Assessing the Sky: What MetaPhase Learned Building AURA
By Sindhu Gangireddy, IT Consulting Intern
A drone costs less than a good pair of shoes. It fits in a backpack, launches from a parking lot, and is over a fence before anyone looks up. That simple fact has rewritten what it means to protect a stadium, a water plant, or a port. The threat no longer arrives at the gate. It arrives from the sky, leaving those responsible for protecting these places asking how exposed they are and what to do about it.
A Counter-UAS site assessment answers those questions by measuring how vulnerable a facility is to drones and how ready its staff is to respond. That work usually falls to a specialist who studies the location and writes a careful advisory. The trouble is that far more critical infrastructure sites exist than there are experts to assess them. AURA was built to help close that gap.
Defining the Problem
No two sites are exposed in the same way. A stadium fills and empties on a public schedule, a federal campus worries about who can approach the perimeter, and a port must account for open sightlines and cargo that cannot be moved. Evaluating that blend of exposure, public access, and asset sensitivity means carefully evaluating the surrounding environment, from what sits nearby to how fast staff could react.
Assessments also vary by person. Two skilled reviewers can describe the same facility in different words and at different depths, making reports hard to compare across a portfolio. AURA brings steadiness, giving every assessment the same structure and starting point so a reviewer can spend energy on judgment rather than assembling context from scratch.
How AURA Works
AURA opens with a library of every site the team has analyzed, so a reviewer can reopen the Washington Monument from last week without starting over. That library matters more than it first appears. Critical infrastructure is not assessed once and forgotten. Sites change, staffing shifts, and events reshape the risk, so a review from six months ago may no longer hold. Keeping every past assessment a click away lets a team revisit and compare its own work instead of rebuilding context each time. Creating a new assessment is just as straightforward. A user searches an address, draws the site perimeter on a map, then hands the process over to AURA, which gathers public and geospatial context and writes a full CISA-style advisory. Because some sites take longer, AURA can email the finished report rather than make anyone wait. The reviewer reads the result, exports a clean PDF, and the assessment is stored as a structured record other tools can use later.
The report reads like a real advisory rather than a page of raw numbers. AURA scored the Washington Monument 64 out of 100 and placed it in the Elevated band, opening with an executive summary, a color-coded Risk Spectrum, and a radar chart that breaks the score into four categories, so a reviewer can see at a glance where a site is strong or weak. From there, it walks through a site overview, a boundary map, and an FAA airspace panel flagging the D.C. Flight Restricted Zone and the P-56 prohibited area overhead. A launch distance threat envelope maps how far different classes of drones could realistically fly, from a toy platform close in to a heavy-lift model miles away, and the advisory closes with layered recommendations across detection, reporting, response, coordination, and training. What keeps it trustworthy is how openly it marks the edges of what AURA knows. The Response Readiness score, for example, carries an "Estimated" label noting the number came from the nearest police station as a stand-in, and the final page states plainly that the report is a decision-support draft, not an authoritative determination.
The Real Challenge Was the Model
The first wall we hit had nothing to do with maps. It came from the model that writes the report. Asking software to reason about how drones threaten critical infrastructure means requesting deeply sensitive content. When asked plainly how a site could be attacked, the model would stall or refuse. The very restrictions that keep this technology safe were also standing between us and a legitimate security mission.
The solution was learning to describe the task honestly. A site assessment is a defensive exercise meant to reduce weakness and recommend protection, never to tell anyone how to do harm. Once we framed the request that way and pointed the model at the exact fields a report needed to fill, the writing came back both useful and responsible. The goal is to shape the task so the model can do real good while staying inside its guardrails.
Designing for the Mission
One idea held the project together. Technology should serve the mission, not the other way around. AURA serves CISA staff, facility operators, assessors, and administrators, each with different goals, so a plain interface and structured output mattered more than the software itself. The value is providing a consistent, reviewable starting point that users can trust. Saving each assessment as structured data alongside the readable report carried the same idea. An assessment is worth more when it is not only a page to read but something other systems can pick up and build on, whether that means tracking a single site over time or feeding a broader portfolio view across many facilities.
The Larger Takeaway
AURA began with a narrow problem. Operators need more Counter-UAS assessments than experts can write by hand. It points to a much broader challenge. As this technology moves into security work, the real test is not whether it can produce a report that sounds right, but whether that report can be produced consistently, framed responsibly, and reviewed by a human before anyone acts on it. AURA is an early prototype, but it shows how MetaPhase works. Protecting critical infrastructure from drones will always come down to human judgment. Tools like AURA exist to give that judgment a faster, clearer place to start.