
L4 driverless delivery, signed and shipped.
Tomco led functional safety, SOTIF, and UL 4600 evidence for an L4 autonomous delivery program — the full hybrid bench across perception, planning, and the cross-layer safety monitor.
How the engagement ran.
The client builds purpose-built, occupant-less delivery vehicles operating on public roads at SAE Level 4. The program required a defensible safety case spanning sensor calibration, perception ML, planning, prediction, and a cross-layer runtime monitor — all signed off as one continuous evidence chain.
Tomco embedded as the safety partner in 2022 and has owned the safety case ever since. AFSPs (Authorised Functional Safety Practitioners) co-signed every release; agents kept the trace matrix, hazard log, and SOTIF argument current to the minute as the perception stack iterated weekly.
The result: three-plus years of continuous L4 driverless operation on public roads, zero recalls across the program lifetime, and a UL 4600 case structure now used as the internal template for new vehicle variants.
Who signed it.
Names withheld by policy. Credentials and program references verifiable on request under NDA.
The regime, line by line.
One signed thread, end to end.
- 01Sensors (lidar/camera/radar) — calibration & FuSa item definition
- 02Perception ML — SOTIF triggering conditions, dataset coverage
- 03Prediction & planning — hazard analysis, decision-time monitor
- 04Cross-layer safety monitor — runtime guard, fail-operational reasoning
- 05Vehicle platform — hardware FMEDA, brake/steer redundancy
- 06Signed release — AFSP co-signature, evidence chain dehydrated to immutable store
Want this for your program?
We embed AFSPs and agents into your safety case the same way we did on this engagement. Client references available under mutual NDA.