Improving Satellite Resource Utilization: Single-Service Siloes to Interoperable Infrastructure
Key Takeaways
- The scaling constraint in space is no longer the rocket. It's the spacecraft.
- Purpose-built design converts every new requirement into a new satellite, which compounds congestion, spectrum contention, and debris risk.
- Unused power, downlink time, and processing capacity are widespread across the operational fleet, and none of it can be reallocated once a spacecraft is in orbit.
- Hosting third-party payloads has been attempted for over a decade, and the barrier has consistently been trust and mission assurance rather than mass or power.
- Compute is the first orbital resource that can be sold to a second tenant, which is what makes secure multi-tenancy commercially meaningful now.
- Attested isolation turns sovereignty from a reason to build another satellite into a requirement that shared infrastructure can satisfy.
The Constraint in Space Is No Longer the Rocket. It's The Spacecraft.
Access to orbit is now abundant in aggregate and scarce in practice. SpaceX's Transporter program entered service in 2019 at an approximately $5,000/kg entry price. By the 2026 Transporter missions, the published sun-synchronous rate stood at $350,000 for 50 kg, or roughly $7,000/kg. Starburst's portfolio analysis found that median rideshare prices rose 14% for smallsats and 18% for cubesats between 2022 and 2026, and that SpaceX raised its smallsat rate by approximately $2,000/kg over five years despite reusability lowering its own costs. Arianespace has described Ariane 6 as booked through 2027 with limited 2028 availability, and SpaceX has described its own manifest as packed through 2028. SpaceNews frames the result plainly as a bottleneck to space access for smallsat operators.

The response to that pressure has been to launch more spacecraft rather than more capable ones. BryceTech counted nearly 2,800 smallsats launched in 2024, representing 97% of all spacecraft launched that year. Because a satellite built around one sensor for one owner can't be repurposed in orbit, every additional requirement becomes an additional spacecraft.
That has a physical cost. Jonathan McDowell's tracking put active payloads at 16,019 as of June 2026, while ESA's Space Environment Statistics listed roughly 14,200 functioning satellites in January 2026. The two figures use different definitions of active, and both are worth citing together rather than choosing one. Peer-reviewed analysis found Starlink alone accounts for 52% of all mass in low Earth orbit. SpaceX has reported an approximately 200% increase in collision avoidance events and is lowering thousands of satellites from 550 km to 480 km through 2026.
Single-purpose design is the mechanism by which commercial demand for space translates directly into pressure on the orbital environment.
Purpose-Built Means Most of What We Launch Sits Idle
The hardware already in orbit is underused, and this pattern can be seen across different missions.
Nanosatellite throughput is constrained by ground station availability, with duty cycles often under 5% according to a 2025 study in Sensors. CubeSat optical payloads are thermally limited to a few minutes to half an hour of imaging per orbit. Communications payloads are sized for peak demand, which leaves available payload power unused during off-peak periods.
Unused power, downlink time, and processing capacity can't be reallocated once a spacecraft is in orbit, because a satellite already flying can't be given a new payload, a new processor, or a new hardware security anchor. In-orbit servicing extends operational life and repositions spacecraft rather than installing equipment, as demonstrated by Northrop Grumman's Mission Extension Vehicles, which provided five years of life extension to Intelsat 901 before undocking in April 2025.
On the small number of platforms already carrying general purpose processors, new software can be uploaded after launch, and we return below to what that does and does not solve. For the remainder of the fleet, the capacity a spacecraft can offer was determined before it left the pad.
The utilization figures therefore measure what single-purpose design has already cost rather than describing an opportunity to recover it, which puts the useful question on the spacecraft not yet built. The 2,800 smallsats launched in a single year also represent 2,800 opportunities to make a different design decision.
Shared Spacecraft Are Not a New Idea, and That Is the Problem
Hosting third-party payloads on someone else's satellite is an established practice, and the results point in both directions.
In cases where multi-tenant spacecrafts worked well, there were substantial cost savings. The CHIRP infrared sensor flown on SES-2 in 2011 saved the Air Force nearly $300 million against mounting the sensor on a dedicated satellite, and the REACH program placing 64 sensors across 32 Iridium NEXT satellites came in approximately $230 million below the cost of a dedicated constellation, according to a 2018 Government Accountability Office review of the Department of Defense's use of commercially hosted payloads. Iridium hosts 250 payloads across its constellations today.
What did not work was the structural setup. The US Air Force awarded its Hosted Payload Solutions contract vehicle to 14 companies in 2014. It expired in 2019 having produced effectively no orders, with budget constraints, misalignment between government and commercial timelines, orbital mismatch, and information assurance concerns all cited.L3Harris summarized the competing logic by noting that for roughly the price of a hosted payload, an operator can own the capability outright and retain control of it.
The commercial picture remains mixed. Loft Orbital raised $170 million in 2025 and operates a genuine payload-as-a-service business, yet its leadership said the shared condosat model is no longer central to the company, with the business shifting toward sovereign programs and dedicated constellations. D-Orbit derives roughly half its revenue from hosted payloads on its ION carriers. Payload-as-a-service is a working business for the companies that have committed to it, but it hasn't generalized beyond them.
Operators Decline to Share Spacecraft Because Isolation Can't Be Proven
The reasons operators decline to share spacecraft are rational and well documented.
The Aerospace Corporation's hosted payload integration guidance centers on a do no harm analysis, an interface failure mode analysis verifying that propagating failures in a hosted payload can't affect the host vehicle's primary mission. NATO's Joint Air Power Competence Centre notes that when bus and payload operators differ, the payload operator is beholden to the actions of the bus, and that co-development between commercial firms carries a high potential for technology exchange barriers. Research published in 2025 on supply chain attack surfaces found that hosted third-party components receive disproportionate trust and are effectively immutable once in orbit.
Export control friction, revenue share economics, competitive sensitivity between co-tenants, and the operational reality that no technician will ever visit the spacecraft all compound those concerns.
Every one of those objections describes the same missing capability. Isolation between tenants is assured today by contract, paperwork, and one-off engineering analysis conducted years before launch, none of which produce evidence at the point where it matters. A host can't demonstrate that a tenant workload is contained, and a tenant can't verify that its workload ran unmodified on hardware it does not own and will never inspect.
Compute Is the First Orbital Resource That Can Be Sold to a Second Tenant
An imaging sensor can only ever produce images, while a processor runs whatever workload fits its power and thermal envelope, which is what makes spare capacity saleable to another party.
That capability becoming more prevalent in orbit is why multi-tenancy is becoming commercially viable in the near-term future rather than a decade ago. Software-defined platforms established the principle in communications. Airbus OneSat and Thales Alenia Space Space Inspire are fully reconfigurable in orbit, and reprogrammability is now the requirement for manufacturers rather than a differentiator. Euroconsult's assessment is that reconfigurability mitigates market risk across a 15-year asset life and drives higher utilization rates.
General purpose compute extends that logic further, because a processor serves any workload that fits its envelope. Starcloud flew an NVIDIA H100 to orbit in November 2025 and ran model training in space. Google's Project Suncatcher is preparing TPU-equipped prototypes for early 2027. ADA Space and Zhejiang Lab launched the first 12 satellites of China's Three-Body Computing Constellation in May 2025, targeting 2,800 satellites. Those constellation and performance targets come largely from company statements and remain aspirational, and independent verification of on-orbit performance is limited.
Idle processing capacity on an orbiting platform has immediate resale value to a second tenant in a way that idle sensor time never did, which is the commercial reason secure multi-tenancy matters. It converts spare capacity into revenue on hardware that is already orbiting Earth.
How Shared Spacecraft Should Actually Be Secured
Two guarantees are required, and both have to produce evidence rather than assurances.
1. The host needs enforced isolation.
When a tenant workload runs on the spacecraft’s processor, it must be unable to reach the bus, the command path, or a co-tenant, and that containment has to hold without depending on the tenant's ‘good behaviour’ or on a review conducted years before launch.
2. The tenant needs proof of execution.
A workload owner who controls none of the spacecraft’s hardware needs cryptographic evidence (aka verifiable proof) of what code ran, that it ran unmodified, and where it ran.
Deploying software to a spacecraft after launch is already proven. ESA's OPS-SAT ran 284 experiments from 134 teams across 26 countries over four and a half years before the mission ended in May 2024, and Mission Control reprogrammed its FPGA in flight to run a modified neural network. The isolation model is what disqualifies it as a template for commercial multi-tenancy, because once an OPS-SAT experiment was running it could take over control of the entire satellite while the bus monitored and stood ready to take control back. That arrangement worked because ESA built a spacecraft it was prepared to lose and ran one experiment at a time, which is the opposite of what a commercial operator hosting paying tenants requires.
Terrestrial confidential computing supplies part of the answer and assumes conditions that orbit changes. Hardware trusted execution environments (TEEs) are designed against adversaries with physical access, and that defence has proven imperfect, with Plundervolt demonstrating that software-driven voltage fault injection can defeat Intel SGX memory integrity protection because the faults occur inside the processor package before results are committed to memory. Attestation over intermittent links introduces a second gap, since platform protections do not indicate which nodes remain trustworthy over time when connectivity is sporadic. A 13-month FPGA experiment on the ISS recorded numerous radiation-induced faults including a rare multi-core event, and we treat the relationship between single event upsets and enclave integrity as a reasoned engineering concern rather than a demonstrated attack, designing for it accordingly.
The governance framework is already in place, with NIST IR 8270 setting out cybersecurity risk management for commercial satellite operations and the Aerospace Corporation's SPARTA framework mapping space-specific adversary tactics against NIST controls. The 2022 Viasat KA-SAT compromise, where attackers reached a trusted management segment through a misconfigured VPN and issued destructive commands across Europe, established why the requirement is operational rather than theoretical.
How We're Building This
Space Fabric is our implementation of those two guarantees, integrated as a hardware payload before launch.
Orbit inverts the terrestrial threat model. Once a spacecraft is deployed, sustained physical access is beyond the reach of any adversary short of a state actor with rendezvous capability. We treat that inaccessibility as a first-class security primitive rather than an incidental property, which allows the architecture to concentrate on software isolation, cryptographic binding, and distributed verification.
Three mechanisms carry the design. All cryptographic signing keys are generated on orbit within co-located secure elements after launch, so no persistent signing secret exists on Earth at any point. The hardware trust anchor is distributed across two independent secure elements from separate vendors, one certified and closed, one fully open and auditable, both of which must co-sign attestation evidence. The Satellite Execution Assurance Protocol then binds a workload to a specific satellite through a Byzantine-tolerant endorsement quorum of distributed ground stations, certifying what workload executed and where it executed.
3/ We're releasing Space Fabric — a satellite-native trusted computing architecture that moves the entire trusted computing stack to orbit.
— frezabek (@rezabfil) May 5, 2026
The core insight: a satellite's post-launch physical inaccessibility is a security primitive no terrestrial data center can match.… pic.twitter.com/9FIVCeC5do
Secure multi-tenant edge computing is a named application of that architecture, in which multiple customers deploy proprietary workloads onto shared hardware, each assured that neither the operator nor a co-tenant can observe their code or data. The full technical treatment is available in the Space Fabric paper.
Sovereignty Is a Specification, Not a Reason to Build Another Satellite
Sovereignty is currently the strongest driver of new siloes, with the European Union's IRIS² constellation committing roughly €10.6 billion to approximately 290 satellites built and operated under European control, and comparable national programs underway across Asia, the Middle East, and Latin America. Concentration explains the motive, given that US operators accounted for 75% of all smallsats launched since 2015.
The academic case for decentralized satellite networks identifies the same driver, with Oh and Vasisht noting that the ability of a single operator to withdraw access arbitrarily during conflict has produced demands for independent constellations, and proposing that participants contribute a small number of satellites while offering spare capacity to the network when not using it themselves.
Sovereignty and sharing are only irreconcilable when trust has to be physical. Where data residency, workload isolation, and non-tampering can be proven cryptographically, a sovereign operator derives its guarantees from the attestation rather than from exclusive ownership of the spacecraft, which converts sovereignty from a reason to build another satellite into a specification that shared infrastructure can meet.
Interoperability Is What Makes Any of This Compose
Secure multi-tenancy on one satellite improves the utilization of one asset, while interoperability across satellites is what makes those assets compose into a system.
The Space Development Agency is running the largest live demonstration of multi-vendor interoperability at scale, with its Proliferated Warfighter Space Architecture mandating an Optical Communications Terminal standard and the NEBULA standard so that spacecraft built by different vendors operate as a single transport layer. More than 60 Tranche 1 satellites were on orbit as of mid-2026.
Standardized interfaces perform the same function commercially, where universal payload adapters and containerized software environments remove the per-mission integration engineering that made hosted payloads uneconomic in the first place. This is the orchestration layer we described in The 6 Layers of Space Internet Infrastructure, where interoperable software is what allows compute, communications, storage, and ground segment to operate as one system across multiple operators.
How many layers of the space internet tech stack do you think have emerged?
— SpaceComputer (@SpaceComputerIO) July 17, 2026
We see six.
Ground stations move data between Earth and orbit.
The comms layer carries it between satellites.
The computing layer processes it where it's generated. More compute is moving to space in… pic.twitter.com/J5TkRhRSWk
What Operators Can Do Now
Audit unused capacity across the existing fleet.
Quantifying unused power, ground contact availability, and processing duty cycle establishes what single-purpose design is costing across current assets, which is the analysis that justifies specifying differently on the next procurement.
Treat do no harm as an enforced property rather than a contractual one.
Isolation assured by hardware and attested software removes the integration cost and liability exposure that ended the first generation of hosted payload programs.
Standardize the payload and software interface.
Recurring integration engineering is the cost that determines whether shared capacity is economic at all, and eliminating it's a design decision made before the bus is built.
Make attestation a procurement requirement.
For any shared or sovereignty-sensitive workload, specify cryptographic proof of execution integrity and data residency rather than contractual assurance of it.
One scenario would weaken part of this case, in that Starship-class vehicles collapsing launch costs and decongesting manifests would soften the scarcity argument considerably. The utilization and sovereignty arguments survive that scenario intact, because unused capacity in orbit remains unused capacity and jurisdictional trust remains valuable at any launch price. Infrastructure designed for secure multi-tenancy holds its value in both futures.
Space is not short of demand for orbital services. It's short of usable capacity on the hardware already flying.
This article is brought to you by SpaceComputer, we're building the secure compute layer for the space internet.
If your team is working on hosted payloads, orbital compute, or sovereign workloads in space, we would like to hear from you. Reach us at product@spacecomputer.io.
Visit our website for more information.
Follow us on X (Twitter) and LinkedIn.
Read more about our trust architecture in our research paper Space Fabric here.
Ready for the next level of orbital compute? Read about cooling mechanisms for orbital data centers:

