A short tour of how the Aphid is designed to fail safely — two redundant channels, one shared safe state, and a hard rule that no single fault is ever invisible.