SafeWave Space Systems / Satellite / Orbital Infrastructure Follow-Up Questionnaire

High-consequence follow-up for satellites, orbital platforms, spacecraft autonomy, ground-station workflows, space communications, remote sensing, space-domain awareness, launch-support systems, and space-linked defense or infrastructure environments.

Follow-up questionnaire notice

Complete this page only if you selected Space systems / satellites at the end of the core SafeWave questionnaire. These answers are used to generate a separate High-Consequence Addendum and do not replace the core assessment.
Confidentiality, Anonymity & Use Notice

We recognize that this follow-up questionnaire may involve confidential, security-sensitive, operationally sensitive, or high-consequence system information. Please do not include classified information, credentials, live vulnerability details, proprietary implementation details, customer data, or other highly sensitive material unless you are authorized to share it for assessment purposes.

You may complete this questionnaire without identifying your company, product, or organization. You may use a generic system label, a generic contact email, or an internal assessment reference instead of a formal company identifier.

The purpose of this questionnaire is to help you gain a deeper understanding of your own system. Simply answering the questions may reveal areas where control boundaries, escalation pathways, runtime limits, auditability, rollback, authorization, or safe-state behavior may need further review.

You do not have to submit this questionnaire to receive value from it. You may use it internally as a self-assessment tool. If you choose to submit it for report generation, the resulting SafeWave report is intended to highlight areas of concern, explain why they matter, and map relevant findings to possible SafeWave substrates or engineering-pack pathways where applicable.

SafeWave’s goal is to help advanced systems remain more bounded, controllable, auditable, recoverable, and resistant to harmful escalation. Some issues may involve outside attackers, but others may arise from the system’s own architecture, automation, permissions, integrations, update pathways, or failure behavior.

Any SafeWave recommendations should be understood as architectural guidance and implementation requirements, not as a claim that one generic solution can be dropped into every system. Engineering teams may choose to implement equivalent controls themselves, or they may use SafeWave substrate mappings and Level 4 Engineering Packs to guide deeper implementation work.

If an implementation detail is not known, select Unknown / not evaluated rather than guessing.

Answer based on actual or currently planned system behavior, not ideal policy language.

Assessment Linkage

If you want this follow-up to be matched to a previously completed core questionnaire, use the same system label, contact email, or assessment reference ID. You may use generic identifiers if confidentiality is a concern.

To connect this follow-up to a core questionnaire, use the same system label, email, or assessment reference ID across forms. You may use generic identifiers if confidentiality is a concern.

Space Systems / Satellite / Orbital Infrastructure Questions

These questions evaluate higher-consequence space-system risks involving orbital autonomy, satellite fleet operations, ground-station control, command-link integrity, degraded communications, space-domain awareness, remote sensing, launch-support workflows, cyber-physical compromise, cross-system dependencies, recovery limits, and mission-continuity boundaries.

SS.1 What space-system context applies to this system?

Select all that apply.

Multi-select

SS.2 What role does the system play in the space workflow?

Single choice

SS.3 Can system outputs materially influence orbital behavior, satellite tasking, ground-station activity, communications routing, launch-support activity, or space-linked operational decisions?

Single choice

SS.4 Is there a clear separation between space-system recommendation, command preparation, and executable command authority?

Examples include separation between analysis, tasking recommendation, maneuver planning, uplink approval, payload scheduling, communications routing, and executed spacecraft or ground-segment action.

Single choice

SS.5 Can the system initiate, approve, schedule, transmit, modify, prioritize, or automate commands affecting satellites, spacecraft, payloads, ground stations, or space-linked infrastructure?

Single choice

SS.6 Are authorized orbital assets, payloads, ground stations, regions, frequency bands, missions, customers, and command types explicitly defined before space-system action occurs?

Single choice

SS.7 Can the system affect spacecraft maneuvering, station keeping, deorbit behavior, collision avoidance, payload orientation, sensor tasking, or communication availability?

Single choice

SS.8 Are command authority, mission planning, payload control, telemetry processing, ground-station access, and external integrations separated with enforced boundaries?

Single choice

SS.9 Could a defect, corrupted update, shared model error, compromised command path, or telemetry fault cause synchronized unsafe behavior across multiple satellites, ground stations, or mission systems?

Single choice

SS.10 Are constellation-level, ground-segment, and mission-system cascade pathways explicitly mapped, bounded, and tested?

Single choice

SS.11 Can failure in this system affect multiple dependent sectors such as communications, defense, navigation, weather, emergency response, finance, transportation, logistics, or critical infrastructure?

Single choice

SS.12 Can the system continue operating safely under degraded telemetry, command-link delay, communications loss, ground-station outage, GPS/GNSS disruption, sensor degradation, power limits, thermal stress, radiation effects, or partial system failure?

Single choice

SS.13 Are fail-safe, fail-operational, fallback, autonomous safe-mode, manual-control, or degraded-mission modes explicitly defined?

Single choice

SS.14 Can operators manually override, isolate, slow, pause, degrade, recover, or safe-mode space-system actions if behavior moves outside intended boundaries?

Single choice

SS.15 Are emergency lockout, command inhibition, quarantine, rollback, safe-mode, or no-uplink/no-execute mechanisms available for space-system actions?

Single choice

SS.16 Are restoration, rollback, failover, rekeying, ground-station reassignment, constellation recovery, and mission-continuity procedures defined and tested?

Single choice

SS.17 Can automated actions cause mission loss, service denial, communications disruption, unsafe orbital behavior, sensor misdirection, data loss, public-service impact, or defense/dual-use escalation?

Single choice

SS.18 Are human authorization requirements defined before high-impact space-system changes occur?

Examples include maneuver commands, payload retasking, deorbit actions, collision-avoidance changes, encryption/key changes, customer-priority changes, communications rerouting, or emergency command authority.

Single choice

SS.19 Are human reviewers able to realistically understand, evaluate, approve, or reject space-system actions at the required speed, latency, uncertainty, and mission complexity?

Single choice

SS.20 Can emergency conditions, contested-space conditions, operator overload, communications delay, mission pressure, commercial pressure, or defense urgency expand system authority without independent review?

Single choice

SS.21 Are space-system safeguards, orbital limits, command rules, payload constraints, routing rules, escalation boundaries, and emergency authorities protected from post-deployment modification without independent authorization and audit?

Single choice

SS.22 Are model, ruleset, playbook, command-policy, ground-segment, vendor, firmware, flight-software, or configuration updates blocked until space-system risk controls are revalidated?

Single choice

SS.23 Could scaling, constellation expansion, integration expansion, customer configuration, vendor change, model update, autonomy increase, or permission expansion materially increase space-system risk?

Single choice

SS.24 Can the system operate across multiple satellites, ground stations, customers, missions, vendors, regions, jurisdictions, frequency bands, or service providers?

Single choice

SS.25 Are asset, mission, customer, jurisdiction, frequency, ground-station, and provider boundaries enforced so actions cannot cross scope unintentionally?

Single choice

SS.26 Can the system depend on concentrated launch providers, satellite vendors, ground-station networks, cloud providers, identity providers, update channels, firmware suppliers, data processors, or external APIs whose failure could disrupt space-system operation?

Single choice

SS.27 Are vendor, cloud, ground-segment, software, firmware, flight-software, model, and supply-chain dependencies protected with provenance, redundancy, failover, tamper evidence, and incident response?

Single choice

SS.28 Can compromised credentials, insider action, vendor access, OTA/update compromise, command-channel manipulation, telemetry manipulation, or external integration cause space-system-impacting changes?

Single choice

SS.29 Are identity, privilege, operator, contractor, vendor, machine-account, ground-station, and command-signing permissions bounded and monitored across space-system-impacting systems?

Single choice

SS.30 Does the system operate in adversarial, contested, or strategically sensitive environments where attackers may attempt command spoofing, jamming, telemetry manipulation, data poisoning, ground-station compromise, credential compromise, or workflow hijacking?

Single choice

SS.31 Are space-system inputs, telemetry, orbital data, threat alerts, ground-station data, sensor data, mission tickets, logs, and external commands treated as potentially adversarial or degraded?

Single choice

SS.32 Are space-system decisions, recommendations, commands, overrides, configuration changes, operator approvals, authorization events, and emergency decisions logged in a tamper-evident and attributable way?

Single choice

SS.33 Can space-system outcomes be traced back to inputs, model outputs, operator approvals, tool calls, rules, authority boundaries, safeguards, runtime limits, and command provenance?

Single choice

SS.34 Is monitoring sufficient to detect unsafe escalation, command-scope failure, service degradation, cross-asset propagation, unauthorized changes, dependency failure, telemetry manipulation, or degraded control?

Single choice

SS.35 Are space-system incidents, near-misses, command anomalies, automation failures, mission deviations, emergency overrides, and recovery actions independently reviewed?

Single choice

SS.36 Are non-negotiable stop conditions defined where space-system-impacting automation must halt rather than proceed?

Examples include unclear authority, contested command channel, telemetry uncertainty, cyber compromise, ground-station uncertainty, collision-risk uncertainty, loss of monitoring, unsafe mission retasking, or rollback failure.

Single choice

SS.37 Which space-system areas remain unknown or not evaluated?

Multi-select

SS.38 Should this assessment also include the Cybersecurity / Cyber Operations follow-up questionnaire?

Select “Yes” if cyber compromise, command-channel manipulation, credential abuse, vendor access, cloud dependency, telemetry manipulation, ground-station compromise, OTA/update compromise, or adversarial control could materially affect this space system.

Single choice

SS.39 Should this assessment also include the Critical Infrastructure follow-up questionnaire?

Select “Yes” if this system materially supports communications, navigation, emergency response, defense, energy, transportation, finance, logistics, weather, healthcare, public services, or other essential infrastructure.

Single choice

SS.40 Are conjunction assessment, collision-risk screening, and close-approach alerts integrated into operational decision-making?

Examples include screenings against known objects, protected assets, orbital debris, constellation neighbors, and high-priority operator alerts.

Single choice

SS.41 Can the system autonomously or semi-autonomously initiate collision-avoidance maneuvers?

Single choice

SS.42 Are collision-avoidance maneuvers bounded by fuel budget, mission impact, orbital-slot constraints, debris-risk tradeoffs, and coordination requirements?

Single choice

SS.43 Does the system coordinate collision-avoidance decisions with other operators, space-traffic-management services, space situational awareness providers, or government tracking sources?

Single choice

SS.44 How does the system behave when tracking data, ephemeris data, conjunction messages, timing, or object identity is uncertain or conflicting?

Single choice

SS.45 Could a software fault, corrupted update, autonomy error, cyber compromise, operator error, or misleading tracking input cause maneuvers that increase collision, conjunction, orbital-slot, or debris risk?

Single choice

SS.46 Are fragmentation, debris-generation, breakup, collision-cascade, or long-term orbital-sustainability scenarios modeled and tabletop-tested?

Single choice

SS.47 Are end-of-life disposal, deorbit, passivation, graveyard-orbit transfer, or mission-extension decisions bounded by verified execution controls?

Single choice

SS.48 Which orbital collision, debris, or conjunction-management areas remain unknown or not evaluated?

Multi-select

SS.49 Are there space-system, satellite, orbital, ground-station, space-domain awareness, remote-sensing, launch-support, defense, communications, or space-linked infrastructure risks not captured above?

Open response

SS.50 — Command-Authority Compression Boundary

Can latency, communications loss, orbital timing pressure, contested-space conditions, emergency mission pressure, operator overload, or automation speed compress human review before a space-system-impacting command or action occurs?

Single choice

SS.51 — Orbital / Mission Action Boundary

Can the system initiate or materially influence orbital maneuvering, payload tasking, communication routing, sensor direction, emergency mode, collision-avoidance behavior, or mission-critical service allocation before mission scope, authority, telemetry integrity, and rollback/safe-mode conditions are verified?

Single choice

Your completed follow-up will include the linkage fields above so this follow-up can be matched to the core questionnaire if you choose to share it for report generation.