The safety case
Nothing in the safety case moves, and nothing is powered.
The HELIX safety concept does not depend on a pump, a valve, an operator, or a network. Reactivity self-limits on the core's own physics, shutdown is fail-safe on loss of power, and decay heat removes itself by natural circulation. The verification layer that makes the reactor checkable is deliberately held outside this boundary, across a hardware one-way path, and can never command a safety function. This page states each of those claims plainly and then states what still has to be proven before any of them is credited.
A modern microreactor safety case is judged on one question: what happens when everything that can be lost is lost, no grid, no operators, no cooling, no controls, and no way to intervene. HELIX is designed so that the answer to that question is set by physics and geometry rather than by equipment that has to work. The sections below walk each layer of that answer, from the reaction itself out to the boundary that keeps the verification layer honest.
How does HELIX shut itself down?
Shutdown happens twice over, once by physics and once by mechanism, and the physics comes first. HELIX is designed for a strongly negative temperature coefficient of reactivity: as the core temperature rises, reactivity falls, so power is self-limiting before any control system is asked to act. This is the same feedback that makes a well-designed reactor inherently stable rather than something that has to be actively held in check.
On top of that physics sit sixteen boron-carbide control drums and one diverse central shutdown rod. Their defining property is that they fail into safety. On any loss of power they rotate or drop their absorbing element into the core under spring return and gravity, needing no generator, no operator command, and no software decision. Our screening shows their combined worth exceeds any credible excess reactivity with margin, and the core remains subcritical even under the conservative assumption that the single most effective drum is stuck out. Those numbers are unqualified screening results and are treated as design inputs, not credited safety analysis, but the architecture they describe is deliberate: the mechanism is a backstop to the feedback, not a substitute for it.
What happens in a total loss of power and cooling?
This is the scenario that defines a walk-away-safe reactor, and it is where the sodium coolant and the sealed low-pressure design earn their place. After a trip, the core still produces decay heat, and in HELIX that heat leaves by natural circulation and thermal radiation alone. Hot sodium rises, sheds heat to the module structure and onward to the environment, and returns cooler, a convective loop that runs on temperature differences rather than on a pump. Nothing has to start, nothing has to be switched, and no operator has to be present.
The consequence is the sentence the whole design is built to earn: a complete loss of power and cooling in HELIX is an availability event, not a safety event. The plant stops making electricity; it does not approach fuel damage. The module's large thermal inertia and the low power density buy time measured in the terms that matter for emergency planning. This is also precisely why the open heat-transport decision, sodium heat pipes versus an EM-pumped pool, does not appear in the safety case at all. Whatever moves heat during normal operation, shutdown cooling is carried by natural circulation, so the safety case never credits a pump of either kind.
Why is there no water and no high pressure?
The primary coolant is low-pressure liquid sodium, and there is no water in the primary system. That single choice removes an entire family of accidents. There is no high-pressure blowdown, because there is no high pressure to release. There is no loss-of-coolant accident of the light-water kind, because the coolant is not a pressurized fluid flashing to steam. And because the power-conversion side is an organic Rankine cycle or supercritical-CO2 cycle rather than a steam plant, there is no energetic sodium-water reaction interface anywhere on the site. Sodium does react with water and air, which is a real engineering constraint we design the sealed boundary and inert cover gas around, but the site is deliberately built so that the aggressive counterpart, water, is never present in the same place as the sodium.
Defense in depth, stated as five independent barriers
Each barrier holds on its own. A release requires all of them to fail at once, and the first two are physics, not equipment.
The fuel kernel
Each TRISO particle is its own containment. Silicon-carbide layers retain fission products to temperatures far above any operating or accident condition. The first barrier is inside the fuel, before any engineered system.
Negative temperature feedback
If the core heats, the reaction slows. Power and temperature are self-limiting on physics alone, screened at roughly -6 to -8 pcm/K, before a single control action is taken.
Fail-safe shutdown
Sixteen control drums and a diverse rod insert on loss of power by spring and gravity. No generator, no operator, no software. Screened shutdown worth far exceeds any credible excess reactivity, even with one drum assumed stuck.
Passive decay-heat removal
After a trip, decay heat leaves by natural circulation and radiation alone. Nothing is pumped, nothing is powered, no valve moves and no action is required.
Low-pressure sealed boundary
The primary is low-pressure sodium with zero water. There is no stored pressure energy to drive a blowdown and no loss-of-coolant accident of the light-water kind.
Where does the verification layer sit, and why can it never cause harm?
HELIX is instrumented for protection by an independent digital-safety platform on an NRC-approved technology lineage, providing deterministic, analyzable trip logic. The RankShield attestation layer, the thing that makes each reactor independently checkable, is deliberately not part of that platform. It observes reactor integrity from outside the safety boundary, across a hardware one-way path: a physical data diode that lets information flow out to be attested and, by the construction of the wiring itself, cannot carry a command back in toward any safety system.
This is a boundary enforced by physics, not by policy. The attestation layer can prove a module's state to an operator, an insurer, or a regulator; it cannot rotate a control drum, override a trip, or touch a protective function, because there is no wire on which such a command could travel. The layer is classified non-safety and observe-only for exactly this reason, which is also what lets it ride on top of the reactor's licensing case without entangling the safety analysis. The reactor is safe whether or not the network exists; the network only makes that safety checkable.
What is proven, and what is still owed?
Every claim on this page is a design intent supported by unqualified reactor-physics screening, produced outside a nuclear quality-assurance program. It is not credited safety analysis and it is not field data. No microreactor of this class has yet operated at its rated life, and we will not describe screening as if it were a demonstrated result. The honest path to crediting these claims is defined: a stood-up NQA-1 quality program, structural and thermal finite-element analysis of the failure boundary, independent physics validation with independent codes and ultimately test data, and NRC review under 10 CFR Part 53. The safety architecture is designed to make that path shorter, because the hardest cases are answered by physics that does not need to be qualified so much as confirmed.