MARVIS
Maritime Anomaly & Risk Visualisation Intelligence System
MARVIS v1 established a 5-layer Bayesian inference pipeline for subsea infrastructure threat detection, hindcast against confirmed European incidents with signed evidence bundles. The system has been returned to development for v2. No prospective monitoring is currently claimed.
5-layer pipeline · 7 hypothesis classes · 2 incidents hindcast · Ed25519-signed evidence
Configured corridor definitions
Svalbard cable, Langeled, NordLink, North Sea Link, NorNed
C-Lion1, Estlink-1/2, Nord Stream 1/2
Viking cable, Ekofisk-Emden, BritNed
SAS-1, regional telecoms and power
Cross-basin pattern detection (H7)
5
Bayesian inference layers
7
Hypothesis classes
2
Confirmed incidents hindcast
v2
Returned to development
ARCHITECTURE INTENT
Four capabilities the v1 architecture combines.
Most maritime surveillance systems use AIS alone. The MARVIS architecture fuses open satellite imagery, physics-based track continuity, Bayesian scoring, and signed evidence governance into a single layer. The pipeline is built; forward operational validation is the goal of v2.
Copernicus SAR analysis
Sentinel-1 IW SLC backscatter and CFAR vessel detection to surface dark (AIS-off) vessels alongside AIS tracks. v1 established the pipeline on Sentinel-1 SAR; v2 builds detection on 6-day S1A/S1C backscatter pairs.
Multi-source AIS fusion
Kalman filter track association fusing Sentinel-1 SAR detections with BarentsWatch AIS, Havbase/Kystdatahuset, DMA open AIS, CMEMS TOPAZ4 ocean model, and ERA5 wave/meteorological data into a unified operational picture.
Bayesian infrastructure scoring
Seven hypothesis classes (H1–H7) scored with Bayesian confidence posteriors, cross-referenced against EU/OFAC/UK/Swiss sanctions lists, with geofence-correlated infrastructure proximity scoring. Three hypothesis classes are novel to civilian maritime surveillance.
Signed evidence output
Alert lifecycle with SHA-256 evidence chains, Ed25519-signed evidence bundles, and role-based access control. Output formats are designed to align with NIS2 Directive notification requirements for critical infrastructure operators. This is a design target, not a fielded alerting service.

The infrastructure that holds Europe together runs under the sea.
Contains modified Copernicus Sentinel-2 data (2022), North Sea, processed by Northflow
ARCHITECTURE
Five-layer processing pipeline.
From raw satellite imagery to signed evidence bundles, the v1 architecture that was built and hindcast for European subsea infrastructure. Authority notification runs in simulation mode.
L1
SAR Dark Vessel Detection
Sentinel-1 IW SLC backscatter analysis. CFAR (Constant False Alarm Rate) vessel detection identifies dark vessels operating without AIS transponders on a 6-day revisit cycle. v2 builds detection on 6-day S1A/S1C backscatter pairs.
L2
Multi-Source Fusion
Fuses SAR detections with BarentsWatch AIS, Havbase/Kystdatahuset, DMA open AIS, CMEMS TOPAZ4 ocean model, and ERA5 wave/meteorological data. Kalman filter track association resolves identity across sources. AIS outside Norwegian EEZ relies on DMA daily CSV (24-hour latency).
L3
Bayesian Intelligence Scoring
H1 to H7 hypothesis scoring with Bayesian confidence posteriors. EU/OFAC/UK/Swiss sanctions cross-reference. Geofence proximity scoring against the configured infrastructure corridor definitions. Infrastructure-correlated threat assessment produces per-vessel risk scores.
L4
Governance & Alert Management
Full alert lifecycle management. SHA-256 evidence chains and Ed25519-signed evidence bundles. Output formats designed to align with NIS2 notification requirements. Role-based access control (RBAC). EWMA persistent vessel risk scoring with 30-day half-life decay (λ = ln2/30).
L5
Authority Integration
Structured notification protocols to NSM Norway, CSIRT-N, Kystverket, FMI Finland, BSH Germany, and NCSC UK. SafeSeaNet integration. Currently operating in simulation mode: API keys from authorities not yet provisioned. Architecture ready for live authority notification.
Seven hypothesis classes
Three hypothesis classes (H5b, H6, H7) are novel contributions to civilian maritime surveillance.
| ID | Hypothesis | Description | Novel |
|---|---|---|---|
| H1 | Shadow Fleet Detection | Sanctions cross-reference: EU/OFAC/UK/Swiss registries | – |
| H2 | Ghost Ship Intelligence | AIS identity manipulation and transponder spoofing | – |
| H3 | Infrastructure Corridor Threat | Geofence proximity + behavioural pattern scoring | – |
| H4 | Regional Traffic Intelligence | Fleet-level baseline deviation and anomaly detection | – |
| H5 | Dark Ship Detection | AIS blackout analysis: 30 min warning / 120 min critical gap | – |
| H5b | Temporal Escalation | 5-level incident persistence scoring, 30-day JSONL ledger | Novel |
| H6 | AIS Tamper Detection | Haversine positional-continuity physics: teleport detection. Flags physically impossible implied speeds (e.g. >1,000 knots) characteristic of AIS spoofing | Novel |
| H7 | Cross-Basin Pattern Detection | Second-order ledger analysis: same vessel in ≥2 basins within 30 days | Novel |
VALIDATION
Hindcast against confirmed incidents.
MARVIS v1 was hindcast against two confirmed European subsea infrastructure incidents, each with a signed evidence bundle. These are retrospective back-tests, not prospective operational detection. The system is in development for v2, targeting forward validation on a live corridor with a pilot partner.
Nord Stream
26 September 2022
Relative orbit 22 descending, Sentinel-1 SAR
Hindcast against this confirmed incident with a signed evidence bundle. A retrospective back-test, not a prospective operational detection.
Eagle S / EstLink 2
25 December 2024
Sentinel-1 SAR with AIS correlation
Hindcast against this confirmed incident with a signed evidence bundle. A retrospective back-test, not a prospective operational detection.
Vessel risk ledger
EWMA persistent risk scoring per vessel with 30-day half-life decay (λ = ln2/30). Scores accumulate across hypothesis activations and decay over time without new signals.
| Tier | Condition |
|---|---|
| MINIMAL | No anomalous signals detected |
| LOW | Minor AIS gap or proximity flag |
| MODERATE | Multiple weak signals converging |
| HIGH | Strong hypothesis activation, infrastructure proximity |
| CRITICAL | Multi-hypothesis convergence, sanctions match, corridor breach |
DATA INFRASTRUCTURE
Open data. No proprietary feeds required.
MARVIS is built entirely on open European data sources. No commercial satellite subscriptions. No proprietary AIS feeds. Every data source is reproducible and independently verifiable.
Data sources
| Source | Provider | Signal | Access |
|---|---|---|---|
| Sentinel-1 IW SLC | ESA Copernicus | SAR backscatter, dark vessel detection | Open |
| BarentsWatch AIS | Norwegian Coastal Administration | Real-time AIS transponder data, Norwegian EEZ | Open API |
| DMA Open AIS | Danish Maritime Authority | Baltic/North Sea AIS, daily CSV (24-hour latency) | Open |
| Havbase / Kystdatahuset | Kystverket Norway | Norwegian coastal vessel registry and historical tracks | Open API |
| CMEMS TOPAZ4 | Copernicus Marine Service | Ocean current and sea state model (Baltic, North Sea, Norwegian EEZ) | Open |
| ERA5 | ECMWF / Copernicus | Wind, wave, and meteorological conditions | Open |
| EU/OFAC/UK/Swiss Sanctions | EU, US OFAC, UK FCDO, Swiss SECO | Vessel and owner sanctions cross-reference | Open |
Regional configuration
New regions require only a new JSON corridor configuration file, with zero code changes to the MARVIS pipeline.
| Region | Corridor definitions | Asset types |
|---|---|---|
| Norwegian EEZ | 7 | Telecoms cables, gas pipelines, power interconnectors |
| Baltic Sea | 8 | Telecoms cables, power interconnectors (Estlink-1/2, Nord Stream 1/2) |
| North Sea | 5 | Gas pipelines (Langeled), power interconnectors, telecoms |
| Mediterranean | 5 | Telecoms cables (SAS-1), regional power and data links |
| European Multi-Basin | All | Cross-basin pattern detection (H7), all regions combined |
Programme status
In development (v2)
MARVIS is in development and is not offered as an operational service. We share the v1 architecture and hindcast evidence with qualified government entities, infrastructure operators, and institutional stakeholders under review.
Request a briefing →Pilot partner
v2 forward validation
v2 targets forward operational validation on 6-day S1A/S1C pairs over a live corridor. We are looking for a pilot partner among national maritime authorities, infrastructure operators, and NSM/CSIRT-equivalent bodies to run that validation with us.
Become a pilot partner →Roadmap
Where v2 is headed
v2 builds detection on 6-day S1A/S1C backscatter pairs, aiming at forward operational validation over a live Copernicus Sentinel-1 corridor with a pilot partner.
View initiatives →Status and scope
In development for v2.
MARVIS is in development. Its current scope is stated plainly:
v1 established the pipeline and was hindcast against two confirmed European subsea incidents; no prospective detection is claimed. v2 builds detection on 6-day S1A/S1C backscatter pairs.
L5 authority notification operates in simulation mode. API keys from NSM Norway, Kystverket, and partner authorities are not yet provisioned.
AIS data outside the Norwegian EEZ relies on DMA daily CSV files with 24-hour latency.
Institutional briefing available
For government entities, critical infrastructure operators, and national security authorities evaluating the MARVIS v1 architecture and its v2 validation roadmap.
Request institutional briefing →