Fihan Systems

Autonomy is easy to build. Autonomy you can sign off on is not.

We build the layer that decides what an autonomous system is allowed to do. For robots, that means a safety filter between the AI and the wheels. For AI agents, it means an enforcement gate between the model and your tools. Both are deterministic, both run on your own infrastructure, and both leave evidence behind.

Built for compliance

Fihan Edge is engineered toward the standards a safety reviewer actually asks for — not bolted on after the fact.

IEC 61508
SIL-2 target across the safety-layer control loop
ISO 3691-4
Safety requirements for AGVs operating around people
DO-178C
Design assurance practices carried over from avionics
Rust runtimesOn-device AIWorks offlineBuilt for safety standardsNo cloud lock-inDefense & industryMade to be auditedRust runtimesOn-device AIWorks offlineBuilt for safety standardsNo cloud lock-inDefense & industryMade to be audited
Products

Two systems. One idea.

A capable model proposes; a simple, predictable component disposes. That is the shape of both products — one for machines that move, one for agents that act.

Tell us which world you work in, and we'll put the right product — and the right detail — in front first.

Robotics · Physical autonomy

Fihan Edge

Robots that move fast and stay safe around people.

Fihan Edge gives autonomous robots the judgement to navigate busy, unpredictable spaces — with a dedicated safety layer that checks every move before it reaches the wheels.

  • Perception and control on-board, no cloud
  • An independent safety check on every movement
  • Built toward IEC 61508, ISO 3691-4, DO-178C
Explore Fihan Edge
AI security · Agent autonomy

Interocept

AI agents that can act — without acting against you.

Interocept reads an agent model's internal state to detect prompt-injection exposure, then gates every tool call through a deterministic, fail-closed enforcement layer that writes a hash-chained audit record.

  • Detects injection exposure from activations, not output text
  • Fail-closed gate on destructive and egress tool calls
  • Hash-chained audit trail a SOC can work from
Explore Interocept
The thesis

Never let the smart part have the last word.

A learned model is the right tool for understanding a messy world, and the wrong tool for guaranteeing anything about it. So we split the two jobs apart.

In the physical world

Between the policy and the wheels.

A trained policy decides how the robot should move. Before that command reaches a motor, an independent safety layer checks it against the space around the robot and slows or stops it if the move would come too close. The policy cannot skip the check or overrule it.

In the digital world

Between the agent and your tools.

An agent decides which tool to call. Before that call reaches a database, an API or the open internet, an independent gate scores the model's internal state and applies a threshold set by how destructive the action is. The agent cannot talk its way past it.

How we build

What both products are held to.

Deterministic when it counts

The component that says yes or no is simple, bounded and predictable. Same input, same decision, every time — which is what a safety reviewer or a security auditor actually needs to sign off on.

Runs on your infrastructure

Everything runs on equipment you own and control, with no dependence on an outside cloud service. It keeps working when the network doesn't.

Evidence, not assertions

Every decision is recorded in a tamper-evident trail that can be reviewed after the fact. Nothing important happens inside a black box.

Which one is your problem?

Tell us what your system does and where it operates — a robot on a warehouse floor, or an agent with credentials and a tool list. We'll tell you plainly whether we can help.