Skip to main content
RotorLab  /  Platform  /  Safety management
Safety Management

Drone safety management system, built on the flight record.

A hazard register with the risk scored twice, controls that point at a checklist, a manual section, a service limit or a training requirement that actually exists, a named acceptance of what remains, and the fleet's own flight data as the leading indicator. The SMS a regulator or an insurer asks a UAS program to show, on the same records as the rest of the program.

14-day trial, no card, for up to 5 people and 3 registered aircraft. Safety Management is an add-on; see pricing.

Read the full guide in the docs →
The RotorLab Occurrences screen: what happened, with the reporting clock computed from the day it happened

What a safety management system has to prove

An occurrence log proves hindsight. A register proves the operation thought about harm before it happened, did something about it, and named who accepted what was left.

You thought about it first.

A hazard is a standing condition that could cause harm, scored for severity and likelihood with nothing done, and recorded with where it came from: an occurrence, an audit finding, a hazard report or a change to the operation.

You did something real about it.

A mitigation links the living record that carries it. The checklist is in use or it is not; the manual section is published or it is not. Free text is allowed and visibly counts for less.

Someone put their name on the rest.

Acceptance is a permanent record: who accepted the residual risk, at what score and band, on what day, in their own words. It lapses, and says so, when the facts under it move.

The register

Risk scored twice, side by side

Each hazard carries a raw score, with nothing done, and a residual score, with the controls in force today. The pair renders together everywhere, so the effect of your mitigations is visible as the movement between two cells.

  • Severity and likelihood, 1 to 5 each. The product, 1 to 25, falls into a band under your own risk policy: acceptable, tolerable or intolerable.
  • A lower residual needs a control in force. Scoring alone never makes a hazard mitigated, and a planned control counts for nothing until its day comes.
  • Status follows the records, never a button. Identified, assessed, mitigated while a control is in force, accepted while the latest acceptance still applies.
  • Nothing is deleted. Every scoring is kept with who, when and why. A retired hazard stays on the record, dimmed, and can be reopened.
1 to 5Severity and likelihood, each a person's judgment. The models never write a score.
3 bandsAcceptable, tolerable, intolerable: your policy sets the lines and who may accept each band.
12 hazardsIn the starter library, from battery thermal runaway to bystanders entering the operating area.
90 daysThe window of flights each hazard's leading indicator is counted over.

An intolerable residual is never accepted: the register reads "needs a control, not a signature". The starting bands are RotorLab's own and come from no regulation.

Mitigations that point at living records

A control is only as good as the thing that carries it. The strong ones link a record the rest of RotorLab already keeps, so an auditor can see that it exists and is in use.

Checklist

The step that carries it

Name the card and the item on it. The hazard's page shows the evidence: complete runs since the control came into force against the flights flown, how often the step failed, and whether the card has been revised since.

Flight records and checklists →
Manual section

A chapter of the operations manual

Link the section of your published manual that describes the procedure. A section switched off in the manual is not offered, and a control linked to one later switched off says so and stops counting.

The ops manual builder →
Service limit or training

A part's life, or a qualification

Link a component's service limit, counted down from the flights on record, or a training requirement whose sign-offs run the currency clock and stamp the manual revision in force.

Maintenance on real hours →

Every mitigation carries an owner, an in-force date and a state: in force, planned or ended. An occurrence is not a control: an occurrence names the hazard it revealed and the controls it prompted, and a hazard raised from one keeps it as its source.

The RotorLab Fleet Health screen: each airframe's standing with the signals behind it
The fleet signalThe flight-data scores that drive fleet health cite the measures behind them, and the register joins on those measures.
Leading indicators

The signal arrives first

A hazard names the signal families it is about: battery, power, propulsion, vibration, navigation, compass, GPS, traffic and link. RotorLab's advisory scores cite the measures that drove them, so each hazard gets a count of flights in the last 90 days that drifted toward it, split into notable and loud.

  • Before and after a control. The in-force date splits the flag history, so the register can say whether the control worked.
  • Flags rising since acceptance. When 3 or more flagged flights since an acceptance are clearly more than the earlier rate would expect, the hazard says so with the figures. A person decides; nothing reopens on its own.
  • Signals with no hazard on the register. Families cited in the last 30 days that no open hazard claims, suggested for review, never created for you.
  • Advisory everywhere. Humans score the matrix; the models supply evidence and never score likelihood.
What an auditor sees

The register, as it stood on the day

The audit binder prints the register with its raw and residual scores, each hazard's mitigations with their state, its latest acceptance with who, when and why, or "lapsed" with why it lapsed, and the safety reviews: internal audit, management review, safety meeting and emergency drill, each with when the next is due.

  • A code on every document. The binder's verification code covers every register it prints, so an edited PDF fails the public check at rotorlab.app/verify.
  • Policy changes are visible. Tighten the risk policy and an acceptance signed in a looser band says so, with the decision a person made about it.
  • A risk card before the sortie. The crew answers a weighted card on the dispatch board; at or over the threshold, going ahead needs a second name. It never grounds anything.
The RotorLab Records page: what is recorded, what is on legal hold and what was disposed of
Records with custodySafety records are voided with a reason rather than erased, and an open legal hold stops disposal.

Questions buyers ask

The short answers. The long ones are in the docs, and sales will walk through your program.

What is drone safety management system software?

Software that keeps the risk-management half of a Safety Management System for a UAS program: a hazard register scored before and after mitigation, the controls in force, who accepted the residual risk and on what basis, occurrences and the safety reviews. RotorLab keeps it beside the flights, aircraft, maintenance and training, so a control can point at the thing that carries it.

Do I need an SMS as a Part 107 operator?

Part 107 does not require one. Insurers, public-safety agencies, enterprise clients and operators flying under waivers often do, and a documented register is the usual answer to "show us how you manage risk". Whether your operation needs one is your call and your regulator's; nothing here is legal advice.

Does the software decide whether a risk is acceptable?

No. People score severity and likelihood, your organization writes its own risk policy, and a person named by that policy accepts the residual risk in writing. The models supply evidence from flight data and never score a likelihood. Readiness and scores gate nothing.

How does flight data get into the hazard register?

Flights come in as logs from ArduPilot, PX4, DJI, Parrot, Betaflight and INAV Blackbox, GUTMA, Litchi, Airdata and CSV. The advisory score on each flight cites the measures behind it, and a hazard naming those families counts the flights drifting toward it. You can read a flight log free before you create an account.

What does it cost?

Safety Management is an add-on to a plan; the Studio bundle includes it. Every add-on is on during the 14-day trial, for up to 5 people and 3 registered aircraft. Prices are on the pricing page, or start the trial.

Put your safety program on the record.

Talk to us about your fleet, or start a trial and add the first hazard from the library today.