RotorLab logoRotorLab
Security posture, with evidence

“Is your aircraft secure?”
Answer it with a document, not an opinion.

The question is already on procurement questionnaires, insurance renewals and agency contracts — and until recently there was no way to answer it that anyone could check. There is now a published, open standard for drone security configuration. RotorLab measures the flight logs you are already storing against it, and hands you the evidence.

The standard, not our opinion

The yardstick is public. That is the point.

The UAS Security Verification Standard is open, vendor-neutral and free to read. Every requirement carries a permanent identifier, an assurance level and a published rule. Which means the result you hand to a client is not a vendor’s say-so: anyone holding the same flight log and the same version of the standard can run it themselves and get the same answer.

  • You are not asking anyone to trust us. The rule behind every verdict is published. So is the log hash it was decided from.
  • Three assurance levels. L1 for any organization, L2 for public safety and recurring operations over people, L3 for high-consequence and contested RF.
  • It moves without you. New advisories and new releases land in the tables the checks read, and every report records the as-of date it used.
N512RL UASVS L2

1 red and 7 amber failures are open. 24 requirements could not be decided from a log, and none of those count as passes.

redU5.1.1Loss of the pilot link triggers a failsafe
FS_THR_ENABLE = 0  (ships as 1)
amberU1.1.4No disclosed, fixed vulnerability for its version
CVE-2026-38971  fixed in 4.7.0
amberU6.1.1A geofence is enabled
FENCE_ENABLE = 0
Every verdict reproducible from the same log bytes
What you get

Findings you can act on, and a document you can send.

It reads the logs already in your account. Nothing to install, nothing to upload twice.

What to fix, worst first

A disabled failsafe, a geofence switched off, pre-arm checks weakened from default, firmware carrying a published vulnerability with a named fixed release. Each one names the parameter it was decided on and the setting to change.

The airframe that drifted

Two aircraft that left the shop identical, answering the same requirement differently. The fleet view gathers open failures by requirement — one requirement failing on four airframes is one job, not four findings buried in a grid.

A conformance claim

A dated document naming every aircraft, what was checked, what was accepted with a reason, and how much of the standard was never assessed. The thing a procurement officer asks for.

Why you can hand it over

It will not invent a pass to make the number look better.

Plenty of requirements cannot be decided from a flight log at all — some need a person, some need live state from your ground infrastructure. A tool that quietly counted those as passing would produce a much better-looking result and a worthless one. Every screen and every report states both figures: what was decided, and what was not.

  • No scanner noise. A finding without the evidence behind it is an assertion, and the standard says so. Every one cites its parameter or record.
  • No score to argue with. Red, amber, informational — and the reason each carries the severity it does.
  • Carry a risk on the record. Accept a failure with a reason and your name against it. Accepted is never shown as passed.
The verdictWhat it means
PassDecided from the log, against a published rule.
FailDecided, and it cites the value it was decided on.
AcceptedFailing, carried deliberately, with a person and a reason.
Not applicableYou attested the condition it depends on does not apply.
Not assessedNeeds a person, or live ground-station state. Never a pass.
Not assessableThe log did not carry what the rule needed.

Run it against the logs you already have.

The Security Analyzer is an add-on on any plan, and included on Studio and above. Assess a log on its own, or every stored log in the account.

Conformance under UASVS is self-attested. RotorLab reports the evidence behind what you claim — it does not certify your operation, and no result here is an approval from any authority.