Technology
Autonomous. Fail-safe. Built for the one day it has to work.
FireShield is a wildfire defense system that decides and acts on its own — from live fire intelligence, without anyone awake, at home or reachable — and that is engineered at every level to fail safe. A wildfire arrives on the day the power is out, the phone network is down and the street has no pressure left. Every choice here is downstream of that.
Fail-safe by design
Fails closed
Lose power or control and the isolation valve shuts on its own. The default state is safe.
Remembers
Every state is written to non-volatile memory. After a power cut it resumes exactly where it was.
Needs no cloud
A button, a remote trigger or an on-site detector starts it with every network down.
Drains itself
When a run ends it empties the lines and returns to unpressurized standby, unattended.
The whole system
One system, wrapped around the whole house
Roof rotors wet the roof and gutters, eave sprayers the walls, perimeter heads the ground around it. One controller on the wall runs every zone, draws from the mains, a pool or a tank, proportions foam into the line, and keeps itself powered from the grid, a battery, the sun or a generator — and talks to the outside world over whichever link is still standing.

Real hardware
Not a render. Installed, reporting, serviced.



Design decisions
Six choices that put FireShield out in front
Each one is a decision not to do the easy thing. Together they are why the system is still working when everything around it has stopped.

01
No fan. No operating system.
The two components most likely to fail in a wildfire are a cooling fan and a general-purpose computer. A fan draws in the dust and ash it is trying to survive; an operating system has to boot, and boot time is the one thing you cannot spare. The controller is a solid-state device built on a microcontroller, sealed in a hooded weather-rated enclosure, with a manual start and a key switch on its face. Nothing to spin, nothing to start up.

02
Behavior lives in a file, not in firmware
Zone count, valve drive times, pressure thresholds, which outputs do what — all of it is read from a configuration file the controller interprets. An eight-zone cottage and a twenty-four-zone estate run identical hardware and identical code. And the display on the wall tells the truth at a glance: Ready, Pending with its countdown, or Active with the zone, manifold and valve it is running, beside supply pressure, power, additive and every link.

03
Standby is unpressurized — and it fails closed
A normally-closed isolation element holds the distribution network empty while the system waits. Cut its power or its signal and it shuts by itself — the safe state is the default state, not something the software has to remember to do. Nothing on your roof sits under pressure for years in the heat, over-pressure relief resets itself, and after every run a drain sequence returns the lines to empty standby.

04
The pump runs on logic, not on a pressure dip
Some systems energize a pump the moment line pressure drops, so it cycles whenever a neighbor opens a tap. The FireShield pump runs only when the controller has determined both that the system is engaged and that supply pressure is genuinely insufficient. Every state is committed to non-volatile memory: if the power drops mid-run, the controller boots straight back into what it was doing — countdown, zone and all — without waiting for the cloud.

05
Three ways to reach it — and it needs none of them
Wi-Fi, cellular and satellite, in interchangeable modules, with the antenna placed where it works rather than wherever the enclosure happens to be. A wildfire takes the power and the phone network together, usually at the moment you are furthest from home. And if every link is gone, it still starts: a manual button, a remote trigger or an on-site detector activates it with no cloud at all.

06
Water from wherever there is water
Mains first, then a pool, a tank or a well, with the switchover managed by the controller and firefighting foam proportioned into the line as it runs. Utility power, then battery, solar and generator. In a neighborhood fire everyone opens a tap at once and the grid goes down with it; the system is designed around both disappearing.
From the drawings
From a satellite pixel to a valve at your house
Satellites, fire cameras, agency perimeters and sensors on the ground are merged into one burn-probability surface, recomputed as the fire, the wind and the fuel change. When the cells around your property cross the line, the system starts itself — only the zones facing the fire, in the order the fire needs — all described in our original patent filing.


Living outdoors
It sits on an outside wall for a decade, in any weather
Conformal coating on the boards, a weather-rated enclosure, and an internal battery with an optional solar top-up so the system does not depend on the power company on the day the power company is the problem.
It also tells you it is alive. Pressure, flow, valve positions, connectivity and battery all report continuously, and the display on the box shows the same thing the app does — so what you see on your phone is what someone standing at the wall would see.

Every property gets its own design
Zone layout, discharge placement and water sources depend on your roofline, your supply and how the wind runs through your street. The hardware is the same everywhere; the configuration is not.