Mission library · Public safety & SAR

Stadium and mass-event overwatch.

The network over a full stadium is not down — it is worse than down: nominally present, practically useless, and it fails at exactly the moment the aerial feed matters. This mission is about keeping command and video alive on top of saturated networks, by refusing to depend on any single one of them.

Who flies it

Event security operators, police aviation units, organisers of matches, concerts and marches.

What breaks

Tens of thousands of phones saturate every cell over the venue — and the uplink, the direction the video needs, dies first.

What Atlas contributes

Two or three carriers bonded into one encrypted tunnel; a reserved floor for command; video sheds quality before continuity.

Runs on

Hardware already aboard — the aircraft’s companion computer and the command-post workstation. One Linux binary, one configuration file.

The mission

A derby, a stadium concert, a city marathon. The security operation flies a drone above the venue: crowd density at the gates, movement on the approaches, the one incident forming in sector C that the cameras on poles cannot see into. The feed goes to the command post; the command channel goes back up. Everything about the flight is routine — except that it happens above the one place in the country where the mobile networks are having their worst hour.

What breaks

Forty thousand phones do not take the network down; they take its capacity. Every cell over the venue runs saturated, and the uplink — the direction the drone’s video needs — saturates first and hardest, because everyone in the crowd is streaming outward too. A single-carrier link that tested clean on Tuesday delivers stutter and multi-second latency on Saturday, and it does so precisely during the incidents, because incidents and crowd phone use spike together.

The classical answers each cost something. A dedicated licensed video link needs spectrum coordination per venue and still gives one path with one failure mode. Carrier priority services for public safety, where they exist at all, cover some networks, some traffic and some contracts. And “more bandwidth” is not purchasable at all on a Saturday evening — the cells are what they are.

The architecture on this mission

Mass-event bonding geometry A drone above a full stadium carries its feed to the command post over two different carriers at once, bonded into one tunnel. a full venue — every cell saturated CARRIER A CARRIER B TWO CARRIERS · ONE BOND Command post at the venue Overwatch drone above the venue
The scene: both carrier paths carry at once — command duplicated across them, video harvesting whichever network currently has capacity. The crowd saturates the cells; it cannot saturate both identically at the same moment.

The aircraft carries modems on two or three different carriers, bonded into one encrypted tunnel to the command post. The load-bearing observation is that different networks do not saturate identically or simultaneously: they have different cells, different backhaul, different subscriber mixes, and their bad moments interleave. A bond across them harvests the capacity that exists at each instant, wherever it happens to be — continuously re-scored, with no switchover event and no operator action.

On top of the bond, the class system enforces the one guarantee that matters: command traffic has a reserved floor the crowd cannot eat. The classifier reads the traffic itself — the autopilot and the camera are unmodified — and when capacity tightens, degradation is ordered: video sheds quality first, telemetry thins next, and the command channel does not flinch. A four-megabit video stream can never crowd out a two-kilobit command channel. When measured loss and latency climb, adaptive redundancy begins duplicating the critical classes across carriers, spending bandwidth to buy certainty exactly when certainty is scarce.

Both ends sit behind ordinary mobile networks, connected through a relay node reachable from anywhere — nothing to negotiate with the carriers, nothing the venue’s infrastructure needs to provide. Where the operation also fields a direct RF link from a rooftop, it simply joins the bond as one more path.

How the match day unfolds

  1. Two hours before gates. The drone crew powers the aircraft at the command post; the node aboard brings up modems on two or three carriers and bonds them into one tunnel. One dashboard shows every link’s measured state — not three signal bars on three dongles.
  2. Gates open. The crowd builds and the cells begin to load. Every link is probed several times a second; as one carrier’s uplink softens, video weight shifts toward the others. No switchover, no operator action — the pilot flies, the feed continues.
  3. The incident. Something forms in sector C, the crowd raises forty thousand phones, and every network over the venue hits its worst minute simultaneously. Ordered degradation engages: the video sheds resolution, telemetry thins, and the command channel — a few kilobits on a reserved floor — does not flinch.
  4. Through the worst of it. With loss and latency climbing on every path, adaptive redundancy duplicates command and the operator’s priority traffic across carriers, spending scarce bandwidth on certainty. The feed is coarser; it is never gone.
  5. The crowd drains. Cells recover one by one, redundancy de-escalates on its own, and video quality climbs back — the same continuous re-scoring, run in reverse.
  6. The debrief. The event journal holds a per-carrier, per-minute record of what each network actually did — which gave out, when, and for how long. That record plans the next venue and answers the review board with data instead of recollection.

What each mechanism contributes

  • Multi-carrier bonding — one tunnel, one fixed address, over every modem aboard; capacity harvested wherever it currently exists. Shipped.
  • Class floors and ordered degradation — command reserved, video elastic, classification transparent to the applications. Shipped, opt-in.
  • Adaptive redundancy — escalating duplication of critical traffic as measured conditions worsen, de-escalating when they recover. Shipped.
  • Continuous measurement and the event journal — a per-carrier, per-minute record of what the networks actually did during the event, for the debrief and for planning the next one. Shipped.

The honest boundary: Atlas cannot conjure capacity the cells do not have — under extreme saturation the guarantee is ordered degradation and the best use of what exists, not a fixed throughput. The carriers’ behaviour, the aircraft and the security operation are yours.

What a pilot should prove

  • Side-by-side link records from a real full-venue event: each single carrier versus the bond, from the built-in measurement.
  • Command-channel continuity through the worst measured interval of the event.
  • The video quality curve under saturation — demonstrably shedding resolution before continuity, never the reverse.
  • A debrief artefact: the per-carrier journal showing when and where each network gave out, usable for the next venue’s planning.

One venue, one event day, instrumented end to end. The evaluation format covers the structure.

Request a briefing

Securing a season of events?

Bring the venue, the carriers that serve it and one match day of data — we will define what a pilot deployment should prove.