# SPEEDERS — Kinetic Glide Footwear
## Engineering Design Brief & Manufacturer Hand-Off Document

**Document type:** Concept design brief for contract-manufacturer / engineering-firm evaluation.
**Revision:** v0.1 (concept)
**Status:** PRE-PROTOTYPE. This is a concept-level engineering brief, **not** a set of certified, production-released engineering drawings. Every dimension, part number, and performance figure below is a starting target to be validated by the engaging engineering firm through prototyping, DFM review, and formal testing. Do not tool any part from this document without an EVT/DVT validation cycle.

> **One-line product definition:** A clean, low-profile **performance tennis / court shoe (built at US Men's size 8.5)** that, at the press of a small recessed button, deploys four small motorized wheels from the sole and lets the wearer glide forward by leaning forward (forward-only, speed-governed), recovers a small amount of energy from walking and braking, and otherwise wears like a supportive court shoe. It is **wireless-charged on a dock** (walking does *not* recharge it — see Section 3), and at ~0.9–1.4 kg/shoe it is a "wear it for the ride" product, not an all-day everyday sneaker.

> **Reader's note on honesty:** The single most over-promised idea in "energy-harvesting footwear" is that walking can recharge a powered device. It cannot, at the scale that matters here. This brief treats the kinetic harvester as a **trickle source for low-power electronics and a small range-extender — not** as a way to power the drive motors. Section 3 quantifies this explicitly. If a marketing claim conflicts with Section 3, Section 3 wins.

---

## CAN A MANUFACTURER BUILD THIS AND HAVE IT WORK?

*Read this first if you're about to send this document to manufacturers. It's the straight answer to the only question that matters: "if I hand this to a factory, do I get a working shoe back?"*

**The honest truth:** **No hardware product "just works" straight from a spec — not this one, not anything.** A spec is not a product; it's the *starting instructions* for building one. There is no factory on earth that reads a document, presses a button, and ships you a finished, certified, working powered shoe. That is true of *every* piece of hardware — your phone, your earbuds, a car — all of it went through months-to-years of build-test-fix before the version you can buy existed.

What this document **is**: a complete, credible, internally consistent **concept design brief.** It names the right parts, the real physics, the hard constraints, and the safety work — enough that a serious engineering firm can pick it up and know exactly what they're building and where the hard problems are. A real contract manufacturer or product-development firm **CAN build a working prototype from it.** What they cannot do is skip the normal product-development cycle. This is a **one-year-ish R&D project, not a one-shot build.** Anyone who tells you otherwise is selling you something.

### The development roadmap (what actually happens, with rough time + cost)

These are *realistic* ranges for a small powered-wearable program, not quotes. A capable firm will give you firm numbers after Phase 0. Costs assume contracting a real engineering firm; doing more in-house shifts money to time.

| Phase | What happens | Rough time | Rough cost (USD) |
|---|---|---|---|
| **Phase 0 — Feasibility & CAD** | Engineers review this brief, build 3D CAD, run the weight†”range†”safety math, confirm the size-8 packaging actually closes, and produce a real project plan + firm budget. The "do we even proceed" gate. | **1–2 months** | **~$15k–50k** |
| **Phase 1 — Breadboard the electronics + firmware on a bench rig** | Wire up motors, ESCs, battery, IMU, and the lean-control + governor + safe-state firmware on a bench (not in a shoe yet). Prove forward-only lean-throttle and "no single fault causes unexpected acceleration" on the bench. | **2–4 months** | **~$30k–80k** |
| **Phase 2 — First mechanical prototype** | Build the deploy/retract mechanism + over-center lock and wheels into a sole, off-body. Prove the wheels deploy, lock, carry load, and retract reliably thousands of times. | **2–4 months** | **~$40k–100k** |
| **Phase 3 — Integrated wearable prototype + battery safety** | Cram everything into an actual wearable shoe. First time it's a "shoe you could stand on." Begin battery safety testing (crush/short/thermal) because now it's on a body. Expect this phase to reveal the hardest problems (weight, comfort, sealing). | **3–6 months** | **~$80k–200k** |
| **Phase 4 — User & safety testing + certification** | Real riders on real surfaces. Measure brake/stopping distance, stability, fall rate. Run the formal certifications: **UL 2272** (whole-system e-mobility cert — the long-lead item, §9.1) + **UL 2271** (pack), **UN38.3** (battery transport), **FCC/CE** (the BLE radio), brake-distance and **fatigue** testing, plus a regulatory-classification ruling. Iterate on what breaks. | **3–6 months** | **~$100k–300k+** (testing + cert labs are expensive) |
| **Phase 5 — Design-for-manufacture, tooling & pilot run** | Re-engineer the proven prototype to be *manufacturable* (DFM), cut injection-mold tooling (plan: §8.3), and build a pilot batch (EVT→DVT→PVT; why the pilot is ~1,000 pairs: §8.5). This is where unit cost finally drops and you have something sellable. | **4–8 months** | **~$150k–500k+** ground-up **OR ~$20–80k adapting an existing e-shoe OEM platform** (see below) |

**Two numbers people constantly confuse — keep them apart:**
- **What a PAIR costs the customer:** **~$199–349 at scale** (§15.1). This is a couple-hundred-dollar consumer product, not a $1,500 one.
- **What it costs a COMPANY to develop from scratch:** the six-figure R&D above. This is a business investment spread across thousands of pairs — it is *not* the price of a pair, and it is *not* what you personally pay.

**And you do NOT need the six-figure route.** That number is only if someone insists on inventing every part from zero. The cheap path to the same couple-hundred-dollar product: **license/adapt an existing electric-footwear or hover-shoe OEM platform** — the factories in Shenzhen/Dongguan already mass-producing powered rideable shoes — and pay for a **custom mold + firmware + your branding**. That is realistically **~$20–80k of development**, not $500k, and it reaches the same ~$199–349 retail because you're standing on an already-tooled, already-certified platform instead of rebuilding it. The from-scratch six-figure program is the *slow, expensive, own-every-patent* route; the adapt-a-platform route is how a small founder actually ships a couple-hundred-dollar product.

*(A bare "does it glide?" proof — Phases 0–2 only — is cheaper still: a few months and tens of thousands, or the ~$100 hoverboard-harvest build for a personal proof. It is not a rideable product, but it proves the idea before any of the above.)*

### The EVT descope list — build ONLY what retires risk

The first prototype's only job is to prove: deploy-lock reliability, lean-throttle + safe-state firmware, battery abuse survival, and ride stability. Everything below is deferred to DVT — cut it from the first build and pocket the savings. Every cut is honesty-compatible: nothing here changes a claim in §3, §5, or §10.

| Cut / simplify at EVT | What it saves | Risk of cutting |
|---|---|---|
| **Kinetic harvester — whole subsystem** | ~60–110 g, ~$60–150/shoe, 2–4 weeks of mechanism dev, and defers the 5–10M-cycle fatigue question | None — §3 already establishes it's a trickle; validate on a bench rig in parallel, integrate at DVT |
| **Wireless charging + dock → wired-only** | Dock program (~$10–30k), coil/IC integration, charge-through-sole thermal unknowns | None for ride validation |
| **Deploy = recessed physical button (baseline design)** | Avoids all flex-electrode tuning + false-trigger debugging vs a tap zone | None — a guarded mechanical button is simpler *and* safer than a tap gesture; already the production choice (§6.1) |
| **Court knit upper → modified donor shoe over the custom chassis** | Sample-room upper development ($10–25k, weeks) | Prototype looks ugly; EVT is not a styling gate |
| **IP67 sealing → dry-lab only at EVT** | Gasket/potting design cycles | Must return at DVT; battery stays fully enclosed regardless |
| **BOA → laces; LEDs/haptics → minimum** | $15–30/shoe + harness complexity | None |
| **Custom FOC ESC → off-shelf dual-channel ESC boards** | A custom board spin | Bulkier package; fine for bench + rig work |
| **NEVER cut:** deploy struts + over-center lock, battery vault + load bridge, IMU safe-state firmware, speed governor, dual-shoe BLE sync | — | These ARE the product risk. An EVT without them proves nothing. |

### What's already de-risked vs. what's unproven

**Already de-risked — every individual technology in here already exists and ships in real products today:**
- **Hub-motor e-skates / e-skateboards** — small in-wheel BLDC motors driven by ESCs are a mature, off-the-shelf micro-mobility technology.
- **Lean / IMU balance control** — self-balancing scooters, hoverboards, and one-wheels already read body lean from an IMU and drive motors from it.
- **Qi / inductive wireless charging** — standard, everywhere, well-understood.
- **Kinetic energy harvesters** — sprung-plate / coil / piezo harvesters are real (just *small* — see §3; that's why this brief never relies on them to charge the drive battery).

None of those four pieces is a science experiment. That's the good news: **the brief isn't asking anyone to invent new physics.**

**Unproven — must be prototyped, because nobody has shipped *this specific combination*:**
- **Cramming all of it into a comfortable, wearable sole** at a tolerable weight. The pieces exist; fitting them under one foot without it feeling like a brick is the unsolved part.
- **Deploy-lock reliability** — wheels that pop out, lock hard enough to carry a person, and retract safely, thousands of times, without failing. This is the single most mechanically risky bit.
- **Stability on small wheels** — a short, narrow, high-center-of-mass platform is inherently tippy; whether it's *rideable enough* for a normal person is a real open question to test.
- **Weight** — landing at a weight people will actually wear (§7.4 is honest: ski-boot/work-boot class) is a make-or-break unknown.
- **A minor riding a lithium-battery device on their feet** — the safety, liability, and certification bar here is high and not yet cleared. This is as much a legal/safety problem as an engineering one.

### Bottom line (plain English)

Yes — a capable engineering firm **can** build a working prototype from this document, because nothing in it requires inventing new technology; it's about *integrating* things that already work. **The finished product is a couple-hundred-dollar consumer item at scale (~$199–349/pair, §15.1)** — this is not a $1,500 product, and its *retail price* is never the same thing as a company's development budget. The cheapest route to that product is not a $500k ground-up program at all: it's **adapting an existing electric-shoe OEM platform** (the factories already making powered rideable shoes) for roughly **$20–80k** in mold + firmware + branding, riding on their already-tooled, already-certified base. The big six-figure number only appears if someone insists on inventing every part from scratch. Whatever route, treat anyone who promises a *guaranteed working product* with no prototyping — with heavy skepticism; that contradicts how all hardware is made. Use this brief to find a partner who talks in phases and honest numbers.

---

## EXECUTIVE SUMMARY — KEY ANSWERS

*Plain-language answers to the questions a non-engineer (or a manufacturer reading this cold) will ask first. Copy-paste friendly. Everything here is a validated-by-prototype target, not a guarantee. Where this summary and the detailed sections differ, the detailed sections win.*

**Size of the build:** Everything in this brief is specced for **US Men's size 8.5** (foot length ~26.4 cm). Finished outsole ~289 mm long, ~100 mm across the forefoot, and the sole sits ~30–34 mm off the ground in Walk mode (wheels retracted). See §1.5 for the full dimensions table — all space budgets (battery bay, wheel wells, plate cavities) are referenced to this size.

**How heavy is it, and will people actually wear it all day?**
- Honest weight: **~0.9–1.4 kg per shoe** (the realistic build), versus a normal sneaker at ~250–350 g. That's **roughly 3–5× a normal shoe** — in the weight class of a **ski boot or a heavy work boot**, not a sneaker.
- **No — this is not a comfortable all-day everyday shoe at that weight.** Be honest with yourself and with customers: it's a **"wear it for the ride / the commute" product**, not something you forget you have on. You put them on to glide somewhere, not to stand in them for eight hours.
- There **is** a real path to make a lighter v1 (~**0.7–0.9 kg**): smaller battery, lighter motors, a magnesium/composite frame with a carbon plate, thinner harvester plates, and hollow wheels. Every one of those costs range or features — the tradeoffs are laid out in §1.6 and the gram-by-gram budget is in §7.4.

**How far does it go on a charge, and how long to charge?**
- Realistic **pure-glide range: ~6–12 km (~4–7 miles)** on flat ground for a 60–80 kg rider at the governed speed. Translation: **a commute or a lap around campus = fine. All day = no.** Hills, a heavier rider, cold weather, or hard riding pull it toward the low end (~4–6 km).
- **Charging is wireless-first.** You set both shoes heel-down on an **inductive dock overnight** (like a giant Qi pad shaped for the shoes). A ~30–60 Wh pack at ~10–15 W of inductive power = **~3–5 hours to full**. A wired USB-C / pogo-contact option charges noticeably faster if you're in a hurry.
- Battery cycle life: ~**300–500 full charge cycles** before the pack noticeably weakens (it's a service-replaceable consumable).

**Does walking charge it? (the big one):** **NO.** The kinetic plates in the sole harvest only **tens of milliwatts up to ~1–2 W in bursts** — that is **~100–400× less energy per km than gliding burns (§3.4)**. Walking **trickle-charges the electronics, sensors, and lights** and adds a *tiny* bit of range at the margins. It does **not** meaningfully recharge the drive battery, and it cannot power the wheels while you ride. **You must put it on the wireless dock regularly. Walking is a bonus, not the charger.** Anyone who claims a shoe recharges its e-mobility battery from walking is wrong about the physics — see §3.

**What does it look like?** Styling target is a clean **performance tennis / court shoe** — low-profile, **white platform** with a colorway-specific knit upper (hero colorway: blue-black knit + cyan light, §7.6), supportive court silhouette — **not** a chunky casual sneaker. See §7.

**Bottom line:** The propulsion, controls, power, and deploy mechanism are all buildable today by a skilled firm with a serious safety program. The two truths to design around: **(1)** walking does not recharge it — wireless charging does; **(2)** the weight†”range†”safety triangle forces a heavy shoe with bounded range and a low speed cap. Build around those and it's a credible product; build around the over-promises and it isn't.

---

## Table of Contents
0. **EXECUTIVE SUMMARY — Key Answers** (size, weight, range, charging, walk-charge verdict)
1. Overview, Design Goals, Hard Constraints & Tradeoffs (incl. §1.5 size-8 dimensions, §1.6 weight-reduction plan)
2. Full Bill of Materials / Parts List
3. Kinetic Energy Harvester (Walk-to-Charge — and why it does NOT recharge the drive battery)
4. Drivetrain — Four Hub-Motor Wheels + Deploy/Retract
5. Power System — Battery, Wireless Charging (primary), Regen, PMIC, Thermal
6. Control Electronics + Firmware (incl. §6.6 wiring harness + pinouts + block diagram, §6.7 full sensor suite, §6.8 PowerDeck battery-safety layout)
7. Upper / Sole / Comfort Construction
8. Assembly Sequence + Serviceability
9. Safety + Regulatory
10. Honest Feasibility Verdict

**PART II — EXPERT ENGINEERING & DESIGN ADDENDUM** — deeper detail from a 5-specialist review panel; *where a figure differs from Part I, Part II governs:*
11. Structural, Drive & Mechanical Engineering — load cases + fatigue, corrected glide/motor current math, deploy-torque reality (unloaded-only), over-center latch design, stability & braking numbers, bearings, materials/finishes, grit management
12. Electrical & Power Engineering — pack C-rate/burst/sag, harness ampacity fixes, protection trip-ladder, wireless-charge physics + carbon keep-out, quiescent/ship-mode/shelf-life, EMI coexistence
13. Safety, Compliance & Regulatory (expanded) — UL 2272/2271 certification matrix, design FMEA, PowerDeck battery abuse-test matrix, rider envelope, brake criterion, labeling/IFU
14. Industrial Design, CMF & Human Factors — design language, PANTONE CMF spec, light + haptic language, ergonomics/mass-placement, size grading, brand-mark usage
15. Manufacturing, Tooling & Cost (DFM) — EVT-vs-1k cost table, tooling plan, EVT descope list, two-factory reality, MOQ / single-supplier / customs
- Appendix A — Footwear tech-pack deliverables (Phase-0 gap list)

---

## 1. Overview, Design Goals, Hard Constraints & Tradeoffs

### 1.1 Product concept
SPEEDERS is a single integrated wearable: each shoe is an independent powered micro-vehicle that masquerades as a clean, low-profile **performance tennis / court shoe** (built at US Men's size 8.5). The two shoes form a paired system over Bluetooth Low Energy (BLE), sharing speed governance, fault state, and rider-intent data so they accelerate, coast, and brake in lockstep. There is no handheld controller — glide intent is read from the rider's body via inertial sensing, and deploy/retract is triggered by a **small recessed physical button** on each shoe (deliberately a guarded mechanical button, **not** a tap gesture — a capacitive tap would false-trigger from walking, bumps, or brushing the shoe, which is a safety event).

The four operating modes:
- **Walk mode (default):** Wheels retracted and locked. Shoe behaves as a normal cushioned sneaker. Kinetic harvester and low-power electronics active; motors unpowered. This is the state the shoe spends ~95% of its life in.
- **Deploy transition:** Press the recessed deploy button → wheels swing/telescope down, shoe lifts ≤5 mm onto the wheels, motors energize to a standby (zero-throttle, position-hold) state. The button is **recessed and requires a deliberate press** (a guard ring + firm actuation force + firmware debounce), so it cannot fire from walking, kicking a curb, or brushing — it deliberately does **not** respond to taps. Deploy is **per-shoe and gait-sequenced**: one button press *arms* both shoes (over the BLE link), and each one actuates only during its own unweighted swing phase (FSR-gated, §4.4) — a loaded shoe cannot lift a standing rider and never tries.
- **Glide mode:** Lean the body's center of mass forward → forward throttle ramps up under a speed governor. Lean back or heel-press → regenerative + friction brake. **Forward-only. No reverse. No powered turning in v1.** Steering is done the way it's done on a longboard — by the rider's balance and edge weighting, within a very limited range.
- **Safe-state / auto-retract:** Detected stairs, curbs, prolonged standstill, fall, or fault → motors coast to stop, wheels retract and lock, shoe reverts to Walk mode.

### 1.2 Design goals (ranked)
1. **Safety first, by a wide margin.** A foot-mounted powered vehicle that can throw a rider is the central risk. Fail-safe (coast-to-stop, retract, lock) must be the default of every fault path. Target: no single electrical or firmware fault produces unexpected acceleration.
2. **It must genuinely pass as a normal, comfortable shoe in Walk mode.** If it doesn't walk well, nobody wears it, and the glide feature is irrelevant.
3. **Honest, bounded performance** over impressive-sounding performance. A modest, reliable 8–10 km/h (6 mph) glide that always brakes predictably beats a 25 km/h product that occasionally doesn't.
4. **Serviceability** of the two consumable/wear items: the battery pack and the wheels.
5. **Manufacturability** at a realistic BOM cost (§10.5) — no exotic processes that can't scale.

### 1.3 Hard constraints
| Constraint | Target | Why it's hard |
|---|---|---|
| Per-shoe mass | **‰¤ 1.2 kg** target, 1.5 kg hard ceiling | Every gram is on the end of the rider's leg; foot-mass dominates walking metabolic cost. This is the binding constraint on everything. |
| Walk-mode feel | As close as possible to a supportive ~250–350 g performance court shoe under the forefoot (it will be heavier — see §7.4) | Carbon plate + wheel wells + harvester plates all fight cushioning. |
| Pure-glide range | **6–12 km realistic** (see §10) on battery alone | Bounded by how much Li-poly fits the size-8 arch bay (‰ˆ 30–60 Wh, §1.5) vs. motor draw. |
| Glide top speed (governed) | **8–10 km/h (6 mph) v1**, hard-capped in firmware | Small wheels + foot platform = low rollover threshold; speed is the dominant injury multiplier. |
| Deploy/retract time | One button press **arms** both shoes; each deploys **< 0.4 s in its next unweighted gait window** (FSR-gated); both locked-deployed within ~2 gait cycles (~1.5–2 s of the command) | A *loaded* deploy needs >10× the specced actuator torque (§4.4) — deploy is unloaded-only by physics. Slow or unsynced lock-up is a fall hazard. |
| Water ingress | **IP67** (dust-tight; survives temporary immersion — puddles + heavy rain) | Sealing a flexing knit shoe full of electronics is genuinely difficult. |
| Battery safety | UN38.3 + IEC 62133 cell, hard short/over-temp protection | Li-poly under a flexing, impacted, sweaty foot is the worst-case pouch-cell environment. |

### 1.4 The three-way tradeoff (weight †” range †” safety)
This is the heart of the engineering problem and the firm must treat it as a single coupled budget, not three separate ones:

- **More battery → more range, more weight.** A 45 Wh pack is ~220–260 g of cells alone; pushing past that to chase range quickly blows the foot-mass budget and degrades the walk experience (which is goal #2). Range is therefore deliberately capped by a weight ceiling, not maximized.
- **More speed/torque → bigger motors + bigger battery + worse stability and worse crash energy.** Kinetic energy scales with v²; a crash at 10 km/h (6 mph) carries ~2.25× the energy of one at 8 km/h. We cap speed low on purpose.
- **More safety hardware (redundant brakes, bigger wheels for stability, robust retract lock, thermal mass) → more weight → less range.**

**Resolution stance for the firm:** Fix the weight ceiling first (‰¤1.5 kg). Inside that ceiling, allocate to safety hardware before range, and cap speed low. Range and top-speed are the *outputs* of the safety-and-weight budget, not the targets. Do not let a spec sheet talk you into a 30 Wh-bigger battery that breaks the walk feel.

### 1.5 Reference size & key dimensions (everything is built to US Men's size 8.5)

**The entire brief — every volume budget, every cavity, every space allocation — is dimensioned to a single reference size: US Men's size 8.5.** Build, prototype, and validate at this size first; grade to other sizes only after the size-8.5 build is proven. All "battery bay," "wheel well," and "plate cavity" volumes referenced elsewhere in this document assume the envelope below.

| Dimension | Target (US Men's 8) | Notes / why |
|---|---|---|
| **Foot length** (last) | **~26.4 cm** | Standard US Men's 8 foot length; drives the last and the internal length budget. |
| **Finished outsole length** | **~289 mm** | Foot length + toe spring + heel wrap + outsole overhang. The hard length envelope for packaging. |
| **Forefoot width** (widest, outsole) | **~100 mm** | Court-shoe last at this size; sets the **track width** ceiling for the wheels (~70–90 mm usable, §4.6). |
| **Heel width** (outsole) | **~70–75 mm** | Constrains rear wheel track + heel coil/dock-contact placement. |
| **Stack height, Walk mode (retracted)** | **~60 mm heel / ~50 mm forefoot** (revised in §4.2b — the earlier 44/36 counted only the wheel bay and left ZERO mm for the outsole, carbon plate, harvester, foam and insole; 30–34/22–26 could not contain the wheels at all) | Heel-to-ground with the wheel system stowed inside the sole. Thicker than a 250 g court shoe (~18–22 mm) because the carbon plate, wheel wells, harvester plates, and arch battery box all live in this stack. This is part of why it reads "supportive/chunky-ish" even in the slim court silhouette. |
| **Ground clearance, Glide mode (deployed)** | **≤5 mm** lift onto wheels | Deliberately minimised (§4.4b-2 Fix 2) so the one-shoe-deployed window is not a trip hazard; raises effective stack only slightly at the heel while riding. |
| **Wheel outer diameter** | **~45 mm** (range 40–55) | Bounded above by the ~~60 mm heel stack + well depth; bounded below by rollover safety (§4.2). |
| **Wheelbase (per shoe)** | **~180–220 mm** | Front-to-rear wheel spacing ‰ˆ length of the rigid carbon plate. |
| **Track width (per shoe)** | **~70–90 mm** | Limited by the ~100 mm forefoot / ~70 mm heel outsole width. Narrow track = inherently tippy (§4.6). |
| **Battery bay (arch enclosure)** | **~90 × 55 × 12 mm usable** (~55–60 cm³) | The flat void under the arch at size 8.5; sets the ~30–60 Wh pouch-pack ceiling. Bigger battery would have to grow the stack or steal forefoot space — both bad. |
| **Wheel wells** | **4 × (~48 × 24 × 20 mm)** at the corners | Sized to swallow a ~45 mm wheel + strut sweep with the sprung covers closed. |
| **Plate cavity (carbon load plate)** | full-length, ~285 × 90 mm footprint, 1.2–2.0 mm thick | The structural spine; spans nearly the whole outsole footprint at this size. |

> **Grading note:** these are size-8 numbers. Smaller sizes have *less* room for the same hardware (the battery and wheels don't shrink as fast as the foot), so size 8.5 is a deliberately middle-of-the-road validation size — not the hardest case. The firm should sanity-check the smallest intended size for packaging feasibility before committing to a size run. Full size-run, grade-rule, and chassis-banding plan: §7.7.

### 1.6 Weight-reduction plan — pushing a v1 toward ~0.7–0.9 kg/shoe

The realistic build lands at **~0.9–1.4 kg/shoe** (§7.4). That is heavy — ski-boot/work-boot class. A lighter, more wearable **v1 target of ~0.7–0.9 kg/shoe** is achievable, but **every gram saved costs range or capability.** This is a menu of explicit tradeoffs for the firm, not free lunches:

| Lightweighting move | Approx. saving (per shoe) | What it costs you |
|---|---|---|
| **Smaller battery** (30 Wh instead of 45–60 Wh) | **~80–130 g** | Cuts pure-glide range proportionally — roughly **~6–8 km → ~4–5 km**. The single biggest lever, and the most painful. |
| **Lighter BLDC motors** (lower-power, optimized-winding hub motors instead of generic micro-mobility class) | **~50–90 g** (4 wheels) | Less peak torque → weaker hill-climb and slower-from-standstill for a heavy rider; may need geared hubs (adds a little noise/wear back). |
| **Magnesium / composite frame + carbon plate** (instead of 7075 aluminum chassis) | **~40–80 g** | Higher material + process cost; magnesium needs corrosion coating (sweat environment). Best stiffness-to-weight win available. |
| **Thinner harvester plates** (reduce stroke/mass, or drop the rack-gen + piezo paths and keep only the EM coil) | **~25–50 g** | Even less harvested energy (already tiny per §3) and slightly firmer underfoot feel. Low risk — the harvester was never the range story. |
| **Hollow / cored PU wheels** (vs. solid cast PU) | **~20–40 g** (4 wheels) | Slightly less impact compliance and a small durability hit; must fatigue-test the core. |
| **Trim structure & fasteners** (topology-optimized struts, fewer/smaller screws, lighter well covers) | **~15–35 g** | Engineering time; watch fatigue margins on load-bearing struts/locks. |
| **Realistic combined v1 saving** | **~230–525 g** | Stacking the safe-ish wins (lighter motors + Mg frame + thinner harvester + hollow wheels + trim) lands a ~1.1 kg build near **~0.8–0.9 kg** *without* shrinking the battery; take the smaller battery too and you reach **~0.7 kg** at the cost of range. |

**Recommended v1 stance:** take the structure, motor, harvester, and wheel savings (they cost little real-world capability), and treat the **battery downsize as the optional last lever** the rider trades for. Ship "lighter but ~4–5 km" and "heavier but ~6–8 km" as the same shoe with a different pack, if the arch bay can accept two pack sizes. **Do not** chase sub-0.7 kg by cutting safety hardware (locks, brakes, thermal mass) — that violates §1.4.

---

## 2. Full Bill of Materials / Parts List

All components below are **per shoe** unless noted. Items labeled **(reference part)** name an off-the-shelf component *category* as a starting point for sourcing — the firm should second-source and qualify equivalents. "Qty" is per shoe.

### 2.1 Drivetrain subsystem
| Part name | What it is | Material / spec | Function | Qty |
|---|---|---|---|---|
| Hub-motor wheel assembly | Small in-wheel BLDC motor with integrated wheel | **(reference part)** outrunner BLDC, 38 mm OD rear / 30 mm front (§4.2b), sensored (3× Hall), **matched to the pack: 7.4–11.1 V nominal (2S–3S)**, 90–110 W continuous (see §4.2c — sized for acceleration + grade, not cruise); e.g. micro-mobility hub motor class | Drives the shoe forward; doubles as regen generator | 4 |
| Wheel tread / tire | Polyurethane wheel bonded to hub rotor | Cast PU, **78A–85A durometer**, 38 mm rear / 30 mm front OD × ~18–22 mm wide, slight crown | Grip, ride compliance, wear surface | 4 (integral to hub) |
| Wheel bearing | Precision bearing pair per wheel | **(reference part)** ABEC-7 608-class sealed (or smaller 686/688), stainless or ceramic hybrid | Low-friction rotation, sealed against grit | 8 |
| Deploy strut / swing-arm | Pivoting or telescoping arm carrying each wheel | 7075-T6 aluminum or carbon-wrapped arm; hard-anodized pivot | Moves wheel between stowed and ground positions; primary load path | 4 |
| Deploy actuator | Motor/solenoid that drives the strut | **(reference part)** compact metal-gear servo (~6–12 kg·cm) **or** bistable rotary solenoid | Deploy/retract motion | 2 (one per axle pair) or 4 |
| Mechanical lock / detent | Over-center latch or pin that locks struts in BOTH stowed and deployed positions | Hardened steel pin + spring, or over-center cam | Carries rider load WITHOUT holding actuator current; fail-safe lock | 4 |
| **Wheel-hub brake pawl** | Sprung pawl that engages the wheel hub the instant it deploys | Hardened steel pawl + torsion spring, elastomer-damped seat (silent, §4.4c) | **Stops the wheel free-spinning while deployed-but-not-gliding — prevents roll-away when a rider stands on one deployed shoe (§4.4b-2 Fix 1).** Holds with zero power; releases only on a gated Glide command | 4 |
| Carbon load plate | Full-length structural plate in midsole | Continuous carbon-fiber/epoxy laminate, ~1.2–2.0 mm, tuned stiffness | Reacts wheel/strut loads into a rigid spine; also the propulsion-day stiffness element | 1 |
| Strut return spring | Spring assisting retract / fail-safe | Stainless music wire or torsion spring | Biases struts to safe (retracted) state on power loss (see §4.5) | 4 |

### 2.2 Kinetic energy harvester subsystem
| Part name | What it is | Material / spec | Function | Qty |
|---|---|---|---|---|
| Heel harvester plates | Spring-loaded plates under the heel that travel a few mm/step | Glass-filled nylon / carbon plate on guided posts | Captures heel-strike compression (largest single impulse) | 2 (medial + lateral heel) |
| Midfoot harvester plate | Plate under the arch/midfoot transition | Glass-filled nylon / carbon plate | Captures roll-through between heel-strike and toe-off | 1 |
| Forefoot harvester plates | Plates under the metatarsal heads + toe-off zone | Glass-filled nylon / carbon plate | Captures forefoot loading and push-off | 3 (medial, central, lateral) |
| Harvester return springs | Springs returning plates after each step | Conical steel springs or molded elastomer, ~3–6 mm stroke | Restore plate, set foot "feel," store/release energy | 12–18 (2–3 per plate) |
| Linear EM generator (moving-magnet) | Coil + moving NdFeB magnet, plate motion → induced current | NdFeB N52 magnet in copper coil, sprung | Converts mm-scale plate travel into electrical energy | 6 (one per plate) |
| Rack-and-pinion micro-generator (alt/supplement) | Rack on plate spins a tiny geared DC generator | Micro DC motor used as generator + gearhead | Alternative/parallel harvest path; better at slow stroke | 0–2 (design choice) |
| Piezo stack (supplement) | Stacked piezo elements under plate | PZT multilayer stack | Captures high-frequency impulse on heel strike; tiny but free to add | 0–2 (optional) |
| Harvester rectifier + conditioning | AC→DC + boost for tiny voltages | **(reference part)** energy-harvesting PMIC (e.g. ultra-low-Vin boost/rectifier class) + Schottky bridge | Rectify and boost variable harvester output to a usable rail | 1 |

### 2.3 Power subsystem
| Part name | What it is | Material / spec | Function | Qty |
|---|---|---|---|---|
| Battery pack | Li-polymer pouch pack in the arch | **(reference part)** Li-poly pouch cells, 2S or 3S, **30–60 Wh** total (~7.4–11.1 V nominal), IEC 62133 / UN38.3 qualified; sized to the size-8 arch bay (§1.5) | Primary energy store for motors + electronics | 1 pack (2–4 cells) |
| Battery management system (BMS) | Protection + balancing PCB | **(reference part)** multi-cell BMS IC with cell balancing, OV/UV/OC/short/over-temp cutoff | Protects pack; hard-cuts on fault | 1 |
| Inductive RX coil (PRIMARY charge) | Wireless charging secondary coil in the heel | Litz-wound Qi-style RX coil + shielding ferrite, heel-mounted for dock alignment | **Primary charge path** — receives ~10–15 W wireless power from the dock | 1 |
| Wireless RX controller | Inductive power receiver IC + rectifier | **(reference part)** Qi/WPC-style (or proprietary) RX IC | Converts coil AC to DC charge current | 1 |
| PMIC / system PMU | Power-management IC: charger + regulators | **(reference part)** buck/boost + Li charger PMIC | Generates 3.3 V logic, motor-rail handoff, charge control | 1 |
| Regen-braking circuit | MOSFET network steering motor back-EMF to pack | **(reference part)** synchronous buck/regen stage built around the ESC FETs | Recovers braking energy; provides electrical braking torque | 1 (shared in ESC) |
| Master fuse + e-fuse | Overcurrent protection | Resettable PTC + solid-state e-fuse IC | Hard overcurrent/short protection on the pack output | 1 |
| Thermistors | Temperature sensors | NTC 10k, multiple | Cell temp, motor temp, MCU temp for thermal cutoff | 3–4 |
| Charge / dock contacts | Backup conductive charge path (wired fast-charge) | Gold-plated pogo pads or gasketed USB-C (sealed) | Optional **faster ~1.5–2.5 h** wired charge; backup to the primary wireless dock | 1 set |

### 2.4 Control electronics subsystem
| Part name | What it is | Material / spec | Function | Qty |
|---|---|---|---|---|
| Main MCU / SoC | Microcontroller with BLE radio | **(reference part)** ESP32-class (dual-core + BLE) or Nordic nRF52/nRF53 (lower power, better BLE) | Runs control loop, governor, BLE link, state machine | 1 |
| IMU | 6-axis accel + gyro (9-axis optional) | **(reference part)** MEMS 6-DoF IMU (accel ±8g, gyro ±1000 dps), e.g. ICM/LSM/BMI class | Lean-angle + motion + fall detection | 1 |
| Deploy button | Recessed sealed momentary push-button (guarded tactile dome switch) | **(reference part)** IP67 sealed tactile switch, ~2–4 N actuation, in a recessed guard ring on the medial midsole | Deliberate deploy/retract trigger — mechanical, cannot false-fire from walking/brushing (replaces any tap gesture) | 1 |
| Motor driver / ESC | 3-phase BLDC gate driver + FETs (4 channels) | **(reference part)** integrated 3-phase BLDC driver (sensored FOC-capable), 1 per wheel | Drives each hub motor; handles regen | 4 (or 2 dual) |
| Hall / encoder feedback | Wheel speed + commutation feedback | Hall sensors in hub motor (+ optional magnetic encoder) | Closed-loop speed control, governor, odometry | 4 sets |
| Deploy-position sensor | Confirms strut stowed/deployed/locked | Hall + magnet or micro limit switch per strut | Verifies safe lock state before allowing throttle | 4 |
| Pressure / load sensor (insole) | FSR or load cell, heel + forefoot | **(reference part)** force-sensitive resistor array | Confirms foot loaded, weight-shift / step detection, brake-press detect | 2–4 |
| Status LEDs / indicators | RGB LEDs (also nighttime visibility) | Side/heel LED light pipe | Mode/charge/fault indication + be-seen lighting | 2–6 |
| Haptic actuator | LRA vibration motor | Linear resonant actuator | Tactile alerts (deploy ready, low batt, fault) | 1 |
| Main PCB / flex-rigid board | The board everything mounts to | Flex-rigid FR4 + polyimide, conformal-coated | Houses MCU/PMIC/ESC/IMU; flexes with shoe | 1 |

### 2.5 Structure / upper / comfort subsystem
| Part name | What it is | Material / spec | Function | Qty |
|---|---|---|---|---|
| Knit upper | Engineered knit shoe upper | Recycled-poly/spandex engineered knit + TPU overlays | Fit, breathability, the "normal shoe" look | 1 |
| Midsole foam | Cushioning foam over carbon plate | Supercritical-foamed PEBA or EVA/TPU blend | Cushioning, energy return, comfort | 1 |
| Outsole tread (walk) | Ground contact rubber for Walk mode | Abrasion rubber, lugged | Grip + protect sole when wheels stowed | 1 |
| Wheel-well covers | Spring-loaded flaps over wheel wells | TPU flap + return spring | Seal wells in Walk mode; open on deploy; keep grit out | 4 |
| Internal chassis / cage | Rigid sub-frame holding battery, PCB, struts | Glass-filled nylon + alloy inserts | Structural skeleton tying drivetrain to load plate | 1 |
| Arch battery enclosure (**PowerDeck vault**) | Sealed, impact-rated battery box in the arch | GF-nylon shell + silicone gasket, vented relief | Protects + isolates the flat pouch cells; IP-sealed; thermal path (see §6.8) | 1 |
| **Load bridge** | Spring-steel arch that spans over the battery vault | Spring steel / Ti, tuned to body-weight | Carries the wearer's weight *around* the cells into the sole rails — **so the foot never compresses a cell** (§6.8) | 1 |
| Wiring harness set | All internal cabling + latching connectors | Silicone/PTFE stranded, JST/XT-class, potted | Interconnects every subsystem; routed in cage channels (§6.6) | 1 set |
| Gaskets / seals | Sealing of all electronics cavities | Silicone/foam gaskets, potting where needed | IP67 ingress protection | as needed |
| Lace / closure system | Closure | BOA-style dial or traditional laces | Secure fit (critical for glide control) | 1 |
| Fasteners | Service screws, threaded inserts | Stainless M1.6–M3, heat-set brass inserts | Serviceable assembly | ~20–30 |

---

## 3. Kinetic Energy Harvester (Walk-to-Charge)

**This is the most over-claimed subsystem in the whole product, so it gets the most honest treatment.**

### 3.1 The actual mechanism — a SIX-PLATE harvester array
**Six sprung plates** tile the underside of the midsole stack, covering the whole foot-strike path so that energy is captured through the *entire* gait cycle rather than at two isolated points:

| Zone | Plates | Captures |
|---|---|---|
| Heel | 2 (medial + lateral) | Heel-strike — the single largest impulse; splitting it medial/lateral also captures the natural pronation roll |
| Midfoot | 1 | The roll-through phase between strike and toe-off, previously wasted entirely |
| Forefoot | 3 (medial, central, lateral) | Metatarsal loading + the long push-off, where the foot applies force for the greatest duration |

Each plate rides on 2–3 guide posts, is backed by return springs sized for **~3–6 mm of vertical travel per step**, and drives **its own generator** — small enough that the wearer perceives it as ordinary midsole compliance, not a trampoline. Because the plates are independent, a partial foot-strike (walking on a slope, cornering, standing shift) still harvests from whichever plates are loaded.

**Why six instead of two:** more of the foot's contact area and more of the gait *timeline* is converted, and generators can be individually tuned to their zone's force and stroke. The honest ceiling is unchanged, however — see §3.3: this improves harvest by roughly **2–3×** over the two-plate design, which raises a trickle to a *bigger trickle*. It does not change the physics verdict that walking cannot recharge the drive battery. Cost: more parts, more mass (~+40–70 g/shoe), more assembly complexity, and more sealing joints — all of which the firm must weigh against a still-small energy return (§15.3 lists the whole harvester as an EVT descope candidate for exactly this reason).

Each plate's motion is coupled to a generator by one (or a hybrid) of three transduction paths:

1. **Moving-magnet linear EM generator (primary).** An NdFeB magnet is fixed to the plate and plunges through a fixed copper coil on each compression and rebound. Faraday's law: induced EMF ˆ (number of turns) × (rate of flux change). Because the stroke is short (mm) and slow (a footstep is ~0.5–0.8 s of loading), the flux-change rate is *low*, which is exactly why output is modest. We get two pulses per step (down + up).
2. **Rack-and-pinion micro-generator (supplemental).** A small rack on the plate spins a geared micro-DC-motor-as-generator. Gearing multiplies the slow linear stroke into faster rotor speed, which suits the slow footstep better than the raw EM coil — at the cost of friction, backlash, and wear. Good candidate to run *in parallel* with the EM coil.
3. **Piezo stack (optional garnish).** A PZT stack under the plate captures the sharp high-frequency impulse of heel strike. Real but tiny — milliwatts. Worth adding only if it's near-free in the molding.

### 3.2 Real physics — how much energy is actually in a footstep, and what we can keep
The *mechanical* energy available per step is the foot force over the plate's travel:
`E_step ‰ˆ F × d`. With a ~700 N peak load region and ~4 mm of usable, *generator-coupled* travel, the gross mechanical impulse is on the order of **~1–3 J per step at the plate** — but you do **not** get to keep that. You only keep the fraction that the generator actually converts, and you must not steal so much that the shoe feels dead underfoot (stealing energy = adding walking effort; that's a real metabolic cost to the wearer and a hard limit).

Stacking the loss chain — partial coupling to the generator, electromechanical conversion efficiency of a tiny generator (poor, often <30%), rectification, boost-converter losses, and the comfort cap on how much we dare to harvest — the realistic *electrical* yield is **a small fraction of a joule per step**, on the order of **~0.05–0.3 J/step** delivered to storage.

### 3.3 HONEST expected output
At a brisk walking cadence (~100–120 steps/min ‰ˆ ~1.7–2 steps/s) across the **six-plate array (§3.1)**, realistic **sustained electrical output is on the order of tens of milliwatts up to ~2–4 W peak-ish while actively walking**, and far less on average across a real day (you are not walking every second). Treat **~0.3–1.2 W time-averaged-while-walking** as the honest planning number for the six-plate design (roughly 2–3× the old two-plate figure), with ~2–4 W as an optimistic instantaneous burst, **not** a steady figure.

> **Plain-language version for the spec reader:** Walking will keep the sensors, Bluetooth, LEDs, and battery-management electronics fed, and over a long day of walking it will *slowly* add a little to the pack. It will **not** meaningfully recharge the drive battery, and it absolutely cannot power the wheels while you ride. Anyone who tells you a shoe-sized harvester recharges an e-mobility battery from walking is wrong about the physics.

### 3.4 Per-km harvest budget vs. motor draw (the reality check)
- **Harvest:** Walking ~1 km takes ~1,200–1,500 steps. At ~0.05–0.3 J/step that's roughly **~60–450 J/km ‰ˆ 0.017–0.125 Wh per km walked.** Call it **~0.05–0.1 Wh/km** as a fair mid-estimate.
- **Motor draw while gliding:** first-principles rolling-resistance math (Crr ‰ˆ 0.03–0.04, 60–80 kg rider + ~2.5 kg shoes, 55–70% drivetrain efficiency) gives **~10–20 Wh/km both shoes combined** (~5–10 Wh/km per shoe) — see §11.2 for the derivation. *(This corrects an earlier draft's "~20–40 Wh/km," which contradicted the §10.3 range table; 120 Wh of pack Ã· 40 Wh/km would be only 3 km, not the stated 6–12 km. The corrected ~10–20 Wh/km is consistent with the range table.)*

**The ratio is the whole story:** glide consumption is on the order of **~100–400× the walk-harvest rate per km** (~0.05–0.1 Wh harvested per km walked vs ~10–20 Wh consumed per km glided). You would need to walk *well over a hundred kilometers* to bank the energy for *one kilometer* of gliding. So the harvester's honest job is: **(a)** run the always-on electronics so they don't tax the main pack, and **(b)** add a slow trickle that extends standby/range at the margins. That's a genuinely useful job — just not the headline one.

### 3.5 Rectification + storage path
Plate motion → (EM coil produces AC pulses / rack-gen produces low-V DC / piezo produces high-V low-current spikes) → **Schottky full-bridge rectifier** per source → **energy-harvesting PMIC** with ultra-low input-voltage cold-start and maximum-power-point tracking (MPPT-style) → boosts to a **small storage buffer (supercapacitor or dedicated harvest cell)** → trickle-charges the main Li-poly pack through the system PMIC under BMS supervision (harvest current is so small it's always within safe charge limits). The buffer cap matters: it smooths the pulsed, bursty harvester output into something the charger can use.

### 3.6 Durability target
The harvester is the highest-cycle mechanism in the product. Target **5–10 million compression cycles** (a few years of daily walking) with <10% output degradation: fatigue-rated springs, low-friction guided posts (self-lubricating bushings), sealed coil/magnet to keep grit out, and a plate stroke deliberately kept small to limit wear. The rack-and-pinion path is the durability weak point (gear/backlash wear) — the firm should fatigue-test it hard or favor the contactless EM path.

---

## 4. Drivetrain — Four Hub-Motor Wheels + Deploy/Retract

### 4.1 Motor choice
**Four in-wheel sensored BLDC outrunner hub motors**, one per wheel — the wheel *is* the rotor. Rationale: hub motors put the torque directly at the contact patch with no belt/chain, survive the cramped sole packaging, and (critically) act as **generators for regenerative braking** when driven backwards by the road. Sensored (3× Hall) for smooth low-speed starting torque and clean closed-loop control; FOC-capable ESCs for efficiency and quiet running.

- Continuous power: **90–110 W per wheel; ~360–440 W system** (revised in §4.2c — the old 30–60 W was sized on cruise only and could not accelerate the rider or climb). Peak/burst ≈ 2× continuous for hill starts.
- Voltage: matched to a 2S/3S pack (~7.4–11.1 V).
- A **geared hub** variant trades top speed for low-speed torque (better for hills/starts) at the cost of gear noise/wear — the firm should bench both; geared likely wins for a heavy-rider-from-standstill case.

### 4.2 Wheels
- **OD: 38 mm rear / 30 mm front** — staggered, and *derived from* the sole stack via the §4.2b fit check (bounded above by sole thickness, below by rollover-safety and rolling resistance — bigger rolls better and trips less, so push to the top of what packages).
- **Durometer 78A–85A** PU: softer = grippier + absorbs cracks/pebbles (safer, but more rolling loss and wear); harder = faster/longer-lived. 80A-ish is the start point.
- Slight crown profile to make edge-weighting steering feel natural and predictable.
- **Small wheels are a fundamental safety limiter:** a 30–38 mm wheel is stopped dead by a pebble or sidewalk crack that a skateboard's 54 mm wheel rolls over. This is a primary reason the speed cap is low and auto-retract on obstacles is mandatory.

### 4.2b ⚠ WHEEL FITMENT — the packaging check that invalidated the first numbers

**This section exists because an earlier draft of this brief was geometrically impossible.** It is documented rather than quietly deleted, because it is the single easiest way for this program to waste money: specifying a wheel that cannot physically fit the sole it retracts into.

**The failed check:**

| Quantity | Earlier draft | Consequence |
|---|---|---|
| Wheel OD | 38 mm rear / 30 mm front (45 mm typical) | — |
| Sole stack, heel | 30–34 mm | **Wheel is 11–15 mm THICKER than the entire heel sole** |
| Sole stack, forefoot | 22–26 mm | **Wheel is ~2× the forefoot sole thickness** |
| Deployed protrusion | ≤5 mm | Travel is only ~5 mm, so the wheel must fit inside the sole in *both* states |

Because the wheel moves only ~5 mm between stowed and deployed, **the whole wheel must live inside the sole thickness at all times.** The requirement is therefore:

> **wheel OD + well walls + strut clearance ≤ local sole stack**

Allowing ~4–6 mm for well walls, bearings, and the brake pawl, the earlier numbers permitted a **maximum ~26–28 mm wheel at the heel and ~18–20 mm at the forefoot** — not 45 mm. **A 45 mm wheel in a 22–26 mm forefoot does not fit. The original spec was impossible.**

**Resolution (the geometry this brief now specifies):** thicken the sole *and* shrink/stagger the wheels until both are real. Front and rear wheels are **deliberately different sizes**, because the forefoot sole is thinner than the heel — a mixed-size axle set is trivially handled in firmware (each motor gets its own RPM target for a common ground speed).

| | Rear (heel) wheels ×2 | Front (forefoot) wheels ×2 |
|---|---|---|
| **Wheel OD** | **38 mm** | **30 mm** |
| Wheel width | 15 mm | 15 mm |
| Well walls + pawl + strut clearance | ~6 mm | ~6 mm |
| Wheel bay subtotal (wheel + clearance) | 44 mm | 36 mm |
| + outsole rubber | 3 mm | 3 mm |
| + carbon load plate | 1.5 mm | 1.5 mm |
| + harvester plate & springs | 5 mm | 4 mm |
| + midsole foam over the bay | 4 mm | 3 mm |
| + insole | 3 mm | 3 mm |
| **TOTAL local sole stack (revised)** | **~60 mm** | **~50 mm** |
| **Fit check** | 44 + 16 = 60 ≤ 60 ✅ | 36 + 14 = 50 ≤ 50 ✅ |
| Deployed protrusion | ≤5 mm | ≤5 mm |

> **⚠ The stack grew again — read this before committing to four wheels.** Once the outsole, carbon
> plate, harvester and foam are counted (table above), a four-wheel design needs roughly a **60 mm heel /
> 50 mm forefoot** sole. That is a **platform boot**, not a court shoe: heavier, hotter, and measurably
> tippier (§4.6). The honest recommendation is to seriously trade this against the **heel-only (Heelys-style)
> option in the alternatives below** — two larger wheels in the heel, where a thick stack is normal and
> visually acceptable, and a slim forefoot. It loses some traction and pitch stability but keeps the shoe
> wearable. **Decide this in Phase 0, before any tooling.**

**What this costs — stated honestly, because these are real losses:**
1. **The sole gets chunky.** 44 mm heel / 36 mm forefoot is a **platform silhouette**, not the slim 30–34 mm court shoe described in §7. The styling brief must be re-cut around a chunkier sole (this is at least a current fashion trend, but it is no longer a low-profile tennis shoe).
2. **Higher CoM → tippier.** A taller stack worsens the §4.6 stability problem. Partly offset by the ≤5 mm deploy lift (§4.4b-2), but the firm must re-run the tip-angle math on the final stack.
3. **Smaller wheels trip more.** 30 mm front wheels are stopped by obstacles a 45 mm wheel would roll over (§4.2). This makes the **6 mph cap, softer 78–80A durometer, and obstacle auto-retract mandatory, not optional** — the small-wheel trip hazard is now the dominant physical risk in the product.
4. **More weight.** A thicker sole adds foam, chassis, and well structure (~+50–90 g/shoe over the §7.4 budget).

**Alternatives the firm should trade before freezing this:**
- **Heel-only drive (the Heelys approach):** 2 larger wheels (~50 mm) in the thick heel only, no forefoot wheels. Best fitment and best obstacle behaviour; worse pitch stability and less traction/torque.
- **Wheels that swing rearward into the arch void** rather than straight up: the arch is the deepest, least-loaded part of the sole, so a larger wheel could stow there. More mechanism complexity, longer travel, but it would allow a ~45 mm wheel without a platform sole. **This is the most promising path to keeping a slim shoe and is worth a Phase 0 CAD study.**
- **Accept a genuinely thick sole** (50 mm+) and keep 45 mm wheels throughout.

**Process rule for the firm (learn from this):** every dimension in this brief is a *target*, and **§4.2b's fit inequality must be re-verified in CAD before any tooling is cut.** A packaging conflict found in CAD costs an afternoon; found after tooling it costs the tooling budget in §15.2.

### 4.2c ⚠ MOTOR SIZING — cruise power is NOT the number to size on

**Bug found by the physics validator and documented here because it invalidated the original 30–60 W motor spec.** §11.3 sized the motors on *steady cruise* (~17 W), which is the easiest load the product ever sees. Motors must be sized for the **hardest** case: accelerating, and climbing.

Power required (75 kg rider + 2×1.1 kg shoes = 77 kg; Crr 0.015; drivetrain efficiency 62%; governed 6 mph = 2.68 m/s):

| Case | Force needed | **Power at the pack** | 4×45 W (old spec) | Verdict |
|---|---|---|---|---|
| Steady cruise, flat | 11 N | **~49 W** | 180 W | ✅ easy — this is the only case §11.3 checked |
| Cruise + modest accel (0.4 m/s²) | 42 N | **~183 W** | 180 W | ⚠️ **marginal fail** — cannot accelerate briskly |
| Flat + accel, 100 kg rider | 54 N | **~234 W** | 180 W | ❌ fail |
| **8% grade** at speed | 103 N | **~444 W** | 180 W | ❌ **fails badly** — cannot climb |
| 4% grade at speed | 57 N | **~246 W** | 180 W | ❌ fail |

**Revised motor specification: 4 × 90–110 W continuous** (≈360–440 W system), replacing the old 30–60 W. Rationale:
- Meets flat-ground acceleration with **≥2× margin** (183 W needed vs ~400 W available).
- Makes a **4–5% grade** genuinely climbable at the 6 mph cap.
- Peak/burst rating should be ~2× continuous for hill starts.

**And a published-limit correction — be honest with riders:** the old §9.5 rider envelope claimed a **max 8% grade**. Even at 90–110 W motors that is not comfortably achievable at speed (444 W required vs ~400 W available, leaving no margin and cooking the motors on a sustained climb). **Publish a 4–5% maximum grade** and state plainly that steeper hills must be walked, with the wheels retracted. A product that quietly bogs down and overheats halfway up a hill is a safety problem, not just a disappointment.

**Knock-on effects the firm must re-run:** larger motors mean more mass (~+15–25 g/motor), higher peak pack current (re-check the §5 C-rate and the harness AWG in §6.6), and more heat (re-run the §5.5 thermal budget). This is a real tradeoff, not a free upgrade — but shipping motors that cannot accelerate the rider is not an option.

### 4.3 Bearings & torque path
Sealed ABEC-7-class bearing pairs per wheel (stainless or ceramic hybrid for grit/sweat tolerance). Motor torque reacts through the strut into the **carbon load plate**, which is the rigid spine of the sole. The plate must be stiff enough that propulsion and braking loads don't flex the sole into the rider's foot.

### 4.4 Deploy / retract mechanism
**Recommended primary approach: servo-driven swing-arm with an over-center mechanical lock.** Each axle pair (front, rear) is driven by one compact metal-gear servo (or each wheel by a bistable rotary solenoid). On deploy, the strut swings/telescopes the wheel down so it protrudes only **≤5 mm** past the outsole (§4.4b-2 Fix 2) and snaps into an **over-center latch** that carries rider load *mechanically* — the actuator does **not** hold current to keep the wheels down. Same latch concept locks the **stowed** position so wheels can't drop while walking.

Why locks-not-actuators: holding a servo stalled against rider weight would cook it and drain the battery; a mechanical over-center/detent lock carries the load for free and is the fail-safe (see §4.5). A **telescoping strut** alternative gives a cleaner straight-down load path (no side load on the pivot) but is harder to seal and package — list both for the firm to trade.

- **Deploy/retract time:** per §1.3/§4.4b — one button press ARMS both shoes; each deploys <0.4 s inside its next unweighted gait window, both locked within ~1.2–1.6 s. The two shoes must confirm each other's lock state over BLE before either enables throttle.
- **Position sensing:** Hall+magnet or limit switch confirms stowed / deployed / locked. **Throttle is hardware- and firmware-inhibited unless all four struts report locked-deployed.**

### 4.4b Can the deploy actually LIFT the rider? — the load case that decides the mechanism

**The question, stated properly:** to go from Walk to Glide the sole must rise onto the wheels (≤5 mm in the final design, §4.4b-2 Fix 2 — but the lift problem below applies at any height). If the wearer's full body weight is on that shoe, the actuator has to lift a person. **It cannot, and it must never try.** Run the numbers:

| Case | Load per shoe | Force per strut (4 struts) | Actuator torque needed (≈40 mm arm) | Verdict |
|---|---|---|---|---|
| **Loaded deploy** (rider standing on it) | ~750 N (75 kg) | ~190 N | **~7.6 N·m per strut** | ❌ **Impossible** at this size — needs a ~10× larger actuator, would drain the pack and cook the servo |
| **Unloaded deploy** (foot in swing phase) | shoe mass only, ~12 N | ~3 N | **~0.12 N·m per strut** | ✅ **Trivial** — a small metal-gear servo does this easily |

**The design answer: the shoe NEVER deploys under load — it deploys during the swing phase of your step.** The mechanism is a **~60× easier problem** when the foot is in the air, and every real gait gives an unloaded window ~0.3–0.5 s long, roughly every second, per foot.

**Sequence (this is the safety-critical logic):**
1. Rider presses the deploy button → firmware **ARMS** both shoes (nothing physically moves yet).
2. Each shoe watches its own **FSR foot-load sensors**. The moment that shoe is unweighted (swing phase, load < ~5% body weight), it deploys — **<0.4 s**, well inside the swing window.
3. The strut snaps into the **over-center lock**, which then carries rider weight **mechanically** — the actuator holds zero current under load. **The wheel itself deploys BRAKED (pawl + short-brake, §4.4b-2 Fix 1) so it cannot roll if the rider steps on it.**
4. That shoe reports *locked-deployed* over BLE. Throttle is inhibited until **both** shoes confirm.
5. Net: both shoes are down and locked within ~1–2 normal steps (~1.2–1.6 s), with only a **≤5 mm** height difference in between (§4.4b-2 Fix 2). The rider just keeps walking; it feels automatic. **If the second shoe fails to deploy within 3 steps, the first one retracts and the deploy aborts** — the rider is never left mismatched.
6. Wheels **unbrake only** when both shoes are locked-deployed, both feet are loaded, speed is zero, and the rider commands Glide.

### 4.4b-2 THE ONE-SHOE PROBLEM — and the three-part fix

**The flaw in naive swing-phase deploy:** during walking there is **no flight phase** — one foot is always on the ground. So the two shoes *cannot* deploy simultaneously. That leaves a window of one or more steps where **shoe A is deployed and shoe B is not**, and the rider must put full weight on a single deployed shoe. Two things go wrong at once:

1. **Roll-away:** the deployed shoe has free-spinning wheels. Weighting it on one foot = it shoots out from under the rider. **This is a fall, and it is the single most dangerous moment in the entire product.**
2. **Leg-length mismatch:** the deployed shoe is taller. A large sudden asymmetry destabilizes gait.

Neither can be hand-waved. The fix is three mechanisms that must **all** be implemented:

#### Fix 1 — Wheels deploy LOCKED, never free (mandatory, non-negotiable)
Wheels are **mechanically and electrically braked from the instant they deploy** and stay locked until *both* shoes report deployed **and** the rider commands Glide. Standing on a locked wheel is like standing on a hard rubber stud — it cannot roll away.
- **Electrical:** ESC holds a **three-phase short-brake** (all low-side FETs on) — a passive, powered-off-safe holding brake on a BLDC.
- **Mechanical:** a sprung **pawl/detent engages the wheel hub** on deploy — holds with **zero power**, survives total power loss, and is the true fail-safe. The pawl releases only on a positive Glide command with both shoes confirmed.
- **Release is gated:** wheels unlock **only** when (a) both shoes locked-deployed, (b) both feet loaded (FSR), (c) rider presses Glide, (d) speed sensors read zero. Any condition lost → **re-lock immediately.**

#### Fix 2 — Near-zero lift (design the height change out)
Reduce the deployed ride-height change from the old 12–18 mm to **≤5 mm** by recessing the wheels deeper into the wells and giving the outsole a **mild rocker** so the four wheels become the contact plane while the outsole clears by only a few mm.
- **≤5 mm is below the threshold people notice** — it's ordinary shoe-sole variation, and smaller than a common natural leg-length difference. Gait absorbs it without conscious correction.
- This also lowers the CoM and **improves the tippiness problem** in §4.6 — a rare change that helps two problems at once.
- Cost: the wheels must sit deeper, so the sole is slightly thicker; and the mild rocker must not make Walk mode feel unstable (validate on real feet).

#### Fix 3 — Fast, aborting sequence with a guided stance
- **Target: both shoes deployed within 2 consecutive steps (~1.2–1.6 s).** The mismatch window is one step, on a *locked* wheel, with ≤5 mm of height difference — a condition a normal person walks through without noticing.
- **ABORT RULE (critical):** if the second shoe cannot deploy within **3 steps**, the first shoe **automatically retracts** during its next swing phase and the whole deploy cancels with a haptic + LED alert. **The system must never leave the rider in a one-deployed-one-not state.** Better to cancel and try again than to leave someone mismatched.
- **Guided "deploy stance" for first-time and cautious users** (default ON for new riders in the app): the rider stands still, and haptics prompt a deliberate weight-shift — buzz left shoe → rider shifts weight right → left deploys unloaded and locks → buzz right → shift left → right deploys. Slower, fully deliberate, zero surprise. Both shoes end up locked before anything can roll.
- **Seated deploy** is always available and is the recommended first-time method: sit down, both shoes deploy fully unloaded, stand up already on locked wheels.

**Verification (add to §13 / §10.4):** ride-rig and human-subject testing of (a) single-shoe weighted stance on locked wheels — must not roll under 1.5× body weight; (b) the ≤5 mm asymmetry across a 20-person gait study; (c) abort-rule coverage with a deliberately jammed second shoe; (d) pawl hold under a 4.7 kN dynamic landing.

**Hard interlocks (must be enforced in firmware AND hardware):**
- **A loaded shoe never actuates.** If FSR says weighted, the deploy command waits. No exceptions — attempting a loaded deploy is how you burn an actuator and destabilize a rider mid-stance.
- **Retract is unloaded-and-near-zero-speed only** (§4.5) — retracting under load would drop the rider onto the outsole.
- If a shoe cannot find an unloaded window within ~5 s (rider standing still), it **cancels the deploy** and signals via haptic + LED. Standing still is not a deploy condition; take a step.
- The actuator is sized for the **unloaded** case with a **≥3× margin** (~0.4 N·m class), *not* the loaded case — deliberately too weak to lift a person, which is a **safety feature**: a runaway actuator physically cannot jack up a standing rider.

**What carries the weight, then:** the **over-center lock + strut + carbon load plate**, sized to **≥4× peak dynamic landing load** (§9.3 FMEA row 4, ~4.7 kN/wheel on a jump-landing). Lifting is the actuator's job (easy, unloaded); *holding* is the lock's job (hard, mechanical, no power). Never confuse the two.

### 4.4c Silent operation — the shoe must not whine or clunk

Noise is a product-killer for footwear: nobody wears shoes that announce every step. Targets and methods:

| Mode | Noise target | How it's achieved |
|---|---|---|
| **Walk (wheels stowed)** | **≤ 25 dBA @ 1 m — inaudible over normal footfall** | Zero rotating machinery active; harvester plates ride on damped elastomer stops, not hard plastic-on-plastic (a hard stop *clicks* every step — the #1 noise risk in the whole design) |
| **Deploy / retract** | ≤ 40 dBA, a single soft *thunk*, no servo whine | Metal-gear servo with damped end-stops; elastomer bumpers at both travel limits; over-center lock seats into a **nylon/elastomer detent seat** rather than metal-on-metal |
| **Glide (cruise)** | **≤ 45 dBA @ 1 m — quieter than conversation** | **Sensored FOC motor control** (not trapezoidal/six-step, which whines audibly); PWM at **≥20 kHz — above human hearing**; helical/precision-ground gearing or direct-drive hub motors (no spur-gear whine) |
| **Rolling noise** | dominated by tread, not machinery | Softer PU (**78–82A**) and a smooth/lightly-siped tread; hard 88A+ wheels on rough pavement are the loudest thing on the product |

**Design rules for the firm:**
1. **PWM above 20 kHz, always.** Audible-band switching is the classic "electric whine." Verify under load, not just at idle.
2. **FOC, not six-step commutation** — sinusoidal drive is dramatically quieter and also smoother at the low speeds this product runs at.
3. **Isolate every motor and actuator from the chassis with elastomer mounts** — structure-borne noise through a rigid carbon plate turns the whole sole into a speaker.
4. **No hard plastic-on-plastic anywhere in the harvester or well covers.** Six plates × 2 steps/s = a *lot* of opportunities to click. Damped stops on all six.
5. **Sealed bearings, correctly preloaded** — a loose bearing rumbles, an over-preloaded one squeals.
6. **Add an acoustic test to the DVT matrix:** measure dBA at 1 m in all four modes, on smooth concrete and rough asphalt, at 10 °C and 35 °C (grease stiffens when cold and gets noisier). **Rattle/BSR (buzz-squeak-rattle) testing after the fatigue campaign** — new hardware is quiet; worn hardware rattles, and that's what the customer lives with.

### 4.5 Fail-safe on the deploy mechanism
Springs bias the struts toward the **safe state**. The design decision the firm must make explicitly: is "safe" *retracted* (wheels up, walk) or *deployed-and-locked*? Retracting under fault while gliding would drop the rider onto the outsole at speed (bad). The recommended rule: **once gliding, a fault triggers coast-to-stop while staying deployed and locked; retract only happens at/near zero speed.** On total power loss the over-center lock holds the current state (it doesn't need power), and the rider coasts to a stop on freely-spinning wheels.

### 4.6 Geometry & stability math (starting numbers — to be validated)
- **Ground clearance (deployed):** sole lifted **≤5 mm** onto wheels (deliberately minimised — see §4.4b-2 Fix 2; the old 12–18 mm created a dangerous leg-length mismatch during the one-shoe window).
- **Wheelbase (per shoe):** front-to-rear wheel spacing roughly the length of the shoe's rigid plate, ~180–220 mm; **track width** limited to roughly the sole width ~70–90 mm.
- **Stability reality:** the rider's center of mass sits ~0.9–1.1 m above two small, short-wheelbase platforms. This is an *inherently* tippy arrangement — closer to skating than to a self-balancing scooter. Lateral stability comes from the *rider's* balance, not the device. The narrow track and small wheels mean the static rollover/trip threshold is low; firmware speed-capping and obstacle auto-retract are doing real safety work here, not marketing.
- The firm must model: rollover angle vs. track width, trip-over threshold vs. wheel diameter at the capped speed, and pitch stability under braking (small front wheels + forward CoM under braking = endo risk → bias braking, ABS-style modulation).

---

## 5. Power System — Battery, Wireless Charging (primary), Regen, PMIC, Thermal

> **Charging summary up front:** SPEEDERS is a **wireless-charge-first** product. The user sets both shoes heel-down on an inductive **dock overnight** (§5.3) — no connectors to fumble with on a sealed shoe. Realistic charge time for the size-8 pack is **~3–5 h to full** wirelessly, faster on the wired backup. **Walking does not recharge the drive battery** (§3) — the dock does.

### 5.1 Battery (honest cell choice)
> **Honesty note:** Solid-state cells at this size, energy density, cost, and availability are **not** production-ready in 2026. Spec the product on a small **Li-polymer pouch pack today**, and list solid-state as a future drop-in once it's real. Do not design the product *around* a battery you can't buy.

- **Chemistry:** Li-polymer pouch (LiCoO‚‚/NMC class), 2S or 3S.
- **Capacity:** **small Li-poly pack, ~30–60 Wh per shoe** (this is the weight-capped sweet spot for size 8.5). ~150–170 g of cells at 30 Wh; ~250–320 g at the 60 Wh top end. The **arch bay at size 8 (~55–60 cm³, §1.5) is the hard ceiling** on how much pack you can fit.
- **Weight †” range tradeoff (state it plainly):** every extra ~15 Wh of pack is roughly **+80 g on the foot** and buys roughly **+2–3 km of glide**. A 30 Wh pack = lighter shoe, ~4–5 km; a 60 Wh pack = heavier shoe, ~10–12 km. You are buying range by the gram. The §1.6 plan treats the battery as the rider's optional weight lever.
- **Charge time:** ~**3–5 h to full** on the wireless dock (~10–15 W inductive); ~**1.5–2.5 h** on the wired/USB-C backup (§5.3). Scales with pack size.
- **Cycle life:** ~**300–500 full charge/discharge cycles** to ~80% capacity (typical Li-poly), then the pack is a **service-replaceable consumable** (§8.2). Partial charges count fractionally; daily commute use ‰ˆ a couple of years before a swap.
- **Placement:** flat pouch stack in the **arch enclosure** — the natural void in the size-8 sole, near the CoM, away from the highest-flex toe and heel-strike zones, in a gasketed impact-rated box with a thermal path to a heat-spreader.
- **Why not bigger:** more Wh = more grams on the foot (breaks §1.3), no room in the size-8 arch bay past ~60 Wh, and more stored energy to go wrong under impact. Range is intentionally bounded by this.

### 5.2 BMS & protection
Multi-cell BMS with per-cell balancing and hard cutoffs for over-voltage, under-voltage, over-current, short-circuit, and over/under-temperature. Pack output also goes through a **resettable PTC + solid-state e-fuse**. Because this pack lives under a flexing, sweaty, impact-loaded foot, treat **mechanical abuse + thermal runaway** as the top hazard: cell selection must be UN38.3 + IEC 62133, the enclosure must contain/vent a failing cell away from the foot, and crush/penetration/nail-test data is mandatory before any human wears it.

### 5.3 Charging — WIRELESS IS THE PRIMARY METHOD

Wireless inductive charging on a dock is the **primary, intended, everyday way the user charges SPEEDERS.** A sealed, flexing, sweaty shoe is a bad place for an exposed connector, so the design leans into contactless charging and treats the wired path as a backup for when you're in a hurry. **This is the answer to "how do I charge it" — you set it on the dock.**

**The dock (primary):**
- A **shoe-shaped inductive dock / mat** the user sets **both shoes on, heel-down, overnight.** A Qi-style / proprietary **TX coil in each heel cradle** aligns with the **RX coil built into the heel of the sole** (heel-down seating gives the most consistent coil-to-coil alignment and the shortest airgap through the sole material).
- **In the shoe:** a litz-wound **RX coil + ferrite shield** under the heel, a **WPC/Qi-style (or proprietary) RX IC + rectifier**, feeding the system charger under BMS supervision.
- **Power level:** ~**10–15 W inductive** delivered into each shoe (a proprietary coil/airgap can push past baseline Qi; bounded by alignment, airgap, and sole-material losses).
- **Realistic charge time:** a **~30–60 Wh pack at ~10–15 W ‰ˆ ~3–5 hours to full** (30 Wh nearer 3 h, 60 Wh nearer 5 h). That's an **overnight / sit-on-the-dock-while-you-do-something-else** charge, not a 20-minute top-up. Perfectly fine for a commute product you dock when you get home.
- **No-connector benefit:** nothing to corrode, nothing to fumble with sweaty hands, and it lets us keep the sole **IP67-sealed** (§7.3) — the coil charges right through the sealed sole.

**Wired fast option (backup):**
- **Sealed, gold-plated pogo contacts** (or a gasketed USB-C port) on the sole, mating to pins in the dock or a cable, give a **faster ~1.5–2.5 h** charge when you need to turn the shoes around quickly.
- This is the "I forgot to dock them and I'm leaving in two hours" path — not the everyday method.

**"Does walking charge it fast enough?" — NO. Explicitly:**
- The kinetic harvester (§3) produces **only tens of milliwatts up to ~1–2 W in brief bursts** while you walk — that is **hundreds of times less power than gliding consumes** (~100–400× less per km, see §3.4).
- That trickle is enough to **keep the sensors, Bluetooth, LEDs, and battery-management electronics fed**, and over a long day of walking it adds a *small* amount to the pack — extending standby and range at the **margins only.**
- It does **not** meaningfully recharge the drive battery, and it **cannot** power the wheels while you ride.
- **You must wireless-charge SPEEDERS regularly on the dock.** Walking is a **bonus trickle, not the charger.** If a marketing line implies "it charges itself as you walk," that line is false — kill it (see §3.3 and §10.2).

### 5.4 Regenerative braking circuit
When the rider leans back / heel-presses to brake, the ESC drives the hub motors as generators, dumping motor back-EMF through a **synchronous buck/regen stage** into the pack (BMS gates it so a full pack doesn't overcharge — excess bleeds to a brake resistor). Regen provides **smooth, controllable electrical braking torque** *and* recovers a little energy. **It is not the only brake:** a fault must still stop the rider with no electronics (free-coast + the rider's body), and the firm should evaluate a small mechanical/friction backup brake. Like the harvester, regen's energy recovery is a *bonus*, not a range strategy.

### 5.5 PMIC / power tree & thermal
- **PMIC** generates 3.3 V logic rail, manages charging (Qi/wired/harvest/regen all merge here under BMS rules), and hands off the motor rail.
- **Power priority firmware rule:** logic + safety + brakes are *never* starved by the motors; motor rail browns out first under low battery, brakes/MCU last.
- **Thermal:** thermistors on cells, motors, and ESC FETs. The sole is a poor heat sink (foam is an insulator), so the ESCs and motor windings are the thermal risk under sustained load/hills. Firmware derates motor power on over-temp before any damage; the metal chassis/heat-spreader carries heat out to the sole surface.

---

## 6. Control Electronics + Firmware

### 6.1 Compute & sensing
- **MCU/SoC:** ESP32-class (easy BLE + dual-core, lots of dev support) or Nordic nRF52/nRF53 (lower power, more robust BLE, better for a battery product). Runs the real-time control loop, state machine, governor, and the dual-shoe link.
- **IMU (6-DoF):** the heart of intent sensing — fuses accel + gyro to estimate **lean angle** (pitch of the rider/shoe), motion, and fall events. Sensor fusion (complementary/Kalman filter) gives a stable lean estimate despite stride bounce and road bumps.
- **Deploy button:** a **recessed, sealed momentary push-button** on the medial (inner) midsole triggers deploy/retract. It is a *mechanical* switch inside a guard ring, needing a deliberate ~2–4 N press — deliberately **not** a capacitive tap, because a tap zone would false-trigger from walking cadence, curb kicks, or a brush of the ankle, and an unintended deploy is a fall hazard. Firmware debounces it and requires a distinct press pattern (e.g. press-and-hold ~0.4 s to arm) so a single accidental bump does nothing.
- **Hall / encoder feedback:** in-hub Halls give wheel speed + commutation for closed-loop control, the governor, and odometry.
- **Insole FSR/load sensors:** confirm the foot is actually loaded (don't deploy/drive an empty shoe), detect weight-shift, and sense heel-press for braking intent.
- **Strut position sensors:** gate throttle on confirmed locked-deployed state.

### 6.2 Dual-shoe BLE link
The two shoes pair as a tight **left†”right BLE link**, exchanging at high rate: speed, throttle command, lean estimate, brake state, lock state, fault flags, battery level. One shoe acts as coordinator (or they run a consensus) so the pair **accelerates, governs, and brakes together** — desynchronized shoes would split the rider's feet apart, which is a fall. **Critical fail-safe:** if the BLE link drops mid-glide, *both* shoes independently fall back to a synchronized coast-to-stop (each shoe is safe on its own; the link is for coordination, not for permission to run).

### 6.3 The control loop — lean → forward throttle (forward-only)
Conceptual loop, ~200–1000 Hz:
1. IMU → fused **lean angle Î¸** (forward pitch of the rider's CoM).
2. **Dead-band:** below a threshold lean, throttle = 0 (so normal standing/micro-adjustments don't creep the shoe).
3. Above dead-band, throttle ramps **monotonically with forward lean**, clamped: `throttle = clamp(k·(Î¸ ˆ’ Î¸_deadband), 0, throttle_max)`. **Negative lean never produces reverse drive** — leaning back maps to *braking*, not reverse. Forward-only is enforced both in firmware (no negative throttle path) and by leaving reverse commutation disabled in the ESC.
4. **Speed governor:** a hard outer loop caps wheel speed at the firmware limit (8–10 km/h (6 mph) v1) regardless of lean — lean past the cap does nothing. Governor also rate-limits *acceleration* (no jerk launches).
5. **Brake:** lean-back or heel-press (FSR) → regen braking torque ramps in, ABS-style modulated to prevent front-wheel lockup/endo.
6. Both shoes mirror the command over BLE so left and right match.

### 6.4 Learner mode + governor tiers
- **Learner mode (default for new users):** very low speed cap (~4–6 km/h), gentle accel ramp, aggressive auto-retract sensitivity, extra dead-band. The shoe literally won't let a first-timer go fast.
- Speed cap unlocks in tiers as the firmware logs stable riding time (and/or the user opts up), never above the v1 hard ceiling. This is both a safety feature and a liability feature.

### 6.5 SAFE-STATE behavior (the most important firmware in the product)
Every one of these triggers a **fail-safe response** — the default is *coast-to-stop, then retract+lock at low speed, revert to Walk*:
- **Stairs / curb / drop detected** (IMU sees a step-down/tilt signature, or wheel speed/load anomaly) → immediate throttle cut + brake + retract sequence.
- **Standstill** beyond a timeout → retract to Walk (don't sit deployed).
- **Fall detected** (IMU freefall/impact signature) → instant throttle cut, brake, retract. *Cutting power when the rider is already falling is mandatory* — no powered wheels under a falling person.
- **Fault** (motor over-temp, ESC fault, sensor disagreement, lock not confirmed, BLE loss, cell fault) → controlled coast-to-stop; if any safety-critical sensor is untrusted, **default to no-throttle**.
- **Low battery** → progressive speed derate, then forced retract-to-Walk with haptic + LED warning *before* the pack can't run the brakes.
- **Sensor sanity / watchdog:** independent watchdog timer resets a hung MCU into a safe (no-throttle, brake) state. Throttle authority requires *positive, fresh, agreeing* sensor data — stale or contradictory data = zero throttle.

**Design axiom:** there must be **no single fault** (stuck FET, firmware hang, sensor failure, dropped BLE) that causes *unexpected acceleration*. Unexpected *stopping* is acceptable (annoying, not dangerous at these speeds); unexpected *go* is not.

### 6.6 Wiring harness, connectors & interconnect (per shoe)

Everything terminates at the **flex-rigid main PCB in the arch**. All wiring runs in **molded channels in the chassis cage below the carbon load plate**, so no conductor ever takes direct foot pressure. There is **no wire between the two shoes** — the left/right link is wireless BLE.

| Harness segment | From → To | Conductors | Wire gauge | Connector (reference) | Notes |
|---|---|---|---|---|---|
| Pack power | Battery pack → BMS → PMIC | 2 (B+, Bˆ’) | 18 AWG silicone | XT30/JST-VH class, latching | Main current path; fused + e-fused at PMIC |
| Cell balance | Pack cell taps → BMS | 3–4 | 26 AWG | JST-PH balance | One tap per cell junction |
| Motor rail | PMIC → 4× ESC | 2 per ESC | 20 AWG | board-to-board / JST-VH | Switched motor bus |
| Motor phases | Each ESC → hub motor | 3 phase | 20 AWG | sealed 8-pin motor pigtail | Twisted; keep short; IP-sealed at well |
| Motor Hall | Each hub motor → ESC | 5 (V+, GND, 3× Hall) | 28 AWG | (in the 8-pin pigtail) | Commutation + speed feedback |
| ESC control | MCU → 4× ESC | SPI/UART + enable/fault | 28 AWG | FPC / flat-flex | Digital command + fault lines |
| Sensor bus | IMU · deploy-button · FSR · deploy-Hall → MCU | I²C / analog / GPIO | 28–30 AWG | FPC + JST-SH | Low-current signal; shielded near motors |
| Deploy actuators | Actuator driver → 2–4 servos/solenoids | 2 power + 1 position each | 24 AWG | JST-GH latching | Position line confirms lock (§6.5) |
| Wireless charge | RX coil → RX controller → PMIC | 2 | 22 AWG | soldered + potted | Heel; primary charge path |
| Wired charge (backup) | Sealed USB-C/pogo → PMIC | 2 power + CC | 24 AWG | gasketed USB-C | Optional fast charge |
| Indicators | MCU → LEDs · haptic LRA | as needed | 30 AWG | FPC | Status + be-seen lighting |

**Wire & connector rules for the firm:** silicone-insulated *stranded* wire everywhere (flex-fatigue life over 100k+ step cycles); PTFE/Teflon insulation on any run near the motors or battery; **every connector latching and conformal-potted** for IP67; twisted pairs for motor phase and Hall runs (EMI); a **single star ground** at the PMIC; service-loop slack + strain relief at every board entry so nothing pulls out as the shoe flexes; harness fully seated in the cage channels and captured, never free in the foam.

**System wiring block diagram:**
```
                 ”Œ”€”€”€”€”€”€”€”€”€”€”€”€ LEFT SHOE ”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”        ”Œ”€ RIGHT SHOE ”€”
   [Wireless dock]                                        )))  BLE  (((   (mirror of
        ”‚ ~10–15 W                                         link †” link     left, syncs
   ”Œ”€”€”€”€–¼”€”€”€”€”€”€”  balance   ”Œ”€”€”€”€”€”€”€”  pack    ”Œ”€”€”€”€”€”€”€”€”   throttle/brake  L/R power)
   ”‚ RX coil + ”œ”€”€”€”€”€”€”€”€”€”€”€”€”¤  BMS  ”œ”€”€”€”€”€”€”€”€”€”€”¤  PMIC  ”‚
   ”‚ RX ctrl   ”‚            ”””€”€”€”¬”€”€”€”˜  18AWG    ”‚ charger”‚
   ”””€”€”€”€”€”€”€”€”€”€”€”˜        cell taps”‚              ”‚ + regs ”‚”€”€3.3V”€”€”
                        ”Œ”€”€”€”€”€”€”€”€–¼”€”€”€”€”€”€”€”€”     ”””€”€”€”¬”€”€”€”€”˜        ”‚
   [USB-C backup]”€”€”€”€”€”€–º”‚ Battery (PowerDeck: flat  ”‚  motor rail ”‚
                        ”‚ pouch cells in ARCH vault,”‚  20AWG      ”‚
                        ”‚ UNDER a load bridge)      ”‚             ”‚
                        ”””€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”˜             ”‚
        ”Œ”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”€”            ”‚
        ”‚                 MAIN MCU (BLE)             ”‚—„”€”€”€3.3V”€”€”€”€”˜
        ”‚  control loop · governor · state machine   ”‚
        ”””€”¬”€”€”€”¬”€”€”€”¬”€”€”€”€”€”€”€”¬”€”€”€”€”€”€”€”¬”€”€”€”€”€”€”€”¬”€”€”€”€”€”€”€”€”€”€”˜
   IMU ”€”€”˜   ”‚   ”‚   cap- ”‚  FSR  ”‚ deploy”‚  ESC×4 (SPI/UART)
 (lean/    haptic LED   touch   load    Hall   ”‚  each: 3-phase + 5 Hall
  fall)                 (tap)  (heel/  (lock   –¼
                               fore)   confirm)  Hub motor ×4 ”€”€ regen back to pack
                                                 ”” Deploy servo/solenoid ×2–4 + lock detent
   [Kinetic harvester: heel + forefoot sprung plates → EM generators → harvest PMIC → pack]
```

### 6.7 Sensor suite (consolidated — every sensor in the shoe, per shoe)

| Sensor | Qty | Measures | Drives which function | Location |
|---|---|---|---|---|
| 6-axis IMU (accel+gyro) | 1 | Lean angle, motion, freefall/impact | Primary throttle command; fall + stair/drop detection | Arch PCB |
| Motor Hall sensors | 12 (3×4) | Rotor position + wheel RPM | BLDC commutation, closed-loop speed, governor, odometry | Inside each hub motor |
| Deploy-position sensor (Hall/limit) | 4 | Strut stowed / deployed / **locked** | Safety interlock — **no throttle unless all 4 locked** | Each strut |
| FSR / load sensor | 2–4 | Foot loaded, weight shift, brake-press, step count | Arm throttle only when foot is loaded; step count for harvest | Insole (heel + forefoot) |
| Recessed deploy button | 1 | Deliberate press (guarded) | Deploy / retract trigger | Medial midsole |
| Thermistors (NTC 10k) | 3–4 | Cell, motor, MCU temperature | Thermal derate + hard cutoff | Pack, motors, board |
| Pack current + voltage sense | 1 | Pack draw + state-of-charge | Coulomb-count SoC, pack current limit | BMS |
| Per-phase current sense | 4 | Motor phase current | FOC torque/current limit + regen control | In each ESC |
| (optional) Magnetometer / barometer | 0–1 | Heading / incline | Advanced control, hill logic (v2) | PCB |

**Sensor-fusion rule (safety-critical):** throttle authority requires *fresh, agreeing* data from **IMU + foot-load + all-locked + plausible wheel speed** simultaneously. Any disagreement, staleness, or dropout = **zero throttle** (ties directly to §6.5).

### 6.8 The PowerDeck — the wearer never stands on the battery

The single most important packaging decision, and the answer to "won't your foot crush the cells?":

- The cells are **flat Li-poly pouches lying horizontally in the arch vault** — the arch is the one zone of the foot that does **not** bear direct ground pressure.
- A **spring-steel load bridge arches over the vault**, transferring the wearer's weight *around* the cells, into the sole rails and carbon plate — so **no foot load ever compresses a cell.**
- The pack is **split into 2–4 small pouches** rather than one brick, so it conforms to the curved arch and any single-cell fault is localized.
- **Rationale (do not skip):** a punctured or compressed Li-poly cell is the **#1 fire/thermal-runaway risk** in a wearable. The load bridge is a **safety structure, not just packaging** — never route foot compression through a cell, and the abuse tests in §9 must verify the vault survives full body-weight stomps, drops, and puncture attempts with **zero cell deformation**.

---

## 7. Upper / Sole / Comfort Construction

> **Styling target (read this first):** the design language is a **clean performance tennis / court shoe** — **low-profile, mostly white, with the supportive wrap-around silhouette of a court shoe** (think a premium tennis trainer), **not** a chunky/maximalist casual sneaker. The court look is also functionally honest: court shoes are built for lateral support and a stable, planted feel, which suits a platform a rider balances on. The hardware (carbon plate, wheel wells, arch battery) does force a **thicker-than-normal sole** (~60 mm at the heel, §1.5/§4.2b), so the brief is "**slim, white, supportive court shoe on a slightly built-up sole**" — keep the upper and lines crisp and minimal so the sole depth reads as "performance," not "clunky."

### 7.1 Stack-up (top to bottom)
1. **Court-shoe upper (engineered knit / synthetic, mostly white)** + supportive TPU overlays — breathable, flexes, hides the side LEDs, and reads as a **clean low-profile tennis/court shoe**, not a casual sneaker. Lateral-support overlays suit both the court look and the balance-on-a-platform use. A secure closure (BOA dial or locked laces) is *safety-critical* — a loose shoe makes glide control impossible.
2. **Comfort insole + FSR/load sensors** — the foot interface; sensors live here.
3. **Forefoot + heel harvester plates** (sprung, ~3–6 mm travel) — integrated *into* the cushioning so their springs *are* part of the felt ride, not an obstruction to it.
4. **Midsole foam** — supercritical-foamed PEBA/EVA over the carbon plate; this is what delivers the "normal comfortable shoe" feel and must not be sacrificed to hardware.
5. **Carbon load plate** — the rigid structural spine; reacts wheel/strut/brake loads and tunes propulsion stiffness.
6. **Chassis cage + arch battery box + PCB + struts/wheels** — the mechanical/electrical guts, packaged into the void below the plate and the arch.
7. **Outsole tread + wheel wells + spring-loaded well covers** — rubber for Walk-mode grip; four wells with sprung TPU flaps that stay closed (sealing out grit/water) in Walk and open on deploy.

### 7.2 Integrating hardware WITHOUT killing cushioning
The central comfort challenge. Strategies for the firm:
- Put the **rigid stuff (battery, PCB, chassis) in the arch**, the foot's least-loaded/least-flexing zone, so the heel and forefoot stay compliant. The battery specifically sits in the **PowerDeck vault under a spring-steel load bridge (§6.8)** so the wearer's weight bypasses the cells entirely — this is a safety requirement, not a preference.
- Make the **harvester plates do double duty** as cushioning elements — their springs are tuned to a pleasant ride rate, so they add compliance instead of subtracting it.
- Keep the **wheel wells at the four corners** where structure is needed anyway, and let foam bridge over them.
- The **carbon plate** adds propulsive stiffness (a feature in premium runners) but must be tuned so the shoe still *flexes* enough to walk naturally — too stiff and it walks like a plank.
- Honest tradeoff: all this hardware *will* make SPEEDERS firmer and heavier than a pure 250–350 g court shoe. The target feel is "a **very supportive, mostly-white performance court shoe on a slightly built-up sole**," not "a featherweight racer" and not "a chunky casual sneaker." At ~0.9–1.4 kg it is **ski-boot/work-boot weight class** — fine for a "wear it for the ride" product, but it must be validated on real feet, because comfort is the make-or-break for adoption and this is **not** an all-day everyday shoe at that weight.

### 7.3 Water sealing — **IP67 requirement (rain + puddles must be survivable)**

**Target: IP67** — fully dust-tight, and survives **temporary immersion (1 m, 30 min)**. This is a hard requirement, not a nice-to-have: a shoe *lives* on wet ground. Rain, wet grass, and stepping in a puddle are **normal use**, not abuse, and there are lithium cells and motor electronics inside. The old IP54 (splash-only) target was not good enough for a product worn on feet.

**Sealing architecture — the "dry box inside a wet shoe" principle.** Do not attempt to waterproof the whole shoe (a flexing knit upper cannot be sealed). Instead, treat the upper as permanently wet and make every *electrical* volume its own sealed vessel:

| Zone | Sealing method | Target |
|---|---|---|
| **Battery vault (PowerDeck)** | Welded/gasketed enclosure, silicone O-ring on a captured groove, pressure-relief vent membrane (Gore-type: passes vapour, blocks liquid) | **IP68** — the most protected volume in the product |
| **Main PCB cavity** | Fully **potted** (thermally conductive epoxy/silicone) or a gasketed shell + conformal coating on both sides | IP68 |
| **Hub motors** | Sealed bearings + shaft lip seals + IP-rated phase-wire gland at the motor exit | IP67 |
| **Wheel wells** | Sprung TPU well covers close in Walk mode; wells drain — **wells are designed WET**, they simply must not be a path into any electrical volume | drained, not sealed |
| **Deploy struts / pivots** | Marine-grade: stainless/anodized, sealed pivot bushings, grease-packed; corrosion-resistant by material choice, not by sealing | corrosion-proof |
| **All connectors** | Potted after mating, or IP67-rated latching connectors; **no unsealed connector anywhere in the sole** | IP67 |
| **Charging** | **Wireless coil only — no exposed charge contacts.** This is the single biggest waterproofing win: there is no port to flood | no opening at all |
| **Sweat (from inside)** | Insole membrane + drainage channels; treat sweat as continuous salt-fog corrosion, worse than rain | 500 h salt-fog on the enclosure |

**Why wireless charging is a safety feature here:** a USB-C or pogo-pin charge port is a hole straight into the electronics and the #1 water-ingress failure point on any wearable. The inductive coil charges *through* a sealed sole, so the electrical envelope has **zero openings**. Any wired-backup option (§5.3) must be behind a gasketed door and is explicitly a dry-conditions-only path.

**Verification (add to the §13 test matrix):**
- **IPX7 immersion:** 1 m, 30 min, powered on, at both 100% and 20% SoC → no ingress, no fault.
- **Puddle-strike:** ride through 30 mm standing water at full speed ×20 → no ingress (dynamic water impact is harsher than static immersion).
- **Rain soak:** IPX4 spray for 4 h while flexing on a gait rig, then function + insulation-resistance test.
- **Sweat/salt-fog:** 500 h per ASTM B117 on the sealed enclosures.
- **Post-immersion battery check:** insulation resistance and cell integrity after every water test — **water + lithium is the highest-severity path in the FMEA.**

**Honest caveat for the buyer:** IP67 means it survives rain and puddle-stepping — it does **not** mean go swimming, ride through a stream, or put it in a washing machine. Seals age; specify the gaskets as serviceable at pack-replacement intervals (§8.2), and re-test IP after the fatigue campaign, because **a seal that passes at build and fails at 100k flex cycles is the realistic failure mode.**

### 7.4 WEIGHT BUDGET — per-component, size-8.5 build (grams; TARGET, to be validated)

This is the gram-by-gram budget for the **US Men's size 8.5** build. The "realistic" column is the honest as-designed build; the "lightweighted v1" column applies the safe §1.6 moves (lighter motors, Mg/composite frame, thinner harvester, hollow wheels, trimmed structure) **without** shrinking the battery. Taking the smaller-battery lever on top pushes the total toward ~700 g at a range cost.

| Component / subsystem | Realistic build | Lightweighted v1 | Notes |
|---|---|---|---|
| Battery pack (Li-poly, 30–60 Wh) | **170–320 g** | **170–250 g** | Single heaviest item. Low end = 30 Wh/~4–5 km; high end = 60 Wh/~10–12 km. The rider's main weight†”range lever (§5.1). |
| 4× hub-motor wheels (motor + PU + bearings) | **180–260 g** | **120–180 g** | Lighter via optimized-winding motors + hollow/cored PU wheels (costs torque + a little compliance). |
| Deploy struts + actuators + over-center locks | **90–150 g** | **75–120 g** | Servos/solenoids + arms + latches. Topology-optimize struts; do NOT thin the load-bearing lock. |
| Carbon load plate + chassis/frame | **90–140 g** | **60–95 g** | Mg/composite frame + carbon plate instead of 7075 Al = best stiffness-to-weight win. |
| Harvester (plates, springs, generators) | **60–110 g** | **35–60 g** | Thinner plates / EM-coil-only (drop rack-gen + piezo). Tiny energy hit only (§3). |
| PCB + ESCs + sensors + wiring + inductive RX coil | **70–110 g** | **60–90 g** | All electronics + the wireless-charge coil. |
| Court-shoe upper + midsole foam + outsole + insole | **170–230 g** | **150–200 g** | The "shoe" part. Slim white court silhouette (§7.0). |
| Gaskets, fasteners, well covers, misc | **40–70 g** | **30–55 g** | Smaller/fewer fasteners; lighter well covers. |
| **TOTAL per shoe** | **‰ˆ 0.9 – 1.4 kg** | **‰ˆ 0.7 – 0.9 kg** | Realistic = ski-boot/work-boot class. v1 target reaches ~0.7–0.9 kg per §1.6. |

> **The wearability reality:** a normal sneaker is **~250–350 g/shoe.** SPEEDERS at ~0.9–1.4 kg is **roughly 3–5× a normal shoe** — the weight of a **ski boot or heavy work boot.** That is the unavoidable cost of putting a motorized vehicle on your foot. **It is NOT a comfortable all-day everyday shoe at that weight — it's a "wear it for the ride/commute" product.** The §1.6 plan + the lightweighted column above are the path to a more wearable ~0.7–0.9 kg v1, and validating rider acceptance of the weight is the **#1** thing to test on real feet.

---

## 8. Assembly Sequence + Serviceability

### 8.1 High-level assembly sequence
1. **Sub-assemble the drivetrain modules:** press bearings into each hub wheel; mount wheels to struts; fit struts to actuators + over-center locks; test deploy/retract + lock on a fixture.
2. **Build the harvester modules:** assemble heel + forefoot plates on guide posts with springs, magnets/coils (or rack-gens); bench-test output curve.
3. **Populate + test the flex-rigid PCB:** MCU, PMIC, ESCs, IMU, deploy-button input, drivers; flash bootloader; functional + ICT test *before* it's buried in a shoe.
4. **Assemble the chassis cage:** mount carbon load plate, chassis, arch battery enclosure (battery installed + BMS verified), PCB, drivetrain modules, harvester modules, Qi coil. Route + strain-relief all wiring. Gasket and seal cavities.
5. **End-of-line electrical test** of the bare powered chassis: deploy/retract, lock sensing, motor spin + regen, harvester output, Qi charge, BLE pairing, full safe-state fault injection — **before** it's wrapped in a shoe (you can't easily test inside a finished shoe).
6. **Build the shoe over the chassis:** lay in midsole foam, last the knit upper, attach outsole + wheel-well covers + closure, fit insole with FSRs.
7. **Final paired test:** pair left+right, run the full self-test (`?selftest`-style EOL routine), IP-spray check, ride-fixture validation, label with battery/regulatory marks.

### 8.2 Serviceability (the two wear/consumable items)
- **Battery:** designed as a **field/service-replaceable module** in the arch behind a sealed, gasketed service hatch (it's a consumable — Li-poly ages, and a swollen pack must be removable safely). Keyed connector, BMS handshake, torque-spec'd screws. *Do not* hard-pot the battery in.
- **Wheels:** the highest-wear part. Hub-motor wheels mount on a **serviceable strut interface** (one screw/clip + the motor connector) so a worn wheel can be swapped without tearing the shoe apart. Stock them as spares.
- **Everything else** (PCB, harvester, struts) is treated as a deeper service item — accessible by a trained tech via the outsole/chassis, not by the end user.
- Provide a **diagnostic mode** over BLE (app or service tool) that dumps fault logs, cell health, motor/harvester stats, and lock-sensor state for triage.

---

## 9. Safety + Regulatory

> **This is a foot-mounted powered personal vehicle with a lithium battery that may be used by a minor. The safety/regulatory burden is large and non-negotiable. The engaging firm owns final compliance; this section is the starting checklist.**

### 9.1 Mandatory testing / certification (starting list — confirm per target market)
- **Battery transport & safety:** **UN38.3** (lithium battery transport) and **IEC 62133** (cell/pack safety) — plus crush, nail-penetration, over-charge, short, and thermal-runaway containment testing *because of the on-foot impact environment.*
- **Radio / EMC:** **FCC Part 15** (US) and **CE RED / EN 300 328** (EU) for the BLE radios; general **EMC** (FCC Part 15B / EN 55032) for the digital electronics.
- **Electrical safety:** low-voltage product safety review; charger/dock safety (UL/IEC 60335 / 62368 class as applicable).
- **Mechanical fatigue:** strut/lock fatigue life, harvester 5–10M-cycle endurance, wheel/bearing wear, carbon-plate fatigue, deploy-lock load test (must hold full rider weight + dynamic/impact loads with margin).
- **Brake / dynamic performance:** measured **stopping distance** at the speed cap on dry and wet surfaces, brake-fade under repeated stops, endo/pitch testing under hard braking, behavior on the failure of regen (does the mechanical/coast backup stop the rider?).
- **E-mobility / PPE / consumer-product regimes:** classification is genuinely murky — SPEEDERS may be regulated as an e-mobility device, a toy (if marketed to minors — strict), and/or general consumer product. Engage a regulatory consultant early; **CPSC** (US) and local micro-mobility laws (where it can be ridden, helmet/age rules) all apply. It is NOT obvious this is street-legal anywhere by default.
- **Helmet/PPE guidance:** the product should *ship with* and *insist on* helmet + wrist guards; treat protective gear as part of the product, not an accessory.

### 9.2 Real liability & safety risks (stated plainly)
- **Falls are the core risk.** Small hard wheels + high CoM + a person who can be a beginner = high fall probability, especially on cracks, gravel, wet ground, and curbs. At 8–10 km/h (6 mph), a fall onto pavement causes real injuries (wrist fractures, head impact).
- **Used by a minor.** This dramatically raises the duty of care: learner mode, low speed caps, mandatory PPE messaging, parental setup/consent, and conservative defaults are not optional. The product, packaging, and any companion app must over-warn, gate speed, and assume an inexperienced rider.
- **Lithium battery on a foot.** Impact + flex + heat + sweat is a worst-case pouch-cell environment; a thermal event happens *on the wearer's body.* Containment, conservative cell selection, and abuse testing are existential, not nice-to-have.
- **Unexpected acceleration / failure-to-brake** is the catastrophic firmware failure mode — Section 6.5's "no single fault causes unexpected go" axiom is the legal and physical line.
- **Mixed-environment use** (street, sidewalk, near cars) raises both injury and regulatory exposure.
- The firm and brand need: extensive warnings/IFU, age gating, an enforced learner mode, robust QA, product-liability insurance, and legal review before any sale. **Do not sell to the public until a qualified safety body signs off.**

---

## 10. HONEST Feasibility Verdict

### 10.1 What is buildable today (the boring-but-real parts)
- **Four small BLDC hub-motor wheels + ESCs + a ~30–60 Wh Li-poly pack + wireless dock charging + ESP32/nRF-class control + IMU lean sensing + a recessed deploy button + BLE dual-shoe link + regen braking.** None of this is exotic — it's standard micro-mobility and wearables tech in a hard package. A skilled firm can prototype this.
- **A deploy/retract strut with a mechanical over-center lock.** Mechanically straightforward; the hard part is doing it small, sealed, reliable, and fail-safe — but it's an engineering grind, not a physics problem.
- **Forward-only lean-throttle with a speed governor and safe-state state machine.** Well-trodden control engineering; the work is in *exhaustive* fault testing.

### 10.2 What is aspirational / the hardest problems
1. **Energy density vs. weight (the binding constraint).** You cannot have long range *and* a shoe that walks nicely — the battery you can fit in the size-8 arch bay (~30–60 Wh) caps both, and every ~15 Wh is ~80 g on the foot. This is physics, not effort. **Solid-state cells would help but aren't buyable at this size/price in 2026** — design for Li-poly now.
2. **The kinetic harvester is small — own it.** Per Section 3 it yields ~tens of mW to maybe ~1–2 W bursts while walking and ~100–400× *less* energy per km than gliding consumes. It powers electronics and trickles the pack; **it does not "recharge the shoe from walking" in any headline sense.** Designing the marketing around walk-to-charge as a *primary* charging method would be dishonest and is the thing to *not* do.
3. **Stability on small wheels.** A short-wheelbase, narrow-track, high-CoM platform is inherently tippy and trip-prone; the small wheels + low speed cap + obstacle auto-retract are mitigations, not a fix. This is the biggest *injury* risk and the hardest *ride-feel* problem.
4. **Comfort with all that hardware.** Keeping a real "supportive court-shoe" feel around a carbon plate, four wheel wells, sprung plates, a battery, and a PCB — at **~3–5× normal shoe weight (ski-boot/work-boot class)** — is a serious industrial-design and biomechanics challenge. It is honestly **not an all-day everyday shoe** at that weight; it's a "wear it for the ride" product. If it walks badly, the product fails regardless of how cool the glide is.
5. **Cost.** Four motors + four ESCs + custom struts/locks + a qualified battery + custom electronics + carbon plate + tooling, **×2 shoes**, is an expensive bill of materials. Realistic prototype BOM is high; even at scale this is a premium-priced product, and that should be assumed from the start.
6. **Sealing a flexing electronic shoe** to IP67 against sweat + weather is genuinely hard — the #1 integration risk after the deploy lock.

### 10.3 Realistic performance verdict (size-8.5 build)
- **Weight: ~0.9–1.4 kg per shoe** as designed (~0.8–1.5 kg honest range), per the §7.4 size-8 budget — **ski-boot/work-boot class, ~3–5× a normal sneaker.** Plan for the high end. A lightweighted v1 (§1.6) reaches **~0.7–0.9 kg.** This is the headline tradeoff the rider feels every step in Walk mode. **Not an all-day everyday shoe — a "wear it for the ride" product.**
- **Pure-glide range (battery alone): ~6–12 km (~4–7 miles) realistic** for a ~60–80 kg rider on flat ground at the 8–10 km/h (6 mph) cap — *less* with hills, a heavier rider, frequent accel/decel, cold weather, or aggressive riding (could fall to ~4–6 km in tough conditions). Translation: **a commute or campus ride is fine; all-day is not.** Regen and the harvester extend this only at the margins.
- **Charging: wireless-first, ~3–5 h to full on the dock** (~1.5–2.5 h on the wired backup); ~300–500 cycle pack life. **Walking does not recharge the drive battery** — the dock does (§3, §5.3).
- **Glide speed: 8–10 km/h (6 mph) governed (v1)** — capped low for safety, not capability.
- **Styling: clean, mostly-white performance tennis/court shoe** on a slightly built-up sole (§7) — not a chunky casual sneaker.

### 10.4 What the manufacturer/engineer MUST prototype & validate before production
1. **Battery abuse + thermal-runaway containment** in the on-foot impact/flex/sweat environment — *gating; do this first, before anyone wears it.*
2. **Deploy-lock strength + fatigue** — prove the lock holds full dynamic rider load with margin over millions of cycles, and is genuinely fail-safe.
3. **The full safe-state fault tree** — fault-inject every sensor/comm/power failure and *prove no single fault causes unexpected acceleration*, and that coast-to-stop + brake always works (including on total power loss and BLE drop).
4. **Brake stopping distance + endo behavior**, dry and wet, with regen-failure backup.
5. **Stability / rollover / trip-over envelope** on real surfaces (cracks, gravel, wet, slopes) at the speed cap — define the auto-retract obstacle triggers from real data.
6. **Honest harvester bench characterization** — measure real J/step and W-while-walking on a gait rig and confirm Section 3's numbers (and confirm it isn't stealing enough energy to make walking tiring). Confirm it does **not** meaningfully charge the drive pack.
7. **Walk-mode comfort + durability on real feet** — wear trials at the real ~0.9–1.4 kg weight; honestly characterize **how long it's comfortable to wear** (it is a "wear it for the ride" product, not all-day) and validate rider acceptance of the weight — the #1 adoption risk.
8. **Wireless charge validation** — confirm real dock charge time (~3–5 h to full at the size-8 pack), coil alignment tolerance heel-down, thermal behavior while charging through the sealed sole, and the wired backup (~1.5–2.5 h).
9. **Dual-shoe sync robustness** — confirm left/right never desynchronize dangerously, including on BLE interference.
10. **IP67 immersion + puddle-strike + sweat-corrosion** validation (including the inductive coil path through the sealed sole).
11. **EVT → DVT → PVT** build cycle with formal DFM, regulatory pre-scans (FCC/CE/UN38.3), and a regulatory-classification ruling *before* committing to tooling.

---

# PART II — EXPERT ENGINEERING & DESIGN ADDENDUM

*The following was produced by a review panel of five senior specialists (mechanical/mechatronics, electrical/power, industrial design, safety/compliance, and DFM/cost). It adds the quantitative load cases, current math, failure analysis, certification detail, CMF, and cost/tooling numbers a contract manufacturer expects. **Where a figure here differs from Part I, this addendum governs** — it carries the derived numbers.*

## 11. Structural, Drive & Mechanical Engineering

### 11.1 Structural load cases & fatigue targets (size struts, locks, plate to THESE — not to "rider weight")
**Design rider for structures: 100 kg (95th-percentile adult + clothing/pack).** The 60–80 kg rider in the range math is an *energy* assumption; structures must not break for a heavier user. Loads per shoe, deployed unless noted.

| Case | Condition | Design load | What it sizes |
|---|---|---|---|
| **LC1** | Static glide, both feet down | 0.5 kN/shoe (55/45 heel/fore) | Normal ops; fatigue baseline |
| **LC2** | Momentary one-foot stance / push | 1.0 kN/shoe | Strut + latch static sizing |
| **LC3** | Step-down / 150 mm curb drop, one shoe | 3–5× BW = **3–5 kN/shoe** → **1.5–2.5 kN/strut** (2-wheel landing) | **Ultimate case: strut, pivot, latch, bearing C0** |
| **LC4** | Max braking (pitch-limited, §11.4) | Full load on front axle + ~0.8 kN longitudinal | Front struts, plate bending |
| **LC5** | Crack/pothole wheel-stop at 10 km/h (6 mph) | ~1.5–2 kN longitudinal at one wheel + pivot moment | Strut bending; latch no-back-drive |
| **LC6** | Walk-mode stomp, wheels stowed | 2–3 kN through closed covers | Stowed lock must not pop; zero load into actuator |

**Safety factors:** 1.5 yield / 2.0 ultimate on LC1/LC2/LC4; ‰¥1.2 ultimate on LC3/LC5. Latch: no functional damage at LC3, no release below 2× LC3.
**Fatigue targets:** deploy mechanism **30,000 cycles** (‰ˆ10/day × 8 yr); strut + latch **2×10¶** road-bump cycles at 1.5× LC1; carbon plate + chassis **5×10¶** walk-step cycles at 1.5× BW heel strike. Apply the anodize fatigue knockdown (§11.6) before claiming margin.

### 11.2 Corrected glide-consumption math (the number the whole honesty argument rests on)
Rolling resistance dominates at these speeds. 60–80 kg rider + ~2.5 kg shoes (N ‰ˆ 620–815 N), 45 mm 80A PU (Crr ‰ˆ 0.03–0.04 on smooth concrete):

| Quantity | Value |
|---|---|
| Drag F = Crr × N | ~19–33 N |
| Mech. power @ 10 km/h | ~52–92 W (+~5 W aero) |
| Electrical @ 55–70% eff. | ~90–170 W (both shoes) |
| **Energy per km (both shoes)** | **~10–20 Wh/km** (~5–10 Wh/km per shoe) |

Cross-check vs §10.3: 2 × 30–60 Wh × ~90% usable Ã· 10–20 Wh/km = **~4–11 km**, consistent with the stated 6–12 km. Harvest-vs-glide ratio: **~100–400×** (gliding costs 100+× the walk-harvest rate).

### 11.3 Per-motor drive math (75 kg rider, 8 motors, r=22.5 mm, governed 10 km/h (6 mph))
| Condition | Tractive force | Per-motor torque | Per-motor elec. (~60% eff.) |
|---|---|---|---|
| Cruise 10 km/h (6 mph), flat | ~25 N | 0.07 N·m | **~17 W** |
| 5% grade | ~66 N | 0.19 N·m | **~45 W** |
| 8% grade | ~90 N | 0.25 N·m | **~62 W → thermal-derate zone** |
| Launch, 1 m/s² from rest | ~108 N | **0.30 N·m** | I²R-dominated: ~10–15 A phase, 2–5 s |

Wheel speed at cap = 3.33 m/s Ã· 0.0225 m ‰ˆ **1,410 rpm** — easy for a small outrunner; **gearing is never needed for speed, only possibly for stall torque.** Spec motors by **torque constant Kt + stall-thermal** ("0.3 N·m for 5 s from stall, winding ‰¤120 °C"), not by watts alone.

### 11.4 Deploy is an UNLOADED-only operation (the actuator can't lift a standing rider)
Lifting even half the rider (~0.5 kN at the wheel, ~30 mm arm) needs **‰ˆ15 N·m (~150 kg·cm)** at the strut pivot — the §2.1 6–12 kg·cm servo is short by **>10×** (25–50× at full one-foot load). **Resolution:** each shoe deploys/retracts **only when its own insole FSR reads < ~20% body weight** (foot in swing phase). Unloaded torque budget ‰ˆ 0.15–0.3 N·m → the specced servo then has 2–4× margin.
**Sequencing (revises the "<1.0 s both shoes" claim):** a deploy-button press **ARMS** both shoes → each deploys in **<0.4 s during its next unweighted step** → both report locked within ~1.5–2 s → throttle enables per the §4.4 interlock.

### 11.5 Over-center latch — design rules (the highest-consequence interface in the product)
- **Self-energizing geometry:** locked strut rests **4–8° past dead center against a hard stop**, so ground reaction always moments the linkage *into* the stop. Verify no-back-drive at worst-case tolerance + full wear under LC3/LC5 vectors.
- **Secondary retention:** a spring pawl the actuator must positively withdraw before the toggle can move.
- **Engagement budget:** overlap **‰¥1.0 mm worst-case** (tolerance ±0.05 + assembly ±0.1 + wear 0.2 + thermal). **The sensor must read the LATCH, not the strut** — "strut down" ‰  "locked."
- **Contact stress:** at 2.5 kN (LC3), Hertz ‰¤ ~1,500 MPa against **440C or 52100 @ 58–62 HRC**. No aluminum-on-aluminum at the latch.
- **Unlock:** actuator breaks pawl + over-center at max grit friction with 2× margin; no crash-load vector may generate that same motion.

### 11.6 Stability & braking first-pass numbers (replaces "the firm must model")
- **Lateral static tip:** half-track ~40 mm, CoM ~1.0 m → **~2.3°. Effectively zero lateral static stability — it's a skate; the rider is the stabilizer.** Spend grams on wheelbase (push to 220 mm), not track width.
- **Braking is pitch-over-limited, not grip-limited:** endo threshold ‰ˆ g·(b/h) → **~0.1 g** (CoM mid-wheelbase) to **~0.2 g** (rider leaning hard back). Tire grip (µ‰ˆ0.8) is never the limit.
- **Stopping distance from 10 km/h (6 mph) (3.33 m/s):** **~5.7 m @ 0.1 g, ~2.8 m @ 0.2 g** + reaction. Consequences: **bias regen to the rear axle; "ABS" must be pitch-triggered (IMU), not slip-triggered;** brake-test pass line **‰¤4.0 m dry** from cap.
- **Obstacle trip:** rigid wheel-stop begins at lip height ‰ˆ …“ wheel radius = **~7–8 mm** for a 45 mm wheel (80A PU absorbs only ~‰¤3 mm). Sets the obstacle-detect trigger and argues for wheel OD at the top of the 38 mm rear / 30 mm front band.

### 11.7 Bearings — corrected (ABEC is marketing here; impact + contamination are the real drivers)
- Rolling fatigue is a non-issue: 688-class L10 ‰ˆ **3×10¹ revs** vs ~10· in 1,500 km. ABEC grade is a *dimensional tolerance*, irrelevant at ~1,400 rpm.
- **Real sizing driver = static impact:** LC3 puts ~1.25 kN on one bearing vs a 688's C0 ‰ˆ 0.9 kN → **brinelling**. Fix: 608-class (C0 ‰ˆ 1.4 kN) or a **strut bump-stop grounding impact before the bearing sees > C0.**
- **Real killer = contamination + sweat:** spec **2RS contact seals, 440C stainless races, calcium-sulfonate grease.** Qualify the hub motor's *internal* bearings against the same table (a reference e-skate hub was built for a 54 mm truck wheel, not a shoe strut at LC3).
- Wheels are consumables: ~2.5 mm radial wear budget, ~300–800 km tread life (§8.2).

### 11.8 Materials & finishes callouts (sweat = warm salt water)
| Interface / part | Risk | Callout |
|---|---|---|
| CFRP plate †” Al/Mg chassis | Galvanic cell (carbon is noble) | **Isolate every faying surface** — glass-ply barrier + sealed fasteners; never bare metal on carbon |
| 7075-T6 struts, hard-anodized | Type III anodize cuts fatigue strength **30–50%**; SCC-prone | Shot-peen before coat; hard-anodize wear faces only; consider **T73**; apply knockdown to §11.1 |
| Mg frame (§1.6 option) | Aggressive corrosion | Keronite/Tagnite conversion + topcoat + isolation washers |
| Springs | "Music wire" rusts in weeks | **302 SS or 17-7PH** for every spring |
| Latch pins/cams | Wear + corrosion | **440C @ 58–62 HRC, passivated** |
| Fasteners/inserts | Crevice corrosion, galling | A2/A4 stainless; brass inserts rated ‰¥20 R&R |

### 11.9 Grit management for the mechanism (IP67 protects boards, not the latch)
Wells open to the road on every deploy. Design the mechanism to **work dirty:** labyrinth + wiper seals at pivots; **self-clearing wedge latch faces**; open drainage at each well bottom; **actuator-current jam detection** with one retry then fault-to-deployed. Validate by deploy/lock/retract cycling in **ISO 12103-1 A4 road dust** + mud/slush, latch engagement measured before/after.

## 12. Electrical & Power Engineering

### 12.1 Pack electrical spec (the numbers a pack vendor asks for first)
Per-shoe loads: ~100 W continuous, ~250 W burst ‰¤5 s.

| Pack | Config | Cont. / C-rate | 5 s burst / C-rate | Cell rating |
|---|---|---|---|---|
| 30 Wh | **3S**, 11.1 V, 2.7 Ah | ~9 A ‰ˆ 3.3C | ~25 A ‰ˆ **9C** | ‰¥5C cont / ‰¥10C burst |
| 60 Wh | **3S**, 11.1 V, 5.4 Ah | ~9 A ‰ˆ 1.7C | ~25 A ‰ˆ 4.6C | ‰¥3C cont / ‰¥6C burst |

- **Prefer 3S over 2S** — 2S pushes ~38 A instead of ~25 A through every FET/connector/wire (loss ˆ I²); 3S is what lets the §6.6 harness gauges close.
- **Weight correction:** ‰¥5–10C pouches run ~120–160 Wh/kg → **~190–250 g for 30 Wh** (~330–380 g for 60 Wh), *not* the ~150–170 g an energy-cell number implies. Energy-cell weight and power-cell current don't coexist — pick one.
- **Sag (3S/30 Wh):** ~60–80 mÎ© loop → a 25 A launch dips the bus **1.5–2.0 V**; at 20% SoC the bus touches ~8.5–9 V. So: UVLO needs ~100–200 ms transient blanking, and firmware derates burst below ~25% SoC so **braking authority is never sag-limited**.

### 12.2 Harness ampacity corrections (the 18 AWG pack lead was ~2× undersized)
"peak" = 5 s launch burst; assumes the recommended 3S pack.

| Segment | Peak current | Was | Fix |
|---|---|---|---|
| Pack power (B+/Bˆ’) | ~25 A @ 3S | 18 AWG | **16 AWG** (14 AWG / 2×18 if 2S) |
| Pack connector | ~25 A | XT30 | XT30 OK at 3S w/ derate; XT60 at 2S |
| Motor rail per-ESC branch | ~6–8 A | 20 AWG | OK **as 4 branches**; a shared trunk must match the pack lead |
| Motor phases | 10–15 A | 20 AWG | OK <10 cm; 18 AWG if Î”T >30 °C |
| Balance / sensor | <1 A | 26–30 AWG | Fine |

### 12.3 Protection coordination — the trip ladder (replaces "PTC + e-fuse")
A PTC is the wrong device here (large, seconds-slow, adds sag, nuisance-trips at 45–60 °C sole temps). Use a coordinated ladder:

| Layer | Device | 3S example | Speed | Catches |
|---|---|---|---|---|
| 1 | ESC per-phase current limit | per §11.3 | µs | stall, phase short |
| 2 | **Bidirectional e-fuse** (back-to-back FET) | ~32 A | ~100 µs | harness fault, failed FET |
| 3 | BMS discharge OCP | ~40 A | ms | anything missed |
| 3b | BMS **charge-direction** OCP | ~10 A | ms | regen / charger overcurrent |
| 4 | Non-resettable pack fuse | ~50 A | hard short | last barrier before cells |

- **Regen pushes current INTO the pack** — the e-fuse must be bidirectional or it blocks/dies during braking.
- **Regen into a full pack needs a dump path:** worst-case stop ‰ˆ 460 J over ~2.5 s ‰ˆ **90 W burst/shoe** — size the §5.4 clamp resistor for N consecutive stops, or guarantee friction backup above a pack-voltage threshold. **"Pack full" must never mean "no brakes."**

### 12.4 Wireless-charge integration constraints
- **Z-gap ‰¤ 6–8 mm coil-to-coil** or 10–15 W transfer collapses. Define a heel coil window: RX ‰¤3–4 mm behind the outsole, ferrite behind it, and **no carbon plate / spring steel / strut metal within the coil footprint +5 mm** (carbon is conductive → eats flux, eddy-heats, trips foreign-object detection). **Terminate the carbon plate forward of the heel coil zone.**
- **Alignment is a designed feature:** molded heel cup (±3 mm XY) + alignment-magnet ring (MagSafe-style).
- **Charge thermals:** ~60–75% end-to-end → **4–8 W of heat** next to the pack in sealed insulating foam for 3–5 h, against a 45 °C Li-poly limit → NTC-gated charge derate mandatory; validate at 35 °C ambient.

### 12.5 Quiescent draw, ship mode & shelf life (absent before — kills battery products in warehouses)
- **Walk-mode standby target ‰¤150 µA avg (300 µA ceiling).** At sloppy 5–10 mA the pack is dead — and over-discharged into permanent damage — in **2–4 weeks**; at ‰¤150 µA it lasts ~9–12 months on a shelf. Treat as a firmware deliverable with a measured EOL test.
- **Ship mode:** BMS FETs open, <10 µA, exits on dock/charger detect — units warehouse in this state.
- **Auto-hibernate** after ~14 days unworn. **Over-discharge ladder:** warn 3.3 V/cell → forced retract 3.0 V → BMS disconnect 2.7–2.8 V → recovery trickle or reject below ~2.5 V.
- **Honest harvester tie-in:** standby draw ~1–3 mW is the *one* load the §3 harvester genuinely covers — "walking keeps the always-on electronics topped up indefinitely" is a claim this doc *can* make truthfully.

### 12.6 EMI coexistence (4 PWM drives + BLE + 100 kHz wireless power in one insole)
Stagger/spread-spectrum the four ESC PWM clocks; LC/Ï€ filter on the motor bus at PCB entry; BLE antenna keep-out ‰¥8–10 mm from the carbon plate, link margin characterized **in the built shoe**; pull the FCC 15B / EN 55032 pre-scan forward to Phase 1 — an EMC re-spin at Phase 4 costs months. **Note:** using a *mechanical* recessed deploy button instead of a capacitive tap zone removes a whole class of EMI risk — there is no electrode near the motor phases to be falsely triggered by switching noise, so a false deploy from EMI is designed out, not merely filtered.

## 13. Safety, Compliance & Regulatory (expanded)

### 13.1 Corrected certification matrix
| Domain | Standard | Applies to | Notes |
|---|---|---|---|
| Battery transport | UN 38.3 (T.1–T.8) | Cells + pack | Required to ship at all |
| Cell/pack safety | **IEC 62133-2:2017** | Li-ion | Cite the **-2** (lithium) part |
| Pack system | **UL 2271** | Pack + BMS | LEV-class pack listing; feeds UL 2272 |
| Device electrical system | **UL 2272** | Whole shoe | Hoverboard-class cert — the retailer/marketplace gatekeeper; long-lead, budget in Phase 4 |
| Radio (US) | FCC Part 15C §15.247 — **certification** | BLE | Use a **pre-certified BLE module** (nRF52-class) to inherit the grant — saves ~$20–50k + months |
| Digital EMC (US) | FCC Part 15B (SDoC) | Device | Unintentional-radiator emissions |
| Radio+EMC (EU) | RED 2014/53/EU: EN 300 328, 301 489, 62368-1, 62479 | BLE + device | |
| EU PLEV mechanical | **EN 17128** | Vehicle | Closest published mechanical/safety yardstick |
| Dock | UL/IEC 62368-1 + its own FCC (15/18) + Qi/WPC | Dock | **Separate mains product**, own cert stack + budget |
| Materials | RoHS, REACH SVHC, CA Prop 65 | All | Skin-contact → phthalate/nickel scrutiny |
| EU battery | Regulation 2023/1542 | Pack | Labeling + removability — the §8.2 replaceable pack already satisfies intent |
| US consumer | CPSC / CPSIA | Product | **Market as 14+** (§13.4); marketing to ‰¤12 → "children's product" → mandatory 3rd-party testing |

### 13.2 Design FMEA — top failure modes (S×O×D, concept-level; firm expands in Phase 1)
S=severity(10=life-threatening), O=occurrence pre-mitigation, D=undetectability.

| # | Failure mode | Effect | S | O | D | Mitigations | Verified by |
|---|---|---|---|---|---|---|---|
| 1 | Cell crush/puncture → thermal runaway | Fire on foot | 10 | 4 | 3 | PowerDeck vault + load bridge (§6.8); vent away from foot; UL 2271 | §13.3 |
| 2 | Wheel jams at speed | Head-height fall | 8 | 7 | 6 | 30–38 mm wheel + 6 mph cap; obstacle auto-retract; **residual risk high → PPE mandatory** | Trip envelope test |
| 3 | Stuck FET/hang → unexpected accel | Rider thrown | 9 | 3 | 4 | No-single-fault axiom (§6.5); watchdog; hardware throttle inhibit | Fault injection |
| 4 | Deploy lock collapses mid-glide | Drop + fall | 9 | 4 | 5 | Lock ‰¥4× peak load; lock sensor gates throttle | Proof-load + fatigue |
| 5 | Regen lost (pack full) → no braking | Can't slow | 8 | 4 | 3 | Brake-resistor dump (§12.3); **friction backup = requirement** | Brake test, regen off |
| 6 | IMU fault → phantom throttle | Surge | 9 | 3 | 4 | Fusion agreement rule (§6.7) | Sensor fault injection |
| 7 | L/R BLE desync | Feet split → fall | 8 | 4 | 4 | Independent coast-to-stop on link loss | RF-interference test |
| 8 | Sweat/water ingress | Fault + latent hazard | 7 | 6 | 6 | IP67 + conformal + potting | Sweat/salt-fog soak |
| 9 | Retract while gliding | Dropped at speed | 9 | 2 | 4 | Retract only at ‰ˆ0 speed (§4.5) | Fault injection |
| 10 | Charge thermal event, unattended | House fire | 10 | 2 | 5 | BMS gating + thermistors; dock over-temp; UL 2272 | Charge-abuse test |

### 13.3 PowerDeck vault abuse-test matrix (numbers §6.8 demanded)
**Pass unless stated:** no fire/smoke/leak, no venting toward foot, **zero cell deformation**, BMS functional. Run at **100% SoC**, on fresh AND **aged packs (‰¥300 cycles)**.

| Test | Method / numbers |
|---|---|
| Static crush (vault) | 3.0 kN (~3× 100 kg rider) via 100 mm platen, 3 min; repeat 32 mm indenter |
| Dynamic stomp | 100 kg surrogate jump-land from 0.6 m (peak ‰¥6 kN) ×10 |
| Stomp fatigue | 200,000 cycles @ 1.5 kN; ‰¤10% bridge stiffness loss, zero cell contact |
| Puncture (underfoot) | 4 mm-tip 60° spike into outsole @ 1.2 kN (body weight on a sharp rock) |
| Drop (shoe) | 1.5 m onto concrete, 6 orientations × 3; wheel locks intact after |
| Curb strike | 10 km/h (6 mph) into 20 mm curb, deployed, ×5; shock ‰¤ UN38.3 T.4 (150 g/6 ms) |
| Charge thermal | 0→100% wireless at 25 & 35 °C; skin surface ‰¤43 °C, cells ‰¤45 °C |

### 13.4 Rider envelope (published limits — enforced by firmware, labels, app)
| Parameter | Limit |
|---|---|
| Minimum age | **14** (under-16 = parental app setup) — keeps out of the CPSC ‰¤12 regime *only if marketing stays consistent* |
| Rider weight | **40–100 kg** (min: FSR/control authority; max: struct margin + brake energy; range model assumes 60–80 kg — derate above) |
| Terrain | Dry, paved, smooth only; max grade **4–5%** (revised in §4.2c — 8% is not achievable at the speed cap without overheating); no gravel/sand/wet/ice/stairs/roads |
| Conditions | Daylight/lit; 0–40 °C |
| PPE | **Helmet + wrist guards required**; knee/elbow recommended |
| Rules | One rider; no towing (defeats the speed cap); no tricks |

### 13.5 Brake acceptance criterion
**Stopping distance ‰¤2.5 m dry / ‰¤4.0 m wet** from the 10 km/h (6 mph) cap, **with regen disabled** (friction backup only), no endo — measured per the §10.4 protocol. (From §11.6: braking is pitch-limited to ~0.1–0.2 g, so this is the achievable window.)

### 13.6 Labeling & manual (IFU) — certification deliverables
On-product (molded/laser-marked, not adhesive): ANSI Z535.4 warning ("Powered riding device. Falls can cause serious injury or death. Helmet + wrist guards required. 14+, 40–100 kg."), model/serial/date code (plan recall traceability **now**), FCC ID / CE / UKCA / WEEE / Li-ion mark **with Wh rating** (airline-legible), "charge only with SPEEDERS dock." Manual/app must publish: the §13.4 envelope verbatim; the honesty statements (walking ‰  charger, real range, not all-day) verbatim; **measured** stopping distance dry/wet from DVT; battery care + swollen-pack warning signs; do-not pictograms (stairs/wet/traffic/tow/2nd rider/submersion).

## 14. Industrial Design, CMF & Human Factors

### 14.1 Design language — the masquerade rule
**Walk mode:** at 3 m, reads as a premium court shoe — zero visible motors/struts/fasteners; only tells are the lateral light line + heel dock mark. **Deploy mode:** the reveal is celebrated — struts and wheel faces finished as jewelry. One product, two faces, never blended.

**Silhouette targets (size 8.5, side view):** two-tone sole split (white foam ~60% over a recessed dark chassis band ~40%, inset 2–3 mm — makes the 44 mm stack read slimmer); ~8 mm heel-toe rake; 8–12 mm toe spring; 10–15° heel bevel; upper:sole visual ratio **‰¥55:45** (below that it reads "platform sneaker"). No fasteners on the show face; well covers flush ±0.5 mm carrying the tread across the seam; one continuous ~2 mm lateral light pipe is the single strongest brand element.

### 14.2 CMF spec — hero colorway "MIDNIGHT CIRCUIT"
White platform (midsole+outsole) = permanent brand equity across colorways; knit carries the colorway. *(Amend "mostly white" → "white platform, colorway-specific knit.")*

| Part | Material | Color standard | Finish |
|---|---|---|---|
| Knit body | Recycled PES/spandex melange | PANTONE 19-3921 TCX Black Iris + 19-4010 TCX Total Eclipse | Matte (blue-black melange, never flat black) |
| TPU overlays | HF-welded film | 19-4010 tint @30% translucency | Semi-gloss 30±5 GU |
| Midsole | Supercritical PEBA/EVA | 11-0601 TCX Bright White | Matte |
| Chassis band | GF-nylon | 19-4007 TCX Anthracite | Bead-blast |
| Outsole + covers | Non-marking rubber | 11-0601 Bright White (solid — translucent yellows in UV) | Matte lugged |
| Light pipe | Diffused silicone/PC | Off 14-4102 TCX; lit cyan Î» 497±8 nm (accents PANTONE 306 C) | Satin |
| Struts / hub faces | 7075 Al | Natural anodize grey | Machined satin (no chrome/polish anywhere) |
| Wheel tread | Cast PU 78–85A | 306 C tint @15–25% | Cast |

**Colorway 002 "Service White":** all-white knit, same platform — yarn change only, zero new tooling. **Finish rules:** matte-first; anodize, never paint, on metal; approve to physical PANTONE standards in a D65 lightbox.

### 14.3 Light & haptic language (rider can't look at their feet — haptics-first mid-glide)
| State | Light line | Heel | Haptic |
|---|---|---|---|
| Walk | Off (‰¤1 breath/10 s) | Off | — |
| Deploy | Fast cyan sweep ×2 <1 s | — | Double pulse = locked, ready |
| Gliding | Solid cyan | **Solid red (rear)** | — |
| Low batt <20% | Amber at heel | Red | 2 short pulses |
| Auto-retract imminent | Rapid flash 500 ms **before** | Red flash | **Long pulse = wheels coming up** |
| Fault | Solid amber | Red | 3 long pulses |

Rules: no flashing 3–30 Hz (photosensitivity); all patterns BLE-synced L/R; distinguishable in daylight at 3 m; cyan reserved for drive/charge, never decoration. Every §6.5 fault-injection test must verify its light+haptic row fires.

### 14.4 Ergonomics — mass placement, donning, collar
**Placement beats total mass** (~1% added energy per 100 g/shoe; forefoot mass costs more — it swings farther): keep **‰¥70% of hardware mass in the rear 60%** (battery/PCB/coil/rear motors), **‰¤30% forefoot**; CoM at/behind the ankle axis ("boot-heavy, not flipper-heavy"). **Donning a 1 kg rigid shoe:** throat opening ‰¥90 mm unlaced; BOA-class one-handed closure; heel pull-loop rated **‰¥300 N**; heel counter doubles as dock-alignment geometry; target don/doff ‰¤15 s. **Collar:** low-top court (~70–80 mm lateral), ‰¥12 mm foam over the malleoli; **do NOT stiffen into a cuff** — edge-weight steering needs ankle articulation; stability comes from stance + governor, not the collar.

### 14.5 Size run & grading (beyond size 8.5)
Launch **US M 7–13** (half to 11); Women = M+1.5 at launch (true women's last is v2). Grade 8.46 mm/full size (half sizes ~4.2 mm); **stack, drop, wheel OD do NOT grade** (constant ride height). **Chassis banding** (the tooling reality): 3 chassis lengths — A 7–8.5 / B 9–10.5 / C 11–13 (wheelbase ~185/200/215 mm); battery/motors/wheels/PCB are **one SKU** across all sizes. Two honest edges: size 7 arch bay → ~30 Wh ceiling (less range — disclose on box); size 13 → riders toward 110 kg (re-run thermal/brake/range; possible mass-derate). Size-13 realistic build ~8–12% over the size-8.5 weight budget.

### 14.6 Brand-mark usage
The **lit lateral line is the de-facto logo** (ownable, reads in motion, photographs at night); the wordmark supports it. Permitted marks only: heel counter (deboss/306 C, 18–22 mm), closure dial, footbed, chassis laser-etch by the service hatch (with serial + regulatory marks), dock top. **Never on the lateral knit** — the light line owns that side. Clear space = one cap-height; min 8 mm wide.

## 15. Manufacturing, Tooling & Cost (DFM)

### 15.1 Honest cost picture — EVT one-off vs 1,000-unit run (per SHOE, USD, budgetary — not a quote)
| Subsystem | EVT one-off (hand-built) | 1k-unit run |
|---|---|---|
| 4× hub-motor wheels + bearings | $160–480 | $48–100 |
| Motor drive / ESC (4 ch) | $120–240 | $12–24 |
| Battery 30–60 Wh + BMS + UN38.3 | $150–400 | $20–45 |
| Main flex-rigid PCBA + sensors + RX coil | $300–700 | $22–45 |
| Deploy struts + locks + actuators | $250–600 | $20–45 |
| Carbon plate + chassis cage | $150–350 | $12–25 |
| Harvester (if not descoped) | $60–150 | $6–12 |
| Footwear: upper/foam/outsole/lasting | $75–200 | $14–28 |
| Wiring/gaskets/fasteners | $40–80 | $6–12 |
| Assembly + EOL test | ~20–40 h engineer time | $8–20 |
| **TOTAL per shoe** | **‰ˆ$1,300–3,200 + engineer time** | **‰ˆ$170–350** |
| **Per pair** | **‰ˆ$2,600–6,400** | **‰ˆ$340–700** |

Dock: proto $150–400; ~$18–35 at 1k. Excludes tooling (§15.2), certification (§13), NRE, freight/duty (§15.5).

**What it actually costs the CUSTOMER — and how it reaches a couple hundred dollars.** The table above is the *first 1,000-unit pilot* — the single most expensive quantity you will ever build. Unit cost falls hard with volume and a leaner v1. The realistic consumer price is **~$199–349 at scale**, not $1,500 (that number is only the tiny first batch) and not $50 sneaker money:

| Stage | Build cost /pair | Realistic retail /pair |
|---|---|---|
| First ~1,000 pilot (all features) | $340–700 | ~$599–999 early-adopter price |
| 10,000-unit run (mature v1) | $150–320 | **~$299–449** |
| 50,000+ (scaled, descoped v1 — §15.3) | $90–180 | **~$179–299** |

Two levers get it to a couple hundred: **(1) volume** — 1k is a tiny pilot; per-pair cost roughly halves by 10k and again toward 50k as tooling amortizes and part prices drop; **(2) a leaner v1** — the §15.3 descope (drop the kinetic harvester + wireless charging, use an off-the-shelf motor platform) cuts real BOM. Existing mass-produced electric hover-shoes hit ~$100–300 retail *precisely because* they are simple and made in the tens of thousands. SPEEDERS is a notch more complex (deploy mechanism + 4 motors), so it lands a little above them — **a couple hundred dollars at scale is realistic; a $999+ tag only exists for the very first batch, and you should not launch at that price.**

### 15.1a ⚠ READ THIS BEFORE THE COST TABLES — three different numbers people confuse

Every cost argument about this product comes from mixing up three completely different things. They are **not** the same number and differ by ~1000×:

| # | The number | Value | What it is |
|---|---|---|---|
| **1** | **Price a customer pays** | **$199–349 / pair** | What SPEEDERS sells for at scale. **This is "the price of the shoe."** |
| **2** | **Cost to build one pair** | **$340–700 / pair** at 1k ($170–350 per *shoe*), less at 10k+ | Factory cost of parts + labour for one pair |
| **3** | **One-time setup (tooling/dev)** | $10k–140k+ | The metal moulds and engineering to be *able* to make shoes at all. Paid **once**, then spread across every pair ever made — **it is NOT charged per shoe** |

**Worked example so #3 is unmistakable:** a $20,000 mould spread over 10,000 pairs adds **$2 per pair**. Over 50,000 pairs it adds **40¢**. Tooling looks scary as a lump sum and is nearly invisible per unit — that is the entire reason mass production makes things cheap.

**So: the shoe costs a couple hundred dollars. Always. The big numbers are business setup, not the price tag.**

### 15.1a-2 How to make the size-tooling cost nearly ZERO (do this)

The "$60k–140k for a size run" figure assumes **fully custom moulds for 6–8 sizes** — a scaled brand's problem, not a starting founder's. Three ways to avoid almost all of it:

1. **Use the factory's EXISTING lasts and sole moulds.** Every shoe factory already owns lasts in every standard size. Building on their standard last means **$0 last tooling** — you pay for your upper pattern and branding. This is how most small shoe brands launch, and it is the single biggest cost-avoidance move available.
2. **Launch ONE size first (US M8.5).** One size = one set of tooling. Prove demand, *then* grade into more sizes out of revenue. Extra sizes are a good problem paid for by sales, not by you upfront.
3. **Chassis banding (§14.5)** — one chassis covers several adjacent sizes, so the *electro-mechanical* tooling never multiplies by size even at full scale; only the foam/outsole/last do.

**Bottom line for a first product:** with an existing last, one launch size, and an adapted OEM platform, **size-related tooling can be ~$3k–15k, not $140k** — and the customer price stays **$199–349/pair** either way.

### 15.1b "What does it cost to actually manufacture the real thing?" — the total program

The §15.1 table is the **per-pair** cost. This table is the **whole program cost** — everything you'd pay to go from this document to real, sellable, certified shoes. Two routes, because they differ by ~10×:

**ROUTE A — Adapt an existing electric-footwear OEM platform (recommended)**
You license/adapt a factory's proven powered-shoe base (already tooled, already certified) and pay for your mould, firmware, and branding.

| Line item | Cost |
|---|---|
| Engineering + CAD adaptation | $8k–25k |
| Custom mould/tooling (upper, sole, chassis mods) | $8k–30k |
| Firmware + app development | $5k–20k |
| Certification (riding on their base cert) | $3k–10k |
| Samples + iterations (2–4 rounds) | $3k–8k |
| **First production order (1,000 pairs @ ~$340–700)** | **$340k–700k** |
| **PROGRAM TOTAL (dev only, before inventory)** | **≈ $27k–93k** |
| **With the first 1,000 pairs of inventory** | **≈ $370k–790k** |

**ROUTE B — Ground-up custom program (invent everything)**

| Line item | Cost |
|---|---|
| Phases 0–4 engineering (feasibility → certified prototype) | $150k–400k |
| Tooling, 12–16 tools, one size (§15.2) | $95k–210k |
| Certification: UL 2272 + UL 2271 + UN 38.3 + FCC/CE | $50k–150k |
| Size grading — **only if you tool custom moulds for 6–8 sizes.** Launch one size on the factory's existing last and this is ~$3k–15k (§15.1a-2) | $0–140k |
| **PROGRAM TOTAL (dev only)** | **≈ $355k–900k** |
| **With the first 1,000 pairs** | **≈ $700k–1.6M** |

**The number that actually matters to a founder:** you do **not** need the full program to start selling. The realistic minimum viable path is **Route A dev (~$27k–93k)** plus a **crowdfunded or pre-ordered first run** — customers' pre-orders fund the $340k–700k inventory, which is exactly how nearly every hardware startup finances its first production run. Your out-of-pocket is the dev cost, not the inventory.

**Smaller first order?** Possible but painful — below ~1,000 pairs the per-pair cost climbs steeply (§15.4 MOQ realities), so a 300-pair run might cost $500–900/pair instead of $340–700. Many hardware startups still do this deliberately to prove demand before committing to a big run.

### 15.2 Tooling plan (pilot, one size — US M8.5, L/R mirrored; China T1 ranges)
Chassis cage $25–45k · battery vault $10–20k · TPU/covers $8–15k · harvester plates $8–15k (·$0 if descoped) · midsole $6–15k/size · outsole $3–8k/size · knit program+lasts $3–6k · struts CNC-at-pilot ($0) → Mg die-cast/MIM at scale $15–35k · lock die $6–14k · load bridge $4–10k · PU wheels $1–3k · carbon plate $5–12k · dock (pair) $15–30k. **Pilot total (one size) ‰ˆ 12–16 tools, ~$95–210k** (consistent with the Phase 5 line). **Size-grading warning:** each added size = new last+midsole+outsole (+$10–25k/size); launch narrow (M7–M11 ‰ˆ +$60–140k) — do not tool 13 chassis, **band onto 3** (§14.5). **Do not cut steel on the struts or lock until DVT fatigue data freezes the geometry.**

### 15.3 EVT descope — build ONLY what retires risk
First prototype's job: prove deploy-lock reliability, lean-throttle safe-state, battery abuse survival, ride stability. Cut everything else:
| Cut at EVT | Saves | Risk |
|---|---|---|
| Kinetic harvester (whole) | ~60–110 g, $60–150/shoe, 2–4 wk dev | None — §3 already says it's a trickle; bench it in parallel |
| Wireless + dock → wired-only | dock program ~$10–30k, coil integration | None for ride validation |
| Deploy = recessed button (baseline) | flex-electrode tuning avoided | None — mechanical button is the design; simpler + safer than a tap |
| Court knit upper → modified donor shoe | sample-room dev $10–25k | Ugly proto; EVT isn't a styling gate |
| IP67 → dry-lab only at EVT | gasket/pot cycles | Return at DVT; battery stays enclosed |
| Custom FOC ESC → off-shelf boards | a board spin | Bulkier; fine for rig |
| **NEVER cut** | deploy struts + over-center lock, battery vault + load bridge, IMU safe-state firmware, governor, dual-shoe BLE | These ARE the risk |

### 15.4 The two-factory reality + assembly time
**No single factory builds this** — footwear lasting and electronics assembly are different plants. Architect the chassis (plate/cage/struts/wheels/PCBA/coil) as a sealed, EOL-tested **"engine module"** from an **EMS**, shipped to the **footwear factory** which does only foam/lasting/upper/outsole/covers. **Battery installs AFTER lasting** through the §8.2 hatch (cement ovens + Li-poly must never meet). Pilot touch time: EMS module 25–45 min + EOL test 10–15 min; footwear 20–40 min; final pack-install + paired test 8–12 min → **~60–110 min/shoe pilot, target <45 min at scale** (the $8–20/shoe labor line). If it can't get under ~2 h/shoe at pilot, unit economics fail — track it from EVT.

### 15.5 MOQ realities, single-supplier risks & duty
**MOQs converge at ~1,000 pairs** (footwear style 300–1,000; UN38.3'd custom pack 1,000–3,000; custom-wound motors 500–1,000; PEBA midsole ~1,000; Qi coil 1,000–5,000). Below that = expensive no-man's-land: run EVT/DVT in **sample quantities (5–50 pairs)** and jump straight to ~1k at PVT — do not ask factories for 200. **Single-source traps to plan around now:** custom hub motors (own the drawings, 2nd-source at DVT), PEBA foam (spec EVA fallback), UN38.3 pack (own pack drawings), BOA (design a no-tool lace alternate), harvest PMIC (dual-footprint or descope), lock-pin heat-treat (100% inspect + 2nd house). **Customs:** a powered shoe straddles HTS Ch.64 (footwear, up to ~20%+ before China 301 tariffs) vs lower mobility/sporting headings — the classification genuinely moves landed cost/MSRP by double-digit % → **get a binding CBP ruling before pricing**, and note footwear lines exist in Vietnam/Indonesia, not only China.

## Appendix A — Footwear tech-pack deliverables (owed by Phase 0)
This is an engineering brief; a footwear factory also expects a tech pack. Phase 0 produces the missing rows:
| Deliverable | Status here |
|---|---|
| Last spec (last ID, girths, toe spring, heel pitch) | Partial (§1.5 envelope, no last geometry) |
| Pattern-piece list (pieces, knit gauge, seams/welds) | Missing |
| Construction spec (**board-lasted over the chassis** — Strobel can't carry it; bonding, lasting margins) | Missing |
| Tolerance table (± on stacks, flush faces, door gaps) | Only the ±0.5 mm door rule |
| Sample plan (size, proto rounds, size-run samples) | Implied by Phases 0–5 |
| Packaging spec (box + insert for a 2–3 kg pair + dock, UN38.3 transport labels, IFU) | Missing |
| Care/service leaflet (cleaning knit over IP67 electronics, storage SoC, pack-swap) | Missing |

---

### Closing statement
SPEEDERS is an ambitious but **internally consistent** concept: the propulsion, controls, power, and deploy mechanism are all buildable today with skilled engineering and a serious safety program. The three things that must stay honest are **(1)** the kinetic harvester is a *trickle for electronics and a marginal range-extender, not a walk-to-recharge engine* — **you charge it wirelessly on a dock (~3–5 h)**, walking does not recharge the drive battery; **(2)** the weight†”range†”safety triangle forces a **heavy shoe (~0.9–1.4 kg, ski-boot class)** with bounded range (~6–12 km) and a low speed cap — by design, and it is a "wear it for the ride" product, not an all-day sneaker; **(3)** the styling is a clean performance court shoe, not a chunky casual one. Build it around those truths and it's a credible product to hand a manufacturer; build it around the over-promises and it isn't.

**This remains a concept design brief, not certified engineering drawings.** Every number here is a validated-by-prototype target, and nothing should be tooled or sold to the public without the EVT/DVT/PVT cycle, full safety testing, and regulatory sign-off described above.

*— End of brief, SPEEDERS v0.1 —*
