Open Source Safety Consortium

Safety-critical systems run on open source.

The assurance evidence to justify that has never been shared. We are building it in the open: hazard analyses, safety arguments, and qualification evidence for the open source components the industry already depends on.

The problem

Everyone qualifies the same components, separately, in private.

A robotics company qualifying a message-passing library for a safety-critical deployment does months of hazard analysis, test campaign design, and evidence assembly. So does the next company. And the next. None of them can see each other's work, none of it goes upstream, and the library's maintainers never learn what was found.

The result is an industry that spends enormously on assurance and accumulates almost nothing. The consortium exists to change where that work lands.

Principles

What the consortium commits to.

01

Evidence, not assertion

A component is safe for a use because someone can show the argument and the evidence behind it, not because it is popular, mature, or widely deployed.

02

Shared assurance artifacts

Hazard analyses, test evidence, and safety arguments are expensive to produce and wasteful to duplicate. Members publish them once, in a common form, for everyone.

03

Upstream first

Safety work belongs in the projects themselves. Findings, patches, and tooling go upstream rather than into private forks that decay in isolation.

04

Honest scope

Every artifact states plainly what it does and does not cover. An assurance claim without stated limits is not an assurance claim.

Members

Organizations building this together.

Member Two
Member Three
Latest

News

Robots & Startups covers the consortium

Andra Keay's newsletter reports on the consortium's first public introduction, at a Silicon Valley Robotics event in San Francisco on September 2, and repeats the call for members.

The first deliverable is a protective stop

The consortium's opening piece of work is the assurance case for an open source safety stop, a device still being built, with its evidence written in public alongside it.

Building something safety-critical on open source?

The consortium is open to organizations that build, deploy, or maintain open source software in systems where failure causes harm. Members produce assurance work as well as drawing on what the consortium publishes.