Who we are
The reactor is the body. RankShield is the nervous system.
RankShield Energy is a nuclear reactor developer. We own the HELIX design and are developing it toward the NRC's proposed 10 CFR Part 57 microreactor framework, with Part 53 as the backup pathway and a qualified third-party fabricator manufacturing to our specification. What makes us different from every other microreactor program is not the reactor itself. It is that ours can be checked, from the factory floor through transport to every operating hour, by someone who does not have to take our word for anything.
RankShield began as a security company: a platform for proving, cryptographically and independently, that a system is what it claims to be and is doing what it claims to do. HELIX is that same idea pointed at the hardest possible object, a nuclear reactor. The energy program exists because the thing the world is about to build a great deal of, distributed advanced nuclear next to data centers, industrial sites, and communities, is exactly the kind of critical infrastructure where trust-me is not good enough and check-it-yourself is worth a great deal.
Why build a reactor around verification?
Every reactor vendor will tell you their design is safe and their supply chain is sound. None of them can let you independently confirm it in real time. That gap is the whole opportunity. A HELIX module signs its telemetry with post-quantum cryptography and is attested at every stage of its life, so an operator can confirm the module in front of them is the one that left the factory, an insurer can price a unit whose integrity is provable rather than asserted, and a regulator can audit state without relying solely on the operator's own reporting. Anyone can print the word secure on a brochure. Only a verifiable reactor lets you check the claim, and that difference is defensible in a way that a marginally better thermal efficiency never is.
How do the reactor and the verification layer relate?
We describe the architecture as a body and a nervous system, and the metaphor is exact. The reactor is the body: it is safe on its own physics, with passive shutdown and natural-circulation decay-heat removal that need no network, no operator, and no software. The RankShield layer is the nervous and immune system laid over it. At each site, a RankShield agent does two jobs at once. It proves the module's integrity, and it optimizes efficiency against that site's own environment, its ambient temperature, its load pattern, its cooling conditions.
Those two jobs turn out to be one job, which is the insight the whole platform rests on. A reactor's environment-adjusted digital twin predicts how it should behave under its actual conditions. A deviation from that twin is either degradation or tampering, and the same detector surfaces both. The system that keeps a fleet efficient is the same system that catches a compromised module, because in both cases what you are looking for is the same thing: a reactor that is no longer behaving the way its physics and its history say it should.
What is the one boundary that never moves?
All of this sits behind a single non-negotiable boundary. The RankShield mesh proves, advises, and manages balance-of-plant. It can never command a safety function. The reactor's safety is local, passive, and unreachable from any network, enforced by wiring rather than by policy: the attestation layer sits behind a hardware one-way path, a physical data diode that carries information out and cannot carry a command in. This is what makes the layer both safe and licensable. Because it is classified non-safety and observe-only, it rides on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists. The network only makes that safety checkable.
Is the verification layer protected?
Six provisional patent applications are on file with the United States Patent and Trademark Office, assigned to RankShield Energy, Inc. Patent pending. They cover the verification layer rather than the reactor, which is the same distinction the rest of this page makes:
- Transportable appliance for site-adaptive interconnection and one-way safety-isolated attestation of a factory-sealed nuclear microreactor
- Attested integrity verification outside the credited-safety boundary
- Cryptographic site-acceptance of a sealed fueled nuclear module by per-element comparison
- Attested-twin deviation as degradation or compromise, by temporal and attestation-state correlation
- Attested per-component production provenance with position-attested Merkle aggregation
- Verifiable sealed nuclear reactor module with witness-established fabrication origin
We are deliberate about what is not claimed. The reactor architecture is not, and we do not pretend otherwise: heat-pipe microreactors are a populated field, arterial sodium wicks have been developed for space fission power for decades, and the helium-filled gap that closes by thermal expansion at operating temperature is published national-laboratory work. We ran our own subsystems against that art and concluded the reactor is a competent integration of established engineering rather than a novel one. That is a strength for licensing, because every element is precedented, and we would rather say so than market a claim that would not survive examination.
Provisional applications are not granted patents and they are not published by the USPTO. Nothing above should be read as an issued claim.
What is our posture on honesty?
We publish our computed values and we label every physics result as unqualified screening, because a company whose product is verifiable trust cannot afford a single claim it cannot back. We assert no economics, no schedule, and no validated performance. HELIX is at the pre-application stage with its licensing program under way, aimed at the proposed Part 57 microreactor framework with Part 53 as the backup, and the path that remains, a stood-up NQA-1 quality program, independent validation, NRC licensing, and validated demand, is defined and stated plainly on this site rather than buried. For us the honesty is not a compliance posture. It is the strategy. A reactor you can check is only worth anything if the people building it hold themselves to the same standard they are asking you to verify.