Multirotor · VTOL · Fixed-wing UAV · Rovers & AGVs

No second attempt.Autonomous navigation for unmanned aircraft and ground vehicles.

KopterMax designs, builds and supports the navigation, autonomy and control systems inside drones, UAVs and rovers — integrating commercial autopilots, radios, receivers and cameras with the custom code and interfaces that make them behave as one system. Once it leaves the ground, nothing can be swapped, restarted or talked through.

Sim UAV survey pattern · 2.4 km · GNSS-denied sector Pass 3
Position error, 95%
1.4cm RTK fixed
Integrity nominal
Solution trusted
Satellites
31 / 4 bands
C/N₀
46 dB-Hz
Link
−74 dBm
Pack
24.8 V · 6s
Inertial + visualholding
Drift rate0.0 cm/s
Last reference0:04 ago
Illustrative simulation, not recorded flight data
How we work

We are the first users of our own products

Everything is designed from the ground up, prototyped, tested through iterations and refined until it behaves — because a good idea developed inaccurately becomes an expensive failure, usually when it's too late

What we build for

Three classes of vehicle, one problem underneath

They differ in almost everything except the part we are hired for: knowing where they are, deciding what to do, and staying commandable when something fails.

A multicopter holding position over open terrain, away from any prepared site.
Multirotor & VTOL

Hold a position to the centimetre, in wind, with nothing to see

Survey, inspection and precision hold, where losing the position means hitting something rather than merely drifting.

A fixed-wing unmanned aircraft on a prepared surface before launch.
Fixed-wing & long endurance

Hours out, beyond the link, and home on its own terms

Long-range control, telemetry and video on links designed against measured spectrum — and autonomy that keeps deciding when the link has gone.

A six-wheeled unmanned ground vehicle on loose gravel, away from any prepared surface.
Rovers & AGVs

Off the prepared surface, in and out of buildings

Ground vehicles that dock, pick and hold a lane to the centimetre — and do not jump half a metre crossing a doorway.

Capabilities

Six areas, usually several at once

A Swiss-registered engineering company that designs, manufactures and supports flight-critical systems — and has been doing it for ten years.

10 yearsdesigning and supporting flight-critical systems
Thousandsof commercial components a month — the catalogue we integrate from
17 vendorsof autopilots, radios, receivers, cameras and motors we build with and distribute for
12 layersARM and NVIDIA video processing boards, from the schematic up
01 — Drawn, not photographed

System architecture

Bus topology, link budgets, and which commercial modules to build on — scored against mass, power, thermal envelope, certification route and whether the part has a real second source.

A coded fiducial target fixed to a stone structure, surveyed in as a known reference point.
02

Resilient navigation

Multi-band RTK and anti-jamming receivers fused with inertial, visual and ranging references. Surveyed markers like this one delete accumulated drift rather than merely slowing it.

Circuit board layout for a KopterMax flight avionics module, routed copper on both layers.
03

Onboard autonomy

Perception, mapping and decision-making that run entirely on the vehicle, sized against the airframe's real continuous thermal limit rather than a burst benchmark.

Ground-station console plotting live channels off a vehicle bus, with a live tuning panel.
04

Datalinks & telemetry

Long-range control, telemetry and low-latency video. The vehicle's own buses extended to the ground station, addressable in flight exactly as on the bench.

Switched-mode power stage: paralleled transformers, heatsinked switching devices and bulk capacitors.
05

Power & safety systems

Packs that know their own condition and report capacity before it is demanded. Alongside them, termination paths that stay commandable precisely when the primary avionics are what failed.

06 — Drawn, not photographed

Fleet operations

Over-the-air updates that are atomic and roll themselves back, staged through a cohort before they reach the fleet. Every unit traceable to the exact commit it runs.

Integration

The datasheet is where the work starts

Almost nothing on a modern vehicle is built from scratch. The autopilot, the radio, the GNSS receiver, the camera, the modem and the motors are all bought — and the programme stands or falls on how well they are made to work together.

What we are actually hired for

Commercial parts, made to behave as one system

Two modules that both claim to speak the same protocol will still disagree about timing, units, start-up order and what to do when the other one stops answering. That gap is where integration programmes are won or lost, and it is almost never in anyone's budget.

We write the code that closes it: Linux drivers for parts that shipped without one, custom ROS 2 nodes where the stock ones are a starting point rather than an answer, protocol bridges between buses that were never meant to meet, and firmware forks we then carry for the life of the product.

Because we also distribute these parts in volume, the selection is made on evidence — which ones come back, which fail in the cold, and which have a real second source rather than a promised one.

Shelved stock: the component catalogue the integration work is selected from.
Thousands of commercial components a month, and ten years of knowing which ones come back
Buses we bridge

CAN and DroneCAN/UAVCAN, RS-422 and RS-485, SPI, I²C, Ethernet and USB — including the translations between them that no vendor supplies.

Protocols we speak

MAVLink, ROS 2 and DDS, NMEA 0183, RTCM3 correction streams, Modbus, and the proprietary serial dialects that arrive with a module and a one-page PDF.

Code we write

Linux and Yocto board support, drivers for parts that shipped without one, custom ROS 2 nodes, protocol bridges, and autopilot firmware forks maintained across upstream releases.

What we qualify

Bench and environmental testing of the parts before they reach a design, second-source analysis, and end-of-life exposure identified before it becomes a redesign.

Components we integrate, qualify and distribute
Linux Yocto Project ROS 2 NVIDIA Qualcomm ArduPilot CubePilot u-blox RFDesign Quectel SIYI Vzense Taisync T-MOTOR Mender Git Grafana
Integrity, not just accuracy

The failure isn't losing position: it's not knowing you lost it

Jamming is cheap and spoofing is no longer exotic, but it's even easier for GNSS to become useless — an urban canyon, a tunnel portal or a hangar roof will do it. The receiver that holds a lock, reports healthy and drifts tens of metres from truth is the dangerous one, because every system downstream believes it.

The part customers value most is the cross-check: the satellite solution is compared against independent sources, and when they diverge beyond threshold the position is declared untrusted and handed over rather than published.

  • Interference-rejecting multi-band, multi-constellation receivers
  • Antenna placement reworked against measured patterns on the real airframe
  • Deterministic, pre-agreed fallback below the confidence threshold
Position error through an interference transit — protected solution against an unprotected receiver
Custom interfaces · live subsystem access

The vehicle itself, not a derived description

Conventional telemetry publishes a chosen set of fields at a fixed rate. It tells you that something happened; it rarely tells you what. The moment you need a register nobody thought to publish before take-off, the flight is already over.

We write the transport that extends a vehicle's internal buses to the ground station over whichever radio it is flying, so a subsystem is addressable in flight exactly as it is on the bench. Faults that take several days to characterise are often resolved within hours.

Ground station addressing the vehicle's own bus mid-flight, with write-back to a live parameter
Selected work

Seven programmes, and what each one settled

Every one of these started as somebody's constraint rather than somebody's specification. The line in red is the thing we would not have known without doing it.

Industrial UAV manufacturer

Extending the manoeuvre envelope of a specialised airframe

A stock flight controller lost authority during exactly the manoeuvres the aircraft existed to perform. We identified the airframe, established what its structure could take, and rebuilt the control laws around both.

Two models needed checking against the real aircraft, not one: the model the controller was tuned against, and the model that said the airframe could take it.

Infrastructure survey
and a restricted programme

Positioning that holds when the signal is jammed, spoofed or simply gone

Survey flights near certain installations were being abandoned. The concerning ones did not abort cleanly — the receiver held a lock, reported healthy, and produced a position that drifted tens of metres from truth.

The requirement was never to keep positioning. It was never to act on a position that cannot be trusted — and to keep working when there is none.

Autonomous ground
and air vehicles

Centimetre positioning that does not stop at the door

Docking into a charger, picking from a rack, holding a lane between structure — all of it fails at half a metre. Outdoors is solved; the hardest part is the doorway, where most systems jump.

Centimetres in the open are easy to buy. The number that matters is the one the vehicle still holds thirty metres inside a building.

UAV manufacturer,
flight test and fleet ops

One fault found in a single flight, and the next one seen coming

Live access to the vehicle's own buses turned a multi-flight fault hunt into a single one — and the archive it built up turned the next failure into something visible as a trend.

The value of telemetry is rarely in the flight it was captured for. It is in the years of flights you still have.

Commercial fleet operator

Updating a distributed fleet without bricking a single unit

Atomic updates that roll themselves back, staged through a cohort, with every unit traceable to the exact commit it runs.

Knowing exactly what every unit is running is not administration. It is a precondition for investigating anything at all.

Propulsion test and launch

An abort path that works when everything else has failed

Separate power, separate command path, separate processing, no shared failure mode with the primary system — and an abort path tested far more than the nominal one.

A safety system is defined by what it does when its own inputs are unreliable. Everything else is a control system.

Commercial operator,
cold-climate operations

Power packs that report their condition in time to act on it

Per-cell monitoring, temperature sensing distributed across the pack, and state of health tracked across cycles — so degradation is visible as a trend long before it is an incident.

A pack that reports voltage tells you it is failing. A pack that reports condition tells you it is going to.

Company

Why our advice is worth more than an opinion

We are regularly engaged for the architecture alone: no hardware, no firmware, just the decisions and the reasoning behind them. The first three weeks of a programme decide what the next five cost.

What makes that advice worth taking is the parts business underneath it. We distribute thousands of components a month, and have for ten years, so we see which parts come back, which fail in the cold, and which have a real second source rather than a promised one. No consultancy without a parts business has that data, and no distributor without an engineering practice knows what to do with it — which is also why it is the part of the job we enjoy most.

The kind of thing a distributor sees and a consultancy does not

Tell us the constraint you cannot get past

The mass budget, the latency, the environment, the certification route. We will tell you honestly whether it is something we should be working on — and if it is not, who should.