Skip to content

Safety & reliability

What the system does on its worst day.

Any connected estate can be described by how it behaves when everything works. The more useful description is what happens when connectivity drops, a bay fails, or a unit is damaged mid-trading.

Scope note

This page describes design principles and the service model. Certification, conformity marking and site-specific risk assessment are handled per deployment and per market, and are documented with the operator.

01Principles

Four rules the design is held to.

  • 01

    Fail safe, not fail open

    A fault must never leave a unit in an unpredictable state. Where a mechanism cannot confirm its own condition, the system withdraws the unit from service rather than assuming it is fine.

  • 02

    The shopper is never trapped by the system

    Loss of connectivity, power or app access must not strand a shopper mid-visit or prevent a unit being returned. Local behaviour at the dock takes over.

  • 03

    Faults are visible before they are felt

    Condition data is used to withdraw a unit ahead of failure. The intended experience of a fault, for a shopper, is that they never encounter it.

  • 04

    Responsibility is written down

    Who inspects, who withdraws, who repairs and who signs off return to service is agreed in the deployment design, not improvised after an incident.

02Failure behaviour

Five things that will eventually happen.

Each of these is an ordinary operating event, not an emergency. The design intent is that a shopper notices none of them.

DegradedConnectivity to the platform is lost
Docks continue to release and accept units using local state. Events are queued and reconciled when the connection returns. Operator dashboards show the zone as degraded rather than silently stale.
IsolatedA dock bay is faulty
The bay is taken out of service and stops offering releases, while remaining bays continue to operate. The bay is raised as an exception for service.
WithdrawnA unit reports a condition fault
The unit is flagged and withheld from release at its next return, then rotated out during trading hours and replaced from the service reserve.
SecuredMains power is interrupted
Docked units remain secured. Return behaviour is preserved so a shopper can always end their session, and the site is raised for attention immediately.
AssistedA shopper cannot complete a release
An assisted route exists at every deployment. Centre staff can release and accept units without the app, using an authorised operator action.

03Service discipline

How safety is kept true after launch.

  • Inspection cycle

    A scheduled physical inspection cycle sits alongside condition data, at a frequency agreed per site and raised for outdoor environments.

  • Withdrawal authority

    Both centre operations and the service provider can withdraw a unit immediately. Neither has to wait for the other to act on a safety concern.

  • Return to service

    A withdrawn unit re-enters service only after the recorded fault is closed, so a unit cannot quietly return to the fleet unresolved.

  • Incident record

    Safety events are recorded with the unit, the dock, the time and the action taken, so patterns are visible across a deployment rather than lost in a shift handover.

Next step

Ask us the hard reliability questions early.

Failure behaviour, withdrawal authority and inspection cycles are agreed during deployment design. Raising them at assessment is the point at which they can still shape the design.