The certified boundary is three Rust crates enforced by the build system. The hypervisor, container runtime, and dataplane run outside the TCB under kernel supervision.
| VxWorks + Helix | INTEGRITY | μKernel | |
|---|---|---|---|
| Language | C | C | Rust |
| Platform LOC | ~500,000 | ~10,000 | ~5,000 |
| Unsafe Audit | N/A (all C) | N/A (all C) | 617 blocks |
| Hypervisor | Helix (separate license) | Separate product | Built-in |
| Containers | Linux VM required | Linux VM required | Native POSIX domain |
| Certification | DAL A | DAL A | DAL C (in progress) |
| Partitioning | ARINC 653 | MILS | CBS + NPT |
| Ownership | Aptiv PLC (Ireland) | Green Hills Software | American |
| License * | Per-seat + unit + Helix | Per-seat + unit | Component-based |
* Competitor licensing based on publicly available information. Actual terms may vary by contract.
Autonomous UAS, mission computers, satellite processors. Hardware-enforced partitioning with formal scheduling guarantees. NDAA compliant. DO-178C certifiable.
Hyperconverged appliances, security gateways, container platforms. Wire-speed dataplane on dedicated cores.
CNC controllers, robotics, medical devices, automotive ECUs. Deterministic real-time scheduling on commodity ARM and x86 hardware.
The small TCB, Rust type system, and CI-enforced safety gates make certification a bounded effort — not a multi-year program.
License each component independently. Terms structured to fit your deployment — from single-board prototypes to fleet-scale production.
RTOS, scheduler, domain isolation, and capability-based IPC. The foundation everything else runs on.
Type-1 hypervisor with Hyper-V enlightenments, virtio backends, and NPT isolation. VM lifecycle management.
Native container runtime with Linux ABI translation. ~100 syscalls. No guest OS required.
Full source access under NDA. Build, test, integrate. 12 months of updates and engineering support.
BSP for TI TDA4VM, x86 reference, and custom hardware. Includes bring-up support.
DO-178C DAL C evidence package. Produced once, licensed independently per program.