Control and Safety Architecture Overview
Kronos's safety architecture is layered defense: bounded reflex, hardwired interlocks, an ML-independent failsafe, and human oversight, each able to hold the line alone.
Layers that do not depend on each other
Safety at Kronos is not one mechanism but a stack of independent ones, ordered so that each can arrest a fault without help from the layers above. The design rule is that the most trusted layer is also the simplest and the least intelligent, because simplicity is what makes trust verifiable.
The layers, fastest and simplest first
- L1 reflex: bounded control laws + envelope clamps on FPGA, microsecond scale.
- Hardwired interlocks: permissives outside the software domain that gate all actuation.
- ML-independent failsafe: passive/analog trip to a defined safe state, no code required.
- Supervisory guardrails: L3/L4 envelope and authorization checks on proposed actions.
- Human oversight: operators with authority to abort, override, and grant exceptions.
The two machines share this architecture but instantiate it differently. The breeder (Hyperion) reflex tier emphasizes disruption mitigation and vertical stability; the burner (Aegis / MetroVolt) reflex tier emphasizes plug stability supervision and plug-coil overstress protection. Both share quench protection and vacuum interlocks.
Honest framing
These machines are design-and-simulation studies. Breeder construction begins Q2 2027 with first-of-a-kind first tritium targeted around 2030; there is no hardware net-gain claim before then. The safety architecture is being designed and validated in simulation and hardware-in-the-loop now, so that it is proven before it ever guards a real plasma. The burner in particular carries open physics gates — documented candidly across this category — that the safety layers are designed to respect, not paper over.
Read next: the defense-in-depth layering that formalizes independence, and the failure response decision table that maps faults to responses.