Rivetira
Book a line assessment

Thirty-one questions, answered without hedging

Grouped by what you are actually trying to find out. Where the honest answer is "we do not know yet" or "that number is modelled, not measured", it says so.

Questions answered

31

six categories

Figures marked modelled

4

flagged inline

Median response to new questions

1.1 days

all enquiry types

Stations answering these in production

70

8 programs

What Rivetira is

Rivetira is an autonomous operations layer for aircraft structural and final assembly. Seven agents perceive the structure in front of them, plan the operation, drive the machines already installed at the station, and verify the result — producing a complete as-built record of every hole, fastener, shim and seal.

No. Rivetira is software that drives robots, drilling machines, fastening cells and shim machining cells that you already own or buy from machine builders. We deliberately do not sell hardware.

Aircraft structural assembly is manual, rework-heavy and rate-limiting. Roughly two thirds of an assembly mechanic’s time goes to fitting, measuring, inspecting, reworking and waiting rather than assembling — because the structure in front of them differs from the model.

It removes the fit-up iteration, the sampling inspection and the rework loop. Every deployment to date has redeployed mechanics to higher-value work rather than reducing headcount, mostly because every customer is already short of skilled mechanics.

A rivet is the smallest unit of an airframe and the place where quality is won or lost. Every fastener, flawless fit.

How the agents work

Drilling & fastening control, metrology & predictive shimming, hole and fastener inspection, sealing & coating, line & takt optimisation, large-structure handling supervision, and quality, NCR & airworthiness traceability.

Yes. A Cell subscription is exactly that — one agent on one station. Most customers start with either predictive shimming or inspection, because those two produce the fastest measurable return.

They share the as-built twin. Inspection findings update the twin, which changes what predictive shimming expects, which changes what drilling control plans. That shared state is the reason the whole loop is worth more than the agents individually.

On measured physical outcomes — 4.2 million inspected holes with known conformance verdicts, plus gap fields, process signatures and defect labels. Models are qualified per material stack and per structure class, not globally.

It escalates rather than guessing. An operation the agent cannot plan within the qualified envelope is handed to a human with the reason attached, and the case is added to the training queue.

How much control agents get

Shadow (observe only), advisory (recommend, human decides), supervised (execute with a human armed and present) and closed loop (execute within the qualified envelope, human reviews exceptions). Every station starts at shadow.

Your site engineering, per station and per agent. Rivetira cannot promote a station. Promotion requires a measured accuracy gate, agreement with the as-built twin, and a human signature.

A single configuration change applied in under 60 seconds by any authorised site engineer. It is a logged, attributed event and requires no involvement from Rivetira.

The safety circuit is Category 3 / PL d hardware, entirely independent of the Rivetira runtime. Measured fail-safe stop is 38 ms at p99. An instruction outside the qualified process envelope is rejected at the edge, before it reaches a controller.

Agent steps are idempotent, so a retried instruction never double-drills or double-fastens. Loss of the control plane drops agents to advisory after a configured window; it never halts the line and never leaves an actuator indeterminate.

About 7% of promotions are later rolled back — 4% triggered by twin drift detection and 3% by an operator decision. We publish this figure because a process with a zero rollback rate is not gating on anything.

Getting it running

Fastest to date is four months from assessment to first closed-loop station; median is around seven. Air-gapped defense programs run longer because accreditation, not software, is the constraint.

Most stations already have the metrology and machine base required. Where sensors are missing we specify commodity hardware you buy directly, typically $40k–$120k per station. Rivetira does not resell hardware.

Often in advisory mode at minimum. Closed-loop control requires a control interface (OPC UA or MTConnect) and an independent safety circuit. Where those are missing, a retrofit is usually cheaper than replacement and we will say so directly.

Yes — bidirectionally, typically two to four weeks of integration. PLM as-designed models import via STEP AP242 or JT, quality systems integrate via webhooks and REST write-back, and historians receive OPC UA HDA.

Yes, and mixed-mode fleets are common. An air-gapped site receives signed model artefacts on offline media and emits no telemetry, while still benefiting from fleet learning on a delivery cadence.

Pricing and contracts

Cell is $16,000 per assembly cell per month. Factory is $100,000 per month for the whole loop across a site. Enterprise agreements land between $800k and $10M ACV depending on sites, programs and outcome components.

Yes, genuinely. Three weeks, one station, no cost and no obligation. About two thirds of assessments do not convert to a deployment, and we say so in the report when the return is weak.

You and Rivetira agree a baseline in writing before go-live, measured from the same telemetry the agents use. Typically 60% of enterprise ACV is earned only when the agreed metric moves. If it does not move, we do not earn it.

Holes inspected, data retained, seats and API calls. Metering any of those would push you back toward sampling, rationing or worse integration — the exact behaviours the product exists to remove.

Cell agreements are quarterly. Factory agreements are annual with a 90-day exit for a missed SLA. Your as-built data is yours and is exported in open formats on request, during or after the agreement.

Who can see what

On your factory edge infrastructure. Geometry, imagery, metrology and the as-built record never leave the plant by default. What syncs to the control plane — if anything — is configurable per program, down to zero.

Not by default and never on controlled programs. Where you explicitly opt in, training uses de-identified derived features rather than raw imagery or program geometry, and never crosses customer boundaries.

SOC 2 Type II is attested. ITAR/EAR handling and air-gapped deployment are supported. Quality records are aligned to AS9100 Rev D. ISO 27001 and CMMC Level 2 are in progress and marked as such.

Program life plus seven years by default, configurable upward. Records are append-only and hash-chained; corrections are appended so the history of a decision survives.

You do, unambiguously. It is your program data on your infrastructure, and it is exportable in Parquet or CSV with a schema and hash-chain manifest at any time.

The seven agents, in one table

Each agent owns one part of the structural build. They share one perception layer, one as-built twin and one conformance record, so a decision made at the drill is visible at the join.

Drill & Fasten

Adaptive control of drilling, countersinking and rivet/bolt installation.

Holes controlled / shift 18,400 · Countersink depth σ 0.011 mm · Adaptive feed decisions/s 240

Hole & Fastener Inspection

Vision + in-process metrology sensing of hole, countersink, fastener, gap and FOD.

Detection recall (FOD) 99.1% · Flushness resolution ±0.008 mm · Inference latency p99 38 ms

Align & Shim

Metrology-assisted alignment and predictive shimming that removes hand-fit loops.

Gap prediction MAE 0.031 mm · Shim iterations 1.0 (from 3.4) · Alignment cycle 22 min

Seal & Join

Sealant application control and fuselage / wing-body join sequencing.

Bead width CV 4.2% · Sealant waste −37% · Join sequence steps 1,180

Line & Takt

Moving- and pulse-line station balancing, takt optimisation and travelled-work control.

Stations balanced 46 · Takt breach warning 4.2 h ahead · Travelled work −44%

Robot & Handling

Crawlers, AGVs, positioners and cranes moving and holding large structures.

Fail-safe stop <40 ms · Crawler positioning ±0.05 mm · Handling events/day 2,900

Quality & Conformance

Right-first-time, non-conformance, rework and full airworthiness traceability.

Traced actions/day 1.4M · NCR cycle time −52% · Audit export < 90 s

Perceive, plan, control, verify, learn

The same loop runs at every station, from a single drilling cell to a whole moving line. Nothing is actuated that has not first been simulated against the as-built twin.

  1. 01

    Perceive

    Vision, in-process metrology, laser tracker and photogrammetry fuse into a live as-built model of the structure, hole, gap and fastener state.

    38 msFusion latency p99

  2. 02

    Plan

    Align, shim, drill, countersink, fasten, seal and join are sequenced against the predicted gap field and the program tolerance stack-up.

    4.1 sTwin sim per join

  3. 03

    Control

    Feed and speed, interference, torque, bead geometry and crawler position are driven adaptively, with fail-safe stop at every actuator.

    240 HzControl loop

  4. 04

    Verify & learn

    Hole, countersink, fastener, gap and FOD are sensed, conformance is logged immutably, and supervised corrections retrain the models.

    1.4MTraced actions/day

As-built twin gates every step Perceive 38 ms fusion Plan 4.1 s twin sim Control 240 Hz loop Verify & learn 1.4M traces/day

Shadow first. Autonomy is earned, not switched on.

Every agent starts by watching. It is promoted only when its measured accuracy clears the mechanic-plus-metrology baseline and the twin agrees.

  1. Weeks 1–4

    Shadow

    Agent observes the station, predicts every outcome, actuates nothing. Accuracy measured against what the mechanics actually do.

  2. Weeks 4–10

    Advisory

    Agent recommends feed, shim geometry and sequence. A human accepts or rejects; every rejection becomes training data.

  3. Weeks 10–20

    Supervised

    Agent actuates with a human in the loop and a live fail-safe stop. Airworthiness-critical dispositions still require sign-off.

  4. Week 20+

    Closed loop

    Agent runs the step. Humans handle exceptions and the twin gates any change to the control policy.

87.5%90.0%92.5%95.0%97.5%100.0%Prediction accuracyWk 2Wk 4Wk 6Wk 8Wk 10Wk 12Wk 16Wk 20Wk 24promotion gateAgent accuracyMechanic + metrology baseline
Agent accuracy against the human baseline during shadow and advisory phasesPromotion to supervised autonomy requires four consecutive weeks above baseline plus twin agreement. The value axis is truncated to resolve the crossover.
Agent accuracy against the human baseline during shadow and advisory phases
WeekAgent accuracyMechanic + metrology baseline
Wk 288.2%94.1%
Wk 491.4%94.0%
Wk 693.6%94.2%
Wk 895.2%94.1%
Wk 1096.4%94.3%
Wk 1297.1%94.2%
Wk 1697.8%94.1%
Wk 2098.3%94.2%
Wk 2498.6%94.3%

Built for programs that cannot leak and cannot fail

Airframe geometry is among the most protected IP in manufacturing, and much of it is export-controlled. Rivetira is architected for that reality from the edge up.

Certified

SOC 2 Type II

Annual audit covering security, availability and confidentiality of the control plane.

Supported

ITAR / EAR aware

US-person access controls, on-prem and air-gapped deployment for controlled programs.

Mapped

AS9100 alignment

Quality records, NCR flow and traceability mapped to aerospace quality requirements.

In progress

ISO 27001

Information security management system certification underway. [PLACEHOLDER: target date]

Data stays where the airframe is

  • Factory edge runtime holds all program geometry, imagery and metrology locally
  • Air-gapped mode: model updates arrive by signed media, telemetry never leaves
  • Per-tenant isolation and per-program cryptographic separation
  • Encryption in transit and at rest; customer-managed keys available

Assurance-grade by default

  • Immutable audit trail for every agent action, sensor reading and human override
  • SSO/SAML, SCIM provisioning and role-based access down to station level
  • Fail-safe stop for drills, fasteners, crawlers and cranes at < 40 ms
  • Human-in-the-loop mandatory for airworthiness-critical dispositions

Where the money actually comes back

Rivetira is priced on the metric it moves. This is the value stack from a representative 14-station wing-box deployment.

$0M$2M$4M$6MShim labour removed$4.9MRework hours avoided$3.6MRate capacity unlocked$3.1MScrap & escapes avoided$2.2MOvertime reduction$1.4MInspection labour$0.9MAnnualised value (USD)
Annualised value by source, 14-station wing-box deploymentAgainst $2.7M annual platform cost at Cell pricing across 14 stations. Illustrative model — your line assessment produces your numbers.
Annualised value by source, 14-station wing-box deployment
Value sourceAnnualised value (USD)
Shim labour removed$4.9M
Rework hours avoided$3.6M
Rate capacity unlocked$3.1M
Scrap & escapes avoided$2.2M
Overtime reduction$1.4M
Inspection labour$0.9M

Annualised value

$16.1M

14 stations

Platform cost

$2.7M

Cell pricing, annual prepay

Payback period

2.4 mo

from first closed-loop station

Net revenue retention

136%

▲ +36% increase expansion by station and module

Assembly autonomy, measured on the line

Every figure below is produced by the same telemetry the agents act on — station cycle, hole quality, gap field, fastener state and conformance. Pilot and design-partner aggregate, trailing 12 months.

Holes drilled under agent control

41.6M

▲ +32% increase cumulative, all lines

Right-first-time, structural joins

97.9%

▲ +9.1% increase vs 88.8% baseline

Shim hours removed per join

68%

▼ -68% decrease 96 h → 31 h

Assembly-line uptime

99.94%

▲ +0.3% increase edge runtime, trailing 90 d

Aggregate across design-partner lines. Baselines are the same stations before Rivetira, measured over an equivalent period.

Ask the question that is not here

If the question you came with is not on this page, it is usually one of three things: a program-specific integration question, an export-control question, or a commercial structure question. All three are better answered by a person.

  • Integration questions → a manufacturing engineer, same day
  • Export-control questions → a secure channel is arranged first
  • Commercial questions → sales, with the contract templates
Line assessment
assessments@rivetira.com
Sales
sales@rivetira.com
Security & compliance
security@rivetira.com
Support
support@rivetira.com
Partners
partners@rivetira.com
Careers & press
people@rivetira.com

Every fastener, flawless fit

A line assessment maps one station, quantifies the rework, shim and rate opportunity, and returns a modelled ROI in three weeks. No production disruption.