System architecture
Bus topology, link budgets, and which commercial modules to build on — scored against mass, power, thermal envelope, certification route and whether the part has a real second source.
KopterMax designs, builds and supports the navigation, autonomy and control systems inside drones, UAVs and rovers — integrating commercial autopilots, radios, receivers and cameras with the custom code and interfaces that make them behave as one system. Once it leaves the ground, nothing can be swapped, restarted or talked through.
Everything is designed from the ground up, prototyped, tested through iterations and refined until it behaves — because a good idea developed inaccurately becomes an expensive failure, usually when it's too late
They differ in almost everything except the part we are hired for: knowing where they are, deciding what to do, and staying commandable when something fails.
Survey, inspection and precision hold, where losing the position means hitting something rather than merely drifting.
Long-range control, telemetry and video on links designed against measured spectrum — and autonomy that keeps deciding when the link has gone.
Ground vehicles that dock, pick and hold a lane to the centimetre — and do not jump half a metre crossing a doorway.
A Swiss-registered engineering company that designs, manufactures and supports flight-critical systems — and has been doing it for ten years.
Bus topology, link budgets, and which commercial modules to build on — scored against mass, power, thermal envelope, certification route and whether the part has a real second source.

Multi-band RTK and anti-jamming receivers fused with inertial, visual and ranging references. Surveyed markers like this one delete accumulated drift rather than merely slowing it.

Perception, mapping and decision-making that run entirely on the vehicle, sized against the airframe's real continuous thermal limit rather than a burst benchmark.

Long-range control, telemetry and low-latency video. The vehicle's own buses extended to the ground station, addressable in flight exactly as on the bench.

Packs that know their own condition and report capacity before it is demanded. Alongside them, termination paths that stay commandable precisely when the primary avionics are what failed.
Over-the-air updates that are atomic and roll themselves back, staged through a cohort before they reach the fleet. Every unit traceable to the exact commit it runs.
Almost nothing on a modern vehicle is built from scratch. The autopilot, the radio, the GNSS receiver, the camera, the modem and the motors are all bought — and the programme stands or falls on how well they are made to work together.
Two modules that both claim to speak the same protocol will still disagree about timing, units, start-up order and what to do when the other one stops answering. That gap is where integration programmes are won or lost, and it is almost never in anyone's budget.
We write the code that closes it: Linux drivers for parts that shipped without one, custom ROS 2 nodes where the stock ones are a starting point rather than an answer, protocol bridges between buses that were never meant to meet, and firmware forks we then carry for the life of the product.
Because we also distribute these parts in volume, the selection is made on evidence — which ones come back, which fail in the cold, and which have a real second source rather than a promised one.

CAN and DroneCAN/UAVCAN, RS-422 and RS-485, SPI, I²C, Ethernet and USB — including the translations between them that no vendor supplies.
MAVLink, ROS 2 and DDS, NMEA 0183, RTCM3 correction streams, Modbus, and the proprietary serial dialects that arrive with a module and a one-page PDF.
Linux and Yocto board support, drivers for parts that shipped without one, custom ROS 2 nodes, protocol bridges, and autopilot firmware forks maintained across upstream releases.
Bench and environmental testing of the parts before they reach a design, second-source analysis, and end-of-life exposure identified before it becomes a redesign.
Jamming is cheap and spoofing is no longer exotic, but it's even easier for GNSS to become useless — an urban canyon, a tunnel portal or a hangar roof will do it. The receiver that holds a lock, reports healthy and drifts tens of metres from truth is the dangerous one, because every system downstream believes it.
The part customers value most is the cross-check: the satellite solution is compared against independent sources, and when they diverge beyond threshold the position is declared untrusted and handed over rather than published.
Conventional telemetry publishes a chosen set of fields at a fixed rate. It tells you that something happened; it rarely tells you what. The moment you need a register nobody thought to publish before take-off, the flight is already over.
We write the transport that extends a vehicle's internal buses to the ground station over whichever radio it is flying, so a subsystem is addressable in flight exactly as it is on the bench. Faults that take several days to characterise are often resolved within hours.
Every one of these started as somebody's constraint rather than somebody's specification. The line in red is the thing we would not have known without doing it.
A stock flight controller lost authority during exactly the manoeuvres the aircraft existed to perform. We identified the airframe, established what its structure could take, and rebuilt the control laws around both.
Two models needed checking against the real aircraft, not one: the model the controller was tuned against, and the model that said the airframe could take it.
Survey flights near certain installations were being abandoned. The concerning ones did not abort cleanly — the receiver held a lock, reported healthy, and produced a position that drifted tens of metres from truth.
The requirement was never to keep positioning. It was never to act on a position that cannot be trusted — and to keep working when there is none.
Docking into a charger, picking from a rack, holding a lane between structure — all of it fails at half a metre. Outdoors is solved; the hardest part is the doorway, where most systems jump.
Centimetres in the open are easy to buy. The number that matters is the one the vehicle still holds thirty metres inside a building.
Live access to the vehicle's own buses turned a multi-flight fault hunt into a single one — and the archive it built up turned the next failure into something visible as a trend.
The value of telemetry is rarely in the flight it was captured for. It is in the years of flights you still have.
Atomic updates that roll themselves back, staged through a cohort, with every unit traceable to the exact commit it runs.
Knowing exactly what every unit is running is not administration. It is a precondition for investigating anything at all.
Separate power, separate command path, separate processing, no shared failure mode with the primary system — and an abort path tested far more than the nominal one.
A safety system is defined by what it does when its own inputs are unreliable. Everything else is a control system.
Per-cell monitoring, temperature sensing distributed across the pack, and state of health tracked across cycles — so degradation is visible as a trend long before it is an incident.
A pack that reports voltage tells you it is failing. A pack that reports condition tells you it is going to.
We are regularly engaged for the architecture alone: no hardware, no firmware, just the decisions and the reasoning behind them. The first three weeks of a programme decide what the next five cost.
What makes that advice worth taking is the parts business underneath it. We distribute thousands of components a month, and have for ten years, so we see which parts come back, which fail in the cold, and which have a real second source rather than a promised one. No consultancy without a parts business has that data, and no distributor without an engineering practice knows what to do with it — which is also why it is the part of the job we enjoy most.
The mass budget, the latency, the environment, the certification route. We will tell you honestly whether it is something we should be working on — and if it is not, who should.