Signal-chain integrity for autonomous systems

Know when
your sensors
stop telling
the truth.

Sensors degrade in silence, and every autonomous system keeps trusting them. obsurver watches the signal chain from the outside and catches the degradation before a wrong picture becomes a wrong decision.

45 minutes with the founding team, on making your autonomous systems safer

  • Read-only
  • Software-only
  • Sensor-agnostic
Member of the NVIDIA Inception Program
Co-founders of IEEE P2020 Peer-reviewed research since 2021 Built with stack providers Sindelfingen, Germany

The problem

The blind spot every autonomous system runs with.

An autonomous stack is judged on its outputs, and nothing in the chain verifies input integrity beyond alive-or-dead health checks. When the signal chain degrades, perception keeps producing confident output from corrupted input. No fault code ever fires. You end up paying for it everywhere except the place it started.

soiling aging miscalibration vibration weather & moisture repair work interference & spoofing

Training data

Degraded frames enter datasets unflagged. KPIs turn unstable and nobody can say why.

Triage

Phantom bugs that never reproduce. Engineering weeks burned chasing a model that isn't broken.

Validation

SOTIF evidence gaps and slower sign-off, because input integrity was never measured.

In the field

A perception fault with no attribution. The blame lands on the stack, not the sensor.

You don't have to take our word for it.

Browse the full research library →

The product

One engine. Three ways to run it.

The obsurver engine measures signal-chain integrity independently of your perception stack. Every deployment below runs the same detection core.

The obsurver engine

The detection core

A fixed library of physical metrics, measured at both interfaces against each sensor's own baseline. Read-only, sensor- and vendor-agnostic.

01 · Embedded

The watchdog

In the vehicle

The engine runs on the vehicle compute as a real-time watchdog. Read-only, no cloud connection required. It monitors the full signal chain while the system operates, and raises a flagged degradation event with severity the moment a sensor departs from its baseline.

02 · Off-device

On recorded logs

In development and service

The same engine runs offline on the drive logs you already record. It surfaces degradation patterns across recordings over time, produces the input-integrity evidence SOTIF and type approval ask for, and turns blanket service intervals into condition-based maintenance.

03 · Fleet

The cloud layer, fed by both

Aggregates embedded and off-device runs

Everything the watchdog and the log runs produce flows together here, on your infrastructure. One view of which vehicles are degrading, where and why, ranked by severity, for fleet operators and program managers.

What an alert looks like

Every metric is a defined physical quantity, computed in real time against the sensor's own baseline. When one departs, the flag names the sensor, the metric, the deviation and the severity, time-stamped.

Nothing new on the operator's screen, and nothing new to do: alerts ride your existing interfaces, at asset level for maintenance and at system level for the decision.

How it works

Read-only on two interfaces. Never inside your models.

obsurver clamps onto the sensor frame before perception and onto the perception output after it: a black-box approach that needs no access to your models, weights or targets. A fixed library of physical metrics, measured against each sensor's own baseline. No model to train, none to drift.

obsurver

read-only sensor-integrity module

At the pre-perception interface

Every frame is measured against the sensor's own baseline: sharpness, noise, saturation, soiling, geometric drift and timing.

At the post-perception interface

The output is correlated against the pre-perception signal. Environment is separated from real degradation, and each fault is attributed to its source sensor.

integrity KPI per sensor flagged event, with severity evidence record

No hardware. No write access. No visibility into your models, weights or targets, and never in the control path.

Without measurement

A degraded frame passes as valid. The output is confident and wrong, the dataset quietly picks it up, and the failure surfaces in the field.

With obsurver

The frame is flagged at ingest, the fault is attributed to its sensor, and the record becomes homologation evidence. Your models never notice a thing.

Use case

The same degraded sensor comes back three times.

Once in development, once at homologation, once in the field. Each time it costs more, and each time your stack takes the blame. The sensor can be a camera, a radar, a lidar or an inertial unit: the sequence is the same.

Without obsurver

01

Silent drift

A sensor in the fleet degrades. Every health check still reports healthy.

Development

02

Phantom regression

Degraded frames enter the dataset. A perception KPI drops, and weeks go into triage on the model side.

Development

03

Evidence gap

Type approval asks for proof of the sensing performance limits. Nothing in the toolchain ever measured them.

Homologation

04

Field incident

The OEM sees a perception fault in service. The cause sits upstream, in the signal chain.

Field

05

Attribution dispute

You cannot show the inputs were out of spec, so the fault stays with your stack.

Field

With obsurver

Caught at the source

The sensor is named in development

Degradation is flagged pre-perception, confirmed and attributed post-perception, and written to an integrity record.

That one record does all three jobs. It clears the dataset in development, it evidences the sensing limits at homologation, and it attributes the fault in the field. Produced once, as a by-product of running.

Illustrative sequence. The order does not vary, only the interval between the moments.

ROI

An unmeasured signal chain is a tax on every budget below it.

Your stack rests on one silent assumption: that the inputs are what you think they are. obsurver turns that assumption into a measurement, and every budget below it gets cheaper.

Data budget

Contaminated frames stop polluting the dataset. Every kilometer driven yields more usable data.

Recovered in: data collection & curation

Engineering capacity

Every KPI regression starts with an answer instead of a hypothesis: was the input healthy?

Recovered in: R&D triage, every release

Validation & homologation

SOTIF and type-approval evidence accrues as a by-product of operation. Sign-off arrives sooner.

Recovered in: the program timeline

Field operations

Environment is separated from real degradation, and condition-based maintenance becomes a feature you resell.

Recovered in: operations & warranty

Why now

The ROI is immediate. Regulation makes it mandatory.

The budget case above stands on its own. What turns it from smart into unavoidable is that European engineering standards, type approval and liability law now converge on one requirement: prove that the sensing your stack depends on performs within spec, at approval and across the whole service life.

The SOTIF standard

ISO 21448 · ISO/TS 5083

Safety of the intended functionality

Sensor performance limitations, including degradation, must be identified as triggering conditions and tied to measurable safety KPIs. ISO/TS 5083 carries the duty into automated-driving safety, and ISO/PAS 8800 extends it to AI-based systems.

Demands: evidence of performance limits

The functional-safety standard

ISO 26262 · Ed. 3

Functional safety, revised

The upcoming third edition of the automotive functional-safety standard tightens the duty to monitor safety-relevant electronics in operation. Detecting degrading sensing moves from good practice toward hard requirement.

Demands: degradation monitoring in operation

The type approval

UN R157 · EU 2022/1426 · UN GTR

Approval for automated driving

Demonstrated perception performance, an audited safety concept and continued in-service reporting, with a UN Global Technical Regulation on automated driving in development to carry the same duties worldwide.

Demands: proof at approval, then in service

The liability regime

EU PLD 2024/2853

Product liability for software and AI

Software is explicitly a product under strict liability, component suppliers are jointly liable, and defectiveness is presumed where evidence is not disclosed. Applies from 9 December 2026.

Demands: a record you can produce in court

And it doesn't stop at approval: the EU roadworthiness revision now moving through the legislative process adds periodic inspection of ADAS and software-integrity testing of safety-relevant systems across the vehicle's operational life.
And it doesn't stop in Europe: Beijing has required periodic sensor-performance inspections for L3+ autonomous vehicles since April 2025. The direction of travel is global.

Industries

One observation principle, every autonomous platform.

obsurver enters through the automotive stack, where regulatory pressure is highest, and the same capability carries to every platform that depends on its sensors to act in the world.

Autonomous stack providers

When perception fails, the stack takes the blame. The stack that can prove its own inputs wins the bid, passes homologation sooner and holds the evidence when it matters. obsurver embeds as that proof, without touching your models.

Defense and uncrewed systems

A sensor that wears out and a sensor that is attacked look the same to the platform. obsurver reports which sensor stopped being trustworthy, runs fully offline where no cloud is allowed, and uses no AI in the watchdog: nothing to train, nothing to poison.

Humanoid and industrial robotics

Collisions and line stoppages start as drift in safety margins. One read-only module covers mixed fleets across vendors, and what one platform teaches carries into every other.

Autonomous agriculture

Dust, vibration and long seasons make field machinery one of the hardest places a sensor will ever work, and harvest the most expensive time to find out one has drifted. obsurver replaces blanket manual checks with condition-based maintenance from the logs machines already record.

The company

Built by people who helped write the standard.

obsurver was founded in Sindelfingen, in the middle of the German automotive industry, by three founders who have spent their careers in autonomous sensing. Two of them co-founded the IEEE P2020 working group on automotive image quality, and the team has published peer-reviewed research on sensor degradation since 2021.

obsurver is developed together with stack providers, suppliers and research partners, so that it fits real architectures rather than idealized ones.

Fabian Schmidt

Fabian Schmidt

CEO & Co-Founder

Serial founder with 7+ years of tech leadership and an M.Sc. in Entrepreneurship from Babson College. Built companies across consulting, supply chain and mobility, and is one of Germany's youngest guest lecturers for AI and entrepreneurship.

LinkedIn →
Benjamin May

Benjamin May

CTO & Co-Founder

M.Sc. in Physics, University of Greifswald. Spent 15+ years leading ADAS and autonomous-driving system development for global OEMs, and co-founded the IEEE P2020 working group on automotive image quality.

LinkedIn →
Dr. Sven Fleck

Dr. Sven Fleck

CSO & Co-Founder

M.S. and Ph.D. in Computer Science, University of Tübingen. Advises premium OEMs on imaging, is co-founder and Vice-Chair of IEEE P2020, and has 35+ scientific publications alongside expert-reviewer work for the European Commission.

LinkedIn →

Backed by

Next Mobility Labs

obsurver was built inside Next Mobility Labs, the global mobility venture studio. NML acted as institutional co-founder: strategic guidance and access to a mobility and industrial network across Europe.

nextmobilitylabs.com →
Göran Göhring

Göran Göhring

MD, Next Mobility Labs · Angel Investor

Peter Mertens

Peter Mertens

Former Audi Board & Volvo Cars CTO

Joachim Langenwalter

Joachim Langenwalter

Board dSPACE · Former NVIDIA Director

Sabina Jeschke

Sabina Jeschke

Advisory Board Rheinmetall & Aumovio

Dirk Wollschläger

Dirk Wollschläger

Former General Manager, IBM Global Automotive

Bram Schot

Bram Schot

Former Audi CEO & Board of Volkswagen

Next step

See what your signal chain is really delivering.

A 45-minute technical session with the founding team, on your architecture, your sensor set and your own recorded data.