
Safety & reliability
What the system does on its worst day.
Any connected estate can be described by how it behaves when everything works. The more useful description is what happens when connectivity drops, a bay fails, or a unit is damaged mid-trading.
Scope note
This page describes design principles and the service model. Certification, conformity marking and site-specific risk assessment are handled per deployment and per market, and are documented with the operator.
01Principles
Four rules the design is held to.
01
Fail safe, not fail open
A fault must never leave a unit in an unpredictable state. Where a mechanism cannot confirm its own condition, the system withdraws the unit from service rather than assuming it is fine.
02
The shopper is never trapped by the system
Loss of connectivity, power or app access must not strand a shopper mid-visit or prevent a unit being returned. Local behaviour at the dock takes over.
03
Faults are visible before they are felt
Condition data is used to withdraw a unit ahead of failure. The intended experience of a fault, for a shopper, is that they never encounter it.
04
Responsibility is written down
Who inspects, who withdraws, who repairs and who signs off return to service is agreed in the deployment design, not improvised after an incident.
02Failure behaviour
Five things that will eventually happen.
Each of these is an ordinary operating event, not an emergency. The design intent is that a shopper notices none of them.
- DegradedConnectivity to the platform is lost
- Docks continue to release and accept units using local state. Events are queued and reconciled when the connection returns. Operator dashboards show the zone as degraded rather than silently stale.
- IsolatedA dock bay is faulty
- The bay is taken out of service and stops offering releases, while remaining bays continue to operate. The bay is raised as an exception for service.
- WithdrawnA unit reports a condition fault
- The unit is flagged and withheld from release at its next return, then rotated out during trading hours and replaced from the service reserve.
- SecuredMains power is interrupted
- Docked units remain secured. Return behaviour is preserved so a shopper can always end their session, and the site is raised for attention immediately.
- AssistedA shopper cannot complete a release
- An assisted route exists at every deployment. Centre staff can release and accept units without the app, using an authorised operator action.
03Service discipline
How safety is kept true after launch.
Inspection cycle
A scheduled physical inspection cycle sits alongside condition data, at a frequency agreed per site and raised for outdoor environments.
Withdrawal authority
Both centre operations and the service provider can withdraw a unit immediately. Neither has to wait for the other to act on a safety concern.
Return to service
A withdrawn unit re-enters service only after the recorded fault is closed, so a unit cannot quietly return to the fleet unresolved.
Incident record
Safety events are recorded with the unit, the dock, the time and the action taken, so patterns are visible across a deployment rather than lost in a shift handover.

Next step
Ask us the hard reliability questions early.
Failure behaviour, withdrawal authority and inspection cycles are agreed during deployment design. Raising them at assessment is the point at which they can still shape the design.