Battery-electric air taxis fly under a hard reserve rule — the FAA's powered-lift SFAR demands 20 minutes of reserve energy under VFR, 30 under IFR, and industry is arguing the number because reserves gate route economics. Every feasibility figure in that argument today is simulation. This page holds the other kind of statement: for a mission whose durations, powers, capacity and efficiency are known only as BOXES, the verdict "every parameter point lands at or above the reserve floor" is decided — CERTIFIED, REFUTED with an exact falsifying witness, or honestly REFUSED — by interval arithmetic with outward rounding. Mathematically certified enclosures; no airworthiness meaning, and the page says so.
The same mission, decided at every cruise duration under each rule. Nothing here is sampled and interpolated: each strip boundary is a change of VERDICT between two adjacent certified probes.
The FAA's 2024 powered-lift SFAR sets energy reserves for eVTOL operations — 20 minutes VFR, 30 IFR — and the industry pushback is public and quantitative: reserves determine which routes close. EASA's 2025 IAM package regulates energy management the same way. Yet every number in that argument — mission feasibility, deconfliction energy overhead, reserve adequacy — is produced by simulation: Monte Carlo percentiles over sampled parameters, floating-point optimizers, no statement that survives an adversarial reading of "for every case in the stated envelope".
The gap is not modeling sophistication — the field's power models are fine. The gap is the QUANTIFIER. "Feasible in 10,000 samples" and "feasible for every point in the box" are different claims, and only the second is the shape a reserve rule actually asserts. Interval arithmetic decides the second shape directly, and nobody in the eVTOL energy literature has published such a certificate.
A mission is segments (hover-climb, cruise, hover-land, …) with duration and electrical-power BOXES; the battery contributes usable-energy and efficiency boxes; the reserve rule contributes a reserve time at a reserve power. Used and required energy are enclosed over the whole box with outward rounding, and the universal verdict follows from two one-sided comparisons: worst case clears — CERTIFIED for every point; best case fails — REFUTED for every point, with the most favorable corner re-proved negative in exact BigInt rationals as the falsifying witness; anything between — REFUSED, with both margins printed. A refusal means the boxes genuinely contain passing and failing aircraft, and no honest instrument can say more until the boxes tighten.
The corner-witness logic is PROVED, not assumed: the battery sweeps all 256 corners of a two-segment instance in exact rationals and requires the interval bounds to be sound AND corner-achieving (tight to rounding) on feasible, marginal and doomed instances alike. Scope, honestly: this is energy accounting — Σ duration·power/efficiency against usable capacity — not electrochemistry. Voltage sag, temperature and aging live INSIDE the boxes a user states, which is exactly why the inputs are boxes: widen them to cover what the model does not resolve, and every verdict above stays sound.
| mission | 20-min reserve | margin (kWh) | 30-min reserve | margin (kWh) |
|---|---|---|---|---|
| short hop (10 min cruise) | CERTIFIED | 27.5 | CERTIFIED | 6.7 |
| design mission (20 min cruise) | REFUSED | -0.9 … 61.1 | REFUSED | -21.7 … 45.2 |
| stretch (35 min cruise) | REFUSED | -43.5 … 31.9 | REFUSED | -64.3 … 15.9 |
| deep stretch (55 min cruise) | REFUTED | -7.1 | REFUTED | -23.1 |
Margins are worst-case for CERTIFIED rows, best-case for REFUTED rows, and the worst…best pair for REFUSED rows — the two numbers a refusal honestly has. The parameter boxes are a representative vectored-thrust class (hover 420–520 kW, cruise 110–150 kW, usable 130–145 kWh, efficiency 0.88–0.94), stated in the page source as inputs — they are NOT any manufacturer's aircraft, and tightening or widening them re-decides every row by the same arithmetic.
Bisecting on cruise duration with a certified verdict at every probe puts the end of the mathematically certified envelope at 19 minutes of cruise under the 20-minute rule and 11 minutes under the 30-minute rule, for the stated boxes. That difference — 7 minutes of provable endurance — is the quantity the reserve debate is actually about, computed here as a theorem about the boxes rather than a fleet average. The same bisection run against an operator's own measured boxes is the instrument's intended use.
This is the first instrument of this site's aerospace front: the cheapest object where a certified universal statement replaces a simulation percentile in a live regulatory argument. The next two are named: an exact-rational audit of a published UAM capacity claim, and the front's flagship — a computer-assisted enclosure of an aeroelastic limit-cycle oscillation, an object with mature literatures on both sides and, as far as three independent searches can establish, no certified instance anywhere.