Incident command, from the officer’s seat.
On-Scene runs a structural fire from the tablet in the appliance: the size-up, the 360, a live tactical map every crew at the incident can see, FIRECOM message drafts, the BA board, and a timeline nobody has to write up afterwards.

An Australian fireground, not a translated one.
Incident command software written somewhere else arrives with somebody else’s words in it. This one was written on an Australian fireground, in the language spoken on it.
Australian wording, throughout
Appliances, not apparatus. CODE 3. FIRECOM. The 360. Sides A, B, C and D taken off the address face. Nothing on the screen has to be mentally translated at two in the morning.
Australian data storage
Incident data is stored and processed in Sydney, in AWS’s ap-southeast-2 region, encrypted at rest and in transit. Australian incidents, on Australian ground, in an Australian data centre.
Built by a firefighter
On-Scene started as one serving firefighter’s tool for his own truck, built with an engineer he has known for years. Two people, and one of them takes it to work.
Everything the officer in charge is holding, on one screen.
Operated through a structural glove, in glare or in the dark, on a tablet bolted into a moving appliance. Every control on it is sized for that.
Live tactical map
Every appliance, every crew and every marker on one map, updating live for everyone looking at it. Positions are held in latitude and longitude, not in pixels, so the officer on the tablet and the duty officer in the station office are looking at the same ground.
Size-up and the 360
The incident form follows the job: Code 3 and arrival, the 360 underway, assuming command. Life risk, building stability, utilities and energy systems, exposures and special hazards, in the order a walk around a building takes them.
FIRECOM messages, drafted for you
The size-up you have already entered becomes a FIRECOM message ready to read. It is a draft: editable, reviewed by the officer sending it, and never transmitted by the app.
BA board
Who is wearing a set, what task they are on, their cylinder pressure and time. Low-air warnings, RIT allocation, and an alert every wearer acknowledges — so the board says who has heard it, not just who was told.
Resource board
One tablet per appliance, signed in as that appliance at commissioning. Nobody signs in at turnout. Status changes from the truck, crew sign-on in one tap, and a record of who attended that nobody had to write down afterwards.
Admin portal and the incident record
A web console for stations, appliances, members and the station roster, with a live read-only view of anything running now. When it is over, the whole incident exports as a report and a zip: the timeline, the map and the attachments, in a form that can be handed to somebody.
The size-up you already entered, as a message ready to read.
Nothing is typed twice. The worksheet the officer has been filling in on the way to the job becomes a FIRECOM message in the order it is transmitted — and it is a draft, not a transmission.
FireCOM, P243 on scene at 12 Jonson Street Byron Bay. We are CODE 3 and we have a large structural fire. Code 3 arrival. House, Two levels. Working fire yes, located Roof space. Persons reported: yes, 2 adults, last known first floor bedroom. Current strategy is Offensive. Exclusion zone Established. Additional resources requested: Additional pump, Ambulance. Over.
All FireCOM message drafts are editable and must be reviewed before use.
Structural fire today. The rest, said out loud.
Structural fire is live today. The rest of the fireground is in development — shown, not hidden, because you should know exactly what you are buying.
This record may be read by a coroner.
What a crew enters on a fireground — the address, who is reported inside, who holds command — can be read years later, by people who were not there. Security is not a hardening pass on this product; it is how it is built.
Default-deny, in the database
Every table is protected by row-level security. Unless a policy explicitly permits a row, it does not exist for that caller — so the application cannot ask a question that returns data it should not have.
Isolation proven, not asserted
Around 970 database-level assertions sign in as each kind of user — a truck at one station, a truck at another, an administrator at a different agency, a stranger — and check what each can actually read. If one stops holding, the build stops.
Nobody else is watching
No analytics, no crash reporting, no advertising SDK, no support widget — not in the tablet app, and not on this page. The only third party is the map provider, which sees the tiles a crew asks for and nothing else.
See On-Scene on your own fireground
A short walkthrough with the people who built it — the size-up, the 360, the tactical map and a handover, on your ground rather than a demo suburb.