Validation program · unqualified screening, pre-QAPD
We test the design against reality before we build it.
HELIX is screened in our own reactor-physics simulations and stress-tested against a structured register of real-life scenarios, nominal, harsh, chaotic, production, grid, and long-run. Every result on this page is an unqualified screening analysis: an input to design, not credited safety analysis and not field data. The qualified-lane program that will supersede it is defined and honestly owed. What follows is exactly what we have run, what it showed, and what it deliberately does not yet prove.
There is a temptation, in a pre-application program, to show only the numbers that flatter the design. We do the opposite, because the entire premise of RankShield is that our claims are checkable. So this page separates three things that are often blurred together: physics we have actually screened, the full register of real-world conditions the design is being tested against, and the destructive-boundary work that still requires tools we are standing up. Reading it should leave you knowing precisely how far along the validation is.
What reactor physics have we actually run?
The screening uses OpenMC, an open-source continuous-energy Monte Carlo neutron-transport code from the same national-laboratory ecosystem that qualified codes come from, with ENDF/B-VII.1 nuclear data, run locally on the design of record. Monte Carlo transport is the reference-class method for this work: it tracks individual neutron histories through the real geometry and materials rather than approximating them. The table below is the current state of that screening. Every row is a design input, pre-QAPD, and will be superseded by qualified analyses once the quality program is stood up.
| Criticality & core sizing | Continuous-energy Monte Carlo (OpenMC, ENDF/B-VII.1) Design of record resized to reach criticality with a beginning-of-life excess-reactivity bank. |
| Reactivity-limited lifetime | Depletion, full-power ~7.6 full-power years as-modeled, giving an 8 to 10 yr calendar swap at 76 to 95% fleet rating. |
| Temperature feedback | Multi-temperature k-eff Strongly negative coefficient (-6 to -8 pcm/K), self-stabilizing. |
| Shutdown margin | Drum + diverse-rod worth Combined worth far exceeds any credible excess reactivity, with ample margin under a stuck-drum assumption. |
| Post-trip xenon | Xenon transient depletion No xenon dead-time at this power density; a tripped module can restart immediately. |
The most consequential finding is the least glamorous one. Depletion screening puts the reactivity-limited life at roughly 7.6 full-power years, which is what sets the 8 to 10 year calendar swap once fleet rating is accounted for. That number, not power or efficiency, is the binding design constraint, and it is the reason the site architecture is built around staggered core swaps rather than a single long-lived unit. We would rather design honestly around a screened lifetime than advertise a sealed life the physics does not support.
How do we test against real-world conditions?
Reactor physics tells you whether the core works. It does not tell you what happens on a 49-degree afternoon when the dry coolers are fouled with dust, or when the grid browns out while a neighboring generator is still spinning down. For that we maintain a register of six scenario families that together cover the conditions a deployed reactor actually meets, from ordinary operation to deliberately chaotic failure. Each scenario is mapped to the analytical tool that is meant to prove it, and we are explicit about which of those tools is already running and which is owed.
Steady full power over the swap interval; daily AI-load swing (the reactor never chases load, storage absorbs it); seasonal ambient sweep; startup and shutdown margins.
Hot-day derate (45 to 50 °C); frozen-sodium cold start; dust, salt, and smoke cooler fouling; seismic; flood; grid-outage islanding.
Single worst-position channel failure; cascade (2 tolerated, 3 forces shutdown, more is beyond design basis); module trip with survivors carrying the site for months; xenon restart; stuck drum; station-blackout walk-away; conversion-island failure.
Fabrication-defect containment (block segmentation, 100% acceptance test); weld-yield Monte Carlo; transport damage to a sealed module (attested custody, site acceptance); vendor-failure supply strategy.
Frequency ride-through; brownout with slow generators (storage bridge, then fast islanding, then fail-safe drum insert); EMI and RFI (self-generated and host-facility); GMD and EMP for defense sites; timing-attack on the attestation layer.
Sodium void reactivity sign (decision-gating); tritium permeation; Na-24 activation dose fields; absorber swelling; graphite dust; state nuclear-law siting screen.
Two design principles show up repeatedly across these families. First, the reactor never chases load: the molten-salt thermal buffer absorbs demand swings so the core runs flat, which turns a whole class of grid-following transients into storage problems rather than reactor problems. Second, failure is designed to degrade gracefully: a site of two to four modules is sized so that survivors carry the load for months if one module trips, and the cascade logic tolerates two simultaneous channel failures, forces an orderly shutdown at three, and treats anything beyond that as outside the design basis rather than pretending it is handled.
What does the failure campaign still owe?
Screening establishes the reactivity and lifetime envelope. It does not establish the destructive boundary, the maximum-power-to-failure case, cascade thermal-stress, and seismic response, because those are structural and thermal problems, not neutronics problems. Answering them requires finite-element analysis, which we are standing up using MOOSE-class multiphysics tools from the same national-laboratory ecosystem as our neutronics. Until that stand-up is complete and validated, we make no claim of demonstrated structural or thermal-mechanical performance, and the failure campaign is explicitly incomplete.
The gates that remain before any hardware are the same ones stated across this site, and the validation program is where several of them are earned: a stood-up NQA-1 quality program so that analysis can be credited at all, independent physics validation with independent codes and ultimately test data, the finite-element failure campaign, NRC licensing under Part 53, and validated demand. None of the screening on this page shortcuts those gates. It exists to make sure that when we walk through them, the design already knows where its limits are.
Honesty statement
Everything on this page is unqualified screening produced outside a quality-assurance program. It informs design decisions and is never credited in a safety case. It is superseded by qualified analyses once the QA program is stood up.
RankShield Energy · HELIX · pre-application