A residual-risk assessment tool for heated shelters — wall tents, tipis, cabins, bunkhouses, pavilions. Eighteen heat sources, 312 risks, 990 controls. Works with no signal, because that is where the work happens.
Somebody has to decide whether it is acceptable to put a stove in that tent. Usually that decision gets made quickly, by the person on site, and recorded as a line in a logbook if it is recorded at all.
The Shelter Heating Risk Calculator turns that decision into an assessment you can hand to someone else. You describe the shelter and the appliance heating it. It scores the risks that actually apply, shows which controls your description already puts in place, and lets you select the rest. It reports the risk that remains after all of it — and produces a Word document you can file, send, or defend.
Assessors do this job at the end of a road, in a camp, on a site with one bar of signal and no data.
So the application makes no network requests. Not for licensing, not for updates, not for telemetry, not once. This is not a claim about intent — outbound requests are blocked inside the application itself, and an automated test fails the build if any code ever attempts one.
Everything you record lives in a single file on your own machine. Copy it, back it up, put it on a stick, hand it to a colleague. The application uploads nothing, because it has nowhere to send it.
It does not ask for permission to use the network — it asks for no permissions at all — so the promise is kept by the operating system rather than by our own care. When you have finished a capture it offers your device's usual sharing options, and if you choose to mail the file to yourself or put it in a cloud folder, that is your decision and the file goes to that service. The application hands it over; it does not send anything.
Eighteen heat sources, covering what people actually use:
Wood stoves, both a modern ULC-certified airtight and a non-certified 1970s unit, because the difference between them is most of the argument
Pellet stoves, and fireplaces both masonry and factory-built
Propane: vent-free radiant, catalytic flameless, outdoor direct-fired with ducting, outdoor indirect-fired
Diesel and kerosene: indoor direct-fired, vented drip, marine and air heaters
Outdoor hydronic with an indoor radiator
Ducted furnaces, natural gas and propane, with the failures a furnace has and a stove does not: a cracked heat exchanger putting carbon monoxide into the supply air and the blower distributing it to every room on the duct. The propane one adds what a stored fuel brings and a piped supply does not — odourant fade in a tank that has stood a season, vaporisation falling away as the tank chills, run-out with no delivery access
A ducted electric furnace, the one heating choice here with no combustion anywhere in it: no carbon monoxide, no venting, no combustion air. What is left is the electrical load and the total dependence on supply
Grid electric heat, and generator with electric heat
Traditional open central fire
Passive and stored-heat methods
312 risks across six categories: Fire and Thermal, Air Quality and Asphyxiation, Physical, Human Error, Regulatory and Insurance, and Cultural and Consequential.
That last category is there deliberately. A stove failure in a remote camp is not only a fire. It is the loss of the shelter, the evacuation, the insurer's next question, and in some settings the disruption of something that matters to the people using the building. Those consequences are part of the risk whether or not a checklist has a box for them.
990 controls, each classified by the hierarchy of controls — Eliminate, Substitute, Engineering, Detection, Administrative, PPE — so you can see at a glance whether a shelter is protected by engineering or by hoping people follow a rule. Solid-fuel installation clearances reference CSA B365.
Most shelters have several, and they interact. Two fuel-fired appliances raise the carbon monoxide load together. Two vented appliances compete for the same make-up air. Two solid-fuel appliances mean two flues on the same maintenance schedule, and the one nobody thinks about is the one that catches.
The application scores the combination, not only the appliance in front of you. And a heat source with no assessment on file is reported as a gap rather than quietly passed over — which is often the finding that matters most.
A shelter is recorded level by level and room by room: what each room is for, its size, its ceiling, how many beds are in it, how many windows open and how many are sealed shut, and how many doors lead out rather than further in.
Levels know where they sit. A basement is a basement, an attic with rooms is not the same as an attic without, and the ground floor is level zero with basements numbered below it — the way the people using the building number it. A heat source is then recorded in a room on a level, chosen from the rooms that level actually has.
And how each level is escaped from: a ground-level exit, an exterior stair, an interior stair, an escape window, a ladder. That is not decoration. A sleeping level whose only recorded way out is the interior stair depends on the route a fire below claims first, and the assessment says so and scores it. A sleeping level below grade with neither a ground-level exit nor an escape window is a finding the report names, because in most jurisdictions the escape window is a code requirement rather than a nicety.
Leaving the boxes clear is read as not recorded, never as no way out. An unknown is reported as an unknown and earns nothing either way.
Shelter Capture for Android is built but not yet published. It is not on Google Play yet, so nothing on this page related to the Shelter Capture is currently offered or available until the Shelter Capture has cleared the Play Store's closed-testing period.
Recording a building room by room is not desk work. Walking nine rooms across two levels, counting beds and doors, measuring the clearance behind a stove — that is done standing up, in the building, usually in the cold.
Shelter Capture is a companion application for a phone or tablet that records the shelter on site. The same form as the desktop: levels and rooms, construction, windows and doors and where each one leads, the appliance and its clearances. It writes a file. Back at a desk, the desktop application imports it and the assessment is made there.
It scores nothing and carries no risk register. That is deliberate — the register belongs where the assessment happens, and a device that scored independently would be a second answer to argue with.
It has no permission to use the network. Android grants network access as a permission, and this application does not request it — nor any other permission at all. That is not a statement of intent: the operating system will not let it open a network connection, whatever its code might ask for. On a phone, the guarantee stops resting on our own care and starts resting on the device.
When you have finished, it writes the file and then offers your device's usual sharing options — mail it to yourself, drop it in a cloud folder, copy it over a cable. The application hands the file over; it does not send anything. And the file is already saved before the sharing screen appears, so declining costs you nothing.
Best on a tablet. It works on a phone, and the form is long enough that a larger screen is worth having.
Propane is heavier than air and pools at the floor. Natural gas is lighter than air and collects at the ceiling. A combustible-gas detector mounted on the wrong plane will never see the leak it was bought for.
So the application records where yours is, and tells you when the position and the fuel disagree. It is the kind of finding that looks like a detail and is not one: the shelter has detection on the report, the insurer has detection on the file, and nobody has detection where the gas actually goes.
Properties hold shelters. Shelters hold heat sources. Each heat source carries its own assessment.
A property is a place in its own right — its type, its size, and its address recorded once and shared by every shelter on it, rather than typed again on each one and drifting.
So you can ask the questions you actually ask: what is at this camp, which shelter carries the worst residual risk, which appliances have never been assessed, and how this bunkhouse compares with that one.
Edit a shelter, or edit the risk data itself, and the application records a new version. Assessments already completed stay pinned to the version they were scored against, and keep their numbers.
They tell you they are behind. Re-assessing is your decision, made deliberately, not something that happens silently while you are looking somewhere else. An assessment signed off last spring still says what it said last spring.
Add and edit mitigations through a management panel. Extend the option lists behind the fields. Adjust the rating scale so the bands match the scheme your organisation already uses. Every edit is versioned like everything else.
Three Word documents: a per-appliance assessment, a shelter-wide report covering every heat source recorded, and a reviewer's advisory report.
Assessments export as a single file carrying everything needed to reproduce them — the shelter, the rating scale, and the exact version of the risk data they were scored against. A colleague imports it alongside their own work, and neither set of figures moves.
The application writes out a review request — save it as a file, or copy it straight to the clipboard. Take it to whichever assistant you use, paste the reply back, and it becomes part of the assessment and goes into the Word report.
There is no API key to buy, no account to create, no subscription, and nothing transmitted by the application. You choose the tool, or you use none — the assessment is complete either way.
This produces structured judgement for comparing sets of controls. It is not a site-specific measurement.
The heat-loss figures are order-of-magnitude planning numbers, calculated from nominal material R-values and assumed air-change rates. They are not a load calculation. Validate the result before relying on it for a regulatory or insurance decision.
It does not replace inspection by a qualified person, and it is not a certification of compliance with any code. What it does is make sure the question got asked, the reasoning got recorded, and the next person can see what was decided and why.
Camp and site managers. Health and safety advisors. Remote operations. Emergency and temporary accommodation. Outfitters and guides. Event and pavilion operators. Anyone signing off on a heated structure that is not a house.
Windows, from the Microsoft Store. Linux, as an AppImage or a .deb.
Version 0.1.0 is on the Microsoft Store; 0.2.0 is in certification. The Linux downloads are 0.2.0, published from the releases repository.
So the counts on this page — eighteen heat sources, 312 risks, 990 controls — match Linux today, and match Windows once 0.2.0 passes. Until then a Windows visitor downloads 0.1.0, which is 16 / 267 / 848.
Update this note when 0.2.0 goes live, and again if a later version changes the counts. The page has been published, so this is now a record of what is true rather than a hold on publishing it.
Shelter Capture for Android is built and not published. It is not on Google Play yet, so nothing on this page related to the Shelter Capture is currently offered or available until the Shelter Capture has cleared the Play Store's closed-testing period. The closed-testing period 'should' be complete around the 30th of September. If you would like to participate in the closed-test please contact the info_shelter_heating_risk_calculator@rann.ca
Sample data is included — two properties, six shelters and ten worked assessments — so the application is usable the moment it opens, without entering anything first.
Contact Info: info_shelter_heating_risk_calculator@rann.ca
SHELTER HEATING RISK CALCULATOR PRODUCT AVAILABLE AT:
Windows Version 0.1.0 is on the Microsoft Store
The Linux version is available on the GitHub repository.
SHELTER CAPTURE COMPANION PRODUCT AVAILABLE AT:
The Google Play Store once it has cleared the closed-testing.