roboblackbox.
contact@roboblackbox.com
Runtime data recorder · ROS 2 / DDS · Passive · Tamper-evidentRuntime data recorder · Passive · Tamper-evident

Roboblackbox

When an AI robot causes an incident, the only record is self-reported — by the machine that caused it. Roboblackbox is the independent flight data recorder — the one they can’t rewrite.

Independent evidence for underwriting, claims, and subrogation.

Talk to us See a recorded run
0.20 m safety policy 0.31 m
recording · seq 0071 · chain intact
Illustrative · 0.20 m safety policy · violation derived the moment the arm crosses the line
How robot safety certification works

Every commercial robot is commissioned with a certified safety envelope. AI changes it — invisibly.

①  Commissioned & certified

Before a robot enters a facility, the operator and integrator establish a safety envelope through commissioning — a documented baseline of exactly how it moves: maximum reach, closest approach to people, force limits. This certified baseline is what the insurer prices against.

②  A new model update can change everything — without anyone realising

AI-controlled robots receive model updates the same way a phone receives a software update. The robot starts moving differently. No alarm sounds. No re-certification is triggered. The operator, the insurer, and the regulator have no way of knowing the certified safety envelope no longer reflects how the robot actually behaves.

③  Roboblackbox detects the violation

We independently record every movement against the operator’s declared safety policy. When the robot’s actual behaviour crosses the certified line — as in the animation above — we derive a tamper-evident violation record. The robot’s own log showed no fault. Ours did.

The runtime evidence gap

When an AI robot causes an incident, who saw it happen?

The manufacturer controls the logs

Every existing record of a robot incident is produced, held, and formatted by the party that built the machine — the party with the most to lose.

AI updates drift behaviour silently

Robots are commissioned with a safety envelope — a verified baseline of how they move, how much force they apply, how close they get to people. AI model updates can silently drift that behaviour past the certified envelope. The robot won't flag it. There is no external record it happened.

Insurers have no independent way to verify, price, or recover

Without independent behavioural data, insurers have no independent way to verify claims, price the risk, or build a subrogation case. The only account of an incident comes from the party with the most to lose.

The market has already responded

January 2026 ISO endorsements (Verisk CG 40 47) give insurers the tools to exclude generative AI injuries from standard policies. The specialty market is inheriting a risk it cannot price.

What Roboblackbox is

A passive recorder. Never in the control path.

Roboblackbox sits alongside an AI-controlled robot — without touching it, modifying it, or interfering with what it does. It observes the robot’s commands and movements on the bus, seals each record so that any alteration is immediately detectable, and independently derives safety findings from the data after the fact. No modification to the robot. Nothing written to any actuator. Deploying it cannot cause an incident, by design.

Independent derivation

Findings the robot never computed, derived from raw recorded data — and re-derivable by any third party from the record alone.

Passive non-interference

In any claim or dispute, the record cannot be challenged as having interfered with the incident — because it is architecturally incapable of doing so.

Tamper-evident proof

Every record is hash-chained at receipt. Alter one byte and verification fails — the tampering becomes the evidence.

One recorded run — from our proof of concept

Robot says no fault. The record says otherwise.

policy: operator_separation_v1 · threshold: 0.20 m — declared by the operator, configurable per site
The robot's own log
No fault.
Produced no evidence anything happened.
Roboblackbox — derived from the sealed record
9.97 cm — violation
Closest approach to a person, against the operator's 0.20 m policy. Derived post-hoc at seq 76. Re-derivable by any verifier.
$ verify_chain observation.chain
→ altered one byte in entry 76 …
CHAIN_INVALID at seq 76 — record rejected, tampering proven

No contact. No injury. No witness. The robot produced no evidence this happened — the sealed record did. That is the difference between an allegation and evidence.

Three outputs, mapped to insurance workflows

Evidence in the formats the market uses

For claims handlers & counsel

Incident Report

On demand: an independent, tamper-evident record of the hours before an incident — which AI model version was running, and whether the robot stayed within its envelope.

For underwriters

Fleet Safety Scorecard

Weekly and retrospective — the loss-run equivalent for robot behaviour. Proximity violations, envelope exceedances, drift since commissioning. Derived from the sealed chain, not self-reported by the robot.

For subrogation

Model-Update Dossier

Per AI model deployment: what changed, and whether it pushed the robot outside its envelope — tying behavioural change to the model version that introduced it.

One record, two moments

The same record — before the incident and after it

Before the incident

The risk becomes priceable

This risk class has been priced on exposure, not behaviour — because behavioural data didn't exist. The Safety Scorecard is the loss-run equivalent for robot behaviour: how often the robot came closer than its policy allows, whether behaviour has drifted since commissioning. That data now exists.

Raw data stays on-site. Derived scorecards and dossiers leave only on explicit operator action.

After the incident

Claims answered. Recovery enabled.

Courts trust records created before a dispute begins. By the time a claim lands, the Roboblackbox record is already sealed and timestamped — it cannot be assembled after the fact. The dossiers collected before the incident become the subrogation case.

We create the record before it is needed — afterwards is too late.

One record — enables pricing before the incident, answers claims after it.

Who we are

Security infrastructure engineers

Mehmet Cenk Ayberkin

Co-founder & CEO

6 years Microsoft Defender — USB device control, security infrastructure (macOS). 5 years Meta — Messenger desktop update & install infrastructure, Facebook iOS performance/reliability, AI infrastructure (GPU allocation).

Yuval Tzairi

Co-founder & CTO

7 years Microsoft Defender — runtime security engineering, core backend services. Leads the recorder and policy-analysis architecture.

Eighteen combined years building security software at Microsoft Defender and Meta — recording adversary-grade events on machines we didn’t control. Both full-time. Working end-to-end proof of concept complete; validating the evidence standard with insurers and operators now.