Skip to content
Leg 04 · Evaluate · the buyer's guide

six questions.one honest answer.

The six tests an honest evaluator runs on any aviation safety platform. eAviora answers each one, and hands you the same tests to run on everyone else on your shortlist.

Answers, not brochures
101bow-tie models
804named barriers
610safety indicators
924IOSA ISARPs
Before you shortlist

Six questions, one honest answer.

The tests an honest evaluator runs on any platform. Run them on us too.

6
Questions to ask
1
Operational graph
0
Blank canvases
Q1
Does the model ship?
A working risk library on day one, not an empty bow-tie to author.
Q2
Is the AI human-gated?
Reproducible classification, and a person between the AI and the record.
Q3
Where does isolation live?
Row-level security in the database, not a filter the app could forget.
Q4
Is the language pinned?
Version-pinned codes, so history stays comparable and benchmarks hold.
Q5
One graph or silos?
One record table joined by links, not four tools dressed up as one.
Q6
Will it pass IT?
An open, documented surface built to survive a security review.
The model ships

Start with a working model.

A pre-built risk library on day one, not an empty canvas to author yourself. Every occurrence maps to a bow-tie family with named preventive and recovery barriers, so what failed and what should have stopped it is answered structurally, not in free text.

101
Bow-tie models
1,727
Risk elements
804
Named barriers
210
Operational scenarios
610
Safety indicators
924
IOSA ISARPs
AI proposes, people decide

The AI proposes. A person decides.

Re-run the classification and it holds. Nothing reaches the record without a person.

Accept, edit or reject. Every copilot suggestion surfaces as a one-click card, and that decision is logged for audit.

State the AI cannot set. Workflow and governance state are non-settable by the AI or the API. Low-confidence output is queued for a person, never written silently.

Confidentiality holds through. An ICAO Annex 19 confidential report stays invisible to an analyst without clearance, even via the copilot.

NORTHGALE AIR · SYNTHETIC OPERATION
OCC-2026-0042CLASSIFIED · LOCKED
Reporter narrative
Crew reported unusual vibration on approach, ILS RWY 25L. Stabilised at 1500ft AGL, monitored to touchdown, no further anomaly.
METAR at occurrenceSYS
VOMM 141330Z 28015KT 9999 FEW020 34/22 Q1008
ICAO classificationAI · 94%
Aircraft upset / Loss of control, in-flight (LOC-I)
Risk bandAI · 88%
4C · Tolerable, monitor
One graph, not silos

One record table. Links between them.

Occurrences, findings and actions on one graph, joined by first-class links. Take one occurrence and follow it to the finding it raised, the corrective action that fixed it, and the training that closed the loop, on one record. If a demo copies and pastes between modules, it is a four-tool stack dressed up as one.

23
View layers, one graph
1
System of record
0
Data silos
Record
Occurrence
weakened
Barrier
Record
Barrier
raised
Finding
Record
Finding
corrected by
Action
Record
Action
changed
Document
UNIVERSAL LINKS · one traversable operation
Built for IT review

Isolation, and an open front door.

Isolation in the database, pinned data, and an open, documented surface.

Isolation in the database. Row-level security forced on, against an app role that cannot bypass it. A missing operation context fails the query, it never exposes a neighbour.

Five layers, not one. Procedure checks, per-query filters, request-bound context, deny-by-default policies, and the database itself refusing a cross-tenant read.

Version-pinned for benchmarking. Taxonomy codes and indicator definitions are immutable, so history stays comparable to itself and cross-airline benchmarking stays honest.

Open by design. A public REST API with an OpenAPI contract, an MCP connector for an AI assistant, and Canadian data residency, encrypted at rest.

Bring your shortlist

Six questions. One honest answer.

Tenant isolation in the database.Row-level security, not app-code filtering. One tenant can never read another.
Your data never trains a model.Tenant data is not used to improve our AI for anyone else. Ever.
Benchmark-safe by design.Version-pinned identifiers, so history stays comparable to itself.
01 WHY 02 THE SHIFT 03 PLATFORM 04 EVALUATE 05 ADOPT
Next leg
05 · Adopt it

You have the questions. The next leg is where you ask them: the experience, the adoption path and the design partner cohort.