Drone safety management system, built on the flight record.
A hazard register with the risk scored twice, controls that point at a checklist, a manual section, a service limit or a training requirement that actually exists, a named acceptance of what remains, and the fleet's own flight data as the leading indicator. The SMS a regulator or an insurer asks a UAS program to show, on the same records as the rest of the program.
14-day trial, no card, for up to 5 people and 3 registered aircraft. Safety Management is an add-on; see pricing.
Read the full guide in the docs →
What a safety management system has to prove
An occurrence log proves hindsight. A register proves the operation thought about harm before it happened, did something about it, and named who accepted what was left.
You thought about it first.
A hazard is a standing condition that could cause harm, scored for severity and likelihood with nothing done, and recorded with where it came from: an occurrence, an audit finding, a hazard report or a change to the operation.
You did something real about it.
A mitigation links the living record that carries it. The checklist is in use or it is not; the manual section is published or it is not. Free text is allowed and visibly counts for less.
Someone put their name on the rest.
Acceptance is a permanent record: who accepted the residual risk, at what score and band, on what day, in their own words. It lapses, and says so, when the facts under it move.
Risk scored twice, side by side
Each hazard carries a raw score, with nothing done, and a residual score, with the controls in force today. The pair renders together everywhere, so the effect of your mitigations is visible as the movement between two cells.
- Severity and likelihood, 1 to 5 each. The product, 1 to 25, falls into a band under your own risk policy: acceptable, tolerable or intolerable.
- A lower residual needs a control in force. Scoring alone never makes a hazard mitigated, and a planned control counts for nothing until its day comes.
- Status follows the records, never a button. Identified, assessed, mitigated while a control is in force, accepted while the latest acceptance still applies.
- Nothing is deleted. Every scoring is kept with who, when and why. A retired hazard stays on the record, dimmed, and can be reopened.
An intolerable residual is never accepted: the register reads "needs a control, not a signature". The starting bands are RotorLab's own and come from no regulation.
Mitigations that point at living records
A control is only as good as the thing that carries it. The strong ones link a record the rest of RotorLab already keeps, so an auditor can see that it exists and is in use.
The step that carries it
Name the card and the item on it. The hazard's page shows the evidence: complete runs since the control came into force against the flights flown, how often the step failed, and whether the card has been revised since.
Flight records and checklists →A chapter of the operations manual
Link the section of your published manual that describes the procedure. A section switched off in the manual is not offered, and a control linked to one later switched off says so and stops counting.
The ops manual builder →A part's life, or a qualification
Link a component's service limit, counted down from the flights on record, or a training requirement whose sign-offs run the currency clock and stamp the manual revision in force.
Maintenance on real hours →Every mitigation carries an owner, an in-force date and a state: in force, planned or ended. An occurrence is not a control: an occurrence names the hazard it revealed and the controls it prompted, and a hazard raised from one keeps it as its source.

The signal arrives first
A hazard names the signal families it is about: battery, power, propulsion, vibration, navigation, compass, GPS, traffic and link. RotorLab's advisory scores cite the measures that drove them, so each hazard gets a count of flights in the last 90 days that drifted toward it, split into notable and loud.
- Before and after a control. The in-force date splits the flag history, so the register can say whether the control worked.
- Flags rising since acceptance. When 3 or more flagged flights since an acceptance are clearly more than the earlier rate would expect, the hazard says so with the figures. A person decides; nothing reopens on its own.
- Signals with no hazard on the register. Families cited in the last 30 days that no open hazard claims, suggested for review, never created for you.
- Advisory everywhere. Humans score the matrix; the models supply evidence and never score likelihood.
The register, as it stood on the day
The audit binder prints the register with its raw and residual scores, each hazard's mitigations with their state, its latest acceptance with who, when and why, or "lapsed" with why it lapsed, and the safety reviews: internal audit, management review, safety meeting and emergency drill, each with when the next is due.
- A code on every document. The binder's verification code covers every register it prints, so an edited PDF fails the public check at rotorlab.app/verify.
- Policy changes are visible. Tighten the risk policy and an acceptance signed in a looser band says so, with the decision a person made about it.
- A risk card before the sortie. The crew answers a weighted card on the dispatch board; at or over the threshold, going ahead needs a second name. It never grounds anything.

Questions buyers ask
The short answers. The long ones are in the docs, and sales will walk through your program.
What is drone safety management system software?
Software that keeps the risk-management half of a Safety Management System for a UAS program: a hazard register scored before and after mitigation, the controls in force, who accepted the residual risk and on what basis, occurrences and the safety reviews. RotorLab keeps it beside the flights, aircraft, maintenance and training, so a control can point at the thing that carries it.
Do I need an SMS as a Part 107 operator?
Part 107 does not require one. Insurers, public-safety agencies, enterprise clients and operators flying under waivers often do, and a documented register is the usual answer to "show us how you manage risk". Whether your operation needs one is your call and your regulator's; nothing here is legal advice.
Does the software decide whether a risk is acceptable?
No. People score severity and likelihood, your organization writes its own risk policy, and a person named by that policy accepts the residual risk in writing. The models supply evidence from flight data and never score a likelihood. Readiness and scores gate nothing.
How does flight data get into the hazard register?
Flights come in as logs from ArduPilot, PX4, DJI, Parrot, Betaflight and INAV Blackbox, GUTMA, Litchi, Airdata and CSV. The advisory score on each flight cites the measures behind it, and a hazard naming those families counts the flights drifting toward it. You can read a flight log free before you create an account.
What does it cost?
Safety Management is an add-on to a plan; the Studio bundle includes it. Every add-on is on during the 14-day trial, for up to 5 people and 3 registered aircraft. Prices are on the pricing page, or start the trial.
Put your safety program on the record.
Talk to us about your fleet, or start a trial and add the first hazard from the library today.
