SafetyOps

Pitch 47 · Robot Skill Release Gate

SafetyOps

机器人不是训练完就上线。SafetyOps 让每次模型、技能、远程协助和 OTA 变更都有权限、ODD、安全包络、Qualcomm edge profile、SBOM/VEX、事故回放、回滚和客户/保险/审计证据。

01 · Problem

企业不是怕机器人不聪明,而是怕策略不可控。

Demo 阶段只要机器人能动;生产阶段必须回答:谁批准了这个技能?它能控制哪些传感器、执行器、ROS/DDS topic?远程接管是谁批准的?事故后如何证明版本、命令、传感器状态、人工接管、停机和回滚?

Change

事故常发生在变更时刻

编程、维护、测试、调试、路线变更、模型升级和人工 override,是企业最需要证据的环节。

Permission

技能边界不清

一个技能到底能读哪些传感器、写哪些 topic、控制哪些执行器、在哪些区域运行,经常留在文档里。

Remote

远程接管缺责任链

客户需要知道谁接入、为什么接入、允许哪些命令、持续多久、是否录像、能否紧急撤销。

Release

模型上线缺门禁

数据集、评测、HIL、replay、QNN profile、机器人 profile 和 rollback 目标没有绑定成一个 release record。

Liability

保险和客户要事件链

事故后需要证明版本、权限、传感器状态、命令、停机、人工接管和恢复动作。

02 · Current Alternatives Fail

现有工具都重要,但没有把模型变更、远程接管、现场命令、事故证据和回滚串成产品链路。

SafetyOps 不替代 Safety PLC,不替代认证实验室,也不替代 Formant、InOrbit、Foxglove 或 OT security 工具。它把 release gate、command authorization、SBOM/VEX、incident replay 和客户审计包连接起来。

Safety PLC

认证安全控制器保护机器和产线,但不记录 AI model lineage、dataset、QNN profile、skill approval 或 remote-assist session。

PDF / Spreadsheet

风险评估材料能支撑交付,但部署后跟不上模型更新、OTA、site config、漏洞处置和 incident replay。

Fleet Ops

Formant、InOrbit、Viam 和 OEM clouds 管 fleet,但不是以 release gate、权限和 standards evidence 为核心。

Robot Logs

Foxglove、MCAP、ROS bag 很适合调试,但还需要 approval、permission、rollback、chain-of-custody 和客户摘要。

Cyber / GRC

OT security、SBOM、AI governance 能回答一部分风险问题,但不回答 learned policy 是否应该移动 actuator。

03 · Solution

SafetyOps 是 robot skill release gate + remote-assist evidence governance。

每个技能上线前必须声明 permissions、ODD、model evidence、Qualcomm edge profile、SBOM/VEX、approvals、canary scope 和 rollback target。运行时,边缘 agent 做 command admission、boundary monitoring、incident capture 和 rollback proof。

Declare

技能声明 sensors、actuators、ROS/DDS allow-deny、ODD、risk level 和 rollback target。

Evaluate

绑定 dataset hash、eval split、HIL clips、replay regressions、SBOM/VEX 和 AI Hub/QNN profile。

Approve

safety owner、fleet admin、site owner 对 remote assist、canary scope 和 rollout gate 签名。

Enforce

边缘 safety-agent 阻止 raw command、越界速度、禁区、传感器失效、延迟异常和未授权远程动作。

Replay

事件进入 MCAP ring buffer、access evidence、incident ledger、rollback record 和 LeRobot/HIL 数据队列。

No cloud in the safety loop. SafetyOps 支持证据、策略、监测和有限 command admission;认证安全功能仍属于机器人 OEM / integrator 的本体安全架构。

机器人技能发布门禁、安全运行时、审计账本和回滚控制台

04 · Why Now

机器人规模、AI 策略更新、监管周期和远程运维同时把 release gate 变成刚需。

机器人已经进入客户现场,skill 更新越来越快,EU Machinery Regulation、EU CRA、ISO 10218:2025、NIST OT/Zero Trust、IEC 62443 和中国 GB/漏洞规则都在把软件更新、远程接入、网络安全和证据留存推入采购语言。

542K IFR 2025:2024 年全球工业机器人新增安装约 542,000 台。
200K 2024 年专业服务机器人销量接近 200,000 台,RaaS fleet 增长 31%。
2026-09-11 EU CRA vulnerability / incident reporting obligations 开始适用。
2027-01-20 EU Machinery Regulation 开始适用,technical documentation 和 software safety evidence 更重要。
OT 机器人 fleet 是 cyber-physical OT system,不是普通 IoT dashboard。

05 · Product

第一版只做一个强 wedge:Skill Release Safety Gate。

SafetyOps 不做认证机构。它交付的是 safety-case workflow:让 robot OEM、SI 和企业客户把每次 robot/model/skill/remote-assist change 变成可追踪、可审批、可回滚、可导出的证据包。

  • SkillManifest:权限、ODD、安全包络、known limitations、rollback target。
  • ReleaseGate:dataset hash、eval、HIL、replay、AI Hub/QNN profile、approvals、canary rules。
  • RemoteAssist:JIT access、MFA、command scope、TTL、dual approval、break-glass reason。
  • SafetyAgent:观察 ODD、sensor health、thermal、network、QoS、E-stop 和 QNN runtime。
  • EvidenceVault:signed logs、MCAP/video ring buffer、access decisions、SBOM/VEX、incident timeline。
SafetyOps 技能权限卡、发布门禁、事故账本和审计包导出

06 · Product API/Evidence

安全不是一个 checkbox,而是一组版本化 artifact。

所有 release 都绑定 skill manifest、dataset hash、edge profile、approvals、remote-access policy、runtime command decision、SBOM/VEX、incident ledger 和 audit pack。ROS policy 是软件 guardrail,不是 Safety PLC。

SkillManifest

skill_id、risk_level、sensors、actuators、ROS allow/deny、ODD、rollback target。

ReleaseGate

dataset_hash、success_rate、intervention_rate、replay regressions、approvals、decision。

EdgeProfile

AI Hub job、target device、QNN runtime、latency p95、memory、compute units、fallback status。

AccessSession

operator、MFA、device posture、allowed commands、expiry、approver、session recording pointer。

SBOM / VEX

firmware、container、ROS packages、edge agent、operator app 的组件清单和 exploitability status。

AuditPack

buyer pack、judge pack、insurer pack、standards map、claim boundaries、data lane summary。

API

Command authorization

POST /v1/robots/{id}/commands:authorize 用 robot state、operator scope、ODD 和 runtime policy 决定 allow / deny。

API

Cyber posture

GET /v1/robots/{id}/cyber-posture 返回 firmware、containers、cert age、open CVEs、VEX status 和 remote access state。

API

Evidence export

POST /v1/incidents/{id}/evidence-pack 导出 timeline、logs、SBOM/VEX snapshot、access sessions、hashes 和 custody。

07 · Market & Business Model

卖给 OEM 的是更快进 pilot;卖给企业的是更少部署风险;卖给保险/RaaS 的是可核验风险证据。

第一批买家是正在从 demo 走向付费 pilot 的机器人 OEM、RaaS operators、系统集成商和企业自动化团队。SafetyOps 帮他们减少 release review 时间、降低 warranty/SLA 争议、生成 insurer-ready evidence,并让客户验收更快。

Buyer

Robot OEM / RaaS

CTO、VP Safety、VP Product、customer success,需要证明每次技能更新、远程接管和事故复盘。

Buyer

Enterprise deployer

EHS、automation engineering、OT security、legal/risk、procurement 需要责任链和验收证据。

China

机器人事故黑匣子

人民币 50k-150k / site-year + 50-200 / robot / month,强调 GB/T readiness、数据驻留和私有化。

Global

Compliance-ready evidence

$25k-$100k / site-year + $20-$100 / robot / month;formal release pack 和 insurer/RaaS API 另收费。

08 · Competition & Moat

竞争证明需求真实,但 SafetyOps 的位置在 physical AI release evidence。

FORT、3Laws、Veo、NVIDIA Halos、Formant、InOrbit、Foxglove、Viam、Safety PLC vendors、AI governance 和 SBOM vendors 都解决一层。SafetyOps 的 wedge 是 robot skill release gate、remote-assist responsibility chain 和 cross-OEM safety event schema。

Safety Event Schema

跨 OEM 记录 skill、ODD、command、policy denial、QNN profile、incident、rollback 和 warranty evidence。

Hazard / Skill Library

dock assist、pick、carry、clean、patrol、elevator、charging 等技能沉淀权限和安全包络模板。

Remote Evidence Vault

operator identity、MFA、command scope、session recording、break-glass、vendor access 和 revocation 形成责任链。

Insurer Risk Ledger

版本、地点、触发、停机、人工接管和恢复形成 underwriting / claims 可读的风险图谱。

09 · Why Qualcomm

Qualcomm 不只需要机器人跑 AI,还需要 AI 策略能被批准上线。

SafetyOps 把 Qualcomm edge 从推理目标升级成 physical AI release target:每个模型都有 AI Hub/QNN profile、runtime artifact、latency/memory、numeric delta、fallback status、rollback 和 incident evidence。

Profile

AI Hub / QAIRT / QNN profile 进入 release gate,不再只说 TOPS 或 demo FPS。

Sensor Trust

Dragonwing target 记录 camera health、frame age、thermal、power、network、QoS 和 sensor confidence。

Identity

device identity、secure boot、OTA、key management 和 signed logs 支撑 edge evidence custody。

Rollback

release manifest 绑定 previous-known-good,事故时一键停用和回滚。

Ecosystem

DragonWorks、EdgeRuntimeBench、SkillCertKit、SkillDock、EdgeFleet 串成完整 Qualcomm edge AI lifecycle。

10 · Demo & Ask

八分钟演示:dock-assist-v2 被门禁拦截、限权上线、触发 incident、再回滚。

比赛 demo 可以用桌面 AMR/机械臂模拟器:上传新技能,缺少 human-proximity eval 被挡住;补上 HIL/replay/QNN/SBOM/VEX 后只允许 canary;运行时 raw /cmd_vel 被拒绝;人进入 keepout zone 触发停机、replay、回滚和 audit pack。

1. Gate

技能卡显示 sensors、actuators、ROS allow/deny、ODD、risk、rollback target 和 missing evidence。

2. Access

JIT remote-assist session 显示 operator、MFA、command scope、TTL、approver 和 recording pointer。

3. Profile

发布门禁读取 dataset hash、replay pass、HIL clips、AI Hub/QNN latency、memory、fallback status。

4. Incident

canary 部署后,unsafe raw command 被拒绝;keepout 或 QoS 事件触发 slow/stop 和 incident ledger。

5. Rollback

打开 MCAP replay,失败片段进入 LeRobot/HIL 队列,一键回滚并导出 judge-audit-pack.zip。

我们的申请:请 Qualcomm 提供 RB3/QCS/IQ target guidance、AI Hub/QNN office hours、device identity / secure lifecycle 建议和 1-2 个 OEM/SI 试点引荐。我们交付一个从技能提交、边缘评测、远程接管、运行时拦截、事故回放到审计包导出的 Qualcomm-first reference demo。

SafetyOps 不声称 certifies robots,不保证 safety,不替代 safety PLC、E-stop、scanner、STO、risk assessment、notified body、TÜV/UL/Intertek 或法律合规审查。它卖的是 audit-ready release evidence:让每个机器人技能在上线前后都有权限、边界、评测、远程接管记录、运行时证据、回滚和审计包。