SYSTEMS
HomeProductWhy usComplianceValidationEvaluateFAQContact
Prognostics for spacecraft actuators

Know the remaining life of every actuator on test, with the uncertainty attached.

G0 turns the telemetry your rig already records into an uncertainty-bounded remaining-useful-life estimate for brushless DC motors, harmonic drives and ball screws, so your test lead can decide to extend, inspect or stop before the unit decides for them. It ships as a Docker container and runs air-gapped on your own hardware.

Evaluate G0 on a full runSee the evidence
Recorded G0 run
NOMINAL
NODE_ISOLATED
Health
0.00
Remaining life
–
Run
0%
Open this run in Evaluate
The problem

Wear-out is gradual, invisible until late, and expensive to find the hard way.

Life tests run for weeks on hardware that is slow to replace. Teams stop early and learn little, or run to failure and lose the unit and the schedule slot.

From rig data to a decision in three steps.

1 · CONNECT

Ingest rig data as CSV: motor current, temperature, vibration, position error and torque. No new instrumentation.

2 · MODEL

A physics-informed model tracks each actuator's degradation continuously, on your hardware, with no network access.

3 · ACT

Health state, remaining life and alarms update with every batch of data, a basis for extend, inspect or stop decisions.

Outputs

What your test team gets.

RUL WITH UNCERTAINTY

Remaining useful life in days with a stated interval, so the number can be acted on, not just reported.

HEALTH STATE AND ALARMS

Healthy to failure imminent at a glance, plus degradation and sudden-change alarms with thermal and electrical false-alarm suppression.

LOCAL CONSOLE

A per-rig console and history, entirely inside your network.

Evidence

Tested on real failures, with the limits stated.

8.79 days

Mean remaining-life error, four real bearing failures, leave-one-out

27.9%

Lower error than a naive baseline, same protocol

One of the four underperformed the baseline, and we publish it. Method and per-failure results

Deployment

Deploys inside your facility, as a Docker container.

OFFLINE INSTALL

Delivered as a signed container image and loaded without internet or registry access.

ZERO EGRESS

No outbound connections. A local console for your team, plus a separate authenticated, read-only admin view.

YOUR LICENCE SERVICE

The licence service ships in the bundle and runs on your hardware, pooled across your rigs.

PER-RIG HISTORY

Telemetry, predictions, faults and state changes are logged per rig to storage you mount.

Full deployment specification · Data sovereignty

Next step

See it on a full run, or bring us your own.

Evaluate G0 on a full run →Request a briefing →
Product

Remaining useful life for rotary actuators, from signals you already record.

What G0 tracks, what it needs from your rig, what it hands your test team, and how it deploys.

What G0 tracks

G0 follows the mechanisms that end rotary-actuator life: bearing fatigue, gear crack growth, thermal stress and, in vacuum and TVAC tests, the condition of solid lubricant. It infers them indirectly from signals the rig already produces, so there is no sensor on the failing component to add or to fail.

What it needs from your rig

  • Five signals: motor current, temperature, vibration RMS, position error and torque.
  • One optional signal: vacuum pressure, which enables the vacuum end-of-life alert.
  • CSV ingestion, processed at 10 Hz. Most existing data-acquisition exports work as they are.

What it hands your test team

  • Remaining useful life in days with an uncertainty interval.
  • Health state: healthy, minor wear, degraded, failure imminent.
  • Degradation alarm when the trend crosses a calibrated level.
  • Sudden-change flag for step events such as debris or shock.
  • False-alarm suppression for thermal-expansion transients and electrical events such as radiation-induced current spikes.
  • Per-rig history of telemetry, predictions, state changes and faults.

Reading the uncertainty

A remaining-life figure without error bars cannot support a decision. G0 reports an interval and separates two sources of uncertainty: noise in the measurement, and distance from what the model has seen before. When the second rises, the actuator is behaving in a way G0 has not met, and the estimate should be read accordingly.

Vacuum end-of-life alert

Lubricant-depletion alert for vacuum and TVAC testing. When a vacuum pressure signal is provided, G0 flags end-of-life lubricant conditions at high torque.

It is raised at end-of-life conditions. It is not an early warning, and it cannot yet tell true depletion from ordinary wear-out. It stays silent at ambient pressure, which you can see on the Evaluate page.

Deployment

G0 is delivered as a single Docker container that you run on your own hardware, inside your own network. This is what your IT and security teams will want to see.

PackagingOne Docker container image. Compiled, with no source code in the image.
InstallationLoaded offline from a signed bundle. No internet or registry access needed.
RuntimeRuns as a non-root user. One container serves many rigs, each with its own slot.
NetworkNo outbound connections. The console is served on one local port; the admin view is on a separate port, authenticated and read-only.
StorageMounted volumes for signed model files, licence, input CSVs and per-rig history.
ComputeCPU only. No GPU required.
LicensingHardware-locked, annual. The licence service ships in the bundle and runs on your hardware, pooled across your rigs. Staged degradation in an outage; signed emergency unlock.
IntegrityCryptographically signed model files.

Your bundle ships with its own deployment instructions and compose file.

Evidence

8.79-day mean remaining-life error on real bearing failures, leave-one-out. Method, per-failure results and limits.

Evaluate G0 on a full run
Why AstraState

Prognostics built for scarce failure data.

Hybrid prognosis for scarce failure data, evaluated the way a reviewer would.

Hybrid prognosis, by design

Prognostics literature distinguishes physics-based, data-driven and hybrid approaches. Physics alone is brittle across operating regimes, and data alone starves when failures are rare. G0 is physics-informed: degradation physics constrains what the model may predict, and learning from data covers what physics cannot capture.

The result is an estimate that stays physically plausible with little failure data, and an explicit signal when conditions fall outside what the model has experienced.

Evaluated the way a reviewer would

We test on real failures the model has never seen (leave-one-out), with one fixed configuration. Choosing the best setting per test failure would leak the answer into the result, so we do not. We publish the per-failure spread and the comparison against a naive baseline, including the trajectory where G0 lost to it.

What we do not claim

  • No alarm false-positive rate is reported on real or synthetic data in our white paper. Ask any prognostics vendor, us included, for the protocol behind such a number.
  • The vacuum alert is an end-of-life indicator, not an early warning.
  • Four real failures is a small sample.

Built for closed environments

Most prognostics products assume a cloud connection. G0 assumes the opposite: air-gapped, on your hardware, no telemetry. Data sovereignty is the starting constraint of the design, not an add-on.

Why existing approaches stall

Prognostics research has long noted that actuator fault-progression data is scarce, because few units are ever run to failure. Physics-only models are hard to calibrate across operating regimes. Purely data-driven models need failure histories that do not exist, and extrapolate poorly outside their training conditions.

Who it is for

Programme and test leads, and the reliability and mechanisms engineers who answer to them, running life, thermal-vacuum and qualification campaigns on rotary actuators: at spacecraft primes, subsystem suppliers and test laboratories where data cannot leave the building.

Why now

Test campaigns are getting longer and costlier per article while failure data stays scarce. Practical on-premise deployment of modern models changes what a test team can know during a run, not only after it.

Compliance

Your sensor data never leaves your facility.

Air-gapped by design, with no telemetry and no outbound connections.

Air-gapped by design

G0 runs entirely inside your network. It needs no internet connection and makes no outbound calls, in normal operation or in emergencies. Your security team can verify that by inspecting the deployment's network behaviour. Deployment specification

No telemetry

No usage data, sensor data, logs or results leave the deployment. We do not receive them and have no route to.

Sensitive environments

G0 is designed with ITAR-sensitive environments in mind. That describes a design principle. It is not a certification or compliance claim, and your own export-control and security review still applies.

Licensing without connectivity

Licences are pooled across your rigs and checked inside your network. If the licence service becomes unreachable, G0 degrades in stages toward lockout instead of stopping abruptly. For extended outages, a signed emergency-unlock procedure works out of band, with no telemetry or remote access.

What is in the container

Trained inference components only. Training code and raw model weights are not shipped. Model files are cryptographically signed so you can confirm what you are running.

This website

The Evaluate page replays recorded simulator runs. It uses no customer data and does not run G0 on anything you enter.

Validation

Tested on real failures. Limits stated up front.

One real-data result, the method behind it, and what it does not show.

Headline result (real data)

8.79 days

Mean remaining-life error (RUL-MAE) across four real bearing failures, leave-one-out

27.9%

Lower error than a naive baseline, same protocol

RUL-MAE is the mean absolute difference between predicted and actual remaining life. Dataset: IMS/Rexnord bearing run-to-failure data. One fixed configuration; no per-failure tuning.

What this does and does not show

It answers the question a test planner asks: for a real degrading component, how close is the predicted remaining life to the truth? It does not address alarm timing or false-alarm rate, which this version of the white paper does not report on real or synthetic data.

Four real failures is a small sample. Leave-one-out is a conservative protocol, and the per-failure table below shows the spread. On set3_bearing3, G0 was worse than the naive baseline on this metric.

Real versus synthetic

The headline result uses real data only. The runs replayed on the Evaluate page are simulator output, with thermal and shock events injected where labelled. They show how G0 behaves. They are not evidence of accuracy on real hardware.

The vacuum end-of-life alert has been tested on simulator data only. It fires at end-of-life conditions and cannot yet separate true lubricant depletion from ordinary wear-out. We quote no lead time.

Technical white paper · September 2026

Read the white paper

Executive Summary

Actuator failure on spacecraft — brushless DC motors, harmonic drives, ball screws — is difficult to predict and expensive to get wrong. Unscheduled failure risks mission loss; overly conservative maintenance schedules waste flight hardware and budget that could extend mission life.

G0 is a physics-informed AI system, built by AstraState Systems, that estimates Remaining Useful Life (RUL) for these actuator types. It is deployed as an air-gapped, on-premise container with no telemetry and no external network dependency — a deployment model built for environments where sensor data cannot leave the customer's control.

This paper reports one result: RUL prediction accuracy, validated against real bearing run-to-failure data from the IMS/Rexnord dataset, using a leave-one-out protocol across all four documented real failures. We report this number and how it was produced in full, rather than pairing it with a second, less certain claim to make the headline look broader than it is.

1. The Problem

Spacecraft actuators degrade gradually before they fail outright — bearing wear, lubricant breakdown, gear mesh degradation. The physical signal is present in motor current, vibration, temperature, and position error well before failure. The difficulty is threefold:

  • Failure data is scarce. Spacecraft actuators rarely run to failure in the field — that is the point of a space program. Real run-to-failure datasets are limited to ground-test rigs and industrial analogues.
  • Physics-only models are hard to calibrate across operating regimes; pure black-box ML models generalize poorly outside the exact conditions they were trained on and offer no physical interpretability.
  • Any prognostics claim is only as strong as the data it was tested against, and only as honest as the paper is about what that data can and cannot support.

G0 pairs physics-informed modelling with an evaluation method designed to avoid the most common way these numbers get overstated: tuning against the same data used to report performance.

2. Methodology

2.2 Evaluation Data

The result in this paper is evaluated against the IMS/Rexnord bearing run-to-failure dataset: four documented real bearing failures, evaluated leave-one-out — the model trains on three failures and is tested on the fourth, held out entirely, repeated so each of the four failures serves as the test case once.

2.3 Avoiding Test-Set Leakage

A single, fixed model configuration was used across all four held-out splits. No per-split hyperparameter search was used to select the reported result — a per-split search was run separately during development and confirmed to produce a similar mean but is not the number reported here, because selecting the best configuration per test split would let information about the held-out failure leak into model selection. The number in this paper reflects one configuration, evaluated identically across all four real failures, with no tuning advantage given to any individual split.

3. Result: RUL Prediction Accuracy

Evaluated leave-one-out across all four documented real bearing failures in the IMS/Rexnord dataset, G0 achieved a mean RUL prediction error of 8.79 days, a 27.9% improvement over a naive baseline (mean-RUL extrapolation from the training failures).

Held-out failureRUL-MAE (days)Naive baseline (days)Improvement
set1_bearing38.899.829.5%
set1_bearing48.789.8210.6%
set2_bearing12.2715.2785.1%
set3_bearing315.2313.84−10.0%
Mean8.7912.1927.9%

Table 1. Per-trajectory breakdown, single fixed model configuration, no per-split tuning. Note set3_bearing3 underperforms the naive baseline on this metric alone — included here rather than omitted, consistent with reporting the full leave-one-out spread rather than a favorable subset.

This result answers the question a maintenance planner needs answered: given a real degrading actuator, how close is the predicted remaining life to the true remaining life? It does not address alarm-timing false-positive rate, which is not reported in this version of the paper.

4. Deployment Model

G0 ships as an air-gapped Docker container with a hardware-locked annual license, designed for environments — defense, aerospace, and other regulated sectors — where sensor data cannot leave customer premises under any circumstances.

  • No telemetry, no phone-home, no logs leaving the deployment environment at any point in normal or emergency operation.
  • Pooled-token licensing across a customer's rig fleet, with a graceful degrade-to-lockout sequence on connectivity loss rather than an abrupt hard stop, and a signed, out-of-band emergency-unlock procedure for extended outages that requires no telemetry or remote access to use.
  • The shipped model artifact includes trained inference components only (context encoder, energy model, physics head); training code and raw model weights are not included in the deployed container.

5. Scope and Limitations

This paper reports RUL prediction accuracy only. It does not report an alarm false-positive rate, on either real or synthetic data. Readers evaluating G0 for a maintenance program should treat alarm-timing performance as a separate question, and should ask any prognostics vendor — including us — for the specific evaluation protocol and dataset behind any alarm-calibration number before relying on it.

The IMS/Rexnord dataset provides four real bearing failures. This is the standard public dataset for this kind of evaluation, and leave-one-out across all four is a conservative protocol, but four failures is a small sample; the per-trajectory spread in Table 1 is included specifically so readers can see that spread rather than only the mean.

6. Conclusion

G0 demonstrates real-data RUL prediction accuracy, evaluated leave-one-out against the standard public run-to-failure bearing dataset for this problem class, with a fixed model configuration and no per-split tuning advantage. We report this one result in full, including the per-trajectory spread and the naive-baseline comparison, and we do not pair it with an unverified second claim.

For a technical evaluation or deployment discussion, contact AstraState Systems.

7. Glossary

  • RUL (Remaining Useful Life): the estimated time remaining before a component is expected to fail, expressed in days.
  • Leave-one-out evaluation: a validation method where the model is tested on one real failure it has never seen, having been trained only on the others — repeated so every real failure gets a turn as the held-out test case.
  • RUL-MAE: mean absolute error between predicted and true remaining useful life, in days.
  • Naive baseline: a simple non-learned predictor (mean RUL of the training failures) used as a reference point for how much a learned model actually improves on the simplest reasonable guess.
  • Held-out data: data never used during training, calibration, or model selection — used only once, at the end, purely to measure performance.
  • Air-gapped: a deployment with no network connection to the outside world, used where data cannot be permitted to leave a secure facility under any circumstances.
FAQ

The questions test and programme leads ask.

Straight answers on data, validation, limits and fit.

Does my data leave my network?

No. G0 runs air-gapped with no telemetry and no outbound calls. We never receive your sensor data, predictions or logs.

Who owns the data and the results?

You. G0 runs on your hardware and everything it produces stays there.

What data do I need?

Motor current, temperature, vibration RMS, position error and torque from your rig, as CSV. Vacuum pressure is optional and enables the vacuum end-of-life alert. For validation, at least one run to failure helps most.

What does integration involve?

Pointing G0 at your existing data-acquisition exports. There is no new instrumentation and no change to your test procedure.

How is G0 deployed?

As a single Docker container, loaded offline from a signed bundle and run on your own hardware. It serves many rigs, mounts your storage for data and history, and makes no outbound connections.

Do we need internet access to install or run it?

No. Installation and operation are fully offline.

What hardware does it need?

CPU only; no GPU is required. We will confirm sizing for your number of rigs and data rates during the briefing.

Which actuators does it cover?

Brushless DC motors, harmonic drives and ball screws, assessed through bearing, gear and lubricant wear.

Does G0 replace qualification testing?

No. It informs decisions during testing. Qualification criteria and sign-off remain with your own process and standards.

What is blind validation?

You give us run-to-failure data without revealing the outcome. We produce predictions from the data alone and hash-check them so they cannot be altered afterwards. You then compare them with what actually happened.

What happens after I request a validation?

We reply within 3 working days to discuss your setup and data. If it is a fit, we run a blind validation on your data and walk you through the results before you decide anything.

How is G0 different from generic machine learning?

G0 builds in the physics of degradation and reports uncertainty, so it stays plausible with little failure data and tells you when it is outside its experience.

How accurate is it?

On four real bearing failures, leave-one-out, mean remaining-life error was 8.79 days, 27.9% lower than a naive baseline. One failure was worse than baseline. We do not report an alarm false-positive rate.

Is the vacuum alert an early warning?

No. It fires at end-of-life lubricant conditions in vacuum or TVAC tests at high torque, and cannot yet separate true depletion from ordinary wear-out.

What if the licence service is unreachable?

G0 degrades in stages toward lockout. For long outages, a signed emergency-unlock procedure works without any remote access.

Can I trust the numbers on the Evaluate page?

They are real G0 output on recorded simulator runs, with run ID and model version shown for each. They show behaviour, not accuracy on your hardware.

Contact

Bring a test setup. We will tell you if G0 fits.

A working conversation, with a reply within 3 working days.

What to expect

A briefing is a working conversation, not a sales call. Bring a test setup, and we will tell you honestly whether G0 fits, what data you would need, and what a blind validation on your own run-to-failure data would involve. We reply within 3 working days.

From first look to decision

Explore recorded runs and size your own cost of failure on the Evaluate page, with no data exchanged. If it fits, we run a blind validation on your run-to-failure data: you hold the outcome, we commit our predictions in advance and hash-check them, and only then do you compare. You review the results, then decide.

Thanks — we'll follow up within 3 working days.

Evaluate

Watch G0 work through a full run to failure.

Replay recorded runs and inspect what G0 reports at every point: health, remaining life with its uncertainty, and the alarms with their timing. Or size the cost of unplanned failure on your own programme. Each view has its own share link, so a test engineer and a budget holder can send each other exactly what they saw.

Failure modes (choose up to two)

Test condition

Vacuum end-of-life alert: for vacuum and TVAC testing. When a vacuum pressure signal is provided, G0 flags end-of-life lubricant conditions at high torque. It is raised at end of life and is not an early warning.

REAL PIPELINE OUTPUTSpeed 2×

Predict, then reveal

At what point in the run (% of life) will the degradation alarm first fire for the first selected mode?

50%

Events log

Provenance

What does an unplanned failure cost you?

Enter your own figures. Nothing is pre-filled from an industry average, because no reliable public failure rate exists for actuators in ground test.

Reference points for cost of one failure (US dollars, selecting one switches the currency), from real NASA project status reports (2004 dollars, small instrument programme): late thermal-vacuum failure with rework and retest about $30k; 35 days of schedule contingency about $50k+; launch delay about $226k. Source. Large programmes will be far higher.

The 30% default is the low end of published industrial benchmarks for condition-based versus reactive maintenance (roughly 30–40% lower maintenance cost, from a US DOE guide that traces to a 2001 pump-industry article). It comes from industrial equipment, not spacecraft actuators. Replace it with your own view.

Estimated annual unplanned-failure exposure

Fleet × failure rate × cost × criticality. Arithmetic on your inputs, not a forecast or a quote.

Request a validation on your data

If this estimate is worth acting on, tell us about your setup and we will reply within 3 working days.

Thanks — we'll follow up within 3 working days.

© 2026 AstraState Systems