Jump to content

Flight software, on a proprietary baseline

From Apollyon Wiki
Software · proprietary autopilot baseline, authored control laws & HIL verification · core subsystem

The flight-critical control loop runs on Embention's Veronte Autopilot 1x, a certified commercial baseline configured for each vehicle. Apollyon authors the guidance modes, control laws, flight envelope limits, and mission logic that run on top of it, verifying every release on hardware-in-the-loop simulators before flight.

01 · Foundation

A proprietary flight-control baseline

Operational defence certification in India requires flight-critical software to have a clear origin, an accountable vendor, and a documented qualification history. Open-source autopilots do not meet this standard for military systems.

Apollyon builds on Embention's Veronte Autopilot 1x, a commercial flight controller widely used across uncrewed platforms. The autopilot operates through parameterised configuration rather than source-code modification. We selected a commercial baseline because it provides a proven audit trail, vendor-backed lifecycle support, and strict configuration governance.

The baseline is not modified at source

Apollyon does not modify the autopilot firmware directly. Instead, our team maintains version-controlled configuration packages containing the control laws, guidance phases, flight envelope limits, control allocation matrices, and failsafe logic. These packages are developed in the vendor's toolchain and loaded onto the controller. The core hardware and baseline firmware remain uniform across our fleet, with one tailored configuration package for each airframe.

Fig. 01one baseline · authored layer
APOLLYON-AUTHORED LAYER OVER A PROPRIETARY BASELINE ONE CONFIGURATION SET PER PLATFORM APOLLYON-AUTHORED — CONFIGURATION PACKAGES MISSION & AUTONOMY route & terrain following · terminal-phase logic · abort and failsafe triggers CONTROL & GUIDANCE LAWS gain-scheduled loops · envelope limits · allocation matrices · per-airframe tuning sets VERONTE EMBENTION BASELINE — PRIMARY PROPRIETARY GUIDANCE–NAVIGATION–CONTROL CORE EKF state estimation · guidance modes · control loops · mixing & actuation SENSOR DRIVERS & I/O SPI · I²C · CAN-FD · UART · serial · PWM · ADS-B REAL-TIME EXECUTION & TELEMETRY deterministic GNC schedule · onboard logging · datalink framing HARDWARE VERONTE AUTOPILOT 1x triple-IMU sensing · single, quadruple and DRx redundant configurations The baseline is identical across the fleet; only the Apollyon configuration package changes.
Fig. 01 The proprietary baseline carries the flight-critical functions; Apollyon owns the configuration layer above it. New airframes change the package, not the core.
02 · Toolchain

Software lifecycle and verification

The toolchain follows four stages around a single configuration package. The exact configuration authored on the bench is what flies in the airframe and what undergoes hardware-in-the-loop simulation, avoiding translation errors between engineering and flight.

The four stages
StageToolRole
Author1x PDI BuilderControl laws, guidance phases, envelope limits, actuation allocation, and safety logic assembled as block programs.
ExecuteVeronte Autopilot 1xFlight-critical guidance, navigation and control, state estimation, and actuator commands.
OperateVeronte OpsMission planning, live telemetry, commanded actions, flight termination, and system alerts.
VerifyHIL SimulatorProduction autopilot hardware flown against simulated vehicle dynamics before any field sortie.
Fig. 02author · execute · operate · verify
THE FLIGHT-CONTROL TOOLCHAIN ONE CONFIGURATION · FOUR STAGES VERONTE AUTOPILOT 1x flight-critical execution GNC · estimation · control · actuation 1x PDI BUILDER authoring control laws · guidance · envelopes · safety upload HIL SIMULATOR verification X-Plane · MSFS · Simulink fly VERONTE OPS operations mission · telemetry · FTS · alerts command state VERONTE LINK PC ↔ autopilot transport HIL flies the production autopilot, not a model—bench results transfer to the airframe.
Fig. 02 The configuration authored in 1x PDI Builder is uploaded to the autopilot, operated through Veronte Ops, and verified on the HIL bench against a simulated vehicle.
03 · The authored layer

What Apollyon authors

The commercial baseline provides the core real-time operating environment and basic estimation routines. Apollyon designs and configures the flight mechanics: the specific control and guidance algorithms that adapt the controller to the dynamics of each vehicle.

Ownership across the stack
LayerOwnerContent
Mission & autonomyApollyonRoute and terrain following, terminal-phase sequencing, target re-acquisition, abort and failsafe triggers.
Control & guidance lawsApollyonGain schedules, envelope limits, control-loop tuning and actuation allocation matrices per airframe.
Safety configurationApollyonFlight-termination logic, safety-bit conditions, phase checklists and configuration locks.
Guidance–navigation–control coreEmbention VeronteState estimation, guidance modes, control execution, mixing and real-time scheduling.
Drivers, I/O & hardwareEmbention VeronteSensor drivers, bus and protocol support, the autopilot hardware itself.
Why the configuration layer matters

Configuring airframes through versioned packages avoids maintaining separate software forks for different aircraft. Improvements to common control or guidance logic can be evaluated across the fleet, while adapting a new vehicle requires writing only the aerodynamic and actuator parameters specific to its airframe, calibrated against the shared physics backbone.

04 · Verification

Hardware-in-the-loop before the rail

No configuration package flies until it has been validated on the bench. The Veronte hardware-in-the-loop simulator runs production autopilot hardware against high-fidelity simulated vehicle dynamics in real time. The flight controller under test is the exact unit that flies.

The autopilot receives simulated sensor streams and commands real servo actuators, verifying that control laws, guidance modes, and emergency logic execute exactly as intended in flight.

Simulation back-ends
Back-endWhat it tests
X-Plane 11 / 12Flight dynamics and control performance for fixed-wing, multirotor and VTOL models.
Microsoft Flight SimulatorExtra flight-dynamics coverage and operator training.
SimulinkCustom plant models and engineering tests connected directly to the autopilot.

Engineers inject simulated failures on the test bench—such as surface jamming, sensor dropouts, GPS loss, and electronic interference—against the identical flight software that takes to the air. Sortie telemetry then feeds empirical flight data back into our aerodynamic models to refine subsequent tuning. The sim-to-real flight loop →

05 · Governance

Configuration control and certification

Using an established commercial baseline supports both airworthiness certification and technical governance. It provides a formal audit trail for all flight-critical functions.

Every Apollyon configuration package is version-tracked, peer-reviewed, and locked before deployment. The controller enforces release locks and pre-flight checklists, preventing unauthorized field alterations and linking every sortie log back to an approved software build.

Certification basis

The flight-control baseline is supplied with vendor compliance and lifecycle documentation, which Apollyon maintains as part of each platform's formal certification evidence. Airworthiness and qualification claims are made strictly against this certified baseline.

06 · Roadmap

Veronte now, an in-house baseline next

Achieving formal military flight certification for a new autopilot core typically takes years of flight trials and tens of millions of dollars. Embention has invested many years and roughly $40 million into certifying and maturing the Veronte platform. Rather than duplicating that development at the outset—which would add substantial schedule risk to our airframe and propulsion development—we use Veronte as our initial production baseline.

This approach allows our team to focus on system-level integration, aerodynamic maturation, and serial manufacturing for initial customer deliveries. Veronte provides a proven, airworthy foundation while we build operational flight hours and scale our production lines.

Once units are in service and serial manufacturing is steady, Apollyon develops its own flight-control core in-house, in parallel. Because our control laws, guidance algorithms, and envelope safety boundaries are already authored in our configuration packages, the in-house replacement will inherit a mature flight baseline. The replacement will be validated against the same hardware-in-the-loop test benches, verified through extensive flight testing, and formally qualified before transitioning onto fielded platforms.

Flight-control baseline by phase
PhaseBaselineFocus
First ordersVeronte Autopilot 1x · Apollyon packagesScale, robustness and full-system integration
Steady productionVeronte in service · in-house baseline in developmentParallel development, HIL and flight testing of the replacement
After certificationIn-house baselineTransition platform by platform once qualified

Supply continuity for the autopilot baseline is maintained through established vendor relationships across our partner network, as outlined in our supply chain strategy.

07 · Used by

Platforms carrying this subsystem

Interfaces with: Robust flight control, Edge compute, GNSS-denied navigation.