Not crashed. Not errored. It produced a confident, specific, entirely wrong answer, and every indicator around it read green. Everything Ashbeck does strangely — every place it refuses, blocks or says "not measured" instead of "fine" — comes from that afternoon.
We were rebuilding a published £25,000 consultancy study of an eleven-storey London tower, clause by clause, to see whether our output could stand next to theirs. One run came back complete. The solver reported success. Sixteen checks passed. A report was issued, with a governing available-safe-egress time of 38 to 42 seconds.
The building in that model was not a building. It was a sealed vessel.
Sixteen leakage paths had been declared and every one of them was internal — door to door, room to room. Not one reached outside air. The fire had nowhere to push, so the solver did the only honest thing available to it and reported the pressure that physics demanded. Nothing in the register was looking at pressure at all.
A crash would have been cheap. This is the expensive shape: confident, specific and wrong, with every other indicator green.
That is the failure this profession cannot absorb. Not software that stops — software that hands a competent engineer a number they have no reason to doubt, in a document that looks exactly like every correct one they have ever read.
We did not fix that one building. We built the check that catches the shape, wrote the test that proves it can still fail, and made it a blocker rather than a warning — because a caveat on page forty is not a safeguard.
Then the fix itself failed. The corrected model declared leakage to outside air, the deck contained it, and the pressure trace came back identical to the sealed run, to five significant figures. The solver needs three things to make a leak real and silently ignores the set if any is missing. We had two.
So we built the reconciliation that compares what the model DECLARED against what the simulation actually CONTAINS, and made a mismatch stop the report. Within a day it had found a defect that had been live for months in something else entirely: every report's check register had been running on an empty record, and quietly saying so in a footnote nobody read.
The checks that matter most are the ones written by someone who has just been embarrassed. Ours block their own author's work.
Anything the assessment could not evaluate is reported as unevaluated, by name. An empty result set is not a pass, and silence is never recorded as one.
Each limit carries the standard it came from. A citation that cannot be resolved stops the report, because guidance that does not govern where the building is, is not guidance.
Ashbeck quantifies and it suggests what is worth testing. It will not tell you a scheme is acceptable. That judgement belongs to the person who signs, and no software should be allowed to imply otherwise.
Where something is built but untested, the product says so — in the report, on the pricing page, in the room. A capability we cannot demonstrate is a capability we describe carefully.
The solver is NIST's Fire Dynamics Simulator — the same tool your reviewer already accepts, and free to anyone. We are not claiming better physics and would not know how to.
What costs £25,000 and five months is everything around it: the fortnight of geometry and meshing, the instrumentation, the post-processing, the report writing, the review round, and then all of it again for the variation nobody budgeted for. That is the work. That is what we automated, and what we check.
It is also not a replacement for a fire engineer, and the day it is marketed as one is the day it becomes dangerous. It is an instrument. Someone competent still has to read what it produces and put their name on it — and our job is to make sure that person is never surprised by what they find underneath.
Thirty minutes, an engineer on both sides, and a straight answer about whether this fits the work you do.