First product

Inert until the person carrying it decides otherwise.

The first thing we are building on the network is a distress beacon. It does nothing at all until it is activated, and only the person holding it can activate it.

The beacon is not yet available. There is no unit to obtain, and no service behind one. Our near-term milestone is a bench demonstration of the device-to-receiver link.

If you are in immediate danger, contact your local emergency number. Nothing on this page is a substitute for that.

Consent is architectural

There is no enrollment step that a third party can perform on someone else's behalf. No account to register, no pairing, no provisioning, no way for anyone to hand out a device that is already reporting. Activation is physical and it belongs to whoever is holding the object.

This is the difference between a safety device and a tracking device, and it is not a setting. A company that stores a way to turn devices on remotely will eventually be asked to use it, by an acquirer, a government, or a court. We would rather not hold that capability at all.

That is a design decision, not a policy. Policies change with ownership. Architecture does not.

Why it has to be nearly free

Everything comparable on the market today costs several hundred dollars and usually carries a subscription. That price is not a margin decision, it is what the underlying networks and hardware require. It also means the product can only ever be sold to someone who anticipated needing it and could afford to prepare.

A device that costs almost nothing is a different kind of object. It can be handed out rather than sold. It can be given by the institutions that already reach people at risk, obtained without a purchase, a subscription, or a name attached to it. And it can be ordinary enough that carrying one is not, in itself, evidence of anything.

None of that is reachable by discounting an existing product. It follows from a cost target and a form factor, and every part of the architecture is downstream of those two things.

What happens when someone presses it

The network establishes where the device is and passes that on. The harder question is the one after it: who receives an activation, in which jurisdiction, and under what obligation to act.

That is not an engineering problem and it does not have one answer. It differs by country, by agency and by the kind of emergency involved, and it will be built partner by partner rather than shipped in a release. We treat it as a central part of the work rather than something to be arranged once the hardware exists. A beacon that reaches nobody is not a product.

On deliberate abuse

The obvious attack is to obtain many devices and activate them at once, to bury real activations in noise. We have designed against it from the beginning, and the useful reframing is this: a flood is not noise. Genuine activations are sparse, scattered, uncorrelated and persistent. A deliberate flood is dense, co-located, tightly correlated in time, and it stops. Those are separable, and an attacker who tries it tells us where they are and roughly how many units they hold.

We also never have to distinguish one real device from one false device in the moment. We only have to guarantee that a real one is not lost. Those are different problems, and the second is far more tractable than the first.

Who pays

Not the person carrying it. The beacon is expected to be subsidised or free at the point of use, funded by public safety budgets, health systems, humanitarian organisations and corporate social responsibility programs. The network sustains itself on low-rate global telemetry, which is a much larger and much less dramatic business.