Plate 1 — A satellite IoT development kit of the type used to build and test two-way satellite messaging. In FireShield the satellite radio carries its own processor, so a slow message can never interrupt a valve mid-travel.
Plate 1 — A satellite IoT development kit of the type used to build and test two-way satellite messaging. In FireShield the satellite radio carries its own processor, so a slow message can never interrupt a valve mid-travel.

The short version

  • In a serious wildfire the grid goes down, cell service degrades, and internet service goes with it. This is normal, not a worst case.
  • FireShield can be started four different ways, and three of them need no internet at all — a button on the controller, a wireless button you press while evacuating, or its own heat and smoke sensors.
  • FireShield treats Wi-Fi, cellular and satellite as interchangeable. It falls back automatically, and comes back to the faster one when it returns.
  • If the power cuts mid-run, FireShield remembers exactly where it was and picks up from there — without asking a server for permission.
  • If you're comparing FireShield with other systems, ask each of them: what can still start this system with no internet and no cell service?

The uncomfortable thing about wildfire infrastructure is that the fire eats it.

Flames reach the distribution poles and the power goes out. It doesn't go out cleanly — it browns out, comes back, drops again. Cell sites run on backup batteries that last hours, not days, and the ones on ridgelines are often the first to go. Utilities sometimes cut power deliberately, in advance, precisely because of fire risk.

So when people ask how a wildfire system stays connected, they're asking a question with a hard answer: for part of the event, it won't be. The real question is what the system does about that.


Part 01: Four ways to start it, three with no internet

FireShield can be told to run in four different ways, and any one of them alone is enough.

From the cloud. FireShield's servers watch the fire and send the start command, either because the fire crossed the distance you set or because FireShield's risk engine decided your address is in trouble. This one needs a connection.

The other three do not.

A button on the controller itself. Physically present, physically pressed. Nothing else involved.

A wireless button somewhere else on the property. Mounted by the door, in the garage, wherever you want it. You press it on your way out with the car already loaded. It talks to the FireShield controller directly — not through the internet.

Its own sensors. Heat, smoke, optical flame, or camera detection wired to the FireShield controller. When one of them trips, FireShield validates it locally and starts.

That's the architecture in one line: FireShield doesn't have a single point of failure for starting, because it doesn't have a single way of starting.

Any one of four pathways is enough on its own. Three of them never touch the internet.

There's a related point worth making. Because FireShield can be started from the cloud or from a sensor or by hand, it isn't dependent on a fire being close enough to detect. A system that only responds to its own heat sensors can't do anything until the fire is already at the house. FireShield can be running for twenty minutes before that, on nothing more than a distance threshold you set yourself.


Part 02: Every radio is the same radio

Inside FireShield, Wi-Fi, ethernet, cellular and satellite aren't four separate features. They're four interchangeable ways to carry the same messages.

FireShield puts a translation layer between the controller and whichever radio is carrying traffic, so sending a command, reporting status, dropping to a backup path, and climbing back to the preferred path when it returns all work identically no matter which radio is doing the work. Each one can be switched on or off in your settings file.

The practical version: your FireShield system uses your Wi-Fi when it's up. When the router dies, it moves to cellular without anyone doing anything. When the cell site gives out, it moves to satellite. When Wi-Fi comes back, it goes back.

Plate 2 — Wi-Fi, cellular and satellite all carry the same commands. FireShield treats them as interchangeable and moves between them on its own.
Plate 2 — Wi-Fi, cellular and satellite all carry the same commands. FireShield treats them as interchangeable and moves between them on its own.

The satellite part is more interesting than it sounds

Two details here that most people would never think to ask about.

The satellite radio has its own processor. Not a shared one — its own. It handles the satellite protocol, the link, and two-way messages by itself.

The reason is timing. FireShield's valves are driven by pulses measured in seconds, and those pulses have to be exact. If the same processor that opens valves also had to stop and negotiate with a satellite, a slow exchange could stretch a valve pulse and leave a valve half-open. Giving the satellite its own brain means satellite traffic cannot interfere with valve timing. Ever.

The antenna goes on the roof, not on the controller. It's an active antenna assembly — it has electronics in it — and it's mounted away from the FireShield enclosure, up where it can see sky. A controller is usually mounted against a wall in the side yard, which is a poor place to talk to a satellite.

And what comes over that link isn't just a status ping. FireShield can receive a full command set over whichever radio survives: start, delay, stop, drain, change settings, even update firmware.


Part 03: The power cut in the middle

Here's the scenario that separates designs.

Your FireShield system is running. It's twenty minutes into a cycle, on zone seven of twelve. The power fails, the backup catches it, something resets, and the controller reboots.

What does it know when it comes back?

FireShield writes down what it's doing before it starts — that it's active, which zone is live, and where it is in the sequence — and updates that record as it goes. When it comes back up it reads that record, drives every valve to where it should be, and resumes from where it stopped.

The important words in FireShield's patent are the last five: it resumes "without re-establishing communication with a remote backend." It does not phone home. It does not wait for a server to tell it what it was doing. It already knows.

The same is true of a countdown. If FireShield had been told start in eighteen minutes and the power dropped at minute nine, it comes back and continues from minute nine. It doesn't restart the clock, and it doesn't need the internet to remember.

There's a watchdog too — a circuit that notices if the software has hung and resets it — and after that reset, the same recovery runs. Whatever knocked FireShield over, it stands back up in the right place.

Your house doesn't stop being protected because the power blinked.


Part 04: Making sure the command is real

One more thing, because a system you can command from a distance is a system somebody else might try to command.

Every message FireShield receives is encrypted with a key belonging to that specific controller — not a shared key across all customers — and carries a check value that proves it hasn't been altered. FireShield verifies both. Anything that fails is discarded without being acted on.

FireShield also throws away commands that are too old or that have been overwritten by a newer instruction, so a stale message can't surface hours later and do something unexpected.

And the enclosure has a tamper sensor whose warning is stored in memory that survives a power loss — so if someone opened your FireShield enclosure while you were away, that fact is still on the screen when you get back.

Plate 3 — A FireShield alert. Getting the message out is only half of it; the other half is being certain the message coming back is genuine.
Plate 3 — A FireShield alert. Getting the message out is only half of it; the other half is being certain the message coming back is genuine.

What to ask before you sign

QuestionWhy it matters
How many ways can this be started?FireShield has four, and three need no internet.
Can I start it without internet or cell service?With FireShield, yes — a button on the controller, a wireless button, or its own sensors.
What happens if power cuts mid-cycle?FireShield resumes from the exact zone it was on, without contacting a server.
Does the satellite radio share a processor with the valves?In FireShield it doesn't — so satellite traffic can't disturb valve timing.
Where does the satellite antenna mount?FireShield puts an active antenna at the roof line, with a view of the sky.

Ask FireShield. Ask the competition. Ask anyone else you're considering.


Every wildfire system works on the showroom floor. The interesting question is what it does at hour six, when the grid is gone, the towers are down, the house is empty, and nobody is coming to press anything. Here is that whole sequence, stage by stage.

FireShield was designed for hour six.

Next in this series

Notes and image credits

On the satellite hardware. Satellite messaging is an option, not a fixture. Not every FireShield installation includes a satellite radio, and the specific hardware varies by model, by revision, and by what a given property needs — some sites are well served by Wi-Fi and cellular alone. The satellite module is deliberately built as a replaceable unit for exactly this reason: it can be added, omitted, or upgraded in a later revision without redesigning the FireShield controller. Talk to us about what makes sense for your address rather than assuming any particular part is in the box you receive.

Plate 1 is a photograph of a general-purpose satellite IoT development kit, shown to illustrate what this class of hardware physically looks like. It is not a photograph of a FireShield product and does not depict FireShield's own satellite module. Image source: electronics-lab.com — https://www.electronics-lab.com/wp-content/uploads/2025/01/Satellite-IoT-Developer-Kit-e1737300011897.png

About FireShield — FireShield builds automated exterior wildfire defense systems for homes across Southern California. The controller described here is covered by FireShield's patent. See the wildfire defense system or talk to us.