Cartos Atlas
Smart City, Maritime, Emergency & a 3D common operating picture.
Cartos · Phase I — Live now
Phase I delivered the substrate — a system that can ingest, serve, and visualize geospatial data in a sovereign deployment, with an AI agent wired in from the start. Every vertical is a slice over the same fabric, agent, and shell.
The substrate
Tenant- and team-isolated data, enforced at the database with row-level security across every tenant table — not just in the application layer.
An agent that answers questions, focuses the map, and drives the platform by conversation — native from the first click.
NASA GIBS satellite, ArcGIS services, and STAC catalogs stream as live, persistable overlays beside your own data.
Vertical modules share one shell, one agent, one fabric. New verticals plug in as slices, not forks.
Per-client config in three Keycloak-backed admin tiers — Provider Admin (modules), Tech Admin (features & the field-app builder), User Admin (users, teams, roles, per-user access).
Container-packaged for in-territory deployment. The platform runs inside your boundary — production-grade from the start: readiness probe, non-root containers, structured JSON logs, and a CI gate that prevents unverified code from shipping.
Architecture
A typed Rust workspace carries the data fabric, agent, and API; a React shell renders MapLibre 2D and Cesium 3D. Everything ships in containers you run in-territory.
Every other edition is the same stack — the shell, agent, API, and sovereign data fabric are identical. Only the department-module catalogue on top and the theme change. Figures 2–6 show the other editions on that one engine — Figure 6 (Cartos Africa) is live at africa.cartosatlas.com.
The verticals
| Module | Focus | What it surfaces | Status |
|---|---|---|---|
| Smart City | Urban operations | Assets, sensors, incidents & jurisdictions with live telemetry and AI summaries | Live |
| Maritime | Ports & vessels | Vessels, ports & port incidents across territorial waters | Live |
| Emergency Services | Command & dispatch | Units, incidents, traffic & CCTV with a live operations dashboard | Live |
| Situational Awareness | 3D common picture | A photoreal 3D common operating picture in a streaming globe | Live |
| Maritime Domain Awareness | Wide-area maritime | Coverage, tracks & context at sea, rendered in 3D | Live |
| Cartos Grid | Electric utility operations | Nine department surfaces (Network, CIP, Storm Response, Fleet, Vegetation & more) with live asset/outage/work-order data and KPI dashboards; connects to utility systems-of-record via a real connector-adapter framework | Live — RAiN Partners |
| Cartos Field | Mobile field capture | No-code field apps; offline capture & sync; captures surface in the modules above | v1.0 — tester |
| Cartos Africa | Continental government ops | Nine surfaces (Continental Command, food security, health, borders, ports, land use, parcel fabric, flood risk, settlements) with a 54-country scope selector and real OSM/Natural Earth data | Live |
| Cartos Guardian | Critical-infrastructure protection | Five domain surfaces (Command & Risk, Energy, Utilities & Transport, Emergency, Defense) over 103 curated UAE sites, each carrying a decomposed 0–100 strike-risk score, plus live AIS/ADS-B traffic and collateral overlays | Live |
| Cartos Sentry | Reactive crisis monitoring | Three surfaces (Crisis Command, Change Detection, Incidents) driven by the platform's first background monitoring daemon — real optical/SAR/thermal detectors, cross-modality confidence fusion, an incident state machine and commercial tasking | Live |
| Cartos Harvest | Agriculture intelligence | Seven surfaces (Harvest Command, crop type, crop health, yield, water & drought, field boundaries & registry, risk & finance) resolved live from Sentinel-2 via Microsoft Planetary Computer | Live |
One engine, many editions
Cartos is the common engine; industries run over it as licensed editions — each a switchable catalogue of department modules over the shared fabric, agent, and shell. One platform, nine industries live, 67 individual department modules — counted from the engine's own module registry. All nine ship today, each on its own sovereign subdomain, each with real operational data seeded per module — including the continental Cartos Africa, the proactive/reactive Guardian + Sentry pair, and Cartos Harvest for agriculture.
Smart City, Maritime, Emergency & a 3D common operating picture.
Nine departments, wired to the utility's systems of record.
Ten airfield departments — airside to landside.
An executive project portfolio, then drill to the work.
A portfolio view across every project, then delivery.
Nine surfaces over an open continental base-map substrate, with a 54-country scope selector. Enter One Africa →
A transparent per-site strike-risk model over UAE critical infrastructure. Enter Guardian →
Reactive optical/SAR/thermal change detection, watching Guardian's highest-risk assets. Enter Sentry →
STAC-native crop type, health, yield, water & agri-risk over Sentinel-2, piloted in Kenya & Nigeria. Enter Harvest →
Dozens of department modules, KPI dashboards, and the ask-the-map agent on one substrate.
See the editionsThe module registry
Not a category count — the actual registry, module by module, exactly as the engine enumerates it. Sixty-seven department surfaces across nine editions, each inheriting the same 31 shared engine capabilities, one permission tree and one agent.
| Edition | Industry | Modules | The full list |
|---|---|---|---|
| Cartos Atlas | Government | 5 | Smart City · Situational Awareness (3D) · Emergency Services · Maritime · Maritime Domain Awareness (3D) |
| Cartos Grid | Electric utility | 9 | Grid Command · Network & Asset Ops · CIP & Major Projects · Storm Response · Fleet & Field · Vegetation · Real Estate · Environmental · Stakeholder |
| Cartos Tower | Airport | 10 | Air Traffic · Surface Condition · Tarmac Lighting · Lane Striping · Signage · Property Lease · Major Projects · Emergency Services · Vehicle Traffic · Weather |
| Cartos Milepost | Transportation · DOT | 10 | Executive Overview · Pavement Management · Facility Management · Lane Striping · Live Traffic · Roadwork & Obstructions · Major Projects · Crew Status · Snow Removal & Treatment · Emergency Response |
| Cartos Blueprint | Infrastructure delivery · AEC | 9 | Portfolio View · Design Status · Site Selection · Constructability Review · Environmental & Cultural · Construction Inspections · Safety Report · Stakeholder Management & Access · Live Traffic |
| Cartos Africa | Government · continental | 9 | Continental Command · Food Sustainability & Agriculture · Health & Immunization · Border Management · Port Management · Land Use & Land Cover · Parcel Fabric Development · Flood & Climate Risk · Settlement Management |
| Cartos Guardian | Critical-infrastructure protection | 5 | Command & Risk · Energy Infrastructure · Utilities & Transport · Emergency Services · Defense & Military |
| Cartos Sentry | Crisis monitoring | 3 | Crisis Command · Change Detection · Incidents |
| Cartos Harvest | Agriculture intelligence | 7 | Harvest Command · Crop Type & Land Use · Crop Health · Yield Forecast · Water & Drought · Field Boundaries & Registry · Risk & Finance |
| Total | 9 industries live | 67 | All 67 live today across nine editions, each on its own sovereign subdomain |
Every one of these is a real surface with its own map, its own seeded operational data, its own configurable KPI dashboard, and the same ask-the-map agent scoped to whoever opened it. Turn any of them on or off per client from the admin console.
Live operational data
Real operational data is seeded into every module through a datasource + layer catalogue — thousands of live features across all nine editions — with a full symbology engine and an agent that can query any of it. Access is scoped by tenant, edition, module, group, role, and user type.
Admins add, hide, and delete map layers from real datasources; the catalogue seeds live features into each module's map and feeds the KPI dashboards.
Attribute-driven colour and size — categorical and graduated — with legends and real 3D: polygon fill-extrusions and deck.gl 3D point columns, configured per layer in-app.
One AI agent reasons across every layer a user is entitled to see — discover layers, filter by attribute, find what's within a distance, group and count — never beyond the asker's scope.
Every module carries a configurable KPI dashboard bound to that live catalog data — compose the cards, read the health, and drill from a KPI to the map.
Cartos Grid · Electric Utility Edition
Cartos Grid ships with a real connector-adapter framework that lets any department surface draw live data from the utility's own systems-of-record. An operator pastes an endpoint and credentials into Admin → Integrations; the connector goes live on the next sync — no schema change, no redeploy.
Queries any ArcGIS Feature or Map Server layer for network assets and upserts them into the Grid asset layer. Verified live against a public ArcGIS service (25 assets fetched and mapped).
Outage management and distribution automation — feeds active outage incidents, feeder IDs, customer counts, and estimated restoration times to the Storm Response surface and KPI API.
Work management and plant maintenance — pulls open and in-progress work orders (kind, priority, crew, due date) from both platforms into a unified work-order view.
Capital improvement program schedules — syncs CIP projects (phase, status, % complete, budget) to the CIP & Major Projects map surface.
A file-picker on the dashboard chip lets operators upload work-order CSVs directly. Bad rows are skipped and counted; re-uploading the same file updates rather than duplicates.
Mock feeds run until a live endpoint is configured — so the platform ships and demonstrates correctly before credentials are provisioned. Switching mock to real takes one config edit.
Honest scope: Esri UN is proven against a live ArcGIS service today. OMS/ADMS, Maximo, SAP, P6, and MS Project run realistic mock feeds pending live credentials from the utility. Each connector requires only a trait implementation and one dispatch arm to go live — no new infrastructure.
Cartos Guardian · Critical-Infrastructure Protection Edition
Guardian is the proactive half of the protection pair: five domain surfaces over 103 curated UAE critical-infrastructure sites, focused on the Strait of Hormuz. Every site carries a transparent 0–100 strike-risk score assembled from three visible components — so an analyst, an auditor, or a minister can argue with any one of them instead of being handed a number.
The rollup surface — every assessed site ranked, the score decomposed on click, and a "how the score works" disclosure next to the list. 3 layers, 3,538 features live.
Power generation, desalination and petroleum — the 14 power and 7 petroleum sites that carry the highest criticality weighting in the model.
Transport corridors, ports and utility networks, with the grid-vulnerability and strategic-vector overlays that show what a single-point failure propagates into.
The 10 emergency assets that have to keep functioning when everything else is degraded — scored on the same scale as what they respond to.
Five military sites, including the two naval and air bases that top the ranking, with the POI-collateral layer showing civilian exposure around each.
No component of the score is hidden. Criticality, Hormuz exposure and category value each render as their own contribution bar — because a protection posture that can't be defended in a hearing can't be acted on.
Cartos Sentry · Crisis-Monitoring Edition
Sentry is the reactive half. It introduced the engine's first background ingestion daemon: a monitoring watchlist whose enabled rows are auto-processed on an interval, searching satellite catalogues, running real change detectors across three independent modalities, and fusing a confidence band that is earned rather than generated. A hard guard means a degraded model raises nothing at all — the failure mode is silence, never a fabricated incident.
The reactive operating picture — the monitored-asset watchlist, active incidents, per-asset scan status and detection state, with priority and interval editable per row.
An Ops View with swipe, side-by-side, overlay and change modes across optical, SAR and thermal, with analyst-tunable threshold, boost and sensitivity, plus an InSAR coherence context layer.
Scored incidents with before/after evidence, severity, a timeline, assignment, and the acknowledged / investigating / dismissed review workflow — plus one-click report and DOCX export.
Agreement between independent modalities raises the band. "Confirmed" is analyst-set only — the system will not promote itself. The percentages shown are measured extents, not model self-belief.
When open imagery can't answer inside the crisis hour, task Umbra, Capella, ICEYE, Maxar or Planet — 0.25 m SAR to 0.5 m optical — with the cost on screen before the order and running spend after it.
The guard is deliberate: a degraded or unavailable model raises no incident rather than a low-confidence one. In crisis monitoring, a false positive costs more credibility than a missed scan.
Cartos Harvest · Agriculture-Intelligence Edition
Harvest is the clearest evidence that the edition model works. It is a genuine STAC-native agriculture-intelligence product for ministries of agriculture, agri-insurers and extension services — and it reused Cartos Africa's country-scope system and foundation-layer fabric outright rather than rebuilding them. Seven surfaces, resolved live from Sentinel-2 via Microsoft Planetary Computer.
The country food-security rollup — crop-calendar status by crop, season and agro-zone, showing what is planting, growing and harvesting right now, plus country-onboarding state.
Seasonal-phenology crop classification returning a parcel-level class and a confidence, over cropland extent — with the best licensed imagery for the current scope resolved automatically.
NDVI-anomaly health against the historical baseline, and a season-NDVI yield proxy that reports an inter-annual uncertainty band rather than a single confident number.
Segmentation-derived boundaries → human-in-the-loop review → an authoritative parcel fabric joined to a farmer registry. The review queue is the product, not an afterthought.
A transparent 0–100 agri-risk score with an index-insurance trigger — the surface that makes the analysis bankable for a lender or an insurer rather than merely interesting.
Country scope, foundation layers and the "Available Here" data registry all came from Cartos Africa unchanged. That reuse is why a new vertical is a matter of weeks — and why edition ten will be faster still.
Sovereign administration
Every Cartos deployment is configured per client through a layered admin model backed by Keycloak identity. A Cartos super-admin grants which editions a tenant is licensed for and deploys modules across them; then three per-client tiers take over — Modules (Provider Admin), Features (Tech Admin), and Users & Teams (User Admin). Everything below is the running console, captured today.
All nine industries licensed to one tenant, each with its deployed-module count. Below it, the cross-deployment table: a module has a default industry but can be deployed into others — so Cartos Field can be added to Sentry, or Harvest’s crop surfaces served inside Cartos Africa.
Harvest’s seven agriculture surfaces are deployed into both Harvest and Cartos Africa — the same module, two editions, one codebase. This is the edition model doing the thing that makes it worth having.
69 of 71 modules enabled here. Each row carries its vertical, minimum licence tier and default feature count; disabling one hides it from the launcher and disables its agent tools. The registry is the 67 department surfaces plus Cartos Field and the GIQ / Energy / Agriculture integration modules.
Each module’s default features, then a global advanced pool — Live Weather, KPI Dashboard, Layer Catalog, Navigate & Coordinates, Gaussian Splats, Field Captures — that a Tech Admin can cross-add into any module. Build a capability once; reuse it in all 67 surfaces.
Esri Utility Network, OMS/ADMS and File/CSV run against live endpoints; Maximo, SAP PM, Primavera P6 and MS Project run mock feeds until the client provisions credentials. The console says which is which rather than pretending.
COG, XYZ raster, GeoJSON URL and internal PostGIS side by side, each connection-tested from the console. Credentials are write-only — entered once, never returned to a client.
OpenAQ, Open-Meteo, GDACS, NASA FIRMS, USGS, OpenSky, AISHub and more — grouped by theme, licence-tagged (open / open* / paid / both), individually testable, and assignable per edition and module with per-user overrides.
GEBCO, EMODnet, GBIF, GeoNames, OpenAddresses and Foursquare reporting a green Pass; OneGeology and Mapillary flagged where a key or endpoint still needs attention. A per-user override can grant or deny any single source.
66 candidate sources keyed by geography and minimum zoom, so the best licensed layer surfaces as an operator narrows scope. Sources marked avoid are never offered, and a proxy source is withheld until it has a backing datasource. The rule is enforced in code, not in a policy document.
Create users, assign roles and teams, reset passwords — through the Keycloak Admin API, in-app. The module-access grid grants an individual user exactly the surfaces they need, across every edition, as the fourth enforcement gate alongside nav, feature panels and the agent’s own tools.
For Milepost and Blueprint, grant the whole portfolio or a single project to a department, agency, team or individual, with an access level. Here: City Planning holds portfolio-wide admin, while a restricted user gets view on I-465 Reconstruction alone.
Identity is Keycloak-backed and federation-ready — a sovereign IdP a client can run in-territory, designed to federate upstream to the client’s own identity provider when a sovereign onboarding calls for it.
Inside the platform
NASA GIBS satellite layers, ArcGIS REST services, and STAC catalogs — searchable, stylable, and now persistable to the data fabric.
Group access enforced by Postgres row-level security across all tenant tables — fields, analytics, Grid operations, and every other data type. Users see only the rows their tenant and teams are entitled to.
Ask a question, focus the map, or drive a workflow — the agent orchestrates the platform's own tools.
Provider, Tech, and User Admin tiers configure modules, features, and users in-app via the Keycloak admin integration — no separate console required. See it
Dockable panels users arrange to taste; admins snapshot the defaults for everyone.
Scrub solar time to relight the map — 3D buildings, hillshade, and sky all shift with the sun — and measure distance, area, or height with terrain-derived slope length.
A drag-and-resize compass rail with live bearing/pitch/zoom, a coordinate readout in WGS84, Web Mercator, UTM, MGRS, or State Plane, and a toggleable UTM/MGRS grid overlay — plus a sketch & markup tool for points, lines, polygons, and callouts, exportable as GeoJSON.
A crowd-sourced coverage overlay of drive-path photos on the map, plus an agent tool that finds street imagery near any place — "any recent photos of this intersection?" Clearly labelled as external reference data, not sovereign ground truth.
A platform-level palette system re-skins the whole surface — one theme across the platform or an override per module, and the map itself recolours to match.
The engine's first autonomous loop: watchlist rows are auto-processed on a per-asset interval, searching satellite catalogues and running detectors without anyone opening the app. Priority sets the cadence; a hard guard means a degraded model raises nothing rather than something wrong. See it
Real optical, SAR and thermal detectors — Sentinel-2 NBR/NDWI, Sentinel-1 backscatter, VIIRS/FIRMS fire radiative power — with swipe, side-by-side, overlay and change views, analyst-tunable thresholds, and a confidence band earned by independent modalities agreeing rather than generated.
A source-agnostic parcel store modelled on ISO 19152 (LADM) — spatial units, basic administrative units, rights/restrictions/responsibilities and parties. Two ingest adapters land in the same schema: one mapped to Esri's documented Parcel Fabric information model, ready for a real ArcGIS Enterprise fabric; the other a config-driven map for any generic ArcGIS cadastre FeatureServer — the adapter behind the live demo (verified end-to-end against a real public cadastre service). A ministry moves between sources without a migration. Human review survives re-sync, and export is LADM-shaped GeoJSON.
A DB-backed candidate catalogue keyed by geography plus a client resolver: as you narrow country scope and zoom, the best licensed layer for here surfaces automatically. The licence verdict is a hard gate — avoid sources are never offered, view-only sources are server-proxied with credentials held server-side.
An 82-source registry — 49 live — spanning HDX, geoBoundaries, GADM, World Bank, UN Data, Eurostat, WorldPop, JRC GHSL, Kontur, national cadastres and Overture, each connection-tested and licence-tagged, resolving per module and per scope.
When open imagery can't answer inside the crisis hour, task Umbra, Capella, ICEYE, Maxar or Planet — 0.25 m SAR to 0.5 m optical — with the cost shown before the order and running spend after it. Plus local and GeoTIFF upload for imagery you already hold.
LAS/LAZ point clouds and Gaussian-splat reality capture rendered client-side in the same 3D scene as terrain, buildings and orthoimagery — no server GPU, nothing leaving the perimeter to view it.
A professional layout composer and mapbook export — the deliverable a ministry actually files, produced from the same live scene the analyst was working in.
The shared engine powers nine live industry editions — government, electric utility, airport, transportation, infrastructure delivery, the continental Cartos Africa, the proactive/reactive Guardian + Sentry pair, and Cartos Harvest — totalling 67 department modules, each a switchable surface in the catalogue. See the registry
Phase II turns this substrate into one that detects change, builds 3D, and writes its own reports.
Go to Phase IIDesign partner program
Bring a real operational workflow and a sovereignty constraint; we'll stand it up on the platform under NDA.