYE, Umbra, Capella, BlackSky, Planet tasking).
Fig. 4  The auto-approve cap is the part worth reading twice. It is set to zero by default, so every order — including free open-data scenes — stops at the vendor's validate step until a person approves it. A monitoring platform that can spend your money on its own initiative is not a platform an auditor will accept. The order path is built and tested against both vendor APIs, but the live run over Pinto Valley was read-only: no capture has yet been purchased.

What a confirming capture costs

Live figures from a read-only availability run over Pinto Valley, a 148 km² box, across the previous 365 days. The search returned 535 archive offers and 53 tasking products, of which 16 were orderable as asked.

OptionResolutionIndicative costUse
Sentinel-1 & Sentinel-210–20 mfreeThe continuous screening layer. Always on.
Very-high optical, archive0.50–0.65 mfrom $16Cheapest look at what the site already looked like.
SPOT, archive1.5 mfrom $322Wide context around a firing.
Super-high optical, archive0.30–0.49 mfrom $399Reading a crest, a breach or a spill margin.
Umbra SAR, tasked0.25–1 m$675–3,250Confirmation through cloud and at night.
ICEYE SAR, tasked0.25–1 m$1,050–3,500As above, different revisit and look geometry.
Satellogic / GEOSAT, tasked0.5–1 m≈ $1,190A fresh optical capture of the box.
Vexcel aerial12 cm$2,024Where satellite resolution will not settle it.
Vantor 30 cm FlexView, tasked0.30 m≈ $4,830The most expensive answer, for the box as drawn.

Prices are what the SkyFi and UP42 APIs returned for that area and window, and will differ for yours. SkyFi returned 516 of the 535 archive offers and most of the listed tasking prices; UP42 tasking products quote rather than list, so they carry no headline figure. Orders carry a recorded margin and the licence chosen at purchase. Delivered scenes are chipped onto the area's grid and become inputs like any other, which means a confirmation is not a separate report but a new row in the same lineage.

Where these numbers come from

Choosing a confirming capture means knowing which operator images the wavelengths in question, what they publish as a rate, and what minimum order they will bill you for regardless of how small your area is. We keep that survey current and public: the Earth observation procurement reference covers every operating provider across optical, hyperspectral, radar and thermal, alongside the free public missions and the zero-cost routes open to university researchers. It states plainly which operators publish nothing, and where a figure came from a reseller rather than the operator.

03 — What we check

A short list of things that ought to stay true

Every kind of asset gets a short checklist: the things that ought to stay true if it is behaving normally. A dam crest should not be moving faster than it was. The gap between the water and the top of the dam should not be shrinking. Water should not be appearing on the outer face. We call these invariants, and each one is checked on its own, against what this asset’s own history says is normal for it.

IMPOUNDMENT IN SECTION · VERTICAL EXAGGERATED12345PONDBEACHCRESTDOWNSTREAM FACETOE1Crestis not settlingfaster than it was2Pond growthtracks thewater balance3Outer facehas no waterappearing on it4Toeis not seeping5Pond to crestis not shrinkingEach is checked on its own, against what this facility’s own history says is normal for it, not against an absolute value.
Fig. 5  An invariant is deliberately not a model of failure. It is a statement about the asset that an engineer would recognise and could argue with, which is what makes a trigger explainable after it fires. Checking each one separately is what lets the report say which checks ran and which did not, instead of returning a single score that hides the difference. Five of the impoundment archetype’s seven invariants are drawn; leach-pad solution outside the footprint and plant activity as context are checked but do not appear in section.

Invariants are archetype-specific but the shape repeats. A conveyance asks whether water is outside the prism and whether a segment is departing while its neighbours are not. A closure asks whether the cap is eroding and whether vegetation is failing to establish. The catalogue in §06 lists which are built.

04 — The product

Every vertical returns the same four numbers

Monitoring products usually report detections. Detections alone cannot be underwritten, because nothing in them says how often the system is wrong. These four travel together, per asset, in every vertical.

NumberWhat it isHow it is obtained
State with confidenceThe estimated condition of the asset now, as a distribution rather than a label.Assimilation over the observation record, with a per-stream error model.
Lead timeHow far ahead the trigger fired on events that actually happened.Replay against dated historical events recorded in the site specification.
False alarm rateHow often the same trigger fires on assets that did not fail.The identical detector run over matched control assets; alerts on controls are recorded identically.
Skill against persistenceWhether the model beats the naive assumption that nothing changes.Scored on the same record, so a model that only repeats yesterday is visible as such. Where a record is too short or too sparse to score it, the statement says so rather than reporting a zero.
Why this is the whole product

No self-serve or enterprise monitoring vendor we have found publishes a false alarm rate, an observability limit, or a calibrated uncertainty. The documented failure mode in the largest mandated market for satellite-derived estimates is precisely uncertainty in those estimates. An insurer, a registry or an Engineer of Record cannot act on a detection whose error rate is unknown, which is why the four numbers are the deliverable and the imagery is not.

05 — What we cannot see

When we cannot see, we say so

Suppose one of those invariant checks comes back with nothing to report. That can mean two very different things: the check ran and found nothing wrong, or the check never ran at all, because there was no usable satellite data that month. Most monitoring tools show you the same silence either way. We separate them, on every check, on every run.

SCHEMATIC — NOT A RECORDONE DEFORMATION INVARIANT, 45 MONTHSCZDTSthree states, alwaysA single-state toolalert, or silenceOBSERVED, WITHIN EXPECTATIONOBSERVED, OUTSIDE EXPECTATIONUNOBSERVEDSHOWN AS NOTHING TO REPORT
Fig. 6  Schematic, not a record. The grey months are the ones that matter: the archive could not support the question, so no claim is made. Collapsed into the bottom row they are indistinguishable from the months that were checked and found normal, which is how a monitoring record comes to look reassuring precisely where it is weakest. No alert month is drawn, because the argument here is about silence rather than alarms; the measured rate at Pinto Valley is 0.14 alarms per facility-year across all seven invariants.

Observed, within expectation

The invariant was measurable on this asset in this window, and the state sits inside the expectation the asset's own history defines. This is the only case in which silence means anything.

Observed, outside expectation

Measurable, and outside expectation past a stated threshold that has held for a stated length of time. You get an alert, an evidence pack of before and after images, the series, and a link to the manifest.

Unobserved

The archive could not support the question: no scene, an incoherent or disconnected interferogram network, an unmeasured unit, no named control. No claim is made, and the statement says which.

This is enforced in the engine rather than left to good intentions. A check with no data behind it is shown as unmeasured, never as a flat line at zero. Where a site has no comparable asset to measure it against, the report says so and substitutes nothing.

06 — Catalogue

Six archetypes built, one declared

An archetype is a family of assets that share a physics and a set of invariants. Trained once, it applies to every asset of that kind an area contains.

ArchetypeWhat it coversInvariantsState
Tailings & impoundment integrityTailings dams, ash ponds, leach and evaporation ponds, water dams, lagoons. Pond encroachment and growth, face wetness, toe seepage, crest movement.7 of 7Built
Corridor & conveyance integrityCanals, pipelines, levees, penstocks, embanked rail and road. Water outside the design prism, one segment departing while its neighbours do not, outer slope wetness, movement at a crossing.5 of 5Built
Subsurface & surface riskDisposal clusters, well pads, geothermal, brine and groundwater basins. The premise is that a subsurface programme should leave no surface expression: deformation rate and its change, a new water body, an expanding scar, a new depression, a plume persisting past its clock.5 of 5Built
Closure & post-closure assuranceClosed impoundments, landfills, capped remediation, legacy mine ground, plugged well sites. Ponding on a cap that should shed water, cover loss beyond its seasonal band, settlement beyond the consolidation curve, a seep at the toe. The payers are bond holders and long-tail liability holders.4 of 4Built
Construction progress assuranceAirports, dams under construction, tailings raises, highway packages, data centre builds. A package outside its planned envelope, clearing beyond the permitted boundary, offsite sediment. Without a milestone plan there is nothing to test against.4 of 4Built
Operating rule & project conformanceReservoirs, irrigation districts, wetland and blue carbon projects, forest concessions, recharge basins. Water outside the rule band, project conversion, survival shortfall, leakage in the belt. The design document is the rule curve.4 of 4Built
Terminal & plant conformanceRefineries, tank farms, LNG, chemical plants, concentrators, data centre campuses. Liquid inside a containment bund, an activity index departing while operations are declared normal, a new discharge outside the perimeter, a flare or thermal anomaly. Declared but not built: no site has been chosen, so nothing is trained or validated.Declared
Overlays, and where methane lives

Some signals cut across several families and are declared once rather than rebuilt in each. The emissions overlay is the first: plume detection, attribution to a registered asset, rate estimation and the regulatory clock are common machinery, while what a plume means depends on the asset under it. It binds into subsurface risk, where a plume persisting past its clock is one of the five invariants, and into closure, where it has been run against the free Carbon Mapper catalogue over an oil and gas county. Thermal and flaring, and water quality, are the same shape and follow later.

Seven families, and twenty-nine verticals classified across them. A vertical is the thing that is actually sold: one asset family, one set of checks, one trained model. Release v0.20.0; backend suite 1,158 passed and 4 skipped, API suite 232 passed.

07 — What you receive

A console, a statement, and an API that answers the same way

The front end never computes. Every number on screen is a row the engine wrote, and the same rows are what the API returns and what the statement prints, so a figure quoted in a meeting and a figure pulled by a partner's application cannot disagree.

Area console
A page per asset showing the state with its interval, the fitted series, the invariant table marked observed or unobserved, and every product available to download. An invariant with no row is rendered as unmeasured, not as a flat line at zero.
Verification statement
A PDF carrying the claim, the evidence, the method version, the confidence, the false alarm rate, the manifest hash and the licence chain, with the run identifier on every page. Immutable: a correction is a new run, never an edit.
Alerts with evidence
When a trigger fires you get the alert row, an evidence pack of before and after chips with the series and a manifest link, and a notification by email or webhook. Acknowledgement is recorded with the user and the time, so the audit trail includes who saw it.
API
Areas, assets, catalogue with licence, per-asset time series with uncertainty by vertical and model version, triggers, alerts, products and orders. A partner application can reproduce any published trigger from the API alone.
Exports
GeoJSON, CSV and GeoPackage. Each carries the same run identifier as everything else in the chain, so an export can be traced back to the observations behind it.
Your data stays yours
Customer rasters, vectors, tables and feeds are processed for your product and your validation only. They are never used to train another organisation's model unless you explicitly opt in, and organisational isolation is enforced in the database rather than in application code.
08 — Provenance

Every number is reproducible or it is not published

LINEAGE Chipitem licence, checksum Cube & featuresregenerable, versioned Modelweights, card, metrics Runcommit, image digest, seeds Productimmutable, run id on every page TERMS DERIVED AT EVERY STEP — an output inherits the terms of the inputs its run actually read, so what may be done with it is computed rather than asserted.
Fig. 7  A corrected deliverable is a new run, never an edited one. The manifest records input checksums, feature versions, model version, code commit, image digest, parameters, seeds, freeze date and prediction hashes, so a result is rebuildable on a clean machine to the same metrics within tolerance.
09 — Who this is for

The customer is whoever bears the cost when a trigger fires

Operators already have dashboards. What they do not have, and what everyone downstream of them needs, is an assessment that does not come from the party being assessed.

Insurers & reinsurers
Portfolio-scale condition and basis-risk reduction on parametric and indemnity covers, from a source with a published false alarm rate and no interest in the outcome.
Lenders & auditors
Independent evidence for diligence, covenant monitoring and conformance audits, with a lineage chain that survives being asked where a number came from.
Registries & regulators
Verification of claims made by the regulated party, at a cost per asset that makes checking all of them feasible rather than sampling a few.
Operators & Engineers of Record
An outside instrument alongside the internal one, and the conformance evidence an Engineer of Record has to produce anyway.
10 — Contact

Send us an area and a question

The useful first conversation names one asset and one thing you currently cannot see about it. We will tell you whether the free archive can answer it, what the confirmation would cost if it cannot, and what the four numbers look like for that class of asset today.