Skip to main content
In development · v2

MARVIS

Maritime Anomaly & Risk Visualisation Intelligence System

MARVIS v1 established a 5-layer Bayesian inference pipeline for subsea infrastructure threat detection, hindcast against confirmed European incidents with signed evidence bundles. The system has been returned to development for v2. No prospective monitoring is currently claimed.

5-layer pipeline · 7 hypothesis classes · 2 incidents hindcast · Ed25519-signed evidence

Configured corridor definitions

Norwegian EEZ7 corridors

Svalbard cable, Langeled, NordLink, North Sea Link, NorNed

Baltic Sea8 corridors

C-Lion1, Estlink-1/2, Nord Stream 1/2

North Sea5 corridors

Viking cable, Ekofisk-Emden, BritNed

Mediterranean5 corridors

SAS-1, regional telecoms and power

Multi-Basin ViewEuropean

Cross-basin pattern detection (H7)

5

Bayesian inference layers

7

Hypothesis classes

2

Confirmed incidents hindcast

v2

Returned to development

ARCHITECTURE INTENT

Four capabilities the v1 architecture combines.

Most maritime surveillance systems use AIS alone. The MARVIS architecture fuses open satellite imagery, physics-based track continuity, Bayesian scoring, and signed evidence governance into a single layer. The pipeline is built; forward operational validation is the goal of v2.

Copernicus SAR analysis

Sentinel-1 IW SLC backscatter and CFAR vessel detection to surface dark (AIS-off) vessels alongside AIS tracks. v1 established the pipeline on Sentinel-1 SAR; v2 builds detection on 6-day S1A/S1C backscatter pairs.

Multi-source AIS fusion

Kalman filter track association fusing Sentinel-1 SAR detections with BarentsWatch AIS, Havbase/Kystdatahuset, DMA open AIS, CMEMS TOPAZ4 ocean model, and ERA5 wave/meteorological data into a unified operational picture.

Bayesian infrastructure scoring

Seven hypothesis classes (H1–H7) scored with Bayesian confidence posteriors, cross-referenced against EU/OFAC/UK/Swiss sanctions lists, with geofence-correlated infrastructure proximity scoring. Three hypothesis classes are novel to civilian maritime surveillance.

Signed evidence output

Alert lifecycle with SHA-256 evidence chains, Ed25519-signed evidence bundles, and role-based access control. Output formats are designed to align with NIS2 Directive notification requirements for critical infrastructure operators. This is a design target, not a fielded alerting service.

Copernicus Sentinel-2 true-colour scene of a North Sea coastline

The infrastructure that holds Europe together runs under the sea.

Contains modified Copernicus Sentinel-2 data (2022), North Sea, processed by Northflow

ARCHITECTURE

Five-layer processing pipeline.

From raw satellite imagery to signed evidence bundles, the v1 architecture that was built and hindcast for European subsea infrastructure. Authority notification runs in simulation mode.

L1

SAR Dark Vessel Detection

Sentinel-1 IW SLC backscatter analysis. CFAR (Constant False Alarm Rate) vessel detection identifies dark vessels operating without AIS transponders on a 6-day revisit cycle. v2 builds detection on 6-day S1A/S1C backscatter pairs.

L2

Multi-Source Fusion

Fuses SAR detections with BarentsWatch AIS, Havbase/Kystdatahuset, DMA open AIS, CMEMS TOPAZ4 ocean model, and ERA5 wave/meteorological data. Kalman filter track association resolves identity across sources. AIS outside Norwegian EEZ relies on DMA daily CSV (24-hour latency).

L3

Bayesian Intelligence Scoring

H1 to H7 hypothesis scoring with Bayesian confidence posteriors. EU/OFAC/UK/Swiss sanctions cross-reference. Geofence proximity scoring against the configured infrastructure corridor definitions. Infrastructure-correlated threat assessment produces per-vessel risk scores.

L4

Governance & Alert Management

Full alert lifecycle management. SHA-256 evidence chains and Ed25519-signed evidence bundles. Output formats designed to align with NIS2 notification requirements. Role-based access control (RBAC). EWMA persistent vessel risk scoring with 30-day half-life decay (λ = ln2/30).

L5

Authority Integration

Structured notification protocols to NSM Norway, CSIRT-N, Kystverket, FMI Finland, BSH Germany, and NCSC UK. SafeSeaNet integration. Currently operating in simulation mode: API keys from authorities not yet provisioned. Architecture ready for live authority notification.

Seven hypothesis classes

Three hypothesis classes (H5b, H6, H7) are novel contributions to civilian maritime surveillance.

IDHypothesisDescriptionNovel
H1Shadow Fleet DetectionSanctions cross-reference: EU/OFAC/UK/Swiss registries
H2Ghost Ship IntelligenceAIS identity manipulation and transponder spoofing
H3Infrastructure Corridor ThreatGeofence proximity + behavioural pattern scoring
H4Regional Traffic IntelligenceFleet-level baseline deviation and anomaly detection
H5Dark Ship DetectionAIS blackout analysis: 30 min warning / 120 min critical gap
H5bTemporal Escalation5-level incident persistence scoring, 30-day JSONL ledgerNovel
H6AIS Tamper DetectionHaversine positional-continuity physics: teleport detection. Flags physically impossible implied speeds (e.g. >1,000 knots) characteristic of AIS spoofingNovel
H7Cross-Basin Pattern DetectionSecond-order ledger analysis: same vessel in ≥2 basins within 30 daysNovel

VALIDATION

Hindcast against confirmed incidents.

MARVIS v1 was hindcast against two confirmed European subsea infrastructure incidents, each with a signed evidence bundle. These are retrospective back-tests, not prospective operational detection. The system is in development for v2, targeting forward validation on a live corridor with a pilot partner.

Nord Stream

26 September 2022

Relative orbit 22 descending, Sentinel-1 SAR

Hindcast against this confirmed incident with a signed evidence bundle. A retrospective back-test, not a prospective operational detection.

Eagle S / EstLink 2

25 December 2024

Sentinel-1 SAR with AIS correlation

Hindcast against this confirmed incident with a signed evidence bundle. A retrospective back-test, not a prospective operational detection.

Vessel risk ledger

EWMA persistent risk scoring per vessel with 30-day half-life decay (λ = ln2/30). Scores accumulate across hypothesis activations and decay over time without new signals.

TierCondition
MINIMALNo anomalous signals detected
LOWMinor AIS gap or proximity flag
MODERATEMultiple weak signals converging
HIGHStrong hypothesis activation, infrastructure proximity
CRITICALMulti-hypothesis convergence, sanctions match, corridor breach

DATA INFRASTRUCTURE

Open data. No proprietary feeds required.

MARVIS is built entirely on open European data sources. No commercial satellite subscriptions. No proprietary AIS feeds. Every data source is reproducible and independently verifiable.

Data sources

SourceProviderSignalAccess
Sentinel-1 IW SLCESA CopernicusSAR backscatter, dark vessel detectionOpen
BarentsWatch AISNorwegian Coastal AdministrationReal-time AIS transponder data, Norwegian EEZOpen API
DMA Open AISDanish Maritime AuthorityBaltic/North Sea AIS, daily CSV (24-hour latency)Open
Havbase / KystdatahusetKystverket NorwayNorwegian coastal vessel registry and historical tracksOpen API
CMEMS TOPAZ4Copernicus Marine ServiceOcean current and sea state model (Baltic, North Sea, Norwegian EEZ)Open
ERA5ECMWF / CopernicusWind, wave, and meteorological conditionsOpen
EU/OFAC/UK/Swiss SanctionsEU, US OFAC, UK FCDO, Swiss SECOVessel and owner sanctions cross-referenceOpen

Regional configuration

New regions require only a new JSON corridor configuration file, with zero code changes to the MARVIS pipeline.

RegionCorridor definitionsAsset types
Norwegian EEZ7Telecoms cables, gas pipelines, power interconnectors
Baltic Sea8Telecoms cables, power interconnectors (Estlink-1/2, Nord Stream 1/2)
North Sea5Gas pipelines (Langeled), power interconnectors, telecoms
Mediterranean5Telecoms cables (SAS-1), regional power and data links
European Multi-BasinAllCross-basin pattern detection (H7), all regions combined

Programme status

In development (v2)

MARVIS is in development and is not offered as an operational service. We share the v1 architecture and hindcast evidence with qualified government entities, infrastructure operators, and institutional stakeholders under review.

Request a briefing →

Pilot partner

v2 forward validation

v2 targets forward operational validation on 6-day S1A/S1C pairs over a live corridor. We are looking for a pilot partner among national maritime authorities, infrastructure operators, and NSM/CSIRT-equivalent bodies to run that validation with us.

Become a pilot partner →

Roadmap

Where v2 is headed

v2 builds detection on 6-day S1A/S1C backscatter pairs, aiming at forward operational validation over a live Copernicus Sentinel-1 corridor with a pilot partner.

View initiatives →

Status and scope

In development for v2.

MARVIS is in development. Its current scope is stated plainly:

v1 established the pipeline and was hindcast against two confirmed European subsea incidents; no prospective detection is claimed. v2 builds detection on 6-day S1A/S1C backscatter pairs.

L5 authority notification operates in simulation mode. API keys from NSM Norway, Kystverket, and partner authorities are not yet provisioned.

AIS data outside the Norwegian EEZ relies on DMA daily CSV files with 24-hour latency.

Institutional briefing available

For government entities, critical infrastructure operators, and national security authorities evaluating the MARVIS v1 architecture and its v2 validation roadmap.

Request institutional briefing →