A flagship is a forcing function: one demanding artifact that must drive the entire kernel from geometry through physics, optimization, and rendering, and come back carrying a certified artifact you can defend rather than a bare number. All three now ship as certified campaigns that run the whole pipeline end to end.

A certified Pareto atlas for a bird-like flyer
Classical aircraft shape optimization returns one design after a hand-tuned run, and asks you to trust that the run converged somewhere good. The ornithoid flagship runs the whole certified campaign end to end instead: it parameterizes a bird-like, multi-inlet, flapping-wing flyer, screens a wide field with the payoff measured rather than asserted, refines the survivors against a real flow solver, proves each one's stability, and returns a Pareto atlas where every row carries its own certificates and its lineage.
- 1
Parameterize
fs-bem · fs-vpmA sectional candidate exposes four levers: wing thickness, trim angle, inlet position, and a flapping gait. Each lever carries a Jacobian action, the BEM adjoint where it exists, so the campaign has exact gradients rather than finite-difference noise.
Certified: BEM adjoint matches central differences to 1.8e-8; the inlet mass-flow proxy tracks the inlet lever
- 2
Screen wide, e-raced
fs-bem · fs-vpm · fs-racePanel lift-to-drag plus a flapping-wake metric score a wide field of candidates, raced generation by generation through an e-process so dominated designs die early and the winner's advantage is measured, not asserted.
Certified: finds the argmax L/D while eliminating 23 of 24 dominated candidates early; 578 evaluations against a fixed-N equivalent of 9,600, a 16× saving
- 3
Refine
fs-lbmThe survivors face a real lattice-Boltzmann channel flow around the rasterized section, with forces read off a control-volume momentum balance over the solver's public moments. The panel-versus-LBM agreement is gated within model-form evidence, and the honesty label travels in the report.
Certified: one flow-through leaves the field unsettled at 1.1e-3; two transits reach 5.5e-6
- 4
Trim & Certify
fs-sos · fs-evidenceEach candidate gets a two-state pitch model whose closed-form Lyapunov matrix an SOS certificate verifies, yielding a certified region-of-attraction volume that is zero unless proven, enforced on every atlas row. A conformal e-band wraps the cheap surrogate screen.
Certified: region-of-attraction certified per row; the conformal band covers 0.97 on 60 fresh candidates
- 5
Pareto atlas
fs-dfo · fs-evidenceNSGA-II searches four objectives at once, L/D × region-of-attraction × maneuver × inlet mass-flow, with the knee design polished by the BEM adjoint. Every row of the atlas ships with its hypervolume, knee point, gene lineage, and its certificates.
Certified: 24 certified rows; adjoint polish lifts the knee design's L/D from 7.64 to 9.41
The whole campaign replays bit-for-bit from its seed, and it degrades honestly: when the LBM budget runs out mid-run, the seven remaining candidates fall back to the surrogate-plus-conformal path with six of seven still inside the band. Zero certificate violations across all 124 crates.
A certified bird, wingtip to Pareto front.

Least material, provable fragility
A building frame should use the least material that still survives an earthquake, and it should be able to prove it. This flagship pairs a ground-structure layout that strips the frame to its load-bearing essentials with a seismic fragility campaign that stops the instant the evidence is decisive, so no core-hours are burned once the answer is settled.
- 1
Layout
fs-trussA ground-structure layout LP, solved by PDHG, strips the frame to its load-bearing members and emits its primal-dual duality gap as a near-optimality certificate.
Certified: PDHG duality gap certifies the layout near-optimal
- 2
Sizing
fs-trussMembers are sized against Euler buckling floors and snapped up to a real steel catalog, with the governing code rows recorded alongside each section.
Certified: catalog-snapped sections, code checks attached
- 3
Time history
fs-solid · fs-scenarioA fiber-hinge story model, Mander concrete and Menegotto–Pinto steel through real sections, is driven by Kanai–Tajimi synthetic ground motions and integrated with Newmark average acceleration.
Certified: nonlinear fiber-hinge response under a Kanai–Tajimi motion ensemble
- 4
Fragility
fs-eproc · fs-uqThe exceedance probability is estimated with an anytime-valid e-stop, so the fragility campaign halts the instant the seismic evidence is decisive, backed by a multilevel Monte-Carlo report.
Certified: anytime-valid e-stop halts when the fragility evidence is decisive; MLMC-backed
- 5
CVaR mass minimization
fs-truss · fs-evidenceFinally a Rockafellar–Uryasev CVaR minimization over the section scale trims mass against the fragility tail, then snaps to catalog with an independent re-check.
Certified: CVaR mass minimization, catalog-snapped and independently re-checked
Smoke tier, honestly: one story, two fiber-hinge columns, synthetic motions. The distributed-plasticity frames, recorded-motion suites, and million-member ground structures are named successors in the contract, not pretended.
The lightest frame that proves it survives the quake.

A laminar-pour vessel, rendered from the same bytes
A pouring vessel that dribbles is a stability failure you can see. This flagship shapes the spout so its stream stays laminar, optimizing a spectral-growth objective and validating it against a real free-surface pour, and then renders the winner from the very same certified geometry, so the beauty shot and the physics are literally the same bytes.
- 1
Parameterize
fs-chebA Chebyshev vessel-of-revolution profile with a scalar lip channel gives a smooth, fully differentiable family of spouts to search over.
Certified: a compact spectral profile; every lever differentiable end to end
- 2
Stability objective
fs-chebQuasi-steady thin-film Reynolds numbers along the pour path feed an Orr–Sommerfeld modal-growth calculation. The objective is a min-max over modes and stations, a differentiable laminarity proxy.
Certified: spectral growth minimized over every unstable mode and station along the stream
- 3
Validation
fs-lbm · fs-materialA free-surface lattice-Boltzmann pour over the lip, under a rotating-gravity tilt schedule, checks the design with a strict mass ledger, a Carreau viscosity band, and Plateau–Rayleigh fragment scoring.
Certified: the mass ledger closes; the open contact-line term travels as a sensitivity band, never a false certainty
- 4
Robustify
fs-raceCandidates are hardened with a CVaR over the fluid band and e-raced, so the designs that only pour well in the easy cases fall away early.
Certified: CVaR over the fluid band; survivors decided by an e-race, not a fixed budget
- 5
Deliverable
fs-renderThe winning pour is rendered by a Woodcock tracker bound zero-copy to the simulation's own mass buffer, so the beauty shot reads the same field the physics wrote.
Certified: the render reads the simulation's mass buffer directly: the same bytes, no re-modeling
Where the physics is genuinely uncertain, at the moving contact line, the campaign reports a sensitivity band instead of a number it cannot back. Smoke tier today; the level-set lip topology and cumulant collision lanes are named successors, not pretended.
A vessel shaped to pour laminar — then rendered from the same bytes.
The forcing function for the whole geometry-physics bridge. A SIMP density field evolves to minimize compliance under a volume fraction, its physics computed by CutFEM directly on the level set. A grey blob resolves into a classic cantilever truss, and every iterate carries a composed error certificate, with the mesh-step counter pinned at zero.
The optimizer reshapes the boundary every iteration; compliance falls as the density field condenses into load-bearing structure.
Underneath, CutFEM-on-SDF supplies FEM-grade physics on the moving level set: the cut cells are certified, so the optimizer never has to wait on a remesh.
FEEC elasticity, CutFEM-on-SDF, matrix-free p-MG + AMG, adjoints, SIMP.
Marquee demo: topology optimization on a raw SDF (no mesh in the loop) with a composed error certificate.
Every flagship bottoms out in the same seven-layer continuum. See how the kernel is built, or clone it and run the vertical skeleton yourself.