46 minutes to notice a vessel go dark
The authority (an anonymized, fictional agency in this demo) monitors a busy stretch of the North Sea: shipping lanes, offshore wind farms, subsea cables and fishing grounds. Its two operations centers track around 11,400 vessels a day from coastal AIS receivers, satellite AIS and radar contacts, with patrol aircraft reporting via ADS-B.
A vessel that stops transmitting AIS (“going dark”) is not always suspicious; receivers drop messages, and some vessels have faulty equipment. But a gap near a cable route or a sanctioned port call deserves attention fast. Analysts were spotting gaps by watching track displays and by running scheduled queries against an Elasticsearch archive. The median time from the last AIS message to an analyst flag was 46 minutes, by which point a vessel could be well outside the zone.
Context lived in separate tools: vessel registries, port-call history, weather, and open-source reporting. Building a case for escalation meant copying identifiers between five screens.
> We stopped watching screens for gaps and started reviewing gaps that matter. The difference is measured in nautical miles.
Coastal maritime authority · North Sea
How the maritime authority set up Kimo
Kimo Defense Intelligence was installed on the authority’s own hardware in its sovereign data center, with no outbound connectivity. AIS and ADS-B streams arrive through the existing Kafka bus, the historical archive stays in Elasticsearch, and OpenStreetMap layers and curated open-source feeds are mirrored internally.
A track-fusion model correlates AIS positions with radar contacts and expected routes. When transmissions stop, Kimo scores the gap against the vessel’s history, the expected receiver coverage at that position, weather, proximity to critical infrastructure and recent port calls. Gaps above a threshold appear in a single queue with the evidence attached, on a map with the last known track and a projected area of uncertainty.
Analysts work from that queue rather than from raw displays. Every flag, escalation and dismissal is recorded with the analyst, the timestamp in Zulu time and the reason, which feeds back into the scoring and gives supervisors a full audit trail.
- Week 101/03Install in the enclave
Signed bundle on the authority’s hardware; Kafka, Elasticsearch and mirrored layers wired.
- Week 202/03Track fusion & gap scoring
AIS, radar and routes correlated; scoring tuned on 90 days of history.
- Week 403/03Operational use
Both centers working from one gap queue with full audit trail.

