Validation program · unqualified screening, pre-QAPD

We test the design against reality before we build it.

HELIX is screened in our own reactor-physics simulations and stress-tested against a structured register of real-life scenarios, nominal, harsh, chaotic, production, grid, and long-run. Every result on this page is an unqualified screening analysis: an input to design, not credited safety analysis and not field data. The qualified-lane program that will supersede it is defined and honestly owed. What follows is exactly what we have run, what it showed, and what it deliberately does not yet prove.

There is a temptation, in a pre-application program, to show only the numbers that flatter the design. We do the opposite, because the entire premise of RankShield is that our claims are checkable. So this page separates three things that are often blurred together: physics we have actually screened, the full register of real-world conditions the design is being tested against, and the destructive-boundary work that still requires tools we are standing up. Reading it should leave you knowing precisely how far along the validation is.

What reactor physics have we actually run?

The screening uses OpenMC, an open-source continuous-energy Monte Carlo neutron-transport code from the same national-laboratory ecosystem that qualified codes come from, with ENDF/B-VII.1 nuclear data, run locally on the design of record. Monte Carlo transport is the reference-class method for this work: it tracks individual neutron histories through the real geometry and materials rather than approximating them. The table below is the current state of that screening. Every row is a design input, pre-QAPD, and will be superseded by qualified analyses once the quality program is stood up.

Criticality & core sizing Continuous-energy Monte Carlo (OpenMC, ENDF/B-VII.1)
Design of record resized to reach criticality with a beginning-of-life excess-reactivity bank.
Reactivity-limited lifetime Depletion, full-power
6.67 full-power years at the current design point, re-derived from a depletion run at the matched double-heterogeneity bias. Bounded 6.67 to 6.91 pending the energy-per-fission normalisation. A worse number than we held a week earlier, reported because it is what the evidence supports.
Temperature feedback Multi-temperature k-eff
Strongly negative coefficient (-6 to -8 pcm/K), self-stabilizing.
Shutdown margin Drum + diverse-rod worth
Combined worth far exceeds any credible excess reactivity, with ample margin under a stuck-drum assumption.
Post-trip xenon Xenon transient depletion
No xenon dead-time at this power density; a tripped module can restart immediately.

The most consequential finding is the least glamorous one. Depletion screening, plus scaling from our validated larger-core run, puts the module's reactivity-limited life at roughly four to five full-power years as modeled, and likely five to seven once known model conservatisms come out, the homogenization bias and the erbium banking not yet applied, with an engineering path toward eight. That number, not power or efficiency, is the binding design constraint, and it is the reason the site architecture is built around staggered sealed-core swaps and rolling factory recharge rather than a single long-lived unit: the modules are multi-year, but the site runs indefinitely. We would rather design honestly around a screened lifetime than advertise a sealed life the physics does not support.

How do we test against real-world conditions?

Reactor physics tells you whether the core works. It does not tell you what happens on a 49-degree afternoon when the dry coolers are fouled with dust, or when the grid browns out while a neighboring generator is still spinning down. For that we maintain a register of six scenario families that together cover the conditions a deployed reactor actually meets, from ordinary operation to deliberately chaotic failure. Each scenario is mapped to the analytical tool that is meant to prove it, and we are explicit about which of those tools is already running and which is owed.

A · Nominal

Steady full power over the swap interval; daily AI-load swing (the reactor never chases load, storage absorbs it); seasonal ambient sweep; startup and shutdown margins.

B · Harsh environment

Hot-day derate (45 to 50 °C); frozen-sodium cold start; dust, salt, and smoke cooler fouling; seismic; flood; grid-outage islanding.

C · Chaotic / failure

Single worst-position channel failure; cascade (2 tolerated, 3 forces shutdown, more is beyond design basis); module trip with survivors carrying the site for months; xenon restart; stuck drum; station-blackout walk-away; conversion-island failure.

D · Production & logistics

Fabrication-defect containment (block segmentation, 100% acceptance test); weld-yield Monte Carlo; transport damage to a sealed module (attested custody, site acceptance); vendor-failure supply strategy.

E · Grid & electromagnetic

Frequency ride-through; brownout with slow generators (storage bridge, then fast islanding, then fail-safe drum insert); EMI and RFI (self-generated and host-facility); GMD and EMP for defense sites; timing-attack on the attestation layer.

F · Long-run internals & siting

Sodium void reactivity sign (decision-gating); tritium permeation; Na-24 activation dose fields; absorber swelling; graphite dust; state nuclear-law siting screen.

Two design principles show up repeatedly across these families. First, the reactor never chases load: the molten-salt thermal buffer absorbs demand swings so the core runs flat, which turns a whole class of grid-following transients into storage problems rather than reactor problems. Second, failure is designed to degrade gracefully: a number-up site carries an N+1 reserve module so the survivors carry the load for months if one module trips, and the cascade logic tolerates two simultaneous channel failures, forces an orderly shutdown at three, and treats anything beyond that as outside the design basis rather than pretending it is handled.

What does the failure campaign still owe?

Screening establishes the reactivity and lifetime envelope. It does not establish the destructive boundary, the maximum-power-to-failure case, cascade thermal-stress, and seismic response, because those are structural and thermal problems, not neutronics problems. Answering them requires finite-element analysis, which we are standing up using MOOSE-class multiphysics tools from the same national-laboratory ecosystem as our neutronics. Until that stand-up is complete and validated, we make no claim of demonstrated structural or thermal-mechanical performance, and the failure campaign is explicitly incomplete.

The gates that remain before any hardware are the same ones stated across this site, and the validation program is where several of them are earned: a stood-up NQA-1 quality program so that analysis can be credited at all, independent physics validation with independent codes and ultimately test data, the finite-element failure campaign, NRC licensing under the proposed Part 57 microreactor framework once it is final or under Part 53 as the backup, and validated demand. None of the screening on this page shortcuts those gates. It exists to make sure that when we walk through them, the design already knows where its limits are.

Honesty statement

Everything on this page is unqualified screening produced outside a quality-assurance program. It informs design decisions and is never credited in a safety case. It is superseded by qualified analyses once the QA program is stood up.

RankShield Energy · HELIX · pre-application

Ask the founder

Every question, answered directly.

The questions a regulator, a partner, or an engineer asks about HELIX, answered by the founder. No forms, no sales pitch.

Jamie Kloncz
Jamie KlonczFounder · RankShield Energy
ONLINE
Pick a question on the left, or search above, and you'll get the direct answer, the way an answer engine would give it.
- / 12
Talk to the founder →