Founded 2016 · AI R&D since 2021 · Engineers + Agents

Safety-critical engineering
for the autonomous world.humanoid robotics.surgical precision.mission-critical flight.medical breakthroughs.the electric grid.mission-critical flight.

Veteran engineers and AI agents, together — across functional safety, cybersecurity, systems engineering, software safety, quality management, AI assurance, and autonomy.

AFSPs on every engagement with AI agents shifting your project left.

7 disciplines · 30+ standards covered
Autonomy · Physical AI · robotics flagship
Cryptographic audit trail on every deliverable
Trusted in programs across
Level 4 autonomous deliveryAutomotive OEMs & Tier-1sAerospace primesDefense & unmannedMedical devicesHumanoid roboticsSemiconductorsEV trucks & racecars
The Tomco model

Veteran engineers & AI agents,
on every engagement.

Every Tomco program runs on a hybrid bench: an Approved Functional Safety Professional leading the work, plus a fleet of agents handling the defensible drudgery — citations, traceability, evidence chains, and the first 80% of every artifact.

  • AFSP-led, agent-augmented. Senior engineers own the rationale and sign every release. Agents accelerate the path there.
  • Cryptographic audit trail. Every artifact, comment, and agent action is hashed into a chain you can ship to your assessor.
  • Evidence-grade by default. Outputs map to ISO 26262, DO-178C, IEC 62304, ISO 21434, UL 4600, and SOTIF clauses on day one.
  • Faster, not lighter. Same rigor your assessor expects. Less typing. Fewer late nights re-formatting tables.
See the Tomco Bench Talk to a safety lead
PM
AFSP · Lead

Program Manager

Reviewed ASIL-D decomposition rationale
Signed FMEDA Part 5
Escalated SOTIF triggering case
S
Agent · Sentry

Program Agent

Scanned ISO 26262 Part 6 amendment
Computed PMHF for subsystem 3
Drafted common-cause analysis v1
Disciplines

Seven disciplines.
One bench. One signature.

Every Tomco engagement draws from the same hybrid bench — six standard disciplines and one flagship — so your safety case, security case, and autonomy case all share evidence, vocabulary, and accountability.

01

Functional Safety

Hazard analysis, ASIL/DAL/SIL decomposition, FMEDA, PMHF, safety cases — built once, defensible forever.

ISO 26262IEC 61508ISO 13849ARP4761
Programs since 2016Learn more →
02

Cybersecurity

TARA, secure development lifecycle, penetration informed reviews, and post-production monitoring strategies.

ISO 21434UN R155DO-326AIEC 62443
Auto · aero · medicalLearn more →
03

Systems Engineering

MBSE, requirements decomposition, interface control, and verification planning that survives audit.

ISO 15288INCOSESysML
Concept → handoverLearn more →
04

Software Safety

Tool qualification, MISRA enforcement, structural coverage, and safety-of-the-intended-function gap analysis.

DO-178CIEC 62304MISRA C/C++
DAL A → DAL ELearn more →
05

Quality Management

ASPICE assessments, IATF readiness, configuration management, and supplier audits that stick.

IATF 16949ASPICEAS9100ISO 13485
Pre-audit to scaleLearn more →
06

AI Assurance

Dataset governance, model risk frameworks, runtime monitors, and regulatory mapping for ML in safety contexts.

ISO/IEC 42001EU AI ActISO/PAS 8800
R&D since 2021Learn more →
07

Autonomy & Physical AI

End-to-end safety assurance for L4 driving, humanoid robotics, drones, and robotaxi fleets — SOTIF, ODD, fallback design, scenario coverage, and the safety case to defend it all.

UL 4600ISO 21448 (SOTIF)ANSI/UL 4600ISO/PAS 8800MISRA AC AGC
Flagship discipline · L4 reference programLearn more →
0
Founded — nearly a decade of safety-critical program delivery
0
AI & agent R&D — four years of in-house tooling, not a 2024 pivot
0
Standards covered across automotive, aerospace, medical, industrial, and AI
0
Engagements led by an Approved Functional Safety Professional — no exceptions
Flagship · Autonomy & Physical AI

The safety case for the autonomous world.

From L4 robotaxis to humanoid manipulation, autonomy is where every discipline collides — perception, planning, ML assurance, cybersecurity, and runtime monitoring. Tomco runs the full stack as a single safety case, not seven disconnected workstreams.

L4 autonomous
Driverless delivery program — L4 reference engagement
0-layer
Sensors → safety monitor — one signed evidence chain
0+
Standards mapped per program — UL 4600, SOTIF, AI Act
100% AFSP
Senior ownership of every safety argument and signoff
L4 Driverless DeliveryHumanoid ManipulationRobotaxi FleetsIndustrial AMRsUnmanned AerialSurgical Robotics
Talk autonomy See the L4 reference case
Industries

One bench, many regulated worlds.

Tomco programs span the regulated industries where safety is non-negotiable. We bring the same hybrid bench, the same evidence model, and the same AFSP accountability into each.

Automotive

OEMs · Tier-1s · EV · racing
ISO 26262ASPICEISO 21434SOTIF

Aerospace

Commercial · defense · space
DO-178CDO-254ARP4754AARP4761

Medical

Devices · diagnostics · surgical
IEC 62304ISO 13485ISO 14971FDA SaMD

Robotics

Humanoids · AMRs · cobots
ISO 10218ISO 13482UL 3300ANSI R15.08

Energy & Grid

EV charging · BESS · utility
IEC 61508IEC 61511UL 9540NERC CIP

Semiconductors

SoC · automotive AI silicon
ISO 26262 P11IEC 61508 P2DO-254
Standards coverage

46 standards. One signed evidence model.

+ Regional & sector frameworks

One bench. Every framework.

Map your program to the right standards on day one — no toolchain swap, no second vendor.

Tomco Bench · the workspace

Where AFSPs and agents ship safety cases together.

One project room. Live conversation, signed artifacts, agents you can audit, a cryptographic evidence chain, and embedded Academy modules — everything an assessor needs, in the same browser tab.

tomco.bench / atlas-l4 / brake-by-wire
LH
Lauren Hart · AFSP
FMEDA · Subsystem 3 · Brake-by-wire
project / atlas-l4 · channel #fmeda-ss3
JK
Jordan KimCLIENT · OEM10:42
Lauren — for the residual rate on the inverter MCU we’re tracking 4.2e-9 /h. Assessor pushed back on the diagnostic coverage assumption. Can the agent re-run with DC@90% and pull the part-quality citation?
LH
Lauren HartAFSP · LEAD10:44
Got it. Kicking the agent now and pinning the updated FMEDA so the assessor sees the same row in the workspace. I’ll co-sign Part 5 once the PMHF re-roll lands.
FMEDA_SS3_v1.4.xlsx
2.4 MB · pinned to thread
S
Sentry · Program AgentAGENT · SAFETY10:45
Re-running FMEDA rows 14–22 with DC=90%. Citing ISO 26262-5:2018 Annex D §D.2.4.3 for the DC claim. ETA 38s · 9 rows affected · PMHF delta will be flagged.
S
Sentry · Program AgentAGENT · SAFETY10:46
Tomco Academy

Train your engineers
in the same room as ours.

Every Tomco Academy course is taught by an active AFSP — the same engineers signing off real programs. Cohorts are small, the labs use your standards profile, and graduates ship into your projects ready to defend their work to an assessor.

FuSaL200
ISO 26262 Part 5 — FMEDA in practice

PMHF, SPFM, LFM derivation. Common-cause analysis. Tool-supported workflows.

2 days12 seats / cohort
CyberL300
TARA + UN R155 readiness

Threat modelling, CSMS evidence, type-approval narrative for OEMs and Tier-1s.

3 days10 seats / cohort
AIL300
ML model risk under ISO/PAS 8800

Dataset governance, drift monitors, runtime assurance patterns for safety AI.

2 days12 seats / cohort
AutonomyL400
SOTIF for L4 — ISO 21448 in depth

Triggering conditions, ODD framing, residual-risk argumentation, scenario coverage.

3 days10 seats / cohort
QMSL200
ASPICE assessment readiness

Process maturity, evidence packaging, audit choreography for capability level 2/3.

2 days14 seats / cohort
SystemsL200
MBSE foundations with SysML v2

Requirements decomposition, interface control, verification planning that survives audit.

2 days12 seats / cohort
FuSaL100
Functional safety primer — ISO 26262 overview

For program managers and clients. Lifecycle, ASIL, work products, assessor expectations.

1 day20 seats / cohort
AIL200
EU AI Act — high-risk system readiness

Risk management system, technical documentation, conformity assessment routes.

1 day16 seats / cohort
Bring Academy on-site for your team.

Custom cohorts at your facility — your standards, your toolchain, your programs.

Request a private cohort
Reference engagements

Same bench. Different physics.

From driverless delivery to humanoid manipulation to surgical robotics — and when no standard exists yet, we write the one that does.

Use the arrows or ← → keys — 8 reference engagements · click the front card for the full case
Reference engagement · Project Atlas

L4 driverless delivery, signed and shipped.

Tomco led functional safety, SOTIF, and UL 4600 evidence for an L4 autonomous delivery program — the full hybrid bench across perception, planning, and the cross-layer safety monitor.

🔒 Client name on request · under NDARead the full case
L4
Driverless delivery on public roads
3+ yrs
Continuous safety case ownership
6-layer
Sensors → safety monitor, one signed chain
0 recalls
Across the program lifetime to date
Robotics portfolio depth

One assurance spine. A whole field of robots.

We didn't just build the assurance tooling for Project Saphira — we then deployed it ourselves across their downstream robotics customers' safety programs. The result is a portfolio of signed evidence chains running on a shared spine.

8
Robotics programs delivered
1,400+
Hazards triaged across the portfolio
6
ISO 10218 / ANSI R15.08 packages shipped
3
SOTIF cases live in production
Project Grove·Agricultural autonomy
Project Atelier·Mobile manipulation
Project Vector·Last-mile delivery
Project Loom·Warehouse picking
Project Pace·Sidewalk robotics
Project Quill·Humanoid teleop
🔒 Client names on request · under NDA
Field notes

From the bench.

Working notes from active programs — what we're seeing in assessor rooms, what agents are getting right, and where the standards are catching up to physical AI.

Bring an AFSP onto your program.
By next week.

Tell us about the standards profile, the deadline, and the gap. We'll come back with a hybrid bench plan — humans in the lead, agents in the loop — within two business days.

About Tomco

Veteran engineers.
Built for the next decade.

Tomco Service Group was founded in 2016 by safety engineers tired of watching good programs stall in evidence formatting. We started with functional safety; today we run a hybrid bench across seven disciplines and seven regulated industries.

We have been investing in AI and agent tooling since 2021 — long before the current cycle — because we needed it to keep up with the pace of physical AI. Every agent on the bench was built by an engineer who had to defend a safety case to an assessor.

Work with our bench See how we work
0
Year founded — nearly a decade of safety-critical work
0
AI & agent R&D — well before the 2024 cycle
0
Disciplines on one bench — one signature, one evidence model
0
AFSP-led engagements — no exceptions, no juniors-only programs
AFSP credentials, decoded

What signs your evidence chain.

Every release on every program is co-signed by an AFSP — an Authorised Functional Safety Practitioner — holding one or more of these credentials. Acronyms below; the point is independent third-party certification, not internal job titles.

TÜV SÜD FSE
Functional Safety Engineer

Issued by TÜV SÜD (Germany). Independent certification that the holder can lead safety lifecycle work to IEC 61508 and its sector derivatives (ISO 26262, IEC 61511, IEC 62061). The benchmark mark in European functional safety.

exida CFSE
Certified Functional Safety Expert

Issued by exida (US). The senior tier of the CFSE programme — requires documented project leadership plus a written exam. Recognised across automotive (ISO 26262), industrial (IEC 61508 / 61511), and machinery (ISO 13849).

INCOSE CSEP
Certified Systems Engineering Professional

Issued by INCOSE (International Council on Systems Engineering). Mid-senior certification covering the full systems lifecycle per the INCOSE SE Handbook / ISO/IEC 15288. The credential of record for systems leads on aerospace, defence, and complex programs.

IEC 62304 Lead
Medical device software lifecycle lead

Recognised lead role under IEC 62304 (medical device software lifecycle) and ISO 14971 (medical device risk management). What a notified body or FDA reviewer expects to see signing Class B / Class C software releases on a regulated medical device.

Plus domain-specific credentials per program: ISO/SAE 21434 cybersecurity engineer, UL 4600 assessor, ISO/IEC 42001 lead implementer, NIST AI RMF practitioner, FAA Part 107.