Editions · open core, Pro and custom study

Free to build on. Pro when it has to stand up in review.

The engine is, and stays, open source under the AGPL-3.0 (GNU Affero General Public License, version 3), with no feature gate. Ashforde OÜ sustains it with expertise and a proprietary overlay, not with seat fees on the open engine. There are no prices on this site: every paid route starts with a message.

One engine · kshana v0.29.1 From the repository
The open engine at the centre: one mark per scenario kind (75), filled where the kind has validated ledger rows, hollow where its rows are Modelled, a dash where no ledger module matches it by name. Kshana Pro and the custom study sit around it and connect to the kinds they build on.

Engine v0.29.1 · 75 kinds from src/api.rs · ledger status from web/data/verification-matrix.json · what Pro and a study build on: the site's editions register · no scenario or seedCompare the editions

01Three ways to work with us

Compare the editions.

The same engine sits under all three. Read across a row to compare why it matters, who each one is for, what it includes and how it starts.

Free · AGPL-3.0 or commercial licence

Open core

The whole validated engine and every surface, free with no feature gate. Everything on this site runs on it.

Why everyone needs it

Anyone who takes position or time from GNSS (Global Navigation Satellite Systems) is exposed: jamming, spoofing and signal loss reach vehicles, networks, grids and spacecraft alike. The open core shows how exposed, and says which figures are checked.

Who it is for
  • Engineers of vehicles, networks, grids and spacecraft that take position or time from GNSS
  • Researchers, students and reviewers who need figures they can reproduce and cite
  • Developers wiring the engine into code, a CI (continuous integration) suite or an AI (artificial intelligence) assistant
What is included
  • All 75 scenario kinds and 132 bundled scenarios: native, Python, JavaScript, in the browser and over MCP (Model Context Protocol)
  • The full verification matrix: 83 of 223 capabilities validated against independent oracles, the rest labelled Modelled
  • Every result stamped with scenario hash, seed and engine version, and written as JSON (JavaScript Object Notation), CSV (comma-separated values) tables and SVG (Scalable Vector Graphics) charts
  • The free kshana --study suite runner
Terms

Free under the AGPL-3.0. The same core is also offered under a commercial licence, for closed integration into proprietary products (below).

Commercial · the same engine, amplified

Kshana Pro

A proprietary overlay that depends on the open core and never forks it: a strict superset of open Kshana. Available under contract.

Why Pro, even more

Open Kshana runs one scenario and tells you what it gives. Kshana Pro answers the questions a programme asks next: which design to fly, how sure the answer is, and whether the mission meets its requirements in a form a review board can check.

Who it is for
  • Programmes that must hand a mission dossier or an audit-grade evidence pack to a review or procurement board
  • Architects choosing a design from the Pareto front of a whole design space, or from trade studies ranked on a figure of merit
  • Timing and hardware teams who need a clock digital twin calibrated to their device
What is included
  • A design optimiser: the Pareto front of a design space, with every front design as a scenario the free engine re-runs
  • Uncertainty and sensitivity over thousands of runs
  • A one-command mission dossier with a verification matrix and a PDF (Portable Document Format) file
  • Audit-grade, reproducible evidence packs, clock digital twins calibrated to a device's published Allan budget, and architecture trade studies ranked on a figure of merit
  • Model-based systems-engineering (MBSE) and programme tooling that checks a programme's requirements against runs of the open engine, reading only the outputs the engine publishes
Terms

Kshana Pro is available under contract. It depends on the open core and never forks it, so nothing is taken out of the free engine.

Paid work · done for you

Custom study

Work done for you, on your system: the paid custom study, not the free kshana --study command.

Why a custom study

When the question is yours but the time, the modelling or the clearance is not: we model your system with the same engine, label every figure Validated or Modelled, and hand back a result you can reproduce.

Who it is for
  • Programme and procurement teams who need an independent, modelled view of a PNT (positioning, navigation and timing) architecture's resilience
  • Hardware builders who want models of their own devices
  • Export-sensitive programmes, and teams who want Kshana in their toolchain
What is included
  • A Modelled PNT-resilience study, for example an optimism-gap audit. Not a certification.
  • Sensor and resilience models calibrated to your hardware
  • Export-controlled resilience work under the appropriate clearance and NDA (non-disclosure agreement)
  • Commercial support and integration, training and consulting
Terms

Scoped to your question and delivered under contract, reproducible from scenario, seed and engine version.

Open core licence

One engine, two licences.

Pick the one that fits how you use it. Both cover the same open engine; nothing is held back from either.

Option A · open source

GNU AGPL-3.0

Use, study, modify and redistribute it free of charge. If you distribute a derivative, or let people use a modified engine over a network, you share its source under the same licence.

Right for academic work, open-source projects, internal evaluation and research.

Option B · from Ashforde OÜ

Commercial licence

  • Embed the engine in a closed-source product
  • Run a network service on a modified engine without the source-disclosure obligation
  • Integrate it into a toolchain whose other parts cannot be AGPL
  • Get warranty, indemnity or support terms the AGPL disclaims

Ask about a commercial licence

Kshana Pro and the other proprietary overlays are separate products under their own contract, not part of either licence. What the commercial licence covers

Kshana Pro · the same engine, amplified

Free runs one scenario. Pro answers the programme's question.

Open Kshana runs one scenario and tells you what it gives. Kshana Pro answers the questions a programme asks next, over the same engine and the same scenario files: which design to fly, how sure the answer is, and whether the mission meets its requirements in a form a review board can check.

  • A strict superset of open Kshana.Every open scenario kind runs in Pro unchanged, and an open scenario runs in Pro with no licence at all.
  • No new physics.Every Pro number comes from runs of the open engine, so a Pro figure is as trustworthy as the open scenario kind it came from, and never more.
  • Reproducible in the free engine.Anyone with open Kshana can re-run one and get the same figure.
  • Honest labels carried through.Every Pro result is labelled MODELLED. Every figure keeps the tier the open engine gave it (Validated, Modelled or Partner), never a higher one.
Design optimiser

Which design should we fly?

  • FreeA free user scores one design they wrote by hand.
  • ProA Pro user states the design space (each variable a scenario setting with its allowed values), the constraints and two or three objectives, and gets the whole Pareto front: the designs that no other design beats on every objective at once.

The base scenario can be of any open kind, so the same tool designs a constellation around the Earth, the Moon or Mars, or trades a link budget. Every design is one run of the open engine. Each front design is written out as a plain open scenario file, with the Secure Hash Algorithm (SHA-256) hash of the result the free engine gives for it.

What it does not do. It has no cost model, so a variable no objective penalises drifts to the edge of its range. Constellation studies score geometry only: no signal power, satellite health or terrain.

Pareto front · Lunar navigation constellationKshana Pro output
025507510081214162024satellites in the constellationavailability over the region, %referenceknee
every design runPareto frontkneereference: Bundled lunar relay design (8 + 6 satellites)

Front design 004 · knee · 16 satellites, 85.0404 % availability · 2 planes at 8,000 km, 45° · re-run in the free engine: same SHA-256 89882372…

608 designs, all run (whole moon): a front of 12 designs at 6 points; 12 of 12 re-run in the free engine with the same result hash. MODELLED.

Kshana Pro 0.2.0 on open engine 0.29.0 · kshana-pro design · 609 engine runs · run digest df81aad4…

Uncertainty and sensitivity

How sure are we, and what drives the result?

  • FreeA free user gets one number, or a spread over random seeds.
  • ProA Pro user states how uncertain each input is and gets confidence bands, the probability of meeting a limit, and a ranking of the inputs that drive the result.

It works on any open scenario. Inputs are ranked by Sobol' sensitivity indices or by standardised regression coefficients, and a ranking that is not reliable is flagged as such. A long study can be stopped and resumed.

What it does not do. Inputs are treated as independent. More runs narrow the sampling error, not the model error: a MODELLED kind stays MODELLED.

Uncertainty and sensitivityKshana Pro output
-50-2002050time error, nslimit ±20 ns100%0%share of runs within the limit0102030405060minutes of holdover
5th to 95th percentile of 2,000 runsmedianbase runshare within the limit

After 60 minutes: 1,366 of 2,000 runs within ±20 ns, a probability of 0.683 (95 % interval 0.6623 to 0.703)

Clock holdover with an uncertain noise level · input q_wf (the clock's white-frequency-noise level): uniform(4.5e-20 to 2.7e-19), ASSUMED · MODELLED · Kshana Pro 0.2.0 on open engine 0.29.0 · kshana-pro uncertainty · 2,000 engine runs · run digest abab765e…

Mission dossier

Does the mission meet its requirements, and can we hand that over?

  • FreeA free user gets one report per run.
  • ProA Pro user gets one mission dossier in one command: requirements checked against real runs, a verification matrix with its open items, and a PDF (Portable Document Format) in which every number can be re-derived with the free engine.

A requirement met on a MODELLED or PARTNER basis is flagged. Requirements to be verified by test, inspection or demonstration stay open items however the run went.

What it does not do. Simulation evidence counts as analysis and does not replace a test, an inspection or a demonstration. A dossier is not a certification, a qualification or an acceptance by any authority.

Mission dossier · Navigation resilience programme: Earth, Moon and MarsKshana Pro output
12requirements
7met
4not met
1not verified
15open items
  • LEO-001ppp.cases[1].median_convergence_min <= 10 minmetMODELLED

    With 240 low Earth orbit (LEO) satellites added, precise point positioning (PPP) shall converge within 10 minutes (median over the seeded runs).

    Method: analysis · run RUN-LEO · value read: 7.5 min

    `ppp.cases[1].median_convergence_min <= 10 min`: 7.5 min <= 10 min is true

    Open item: MODELLED basis

  • LEO-002ppp.cases[0].median_convergence_min <= 10 minnot metMODELLED

    With GPS and Galileo alone, precise point positioning (PPP) shall converge within 10 minutes (median over the seeded runs).

    Method: analysis · run RUN-LEO · value read: 11.5 min

    `ppp.cases[0].median_convergence_min <= 10 min`: 11.5 min <= 10 min is false

    Open item: not met

  • LEO-003fusion.fused.rms_error_3d_m <= 0.5 mmetMODELLED

    With the LEO layer the fused three-dimensional position error shall be 0.5 m root mean square (RMS) or better.

    Method: test · run RUN-LEO · value read: 0.4349 m

    `fusion.fused.rms_error_3d_m <= 0.5 m`: 0.434888 m <= 0.5 m is true

    Open item: method, MODELLED basis

  • LUN-001global.availability_pct >= 95 %not metMODELLED

    The lunar relay constellation shall give a position fix with a position dilution of precision (PDOP) of 6 or better over at least 95 % of the lunar surface and of the day.

    Method: analysis · run RUN-LUNAR · value read: 21.3286 %

    `global.availability_pct >= 95 %`: 21.3286 % >= 95 % is false

    Open item: not met

  • LUN-002global.pdop.median <= 6metMODELLED

    Where the lunar relay constellation gives a fix, the median position dilution of precision (PDOP) shall be 6 or better.

    Method: analysis · run RUN-LUNAR · value read: 5.22 1

    `global.pdop.median <= 6`: 5.22 <= 6 is true

    Open item: MODELLED basis

  • SPC-001timeline.bands[3].min_cn0_dbhz >= 25 dB-HzmetPARTNER

    Under the scripted L-band interference, the GPS L5 carrier-to-noise density ratio (C/N0) shall stay at or above 25 dB-Hz.

    Method: analysis · run RUN-SPECTRUM · value read: 44.0752 dB-Hz

    `timeline.bands[3].min_cn0_dbhz >= 25 dB-Hz`: 44.075187 dB-Hz >= 25 dB-Hz is true

    Open item: PARTNER basis

  • SPC-002timeline.bands[0].min_cn0_dbhz >= 25 dB-Hznot metPARTNER

    Under the scripted L-band interference, the GPS L1 coarse/acquisition (C/A) carrier-to-noise density ratio (C/N0) shall stay at or above 25 dB-Hz.

    Method: analysis · run RUN-SPECTRUM · value read: 3.2329 dB-Hz

    `timeline.bands[0].min_cn0_dbhz >= 25 dB-Hz`: 3.232859 dB-Hz >= 25 dB-Hz is false

    Open item: not met

  • CMP-001timeline.channels.time_error_ns.values <= timeline.channels.guard_ns.values for all valuesnot metPARTNER

    In the chained jamming, spoofing and holdover mission the clock time error shall stay within its 50 ns guard at every timeline step.

    Method: analysis · run RUN-CAMPAIGN · value read: 51.7825 ns

    `timeline.channels.time_error_ns.values <= timeline.channels.guard_ns.values` for all: 275 of 458 elements satisfy (first failing); element 214: 51.782497 ns <= 50 ns

    Open item: not met

  • CMP-002min(timeline.events[].t_s) <= 30 minmetPARTNER

    In the chained mission a spoofing alarm shall be raised within 30 minutes of the start.

    Method: demonstration · run RUN-CAMPAIGN · value read: 1,200 s

    `min(timeline.events[].t_s) <= 30 min`: 1200 s <= 1800 s is true

    Open item: method, PARTNER basis

  • MARS-001fom.rms_error_relays_m <= 5 mmetMODELLED

    Around Mars the constellation-only position error shall be 5 m root mean square (RMS) or better over one sol.

    Method: analysis · run RUN-MARS · value read: 1.8827 m

    `fom.rms_error_relays_m <= 5 m`: 1.882704 m <= 5 m is true

    Open item: MODELLED basis

  • MARS-002fom.availability_relays >= 99 %metMODELLED

    Around Mars the constellation shall give a position fix at 99 % of epochs or more.

    Method: analysis · run RUN-MARS · value read: 1 1

    `fom.availability_relays >= 99 %`: 1 >= 0.99 is true

    Open item: MODELLED basis

  • OPS-001no machine-checkable criterionnot verified

    The receiver housing shall carry the programme's identification label.

    Method: inspection · run none · value read: no run traced

    Open item: no evidence, manual verification

Page 1 of the generated mission dossierPage 2 of the generated mission dossier

21 pages, one command. Open the generated PDF (Portable Document Format)

Kshana Pro 0.2.0 on open engine 0.29.0 · kshana-pro mission build · 5 runs and one trade study · 7 met, all on a MODELLED or PARTNER basis · dossier SHA-256 49df1e0e… · development build

Three more answers

Did the last change make a figure we care about worse?

  • FreeA free user runs a campaign and reads the result.
  • ProA Pro user names the figures that matter in a set of scenarios, says what worse means for each, and gets a pipeline that fails when a change to a scenario, a model or the engine makes one of them worse, or stops meeting its requirement.

It extends the scenario regression check. A Monte Carlo figure is judged with statistics instead of a tolerance, so a new set of random seeds is not called a regression and a doubled spread is. Every run is appended to a history in which each record carries the hash of the one before, and a check reports whether that chain is intact.

What it does not do. A watch proves that a MODELLED figure stayed stable or moved; it does not prove the figure is true. A figure with no stated direction is reported and never fails a run.

Campaign watch · six revisions, one historyKshana Pro output
Watched figure · revision
carrier-to-noise density ratio (C/N0) at the end of the jamming phase○·▲▼··
largest time error on the mission timeline○····≈
satellites tracking at the end of the jamming phase○··▼··
share of the mission under alarm○··▼·▲
spoofing detected (phase length)○····▲
time error at the end of holdover○····≈
▼regressed▲improved·unchanged≈moved within its tolerance○first run: becomes the baseline

Revision r4-stronger-jammer · jammer raised from -33 to -24 dBW (decibels relative to one watt): C/N0 at the end of the jamming phase 30.60 → 21.82 dB-Hz (decibel-hertz), below the 25 dB-Hz floor, requirement not met; satellites tracking 8 → 0; three watches regressed · fail, exit code 1

The bundled campaign pack, 10 watched figures over three open campaigns, run twice: pass both times, 0 of 125 figures moved, history of 2 records intact.

Kshana Pro 0.2.0 on open engine 0.29.0 · kshana-pro ci · demonstration revisions of campaign-jam-spoof-holdover-integrity.toml · history 6 records, chain intact, last hash bb2f10eb… · MODELLEDOpen in Kshana Studio

Also in Kshana Pro

Requirements and traceability

Kshana Pro's model-based systems-engineering (MBSE) and programme tooling checks a programme's requirements against runs of the open engine: it imports requirements as comma-separated values (CSV), or as a documented subset of the Requirements Interchange Format (ReqIF) or of Systems Modeling Language version 2 (SysML v2) text, and produces a verification cross-reference matrix (VCRM), a SysML v2 model, a change-impact report and an offline evidence pack. It re-runs and recomputes nothing.

The open engine's outputs it reads
  • result.jsonthe fields a criterion names, their units, the reproducibility stamp of scenario hash, seed, engine version and schema version, and the run's label and figure tiers
  • report.jsonkind, reproducibility record and capability labels
  • scenario fileits hash, kind, seed and parameters
  • field-units schemaeach field's unit, provenance and evidence tier
  • verification matrixeach capability's VALIDATED, MODELLED or PARTNER label

Trade studies

A trade study runs every architecture option as an unchanged open-engine scenario, ranks the options on a figure of merit read from each run's result, and writes an evidence pack that records each option's scenario hash, so any figure in it can be reproduced by re-running that scenario.

Clock digital twin

A clock twin is calibrated to a device's published Allan-deviation budget, then checked by estimating the twin's own Allan deviation with the open engine's estimator and comparing the two within a stated tolerance. A twin of your own device needs your characterisation data and is built under contract and a non-disclosure agreement.

Study dossier

One scenario becomes a reproducible technical note in HTML (HyperText Markup Language) and JSON (JavaScript Object Notation): scope, method, results with a tier on every figure, limitations, and the exact scenario text run.

  • Pro needs a licence. Without one, Pro runs open scenarios only and refuses every Pro feature with a message naming what is required.
  • Some work needs a signed customer. A twin of your own device needs your characterisation data and is built under contract and a non-disclosure agreement.
  • Nothing Pro produces is a certification. Every result is modelled, and says so.

Done as a custom study

  • Models of your hardware. Sensor or resilience models calibrated to your hardware are built only under contract, with your data.
  • Export-controlled resilience models are not publicly offered. Such work is done only under the appropriate clearance and a non-disclosure agreement.

The charts in this section are drawn from the files the Pro commands wrote for the worked examples that ship with Pro: modelled results, not statements about any real mission. The wording is quoted from the public Kshana Pro page of the open repository.

02Custom study · how it runs

When you need an answer, not a tool.

A custom study uses the same engine you can run yourself, so every figure in it can be checked by anyone.

  1. Tell us the question. Mail contact@ashforde.org with the system and the decision it feeds. There is no form.
  2. We scope it. What will be modelled, with which scenarios, and what stays out of scope, under the appropriate clearance and NDA where the work needs it.
  3. We model it with the same engine. Every figure is labelled Validated or Modelled, exactly as on this site.
  4. You get a reproducible result. Reproducible from scenario, seed and engine version. A modelled study, not a certification.

Not the same as kshana --study: that free command runs a suite of scenarios you write into one stamped report (Developers). A custom study is paid work we do for you.

Install the open coreFrom the manifests

For anyone, nothing to install.

The engine runs locally as WebAssembly; nothing is uploaded.