No second attempt

Once it leaves the ground, nothing can be swapped, restarted or talked through. KopterMax builds the flight-critical systems that off-the-shelf hardware cannot deliver — architected, built and kept working by the same people, for the whole service life.

Ten years in, we still use everything we sell — which is why we are willing to sell it.

What we do

Reliability and robustness. Adaptation to the real environment rather than the one in the datasheet. Maintainability across a decade of service. Safety and security designed in at the architecture stage, where they are cheap. These are the properties that let a customer commit to a programme rather than hedge it.

System architectureWe are engaged for the decisions alone: bus topology, link budgets, compute and sensor selection, and the reasoning behind each one. Trade studies scored against mass, power, thermal envelope and certification path rather than preference — delivered as a written architecture your team can build from.Resilient navigationMulti-band RTK and anti-jamming receivers, fused with inertial, visual and ranging references weighted by measured confidence. Centimetre-class positioning that holds through interference, spoofing and GNSS-denied stretches — and says so honestly when it cannot.Onboard autonomy and edge AIPerception, mapping and decision-making that run entirely on the vehicle, sized against the airframe's real continuous thermal limit rather than a burst benchmark. ROS 2 on GPU compute, with deterministic, testable behaviour when confidence drops.Robust datalinks and live telemetryLong-range control, telemetry and low-latency video on links designed against measured spectrum rather than an assumed model. The vehicle's own buses extended to the ground station, so every subsystem is addressable in flight exactly as it is on the bench.Smart power and safety systemsPower packs that know their own condition: per-cell monitoring, thermal management and CAN integration, reporting capacity before it is demanded. Alongside them, termination and abort paths that stay commandable precisely when the primary avionics are the thing that failed.Fleet operations at scaleOver-the-air updates that are atomic and roll themselves back, staged through a cohort before they reach the fleet. Every unit traceable to the exact commit it runs, with telemetry kept long enough to warn before a failure rather than report it afterwards.

What becomes possible

A vehicle that holds centimetre accuracy thirty metres inside a steel structure. A fleet of several hundred units updated overnight with none lost. An aircraft that finishes its task with no satellite, no radio link and nothing placed in the environment to help it. A battery that says it cannot meet the next demand before the demand is made.

Every one of those began as something a customer wanted and could not buy. That is the work: taking a requirement with no product behind it and turning it into hardware that flies.

Why our advice is worth more than an opinion

We are regularly engaged for the architecture alone: no hardware, no firmware, just the decisions and the reasoning behind them. The first three weeks of a programme decide what the next five cost.

What makes that advice worth taking is the parts business underneath it. We distribute thousands of components a month, and have for ten years, so we see which parts come back, which fail in the cold, and which have a real second source rather than a promised one. No consultancy without a parts business has that data, and no distributor without an engineering practice knows what to do with it — which is also why it is the part of the job we enjoy most.


Selected work

Industrial UAV manufacturer

Extending the manoeuvre envelope of a specialised airframe

A stock flight controller lost authority during exactly the manoeuvres the aircraft existed to perform. We identified the airframe, established what its structure could actually take, rebuilt the control laws around both, and released the envelope the design had always implied.

Infrastructure survey, and a restricted programme

Positioning that holds when the signal is jammed, spoofed or simply gone

Three ways a position fails — lost, quietly wrong, or never available at all — and one requirement underneath all of them: never act on a position you cannot trust, and keep flying when there is none.

Autonomous ground and air vehicles

Centimetre positioning that does not stop at the door

A vehicle that knows where it is to a couple of centimetres outside is no use if it loses that the moment it goes in. Warehouses, plant buildings, parking structures and tunnels are where much of the work is — and where GNSS ends.

UAV manufacturer, flight test and fleet operations

One fault found in a sortie, and the next one seen coming

Bench-grade access in flight found a fault that had never reproduced on the ground. Keeping that capture rather than discarding it is what, years later, made it possible to warn before failures instead of reporting them.

Commercial fleet operator

Updating a distributed fleet without bricking a single unit

A fleet that had quietly drifted into a dozen firmware and configuration combinations, spread across sites, with no practical way to recall units.

Propulsion test and launch

An abort path that works when everything else has failed

Shutoff and bleed control for rocketry, designed to remain commandable precisely when the primary avionics are the thing that has gone wrong.


Businesses, OEMs and integrators talk to us directly. If you already know the part you need, our products and the brands we distribute are in the HeliEngadin shop.