India’s Drone Sovereignty Problem Is Moving Inside the Firmware
- AASHVAST is a New Delhi Indian Army facility for inspecting military drones and critical electronics for hidden vulnerabilities, unauthorised modifications and risky foreign components.
- Its reported air-gapped, read-only model examines firmware, credentials, update controls, remote-access paths and behaviour under GPS spoofing or jamming.
- The strategic shift is from platform indigenisation to software and component trust assurance: an Indian-assembled system is not automatically a sovereign system.
- The facility is distinct from existing drone-platform, counter-drone and field-evaluation signals; it is an acceptance and sustainment control point.
- Its value will depend on whether findings change procurement clauses, certification, fleet recertification, vendor disclosure and domestic design practices.
- AASHVAST is a New Delhi Indian Army facility for inspecting military drones and critical electronics for hidden vulnerabilities, unauthorised modifications and risky foreign components.
- Its reported air-gapped, read-only model examines firmware, credentials, update controls, remote-access paths and behaviour under GPS spoofing or jamming.
- The strategic shift is from platform indigenisation to software and component trust assurance: an Indian-assembled system is not automatically a sovereign system.
- The facility is distinct from existing drone-platform, counter-drone and field-evaluation signals; it is an acceptance and sustainment control point.
- Its value will depend on whether findings change procurement clauses, certification, fleet recertification, vendor disclosure and domestic design practices.
- Initial report identifying AASHVAST and its focus on hidden access paths, vulnerabilities and foreign components
- Detailed account of the facility's scope, air-gapped read-only design, DG EME role and inauguration
- Independent corroboration of firmware, remote-access, update and GPS-spoofing checks
- Context on the facility's broader electronic-systems and foreign-technology assurance role
- Additional independent reporting on unauthorised modifications, embedded keys and navigation-security controls
The development
The Indian Army has set up a specialised AASHVAST facility in New Delhi to inspect military drones and other critical defence electronics for vulnerabilities, unauthorised modifications and potentially risky foreign components. The facility was inaugurated by Chief of the Army Staff General Dhiraj Seth on 14 August 2026 and was developed as an analysis and validation suite for the Directorate General of Electronics and Mechanical Engineers. Its existence became public through reporting in September.
What AASHVAST examines
The facility looks below the airframe. Reports describe checks for hidden passwords, embedded encryption keys, secret command paths, remote-access tools, unauthorised firmware changes and whether software updates are accepted only from an approved manufacturer. It also examines controls that govern location-related behaviour when a drone faces GPS spoofing or jamming. These are not defects that a conventional weighing, visual inspection or bench test will necessarily reveal.
The deeper shift: from indigenisation to trust assurance
India's defence-indigenisation debate often asks where a platform was designed, assembled or manufactured. AASHVAST addresses a different question: can the user verify what the platform actually contains and what its software is capable of doing? A drone can carry an Indian badge while its flight controller, camera payload, firmware, update mechanism or navigation logic remains opaque. Security assurance is therefore a layer beneath platform indigenisation.
Why the air-gapped design matters
An air-gapped, read-only facility is designed to separate forensic inspection from the equipment's operational environment. The reported approach allows software to be extracted from a flight controller or payload, or examined from a stored image, without writing information back to the system. That design is important because the inspection process itself must not become a path for contamination or accidental modification. It also creates the possibility of repeatable evidence records rather than informal visual assurance.
A supply-chain control point, not only a cyber lab
AASHVAST's strategic value extends beyond identifying Chinese components. The wider issue is supply-chain visibility. Military electronics increasingly combine imported chips, contract-manufactured boards, open-source software, proprietary firmware and frequent updates. Without component authentication and software inspection, procurement officers may know who delivered the drone but not fully know what is inside it or what commands it will accept. A formal security posture record can turn that hidden uncertainty into a procurement and sustainment decision.
The limitation: inspection is not the same as control
A facility that detects vulnerabilities does not by itself remove them. The Army will need mechanisms to quarantine, remediate, reject, recertify or redesign affected systems. It will also need access to source material, component provenance, software bills of materials, trusted update infrastructure and vendors willing to disclose enough information for meaningful verification. The value of AASHVAST will ultimately depend on whether its findings change acceptance, contract clauses, fleet maintenance and domestic design practices.
How this differs from India's existing drone signals
S-050 covers the IAF's Pokhran evaluation of indigenous unmanned systems. S-061 covers Indrajaal's mobile counter-drone vehicle and its cyber takeover, spoofing, jamming and physical interception capabilities. S-078 covers Paras Defence's manufacturing rights for the Guardian interceptor. AASHVAST is different: it is a security-assurance and acceptance-control facility for examining the electronic and software integrity of military systems, not a drone, counter-drone weapon or field demonstration.
The Techadyant view
AASHVAST is an early but important sign that India's military technology sovereignty agenda is moving inside the platform. As drones become cheaper, more numerous and more software-defined, the vulnerability is no longer limited to imported airframes or visible components. It sits in firmware, update channels, navigation logic and undocumented access paths. A domestic capability to inspect those layers can become a strategic control point—provided it scales beyond one facility and feeds directly into procurement, certification, design and fleet sustainment.
What to watch next
The next evidence will be whether AASHVAST becomes mandatory for new drone acceptance, periodic fleet recertification and imported or joint-venture systems. Watch also for expansion to loitering munitions, radios, robotic vehicles, radars and battlefield networks; formal vendor-security requirements; software bills of materials; component-authentication rules; and feedback from the lab into Indian system design. The most important question is whether the Army is building a one-off forensic capability or a repeatable electronic-trust infrastructure for the entire force.
Track the systems we watch
Signals, reports and briefings on India’s industrial transformation.