Annualised value
$16.1M
When one factory proves the loop, the question becomes governance: how do you promote a model across sites, hold an SLA against a production commitment, and keep an export-controlled program isolated while still learning from the fleet?
Sites live
4
▲ +33% increase
Stations
184
▲ +21% increase
Fleet RFT
97.6%
▲ +6.9% increase
SLA breaches
0
■ 0.0% no change
| Month | Everett | Charleston | Wichita | Queretaro |
|---|---|---|---|---|
| Jan | 94.1% | 91.6% | 93.2% | 86.4% |
| Feb | 95.2% | 93.2% | 94.6% | 88.9% |
| Mar | 96.1% | 94.8% | 95.8% | 90.8% |
| Apr | 96.8% | 95.9% | 96.6% | 92.4% |
| May | 97.4% | 96.7% | 97.2% | 93.8% |
| Jun | 97.9% | 97.3% | 97.7% | 94.9% |
| Jul | 98.3% | 97.8% | 98.1% | 95.8% |
| Aug | 98.7% | 98.2% | 98.4% | 96.4% |
Enterprise deployments do not share one global model. They share a registry, a promotion process, and a set of gates that every site enforces locally.
A trained model is registered with its training provenance, evaluation set and the structures and materials it is qualified for.
Models in registry148
The candidate is replayed against held-out as-built data from every site, including sites it was not trained on.
Replay corpus4.2M holes
Predictions are simulated against each site’s as-built twin. A model that disagrees with a site’s physical reality does not promote there.
Gate pass rate71%
Site engineering approves promotion per station and per agent. Rollback to any prior version is a single, audited action.
Rollback time< 60 s
A 99.9% uptime target on the control plane, and — more importantly — a defined degradation path. Losing connectivity drops agents to advisory, never to an unsafe or blocking state.
| Month | Measured uptime |
|---|---|
| Mar | 99.94% |
| Apr | 99.97% |
| May | 99.91% |
| Jun | 99.99% |
| Jul | 99.96% |
| Aug | 99.98% |
Enterprise agreements blend platform subscription with outcome-based components on the numbers the plant is actually accountable for.
| Right-first-time improvement | Same stations, 90-day pre-deployment | +6.0 pts | 12% |
|---|---|---|---|
| Shim hours per join | Same joins, 12-month pre-deployment | −50% | 14% |
| Rework hours per airframe | Program quality records | −40% | 11% |
| Takt adherence | MES station cycle data | +8.0 pts | 9% |
| FOD events per month | Quality incident record | −60% | 6% |
| Escapes to next station | Station acceptance records | −50% | 8% |
| Total outcome-linked | 60% |
Baselines are agreed in writing before go-live and measured from the same telemetry the agents use. [PLACEHOLDER: contract templates available under NDA.]
Airframe geometry is among the most protected IP in manufacturing, and much of it is export-controlled. Rivetira is architected for that reality from the edge up.
Certified
Annual audit covering security, availability and confidentiality of the control plane.
Supported
US-person access controls, on-prem and air-gapped deployment for controlled programs.
Mapped
Quality records, NCR flow and traceability mapped to aerospace quality requirements.
In progress
Information security management system certification underway. [PLACEHOLDER: target date]
Rivetira is priced on the metric it moves. This is the value stack from a representative 14-station wing-box deployment.
| Value source | Annualised value (USD) |
|---|---|
| Shim labour removed | $4.9M |
| Rework hours avoided | $3.6M |
| Rate capacity unlocked | $3.1M |
| Scrap & escapes avoided | $2.2M |
| Overtime reduction | $1.4M |
| Inspection labour | $0.9M |
Annualised value
$16.1M
Platform cost
$2.7M
Payback period
2.4 mo
Net revenue retention
136%
Every agent starts by watching. It is promoted only when its measured accuracy clears the mechanic-plus-metrology baseline and the twin agrees.
Weeks 1–4
Agent observes the station, predicts every outcome, actuates nothing. Accuracy measured against what the mechanics actually do.
Weeks 4–10
Agent recommends feed, shim geometry and sequence. A human accepts or rejects; every rejection becomes training data.
Weeks 10–20
Agent actuates with a human in the loop and a live fail-safe stop. Airworthiness-critical dispositions still require sign-off.
Week 20+
Agent runs the step. Humans handle exceptions and the twin gates any change to the control policy.
| Week | Agent accuracy | Mechanic + metrology baseline |
|---|---|---|
| Wk 2 | 88.2% | 94.1% |
| Wk 4 | 91.4% | 94.0% |
| Wk 6 | 93.6% | 94.2% |
| Wk 8 | 95.2% | 94.1% |
| Wk 10 | 96.4% | 94.3% |
| Wk 12 | 97.1% | 94.2% |
| Wk 16 | 97.8% | 94.1% |
| Wk 20 | 98.3% | 94.2% |
| Wk 24 | 98.6% | 94.3% |
Rivetira is not a rip-and-replace. It connects to the drilling machines, crawlers, trackers, shim cells, sealant robots and MES already on your floor over APIs and OT protocols.
OPC UA, MTConnect, MQTT, ROS 2, REST and file-drop connectors. Read-only shadow mode first; write-back enabled only after twin validation.
Sort any column. The same table backs the audit export an airworthiness engineer hands to a regulator.
| FA-01 · Fuselage section join | Section 41/43 | 0.041 mm | 18 h | ||
|---|---|---|---|---|---|
| FA-02 · Wing-body join | Wing box | 0.062 mm | 31 h | ||
| FA-03 · Empennage attach | Vertical/horizontal | 0.028 mm | 9 h | ||
| FA-04 · Systems installation | Hydraulics/electrical | 0.055 mm | 12 h | ||
| FA-05 · Final assembly | Interiors/doors | 0.037 mm | 6 h | ||
| WG-11 · Wing skin-to-spar | Lower skin | 0.033 mm | 22 h | ||
| WG-12 · Wing skin-to-spar | Upper skin | 0.048 mm | 26 h | ||
| FS-21 · Fuselage panel | Barrel section | 0.030 mm | 11 h |
Plant directors, liaison engineers and airworthiness leads on what autonomy did to their numbers.
“We stopped arguing about whether the gap was 0.4 or 0.6 millimetres. The twin predicted it, the shim came off the machine right, and the join closed in one pass.”
−64% shim hours per join
“The rate ramp was going to cost us four more positions. Instead the line rebalanced itself every shift and we found the capacity inside the stations we already had.”
+38% delivered rate
“Every hole is now inspected, not one in four. My airworthiness record writes itself, and I can hand an auditor a complete trace in ninety seconds.”
100% inspection coverage
Anything else goes to the people who build it. Ask an assembly engineer or read the full FAQ.
Yes. Mixed-mode fleets are common. An air-gapped site receives signed model artefacts on offline media and emits no telemetry; it still benefits from fleet learning, just on a delivery cadence rather than continuously.
You do. Program geometry, imagery, metrology and the as-built record are yours, held on your edge infrastructure. Rivetira trains on de-identified derived features only where you explicitly permit it, and never across customers on controlled programs.
Typically one lead site to closed loop in months one to six, a second site in months five to ten with the lead site’s models as a starting point, then parallel rollout. Each additional site reaches closed loop roughly 40% faster than the one before it.
New programs are onboarded as a separate model family with their own tolerance study and twin seed. Enterprise agreements include a defined number of program onboardings per year.
A line assessment maps one station, quantifies the rework, shim and rate opportunity, and returns a modelled ROI in three weeks. No production disruption.