A physics engine, and a verification tool enforced on top of it. PhysWall inverts a closed, published, non-linear physical law at a single measurement point — and refuses when the inverse is not unique. Seven laws, one engine, and the same refusal in all of them.
One person and an AI, and everything here is checkable.
There is no company behind this yet. What there is: an engine, the enforcement layer, the test suite, and a written record of every time we were wrong.
Fifteen times we thought something here was new. Fifteen times a search found it already existed — Reiter's consistency-based diagnosis from 1987, structural identifiability from the seventies, mutation testing from 1978, bias separation in Kalman filtering, and BIPM key comparisons.
Each time the honest version came out stronger than the one we started with, and three of those searches caught an error before it reached a headline. One of them was a figure we were about to publish as our machine's precision; it turned out to be a rounding artefact in our own input.
Every bound here was built by us, in a field we picked. So we ran a test twice: hand somebody the declaration format and nothing else, and let them pick the field.
They came back with open-channel hydraulics — water in a ditch. A field with no overlap with anything here.
It ran. And it refused correctly: fed a roughness value no concrete channel could have, it said so rather than returning it. Nobody had taught it what concrete is.
The next came back with glacier mechanics: the shear stress under an ice sheet, which nothing measures directly.
τ = ρₓ · g · H · sin α 100 m of ice at 6° → 94 kPa ok 100 m of ice at 45° → 636 kPa refused
Neither input is absurd on its own. A hundred metres of ice is ordinary, and so is a 45° slope. The combination is what does not exist, and that is the harder case to catch.
That law has two measurements: thickness from radar, and slope from a terrain model. Each with its own error.
And every bound here was built around one. Not as a decision — nobody ever wrote it down. Seven laws happened to take one measurement each, and the shape rolled forward.
The failure is the quiet kind. The declaration still runs: push the second measurement in as an ordinary input and it computes fine. But its error is then counted nowhere, and the verdict comes back more confident than the measurements can support.
A tool that refuses is doing its job. A tool that answers too confidently is doing the opposite of its job — and that is the one failure this whole thing exists to prevent.
So it now refuses. A law that declares it needs more than one measurement is turned away, with the reason, until the engine can carry several properly. That is a change to the shape of the thing, not a field, and it is not being rushed.
⚠ And the caveat on the second test: the reviewer read the whole brief before choosing a field, which the instructions asked them not to do. They reported it themselves. It makes that run weaker than the first, and it is counted that way.
The components, and the connections between them, have been reviewed by an electrical engineer. The review covered the structure and the derivations — not behaviour against hardware, and no measurement was taken.
Which is worth saying plainly, because "reviewed by an engineer" on its own would read as validation, and it is not. Nothing here has been run against a board, an antenna or an instrument.
PhysWall was developed and architected by Gadi Zion. The deployment credit is in the licence, where it belongs — and it says code, not system. The system has still never been measured against hardware, and those are different claims.
Every tool here runs on the same structure: a closed law, read backwards, with a refusal when the measurement cannot carry a conclusion. What differs is how much of that has been checked by somebody outside.
VALIDATED — something outside was in a position to move
it, and did
basketball ~180,500 shots from four sources, none of them
ours. Two of the four took something away.
adjudication 30 of 464 aviation reports, coded from the
reports alone. Agreed on the cause in 26.
engine handed laws from two fields nobody here works
in. One ran. One broke it.
D7 seven published anapole measurements narrowed
a band that was 3.1x too wide.
VALIDATED — continued
climbing published anthropometry answered the open claim
and answered it against us: speed climbers are
1.5 cm taller between disciplines, and height
separates nothing inside one.
waves three NOAA records each killed a claim we had
already made: 2,100 rows of MM where we
expected a partition, sampling rates that
turned a twenty-minute finding into an
artefact, and a station in Alaska we had
assumed was in California.
gauge 91 USGS annual peaks broke our first version
outright -- we had compared a curve fitted to
daily means against instantaneous peaks. The
corrected answer holds on two instruments:
peaks x1.47, current meter x1.56.
BETA — complete, running, consistent, and nothing outside
has touched it yet
D1 cross-checked by our own declaration engine,
which is not an outside check.
D2 two constants and a temperature. Nothing in it
for an outside measurement to move.
D3 calibrated against two boards, one of which is
a model constant rather than a measurement.
FILTER — runs forwards only, and for a reason in the law
D4, D5 D4 answers 'is this possible' and shares its
relationship with D1. D5 has three unknowns
against one reading.
D6 Landauer is an inequality, and an inequality has
no unique inverse. Nothing in a dissipation figure
says whether erasure happened.
HELD — the inputs are missing and they are not ours to get
energy four of them, and a distribution operator holds
all four.
Three of those need saying plainly.
D7 is the one bound here that outside measurements have already reached. Seven published anapoles, four of them measured, narrowed a band that had been too generous — so the figure on that page is theirs as much as ours. That is what the beta label means everywhere else on this site: a number that something outside was in a position to move, and did.
D1–D6 are not one thing. One is calibrated against published measurements of the same material. One was cross-checked by the declaration engine, which was given the law and told nothing about radio. Two are constants, with nothing in them to be wrong about. Each is anchored to something, and none of them yet to a measurement made independently — which is what D7 has, and what the others are working towards.
And the laws themselves are not in doubt: Bode-Fano is a theorem from 1945, the Landauer limit was measured in 2012, and the thermal ceiling is standard thermodynamics. What has not been checked is our code — whether what it returns matches what an instrument would read. Nobody has held these numbers against a board or an antenna.
Adjudication. It has now been run against real investigations — thirty aviation accident reports, coded from the reports alone. It agreed with the stated cause in twenty-six. In two, the investigators had returned no verdict themselves, in the same words this tool uses. In one, evidence sat in the report that the verdict did not touch.
And reading twenty rather than eleven turned up something that one report alone would not have shown. In several of them the toxicology field is simply empty — and in one, there was no autopsy, no toxicology and no cockpit voice recorder at all. Those questions returned no verdict not because the evidence was ambiguous, but because it was never collected.
That is a different kind of gap from the ones this tool separates, and it is not rare. It follows the class of accident: where nobody was hurt, there is no autopsy, and a whole line of enquiry is closed before it opens. A tool reading these reports has to tell that apart from evidence that exists and does not decide — and this one currently does not.
Thirty out of how many? The full aircraft accident report series runs from 1967 to 2021 and carries 473 numbers, of which nine are duplicates — 464 distinct investigations. The rate has fallen fivefold: seventeen a year in the seventies, three a year now. Most of the corpus predates 1990.
Thirty also made one thing measurable that eleven could not. Five of them were engines that ran out of fuel, which raises the question of what gets called the cause. Three of the five name the pilot's fuel planning, and put the empty tanks as the result. Two name the empty tanks and stop there.
That split matters because empty tanks are not a cause — they are what needs explaining, and a miscalculation and a pilot who had been drinking produce identical tanks. And both of the reports that stopped at the tanks are the ones where evidence sat unaddressed. The distinction this tool enforces turns out to be one these investigators mostly make already, and the exceptions are where things go missing.
That is a weaker check than basketball's and it is a real one: it could have disagreed everywhere, and did not. What it does not do is prove the tool right — agreeing with a formal investigation is what a working tool should do, and it is not a discovery.
And there is no physics in it at all — it runs on the same structure anyway. That is the part worth stating carefully, so here it is in full:
a relationship, read backwards hypothesis → what you would see
becomes: what you saw → what survives
a window does this observation rule it out
or does it not
a refusal returns no verdict when nothing survives,
and says so when two do
a stated source every hypothesis must state what it
predicts, or the tool will not run
Four requirements, and it meets all four without a single physical law in it. Which is the claim: the structure is what makes an answer trustworthy, and it does not need physics underneath to work. Physics is where we found it, not what makes it hold.
And that is testable rather than asserted — because if the structure were doing nothing on its own, this tool would fail where the others do not. Whether it does is the next thing to check, against sixty years of aviation investigations that were written without knowing it exists.
beta checked against something we did not write,
and the check could have failed
filter runs forwards only. A different job,
not a lower grade.
held exists, does not ship, and the reason
is written down
Nothing here is labelled finished, and the two apps that are not on this site are named on the home page with the reason.
Not that the arithmetic is more precise — IEEE 754 gives everyone the same sixteen digits. Not that the mathematics is new. Not that anything here has been measured against hardware: zero measurements of our own, across every domain.
What we claim is that no free public tool takes an observed discrepancy and says how much of it is yours. If you know one, we would rather hear it from you.
Every app is a single HTML file that runs in your browser. Open the source — there is nothing hidden in there, because there is nothing that could be. What is not in those files is the reasoning: twenty-seven gates, each born from a real bug, each documented with the bug beside it.
You get the numbers. The reasons stay here.