One Pipeline. From Behaviour to Certified Code.
Dextra is the first platform to co-design hardware and software, explore the design space formally, and generate certified implementations — all from a single behavioural specification.
Requirements
Engineer imports or writes system requirements — from IBM DOORS, Jama, plain text, or natural language. AI structures them, flags ambiguities, and auto-suggests security threats from the threat library based on system type. Output: a structured, validated requirement set.
Behaviour Specification
Engineer provides or co-designs the system behaviour using timed automata. Provide mode: define your own automaton directly. Assisted mode: Dextra AI proposes timed automata from requirements, you review and validate — TCTL properties are derived here. This stage is the formal behavioural contract the rest of the pipeline is built on.
AG(gps_anomaly → AF≤200ms safe_mode)
Design Space Exploration
Given the formal behaviour and your constraints — BOM cost, weight, processor family, power budget, security level — Dextra explores the joint hardware-software design space and outputs an interactive Pareto frontier. Every design point is traceable to requirements and formally checked against the timed automaton.
Select a design point on the Pareto frontier to inspect its full specification.
Platform Selection
Engineer selects a design point from the Pareto frontier. Dextra confirms the full hardware-software configuration: processor choice, peripherals, scheduling policy, security mitigations. This is the co-design output — a fully specified platform, not just software.
- Power: 4.5W
- BOM: €1,400
- DAL-C baseline
- Power: 6.1W
- BOM: €1,980
- DAL-A native hardware redundancy
Code Generation
Verified, hardware-aware code generated specifically for the selected platform. Scheduling analysis (RMA/EDF) included. Output targets qualified backends: Green Hills MULTI, SPARK Ada, or SCADE model. The generated code is provably correct with respect to the timed automaton from Stage 2.
Certification Artifacts
Full certification evidence package generated automatically: requirements traceability matrix, formal verification report, scheduling analysis, safety case fragments, security assessment. Formatted for DO-178C, EASA Specific category, or DEF-STAN as appropriate.
Ask. Explore. Decide.
Ask what happens if you remove a component, change a processor, or relax a timing constraint — and see the formal impact instantly.