Case Studies

Under confidentiality.

Our deployments are active operations. The clients who've allowed us to share outcome data have done so under strict confidentiality agreements — sector disclosed, identity protected. Full case study documentation is available to qualified operators during the briefing process.

Site identity, precise location, and platform configuration detail are disclosed under NDA only.  ·  Outcome data published with client permission.  ·  All numbers are operational records, not projections.
Current published outcome
PAR-005  ·  Platinum mining · South Africa · Month 19 active  ·  Platform: Zerathis Blindspot™  ·  Threat classification: Extreme
97%
Opportunity Denied Rate
peak, sustained months 12–19
0
Successful extractions
across 19 months
100+
Suspects at peak activity
single peak period
Tonnes
Cable recovered
before extraction
14 days
Adversary re-model window
broken before threshold
Large coordinated crew
Insider access confirmed
Industrial extraction equipment
Cross-boundary syndicate coordination
Criminal logistics infrastructure
Threat classification: Extreme
The 19-month arc
Months 01–02
Deployment phase
Sustained adversary contact under full pressure — every attempt detected and denied. Zero successful extractions from day one.
Months 03–08
Pattern variation bites
Probe frequency falls sharply as the adversary cannot reconcile the shifting pattern with the model they built. Incident frequency collapses.
Peak period
Peak adversary activity
Peak adversary activity — large volumes of pre-staged material and criminal logistics supplies intercepted. Threat profile elevated to HIGH RISK. Every attempt denied. Zero successful extractions.
Months 09–16
Eight consecutive months, every extraction denied
Despite peak adversary activity, every attempted extraction was denied across eight consecutive months — not zero adversary presence, but zero successful extractions. The adversary was present, was detected, and could not predict where the drone would be. ODR sustained at 97%.
Months 17–19
Adversary escalates
Returns with modified approach. Cross-boundary coordination. Large-group operations. Method shifts flagged 28 days prior by the platform. Emergency variance directive issued. Every operation denied.
Operational cases
Peak adversary activity · HIGH RISK
100+
Suspects
Tonnes
Copper recovered
Yes
Criminal logistics intercepted
0
Successful extractions

The most sustained adversarial pressure across the deployment. Industrial extraction capability and large-scale logistics supplies indicating planned extended operations. Threat profile elevated to HIGH RISK. The platform had been actively disrupting for weeks prior. The adversary left with nothing.

Largest coordinated operation denied
30+
Suspects
Tonne+
Copper recovered
0
Successful extraction

A large group moves toward the perimeter under cover of night, with cross-boundary coordination between adjacent illegal mining syndicates confirmed. A significant volume of pre-staged cable is located and recovered before extraction. A variance directive had been issued weeks prior, after the platform detected group-size escalation and timing-shift signals.

The adaptation dynamic
Variable
Range observed across 19 months
Outcome
Group size
1 individual to large coordinated groups
DENIED
Timing
Operations across all hours — systematic timing shifts throughout
DENIED
Method
Opportunistic theft → pre-staged underground operations
DENIED
Coordination
Solo actors → cross-boundary syndicate coordination
DENIED
Logistics
Opportunistic theft → organised criminal logistics infrastructure
DENIED
Persistence
Returned after every interception. Never stopped adapting.
DENIED
The adversary cannot execute a plan they cannot complete.
Prior published outcome
Critical infrastructure · Freight rail · South Africa
70%
Incident reduction
measured period
ODR not yet built
this deployment changed that
Coordinated syndicates
Division-of-labour teams
Decoy attacks confirmed
Environmental timing used
Span taken down in under 10 minutes

Measured by incident reduction — the metric used before Zerathis was built. 70% reduction in incidents across the measured period against coordinated syndicates using decoy attacks, division-of-labour operations, and environmental timing to execute in under 10 minutes.

ODR is why we stopped counting incidents. This was the deployment that changed that.

Incident reduction tells you what happened. Opportunity Denied Rate tells you what the adversary couldn't build confidence in executing. The difference between those two metrics is the difference between reactive and preventative security.

We built Zerathis because 70% incident reduction wasn't the right answer — it was the right metric asked in the wrong direction.
Full documentation available under NDA

Additional case study documentation available to qualified operators and underwriters.

Site intelligence methodology, Zerathis platform configuration, variance directive logs, and the complete data sets for both deployments are available under a mutual NDA. The architecture is not disclosed publicly. The outcome is.

Commission a Blindspot Audit → Request full documentation →
High-risk operational environments only  ·  SACAA UASOC G1424D  ·  PSIRA Reg. 4340995
How to cite this paper
Parthenius Air, 19 Months. One Site. Zero Successful Extractions., Parthenius Air Research, PAR-005, 2026.
parthenius-air.com/case-studies
Continue reading
→ PAR-001 · What Is Adaptive Deterrence? → PAR-006 · The Adversary Learning Cycle → PAR-002 · The Learnability Problem ← Research library