Three obligations we take on
An agent acting on hazard data is only as safe as the honesty of the data it is given. A model that cheerfully returns a number for a question it cannot answer will get someone hurt. So the platform owes an agent three things, and owes them in machine-readable form.
- Provenance per figure. Not a footer credit on a page — a source and a licence travelling with the value itself, so an agent that reproduces a figure can also reproduce its origin.
- Age per figure. Every value states when it was measured. Nothing is presented as live or certain when it is not, and an agent can decide for itself whether an hour-old wind field is good enough for the question at hand.
- Refusals as values. When a question falls outside what we measure, the answer is a structured refusal carrying the reason — not a plausible number, not a silent empty result. Some questions are refused by name because answering them badly is worse than not answering: seismic-retrofit advice is one, and it stays refused.
The register is the contract
Marketing claims are cheap; a register a customer can query is not. OrbiVigil publishes its own capability register — for every product and every market, whether the capability is live, beta or planned, computed at the moment of the request rather than edited by hand. Every status claim on this website is meant to be checked against it. If a page says live and the register says planned, the page is wrong.
The same principle governs the data surface. The confidence-scored events, observations, wind and danger layers an agent consumes are the same ones the live map renders; there is no second, more flattering dataset behind the console. A Model Context Protocol server exposes that intelligence as tools, so an AI assistant can query it directly without an account.
What runs today, and what the architecture is built for
Today. Open, edge-cached JSON for events, observations, wind and danger layers is live. The MCP server is live. The capability register is live and computed per request. Machine-readable provenance, data age and a confidence level accompany the payloads, and analyst validation — never an automatic promotion — is what turns a probable detection into a confirmed event.
Built for, not yet serving. The same contract is designed to be what a robotic asset acts on, and a unified alert delivery standard across every hazard product is on the roadmap. Both are described as planned here and on the homepage until they serve.
Why this matters to a buyer, not just to an engineer
An institution adopting AI is asked, sooner or later, to explain a decision. A system whose every figure arrives with a source, a timestamp and an explicit uncertainty is a system whose decisions can be reconstructed months later in front of an auditor, a regulator or a court. That is not a feature we added for agents; it is the reason the platform is usable by an authority at all.
Related: the world model agents read; physical AI — the assets that act on it.