The night the embankment gave way
The scene that follows is illustrative. It describes no real agency, place or event.
A river has broken through an embankment after three days of rain. A disaster-response cell has an operations room for the night: a duty officer, the flight director for an imaging satellite the cell can task, a drone team with a pilot in command, and an analyst. The request is one sentence: image the embankment on the next pass, then fly an inspection of the breach.
The satellite will be overhead for a few minutes. The room's network does not reach the internet, and nobody wants tonight's imagery on someone else's servers. Every step will be taken by someone with a name, because tomorrow somebody will ask who decided what, and on what.
The room is not short of intelligence. It is short of time, and it needs a record.
One request, seven steps
Each step names the part that does the work. Mission control is the ordinary name for a room like this one.
1 · The sentence becomes one command, or none
Tatva Edge turns a typed or spoken instruction into exactly one spacecraft command, or no action if it is not a spacecraft command. It does not write free text: the only possible outputs are a valid command with named arguments or an explicit NO ACTION.
2 · A policy outside the model checks it
Kavach, a policy engine outside the model, checks the candidate command against geometry, envelope and permissions the model cannot talk its way around.
3 · The flight director approves the uplink
Tatva never uplinks on its own. The flight director approves every command before it is sent.
4 · The imagery is listed, and the analyst decides
Drashta reads satellite and aerial imagery offline and hands the analyst structured findings to review: what it found and where. Today it finds and lists objects such as structures and aircraft. It does not map water or measure a breach; the analyst does that, and decides what a finding means.
5 · The inspection flight is tasked the same way
An operator's instruction becomes exactly one flight command, such as survey this block or return home, or no action if it is out of scope. The policy checks it against the mission's rules and the pilot in command approves anything consequential. The aircraft's own autopilot flies it.
6 · A warning before the failure
Sanjaya is fleet and telemetry intelligence: battery, link and subsystem health watched across the fleet, with a warning before a fault takes a machine out of service. What we show of it is a demonstration: a satellite pass replayed from public spacecraft telemetry, and recorded output in a simulated drone scene. In Launch Watch the early warning is a labelled rule, not a model.
7 · The record
Every proposal, policy check and approval is written to a signed, hash-chained receipt that can be verified offline, later, by someone else: what was asked, what was proposed, what the policy said and who approved.
What the platform is doing underneath
The seven steps are one pattern, and the platform page states it for this kind of room: the agent recommends, a policy outside the model blocks what must never happen, a named controller approves.
It deploys inside the perimeter. AgentAnywhere Swaraj is the sovereign deployment of the platform. For the highest-classification environments it ships as a fully offline package, with an offline model registry, a manual update workflow and physical media support.
Approval is a step in the flow, not a habit. In Flow Studio an approval is a checkpoint with an explicit queue, named approver groups, escalation rules and SLA timers, and the approval state lives in the run record.
Nothing runs unowned. The Registry keeps every agent, flow, prompt, model and policy under a named owner, an approval workflow and a cryptographically chained record. A policy update is a release, with an approval, a diff and a rollback.
The record is built to be checked by someone else. A Trust Receipt is an Ed25519-signed, offline-verifiable record. Receipts are chained: change one character and every receipt after it fails verification. The Trust Center describes them.
Launch: what the demonstration shows, and what no model does
A satellite's working life starts at a launch, so one of our demonstrations starts there. Launch Watch, on our demo hub, follows a fictional civil orbital launch from the count to payload separation. An early warning flags a reading that is trending the wrong way, and the launch director approves a hold and then the resume. After separation a spacecraft controller commands the satellite in plain words, and a signed report closes the mission: change one word in it and the chain breaks.
Read the labels as carefully as the demonstration. The launcher, the pad, the flight, the satellite and every telemetry reading are simulated and fictional. The early warning is a simple trend rule, labelled as a rule, not a trained model. The satellite command outputs are real recorded model output, replayed unchanged.
Tatva and Sanjaya never arm, ignite, steer, stage or terminate a launch vehicle. Flight termination and range safety stay with the range's own certified system. No model commands the launch vehicle, and there is no launch-vehicle command set. The launch-vehicles page says the same.
What you can see today
The demo hub is behind sign-in. Ask us for access, or for a walkthrough on your own mission profile.
In the demonstrations
Tatva Ops Console. Speak a spacecraft command and the command model emits the exact command or refuses. It runs at a ground console, not on a spacecraft.
Drone Mission Ops. Three missions, a solar-farm inspection, a search-and-rescue sweep and a perimeter patrol, where you approve or reject each recommendation and then verify the signed receipts yourself. Flights are simulated; the policy, referee and receipt code is real.
Launch Watch. One fictional civil orbital launch, as described above.
Built with design partners
Running Tatva Edge on board a spacecraft. Today's command demonstration runs at the ground console.
Integration with specific airframes and flight controllers, and perception on the aircraft itself.
Launch-side work with Tatva and Sanjaya. Sanjaya and Drashta are engaged through design partnerships.
The same chain, for defence and security teams
Proposal, check, approval, record: this is what defence and security teams ask of any system that comes inside the perimeter, and it is the same chain. The model proposes, a policy outside the model checks, a person approves what matters, and every step is signed.
One line shapes everything else: no targeting, no weapons release, no autonomous engagement.
Specifics for defence and strategic users are not published on a web page. If that is your organisation, contact us and we will take it from there, under the agreements your programme requires.
Which rules apply, and where the platform helps
Indian rules only, one row per text, as read on 8 October 2026. The second column says whom the text addresses.
| The rule | Who the text addresses | What it asks for | Where the platform helps | What it does not cover |
|---|---|---|---|---|
| The rule: Drone Rules, 2021, as amended: rules 2, 6 and 14 and the airspace zones 1 | Persons owning or operating an unmanned aircraft system in India. Under rule 2(3) the Rules do not apply to one belonging to, or used by, the naval, military or air forces of the Union. | Conformity to a type certificate unless exempt. Registration on the digital sky platform with a unique identification number. In a yellow zone, permission from air traffic control; in a red zone, operation only as the Central Government permits. | The policy check outside the model is where a mission's geometry and envelope limits are applied to each proposed command before the pilot approves, and the receipt shows who approved. | Registration, type certification, the pilot's qualification and every airspace permission, which are the operator's. The platform applies the limits the operator gives it; it does not hold the official airspace map or any permission. |
| The rule: Indian Space Policy 2023, sections 5 and 9 2 | Any space activity to or from Indian territory or within India's jurisdiction, by government entities and non-government entities. | IN-SPACe is the single-window agency that authorises, among other things, operating space objects, launch, satellite control centres and data reception stations. Its authorisation is required to disseminate earth-observation data at a ground sampling distance of 30 cm or finer; coarser data is intimated to it. | It does not obtain any of these. A signed record of which command was approved by whom may be useful in the operator's own procedures. | Every authorisation, which the operator holds. |
| The rule: Guidelines for acquiring and producing Geospatial Data and Geospatial Data Services including Maps, Department of Science and Technology, 15 February 2021 3 | Anyone acquiring, producing or holding maps and geospatial data of India. | Data finer than one metre horizontally or three metres vertically may be created and owned only by Indian entities, and must be stored and processed in India, on a domestic cloud or on servers physically in India. A negative list of sensitive attributes is regulated. | The platform and the models run on hardware you control inside your perimeter, so imagery is read where it is held. | Who may own the data, the negative list, and any licence. |
| The rule: Digital Personal Data Protection Act, 2023, sections 8(5) and 17(2)(a) 4 | Data fiduciaries. Under section 17(2)(a) the Act does not apply to processing by an instrumentality of the State that the Central Government notifies in the interests of, among other things, the security of the State. | Of everyone else, reasonable security safeguards to prevent a personal data breach, from May 2027. Imagery and reports from a flooded village can contain personal data. | On text, such as a request or a report, the platform masks the designated fields it detects before a model sees them, and it runs inside the perimeter. | Imagery: masking is shown on text only. Whether an exemption applies to you is a question for counsel. |
This table states what the texts say and where one platform helps. It is not legal advice.
What it does not do
It has not flown. No mission, operator or launch has used these models in flight. The consoles simulate the spacecraft.
It does not fly, steer or uplink. Tatva is not a flight controller, and it never uplinks on its own.
It does not command a launch vehicle. There is no launch-vehicle command set.
It does not see from the aircraft yet. On-device perception is being built with design partners. Where a demonstration shows detection on the aircraft, it says it is a concept.
It does not judge what a finding means, or assess damage. Drashta finds objects such as structures and aircraft and lists them. We make no claim that it measures a breach or a flood.
It does not make a command correct. A valid command is not the same as a correct one, which is why a person approves.
It is never placed in a safety path or a control loop.
It is not a certification of your deployment. ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment, not certifications of your deployment or binding regulatory claims.
The same subject, one setting at a time: satellites, drones, launch operations, AI agents for space and AI agents for defence.
Frequently asked questions
Can AI run in an operations room with no outside connection?
Yes. The models run on the operator's own hardware at the console, with no outside connection, and the platform deploys air-gapped. Commands, telemetry and imagery stay inside the operator's network, and the signed records can be verified offline.
Who approves a command that a model proposes?
A named person. For a spacecraft it is the flight director, before anything is uplinked. For an aircraft it is the pilot in command. In the launch demonstration it is the launch director who approves a hold and a resume. The model only proposes.
Has this been used on a real mission?
No. No mission, operator or launch has used these models in flight. The consoles simulate the spacecraft, and on-board operation is being built with design partners.
Does an AI model control the launch vehicle in your demonstration?
No. No model commands the launch vehicle, and there is no launch-vehicle command set. Tatva appears only after payload separation, for the satellite, and a spacecraft controller approves consequential commands.
What record exists after a command is approved?
A signed, hash-chained receipt of what was asked, what was proposed, what the policy said and who approved. It can be verified offline, later, by someone else.
How do we see the demonstrations?
The demo hub is behind sign-in. Ask us for access, or for a walkthrough on your own mission profile.
Sources
The texts as read on 8 October 2026.
- 1Ministry of Civil Aviation: Drone Rules, 2021, G.S.R. 589(E), Gazette of India, 25 August 2021, as amended; rules 2, 6 and 14 and the definitions of green, yellow and red zones.
- 2Government of India: Indian Space Policy 2023, sections 5 and 9.
- 3Department of Science and Technology: Guidelines for acquiring and producing Geospatial Data and Geospatial Data Services including Maps, F.No.SM/25/02/2020 (Part-I), 15 February 2021.
- 4Parliament of India: Digital Personal Data Protection Act, 2023 (No. 22 of 2023), sections 8(5) and 17(2)(a); and Ministry of Electronics and Information Technology: Digital Personal Data Protection Rules, 2025, G.S.R. 846(E), November 2025, Rule 1, for the dates.
Written by
AgentAnywhere Research
The team that builds the platform and the models
AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration, it says so.