FireShield

Technology

Autonomous. Fail-safe. Built for the one day it has to work.

FireShield is a wildfire defense system that decides and acts on its own — from live fire intelligence, without anyone awake, at home or reachable — and that is engineered at every level to fail safe. A wildfire arrives on the day the power is out, the phone network is down and the street has no pressure left. Every choice here is downstream of that.

Fail-safe by design

  • Fails closed

    Lose power or control and the isolation valve shuts on its own. The default state is safe.

  • Remembers

    Every state is written to non-volatile memory. After a power cut it resumes exactly where it was.

  • Needs no cloud

    A button, a remote trigger or an on-site detector starts it with every network down.

  • Drains itself

    When a run ends it empties the lines and returns to unpressurized standby, unattended.

The whole system

One system, wrapped around the whole house

Roof rotors wet the roof and gutters, eave sprayers the walls, perimeter heads the ground around it. One controller on the wall runs every zone, draws from the mains, a pool or a tank, proportions foam into the line, and keeps itself powered from the grid, a battery, the sun or a generator — and talks to the outside world over whichever link is still standing.

Engineering drawing of a protected house: roof rotors along the ridge, eave and perimeter sprayers, the controller, hub and manifolds on the wall, a pool with its pump, a foam tank, solar, battery, generator, satellite antenna and the municipal supply
The complete arrangement, from our original patent filing.

Real hardware

Not a render. Installed, reporting, serviced.

The FireShield controller display in daylight, showing READY with the supply-pressure gauge and status icons
The display on the wall, reading Ready.
The FireShield monitoring dashboard: a live map of installed systems and a list of each one with its status and last heartbeat
Every installed system reports in, live.
A FireShield service van parked outside a protected home
Installed and serviced by our own crews.

Design decisions

Six choices that put FireShield out in front

Each one is a decision not to do the easy thing. Together they are why the system is still working when everything around it has stopped.

The FireShield controller: hooded weatherproof enclosure with its display, manual start buttons, key switch and external antenna

01

No fan. No operating system.

The two components most likely to fail in a wildfire are a cooling fan and a general-purpose computer. A fan draws in the dust and ash it is trying to survive; an operating system has to boot, and boot time is the one thing you cannot spare. The controller is a solid-state device built on a microcontroller, sealed in a hooded weather-rated enclosure, with a manual start and a key switch on its face. Nothing to spin, nothing to start up.

The controller display in its three states: Ready, Active with zone and valve, and Pending with a countdown

02

Behavior lives in a file, not in firmware

Zone count, valve drive times, pressure thresholds, which outputs do what — all of it is read from a configuration file the controller interprets. An eight-zone cottage and a twenty-four-zone estate run identical hardware and identical code. And the display on the wall tells the truth at a glance: Ready, Pending with its countdown, or Active with the zone, manifold and valve it is running, beside supply pressure, power, additive and every link.

The main hub: supply inlet, normally-closed fail-safe isolation element, flow sensor, automatic over-pressure relief and drain branch

03

Standby is unpressurized — and it fails closed

A normally-closed isolation element holds the distribution network empty while the system waits. Cut its power or its signal and it shuts by itself — the safe state is the default state, not something the software has to remember to do. Nothing on your roof sits under pressure for years in the heat, over-pressure relief resets itself, and after every run a drain sequence returns the lines to empty standby.

Detail of the system drawing: city supply with backflow preventer and pressure sensor, booster pump, variable-frequency drive, secondary-source pump and the main hub

04

The pump runs on logic, not on a pressure dip

Some systems energize a pump the moment line pressure drops, so it cycles whenever a neighbor opens a tap. The FireShield pump runs only when the controller has determined both that the system is engaged and that supply pressure is genuinely insufficient. Every state is committed to non-volatile memory: if the power drops mid-run, the controller boots straight back into what it was doing — countdown, zone and all — without waiting for the cloud.

Detail of the system drawing: the controller with its Wi-Fi, cellular and satellite modules, the cloud platform, and local manual, remote, sensor and third-party triggers

05

Three ways to reach it — and it needs none of them

Wi-Fi, cellular and satellite, in interchangeable modules, with the antenna placed where it works rather than wherever the enclosure happens to be. A wildfire takes the power and the phone network together, usually at the moment you are furthest from home. And if every link is gone, it still starts: a manual button, a remote trigger or an on-site detector activates it with no cloud at all.

Detail of the house drawing: a pool as secondary source with its pump, the firefighting foam tank and proportioning, and the municipal connection with its booster pump

06

Water from wherever there is water

Mains first, then a pool, a tank or a well, with the switchover managed by the controller and firefighting foam proportioned into the line as it runs. Utility power, then battery, solar and generator. In a neighborhood fire everyone opens a tap at once and the grid goes down with it; the system is designed around both disappearing.

From the drawings

From a satellite pixel to a valve at your house

Satellites, fire cameras, agency perimeters and sensors on the ground are merged into one burn-probability surface, recomputed as the fire, the wind and the fuel change. When the cells around your property cross the line, the system starts itself — only the zones facing the fire, in the order the fire needs — all described in our original patent filing.

Engineering drawing: fire data sources flowing through ingestion, normalization and de-duplication into the hazard analysis engine, a burn-probability surface, and an activation output to the controller
Many sources in, one decision out — delivered to the controller at the house.
Engineering drawing: a grid of burn-probability values around a protected house, with the fire approach vector, brush area and wind direction
Every coordinate carries its own burn probability, continuously updated.

Living outdoors

It sits on an outside wall for a decade, in any weather

Conformal coating on the boards, a weather-rated enclosure, and an internal battery with an optional solar top-up so the system does not depend on the power company on the day the power company is the problem.

It also tells you it is alive. Pressure, flow, valve positions, connectivity and battery all report continuously, and the display on the box shows the same thing the app does — so what you see on your phone is what someone standing at the wall would see.

The FireShield controller installed on an exterior wall, showing the weatherproof enclosure and status display
The installed controller.

Every property gets its own design

Zone layout, discharge placement and water sources depend on your roofline, your supply and how the wind runs through your street. The hardware is the same everywhere; the configuration is not.