Home / Engineering Services
Engineering services for safety-critical software.
The disciplines we use to build our own flight software, available on your programme: from requirements through models, code and test to certification evidence, in aerospace, defence and automotive.
Systems engineering and requirements
Requirements defects cost far less to fix before design starts than after integration. We work with your architects and product owners to elicit, structure and verify requirements before a model block is drawn, using INCOSE-aligned practice and MBSE tooling that keeps the programme traceable end to end.

What we do
- Stakeholder needs and system requirements definition
- Requirements elicitation workshops
- System architecture: SAD, logical architecture and ICDs
- Integration and integration verification planning
- System verification and compliance evidence
- MBSE
- Enterprise Architect, MATLAB System Composer, SysML
- Requirements management
- Polarion, IBM DOORS, MATLAB Requirements Toolbox
Control system design
Control algorithms for batteries, high-voltage switching, thermal systems, vehicle motion and now flight, designed so every model element traces to a requirement and every safety boundary is designed in rather than retrofitted.

What we do
- Requirements analysis and decomposition into control functions
- Requirements-based control design in Simulink and Stateflow
- Conversion of hand-written or UML designs to autocoded models
- Simulation and verification against requirements
- Safety partitioning and safe-state logic from the start
- Modelling
- MATLAB, Simulink, Stateflow, TargetLink, ASCET
- Calibration and data
- ETAS INCA, Vector CANape, CANoe
- Network simulation
- CANalyzer, CANoe
Model-based design
Model-based design lets requirements be tested before code exists and architecture be validated before hardware arrives, with production code generated from the verified model. In aerospace we apply it under DO-331, the model-based supplement to DO-178C.
What we do
- Modelling standards and architecture guidelines
- Bidirectional traceability between requirements, model and tests
- Closed-loop plant models for early verification
- Reusable, versioned Simulink library architecture
- Test environments
- MiL, SiL, PiL, HiL and vehicle or aircraft testing
- Standards
- DO-331, ISO 26262, IEC 61508
Embedded software
Whether the path is autocode or hand-written C, every line we deliver is MISRA-compliant, reviewed, statically analysed and traced to its requirement. Our engineers have deployed embedded software to production ECUs from ASIL A to ASIL D.
What we do
- Production code generation from Simulink and TargetLink
- Hand-written embedded C to the same standard
- Static analysis and code review with Polyspace
- Software integration on target hardware
- Code generation
- Embedded Coder, TargetLink
- Analysis
- Polyspace, MISRA C:2012 checking
AUTOSAR Classic
AUTOSAR Classic application software components, from model-based design to compliant C and ARXML, ready to integrate with your basic software stack.
What we do
- Application software component development
- ARXML configuration and interface description
- Embedded Coder AUTOSAR workflow
- Runnable-to-task mapping and COM signal configuration
- Integration support for third-party BSW stacks
- Tools
- Simulink, Embedded Coder
- Outputs
- AUTOSAR C and ARXML
Verification and validation
Verification is planned before design begins and runs through every stage. Every test case traces to a requirement, and every structural coverage gap is closed or justified, so the evidence holds up under independent assessment.
What we do
- Software unit verification and structural coverage analysis
- Component and integration verification
- Requirements-based testing with full traceability
- System integration verification
- Evidence packages for DO-178C, ISO 26262, ASPICE and IEC 61508
- Desktop testing
- Simulink Test, TPT, Tessy, BTC EmbeddedTester
- On-target testing
- ETAS INCA, Vector CANape, CANoe, vTESTstudio
- Coverage
- Statement, decision, condition and MC/DC
- Formal methods
- Simulink Design Verifier
MiL, SiL and HiL testing
The earlier a defect is found, the cheaper it is to fix. Model-in-the-loop finds algorithm errors before an ECU exists; software-in-the-loop confirms the generated code behaves like the model; hardware-in-the-loop exercises the final software against real I/O and timing. We run all three with the same test cases and one coverage report.

What we do
- MiL testing with full requirements coverage
- SiL testing and code equivalence checks
- HiL testing on Vector and dSPACE platforms
- Fault injection and safety mechanism testing
- Test case development at system, software and structural level
- MiL and SiL
- Simulink Test, TPT, Tessy, BTC EmbeddedTester
- HiL
- Vector and dSPACE rigs, CANape, CANalyzer, INCA
Functional safety and certification
Safety is an architecture decision, not a document at the end. We support airborne software to DO-178C and automotive software to ISO 26262 Part 6, with engineers who have produced certification evidence on live programmes.
Airborne software
- Planning data: PSAC, SDP, SVP, SCMP and SQAP
- DAL tailoring and independence planning
- Tool qualification to DO-330 and model-based development to DO-331
- Structural coverage to MC/DC for higher design assurance levels
- Stage of involvement audit preparation
Automotive software
- Software safety planning and safety requirements
- ASIL decomposition and freedom from interference
- Fault injection and safety mechanism verification
- Safety-compliant code generation settings
Read our DO-178C certification lifecycle practitioner guide.
ASPICE process
Automotive OEMs expect suppliers to demonstrate ASPICE capability, with Level 2 as the entry point and Level 3 increasingly required for safety systems. We set up, run and mature compliant processes across the system, software, support and management groups.

What we do
- Software engineering processes SWE.1 to SWE.6
- System engineering processes SYS.1 to SYS.5
- Project management (MAN.3)
- Configuration, problem and change management (SUP.8 to SUP.10)
- Gap analysis and assessment preparation
- Systems
- System Composer, Enterprise Architect, Polarion, IBM DOORS
- Software
- Polarion, Simulink, Requirements Toolbox, Simulink Test
- Support
- Jira, Azure DevOps, Git
Toolchain and CI
A poorly configured toolchain is a common cause of programme delay and failed assessments. We set up toolchains where every commit runs traceability checks, model build, code generation, static analysis, testing and coverage, with no manual steps between gates.
What we do
- Requirements, modelling, code, test and release toolchain set-up
- CI/CD pipeline configuration
- Tool qualification support for DO-330 and ISO 26262
- MATLAB ecosystem
- Simulink, Embedded Coder, TargetLink, ASCET
- Configuration management
- Git, Jenkins, Azure DevOps
- Testing
- BTC EmbeddedTester, TPT, Simulink Test