{"schema_version":"1","site":"https://decosa.ai","id":"incident-notification-pack","num":"56","name":"Incident notification pack","tool_name":"Draft breach notices and deadlines","short":"Incident notices","blurb":"For the CISO and general counsel during a cyber incident. From the team's incident log it builds a signed, hash-chained timeline and a deadline clock per report (SEC 8-K Item 1.05, NIS2, DORA, the Cyber Resilience Act, California), computed in code from the entries you tag. It drafts each notice or checks yours sentence by sentence against the log entries it cites: times and counts in code, other facts by a grounding judge. It lists the required elements each notice lacks and the facts two notices state differently. Counsel decides and files.","status":"live","labels":{"industry":["compliance-trust","software"],"job":["draft","review"],"input":["text"],"deploy":["selfhost"],"status":"live","output":["text","record"],"data":["confidential"],"hardware":"gpu-96","licence":"permissive"},"industries":["compliance-trust","software"],"runs_in":["selfhost"],"part_of":[],"built_from":["signed-record","grounding","numeric-grounding"],"models":"Qwen3.8-27B drafts, reviews and judges; the clocks, times and numbers are plain code","where":"Self-host for real incidents (privileged, possibly material non-public); the hosted demo takes synthetic incidents only","hardware":"1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for Qwen3.8-27B; the clocks, the time and number checks and the record run on CPU","final_artifact":"A Markdown pack with the clocks, the cited notices and every check, a clean copy of each notice without held sentences, a signed JSON report, the sealed timeline record, and counsel's signed sign-off.","self_host_first":true,"verification":{"receipt_coverage":"full","summary":"Receipt per model call; every time and number checked in code against the cited entries; hash-chained timeline; signed pack and a signed counsel sign-off","manual_qa":{"hosted":{"date":"2026-09-26","result":"pass","p50_ms":23320,"p95_ms":null,"runs":null,"receipts_per_run":16,"cost_per_run_usd":0.006},"selfhost":{"date":"2026-09-26","result":"pass","method":"fresh clone, compose up, sample against local model servers","notes":"A fresh clone of a decosa-api pre-release build (not yet merged to main) into a clean directory, the api image built from docker/api/Dockerfile, compose api service with a named data volume, DECOSA_INCIDENT_SYNTHETIC_ONLY=0, direct route to the already-running local Qwen3.8-27B vLLM (network_mode host instead of starting a second model server). The ransomware sample without the synthetic flag: both planted sentences held, impact missing, 3 contradictions, the NIS2 early warning late, report and timeline record verified, a changed status failed, receipts attested, 3.8 s; the CRA sample with a drafted final report 4.4 s. Torn down after. Model-server startup itself not re-verified."},"known_limits":["Synthetic only on the hosted demo, and every number here comes from our own synthetic incidents.","Coverage says a traced sentence addresses an element, not that it says enough.","The contradiction check can read a later time as the detection time (seen in 2 of 4 clean held-out packs).","Member State bank holidays, national NIS2 formats and other US states are not modelled.","The clocks are only as right as the tags: the team marks when it became aware, classified or determined materiality."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Planted problems caught, held-out scenarios","value":"20 / 20","unit":null,"n":20,"split":"test","note":"Two scenarios run twice: wrong times, wrong counts, unsupported and contradicted claims, removed elements, stale figures, a late 8-K."},{"name":"Planted problems caught, dev scenarios","value":"28 / 28","unit":null,"n":28,"split":"dev","note":null},{"name":"Deadlines right, hand-labelled cases, first run","value":"35 / 44","unit":null,"n":44,"split":"test","note":"Labelled from the rules by a separate agent; the 9 misses were one bug, fixed, after which 44 / 44 (not independent)."},{"name":"Clean sentences held, held-out scenarios","value":"1 / 42","unit":null,"n":42,"split":"test","note":"3 of 42 flagged as partly supported."},{"name":"False contradictions on clean held-out packs","value":"2 / 4","unit":null,"n":4,"split":"test","note":"One pattern: a later time read as the detection time."},{"name":"Model-drafted sentences held (real errors caught)","value":"2 / 108","unit":null,"n":108,"split":"synthetic","note":"Both were times copied from the wrong entry; 9 flagged; 28 / 28 required elements given."}],"dataset":"Five synthetic incidents written by the building agent (ransomware at a SaaS vendor, a public bucket at a DORA payment institution, an exploited router vulnerability under the CRA; held out: a DDoS on a DNS provider and email compromise at a billing company), each run clean and with planted problems, twice; plus 44 deadline cases hand-labelled by a separate agent.","held_out":true,"caveats":["Everything is synthetic, written by the same agent that wrote the checker and the prompts; small n (5 scenarios).","Plants are single clear errors; legal adequacy and subtle understatement are not measured.","The deadline set was used to find and fix a bug, so 44 / 44 after the fix is not held out.","The judge varies run to run: the same clean sentence was traced in one run and flagged or held in another.","Hand labels are by an AI agent from the rules text, not by counsel."],"date":"2026-09-26","doc_url":"https://decosa.ai/metrics/evals/incident-notification-pack"},"stack":{"summary":"For a CISO and general counsel during a cyber incident. Send the incident log (tickets, chat, alerts, notes), each line with its time, source and tags for the moments that start the clocks. You get a hash-chained timeline, each regime's deadlines computed in code (SEC Form 8-K Item 1.05, NIS2, DORA, the Cyber Resilience Act, California), and each notice drafted by Qwen3.8-27B or checked as you wrote it. Every sentence must cite log entries; its times, counts and dates are checked in code and its other facts by a grounding judge that sees only what it cites. The pack lists the required elements a notice lacks, the facts two notices state differently and any missed deadline, and is signed; counsel signs off on the exact version. A drafting and checking aid: counsel decides and files.","tagline":"A signed incident timeline, a deadline clock per regime, and every sentence of each notice checked against the log.","deployment":"self-host-first","regulatory_note":"Checked 26 Sep 2026 against primary sources (links under Tools). SEC Form 8-K Item 1.05: file within four business days after determining the incident is material (General Instruction B.1; Release 33-11216; compliance from 18 Dec 2023, smaller reporting companies 15 Jun 2024); an undetermined incident may go under Item 8.01 (SEC Corp Fin statement, 21 May 2024); we show 17:30 Eastern because later EDGAR submissions are dated the next business day (17 CFR 232.13). NIS2 Art. 23: early warning within 24 hours of becoming aware, notification within 72 hours, final report one month after the notification (national law applies; amendments proposed 20 Jan 2026, COM(2026) 13, not adopted). DORA Art. 19 and Delegated Regulation (EU) 2025/301 Art. 5: initial notification within 4 hours of classification as major and no later than 24 hours from awareness, intermediate within 72 hours, final within one month; weekend relief to noon of the next working day except for some entity types (Member State bank holidays are not modelled). Cyber Resilience Act Art. 14 (applies from 11 Sep 2026, Art. 71(2)): actively exploited vulnerabilities and severe incidents, early warning 24 hours, notification 72 hours, final report 14 days after a fix (vulnerabilities) or one month (incidents), through ENISA's single reporting platform. California Civ. Code 1798.82 as amended by SB 446 (from 1 Jan 2026): notice within 30 calendar days of discovery, required headings and contents, AG sample within 15 days if more than 500 residents. Unverified: national NIS2 rules, whether CRA format acts were adopted, whether Regulation 1182/71 extends EU day and month periods (shown as an extended date, weekends only). Whether a regime applies, and whether an incident is material, significant, major or severe, is counsel's call; the clocks only run from the entries the team tagged. Not legal advice and never a compliance determination. Model licence: Apache-2.0 (Qwen3.8-27B).","components":[{"id":"pack","role":"Timeline, hash chain, deadline clocks, citation, time and number checks, element coverage, cross-notice consistency, signed pack and sign-off (no model; CPU)","name":"decosa-api incident pack (decosa_api/verticals/incident) with the numeric block (decosa_api/verticals/numeric), the dates module (decosa_api/verticals/claims/dates.py) and the grounding module (decosa_api/verticals/grounding)","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12; zone-aware times; US business days with federal holidays; EU hour, day and month periods; rule-based extraction of clock times, hour spans, counts, amounts and dates","receipt_coverage":"partial","in_hosted_demo":null,"tiers":["lite","standard"],"alternative_to":null},{"id":"model","role":"Notice drafting, the grounding judge, and the review call (element coverage and quoted facts)","name":"Qwen3.8-27B (NVFP4)","hf_repo":"nvidia/Qwen3.8-27B-NVFP4","license":"Apache-2.0","params":"27.8B","quant":"NVFP4 (MLP NVFP4, GDN/attention FP8) + FP8 KV cache; MTP head, 3 draft tokens","vram_gb":20,"memory_gb_estimate":null,"engine":"vLLM 0.29.0, temperature 0, thinking off, prefix caching","receipt_coverage":"strong","in_hosted_demo":true,"tiers":["standard"],"alternative_to":null}],"tiers":[{"id":"lite","label":"Lite · clocks and timeline, no GPU","summary":"POST /incident/clock: the timeline, log issues and every regime's deadline from the tagged entries. No drafting and no sentence checks.","components":["pack"],"hardware":"Any CPU","quality_evidence":[{"metric":"Deadlines right, 44 hand-labelled cases (SEC, NIS2, DORA, CRA, California)","value":"44 / 44 after one bug fix; 35 / 44 first run","source":"docs/evals/incident-notification-pack.md, part 1, 26 Sep 2026"}],"latency_note":"no model call; milliseconds on CPU (not separately timed)","in_hosted_demo":true,"receipt_coverage":"none","receipt_note":"No model call, so no receipts; the clocks are deterministic code. The timeline record is signed by the instance key.","hosting":null},{"id":"standard","label":"Standard · one GPU for the model (hosted demo)","summary":"Qwen3.8-27B drafts notices, judges each sentence against what it cites, and maps required elements; clocks, times, numbers and contradictions are code. This is what the hosted demo runs, on synthetic incidents only.","components":["pack","model"],"hardware":"1x RTX PRO 6000 96 GB (measured) or 1x RTX 5090 32 GB (estimate)","quality_evidence":[{"metric":"Planted problems caught in supplied notices (2 repeats)","value":"28 / 28 dev; 20 / 20 held-out test","source":"docs/evals/incident-notification-pack.md, parts 2-6"},{"metric":"Unsupported or contradicted claims held","value":"10 / 10","source":"docs/evals/incident-notification-pack.md, parts 2-6"},{"metric":"Clean sentences held / flagged","value":"1 / 102 held; 14 / 102 flagged","source":"docs/evals/incident-notification-pack.md, part 7"},{"metric":"False contradictions on clean packs","value":"0 of 6 dev packs; 2 of 4 test packs (one pattern)","source":"docs/evals/incident-notification-pack.md, part 7"},{"metric":"Model-drafted sentences traced / flagged / held (5 scenarios)","value":"97 / 9 / 2 (both held were real errors)","source":"docs/evals/incident-notification-pack.md, part 8"}],"latency_note":"measured: under a minute per sample through the shared gateway; seconds self-hosted on the direct route","in_hosted_demo":true,"receipt_coverage":"strong","receipt_note":"Every model call has a gateway-signed receipt; the signed pack lists the receipt ids.","hosting":null}],"alternates":[],"services":[{"name":"decosa-api","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:<tag>","purpose":"GET /incident/info, /incident/samples; POST /incident/clock, /incident/pack (SSE or JSON), /incident/signoff, /incident/verify. Keeps no log text."},{"name":"vLLM (model)","port":8114,"image":"vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1","purpose":"Qwen3.8-27B NVFP4 behind our gateway (hosted) or called directly (self-host)."}],"tools":[{"name":"SEC Form 8-K (General Instruction B.1, Item 1.05)","url":"https://www.sec.gov/files/form8-k.pdf","license":"US government work (public domain)","purpose":"The four-business-day clock and the required contents (nature, scope, timing, impact)."},{"name":"SEC Release 33-11216 (26 Jul 2023)","url":"https://www.sec.gov/files/rules/final/2023/33-11216.pdf","license":"US government work (public domain)","purpose":"Adopting release; compliance dates."},{"name":"SEC Corp Fin statement on Items 1.05 and 8.01 (21 May 2024)","url":"https://www.sec.gov/newsroom/speeches-statements/gerding-cybersecurity-incidents-05212024","license":"US government work (public domain)","purpose":"Item 1.05 only for incidents determined material."},{"name":"17 CFR 232.13 (EDGAR filing dates)","url":"https://www.ecfr.gov/current/title-17/section-232.13","license":"US regulation (public domain)","purpose":"The 5:30 p.m. Eastern filing-date cutoff."},{"name":"Directive (EU) 2022/2555 (NIS2), Art. 23","url":"https://eur-lex.europa.eu/eli/dir/2022/2555/oj","license":"EU legislation (reuse permitted, Decision 2011/833/EU)","purpose":"24 h / 72 h / one month and the contents of each report."},{"name":"Regulation (EU) 2022/2554 (DORA) and Delegated Regulation (EU) 2025/301","url":"https://eur-lex.europa.eu/eli/reg_del/2025/301/oj","license":"EU legislation (reuse permitted)","purpose":"Time limits, weekend relief and report contents for major ICT-related incidents."},{"name":"Regulation (EU) 2024/2847 (Cyber Resilience Act), Art. 14 and 71","url":"https://eur-lex.europa.eu/eli/reg/2024/2847/oj","license":"EU legislation (reuse permitted)","purpose":"Manufacturer reporting from 11 Sep 2026: clocks and contents."},{"name":"California Civil Code 1798.82","url":"https://leginfo.legislature.ca.gov/faces/codes_displaySection.xhtml?lawCode=CIV&sectionNum=1798.82","license":"US state statute (public domain)","purpose":"30-day notice, headings and contents, AG sample."},{"name":"scripts/eval_incident.py, scripts/eval_incident_clock.py and docs/evals/incident-notification-pack.md","url":null,"license":"Apache-2.0","purpose":"The planted and clean packs, the 44 hand-labelled deadline cases, and every result file."},{"name":"POST /incident/clock, /incident/verify and /record/verify","url":null,"license":"Apache-2.0","purpose":"Clocks alone with no model call; verify a pack, its sign-off and the hash-chained timeline."}],"hardware":[{"tier":"1x RTX PRO 6000 Blackwell 96 GB","fits":true,"notes":"Measured on our server: the hosted demo, the eval and the self-host check ran on this card."},{"tier":"1x RTX 5090 32 GB","fits":true,"notes":"Estimate: Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache; not run for this tool."},{"tier":"CPU only","fits":true,"notes":"The lite tier (clocks and the timeline, POST /incident/clock) needs no GPU."}],"latency":[{"lane":"check two supplied notices (15 sentences), hosted gateway route","typical_ms":23320,"source":"measured on our server 2026-09-26: the ransomware sample streamed, gateway shared with other workloads; eval medians 11.8 s (dev) and 24.1 s (test)"},{"lane":"one drafted notice plus one supplied notice, hosted gateway route","typical_ms":32493,"source":"measured on our server 2026-09-26: the DORA sample streamed"},{"lane":"same, self-hosted on the direct route","typical_ms":3800,"source":"measured on our server 2026-09-26: fresh self-host sandbox, ransomware sample 3.8 s, CRA sample with a drafted report 4.4 s"},{"lane":"clocks only (POST /incident/clock)","typical_ms":null,"source":"no model call; milliseconds on CPU (not separately timed)"}],"benchmark":null,"notes":["All 48 problems planted into supplied notices were caught over two repeats: wrong clock times, wrong counts, claims the log contradicts or does not make, removed required elements, stale figures between notices, and late submissions (28/28 on the dev set, 20/20 on two held-out scenarios).","Deadlines: 44 of 44 hand-labelled cases after one bug fix; 35 of 44 on the first run (the 9 misses were one bug in reports that run from an earlier submission).","False alarms on clean packs: 1 of 102 sentences held, 14 flagged as partly supported, 0 required elements reported missing; the contradiction check read a later time as the detection time in one held-out scenario (2 of 4 clean test packs).","When the model drafted every notice (108 sentences) the checker held 2 sentences, both real errors (a time copied from the wrong entry); all 28 required elements were given.","Everything is synthetic and written by the agent that built the checker; not run on real incident logs.","Planned, not built: pull the log from Slack/Teams exports, tickets and EDR alerts, and fill national NIS2 portal formats and the DORA ITS template. This is connector work, not a bigger model, so it has no wanted tier."]},"buyer_facts":[{"label":"Data retention","value":"Nothing stored: the log lives in memory for the request. The signed pack holds hashes, ids, verdicts, clocks, receipt ids and the facts read from each notice (counts, yes/no fields, matched times and numbers), never the log or notice text itself; the timeline record goes back to you; logs carry counts only."},{"label":"What leaves the box","value":"Hosted: every model call goes through our gateway to the GPU serving Qwen3.8-27B, and only incidents marked synthetic are accepted. Self-hosted on the direct route: nothing leaves the box."},{"label":"What it will not do","value":"Decide whether a regime applies or whether an incident is material, significant, major or severe; file anything; or call a notice compliant. A clean result reads 'every sentence traced to the log (counsel review still required)'."},{"label":"Input formats","value":"Log lines 'time | source | text | #tag' or JSON entries, up to 300 entries and 150,000 characters; every time needs a zone. Up to 6 notices per pack, each up to 60 sentences with [E3, P.name] citations, or left blank to be drafted."},{"label":"Typical run","value":"The ransomware sample: a dozen or so model calls and a fraction of a cent at the gateway list price; a drafted DORA notice adds a few calls. Each run shows its own measured cost."}],"data_handling":{"page":"/data#incident-notification-pack","self_host":{"level":"confidential","leaves":"nothing","summary":"Runs on your machine; nothing is sent to Decosa or a third party by default."},"hosted":{"level":"operator-processed","demo_only":true,"summary":"Hosted demo on sample or public data only; self-host for real data.","gpus":"operator-contracted","third_parties":[],"retention":"Nothing stored: the log lives in memory for the request. The signed pack holds hashes, ids, verdicts, clocks, receipt ids and the facts read from each notice (counts, yes/no fields, matched times and numbers), never the log or notice text itself; the timeline record goes back to you; logs carry counts only.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[]},"console":{"href":"/tools/finance/incident-notification-pack","input":"incident","lanes":[{"id":"clocks","title":"Deadline clocks","kind":"list"},{"id":"timeline","title":"Hash-chained timeline","kind":"list"},{"id":"notices","title":"Notices, sentence by sentence","kind":"list"},{"id":"pack","title":"Contradictions, signed pack and sign-off","kind":"json"}],"samples":[{"n":1,"id":"ransomware-saas","title":"Ransomware saas","deep_link":"/tools/finance/incident-notification-pack?sample=1&autorun=0"},{"n":2,"id":"cloud-leak-dora","title":"Cloud leak dora","deep_link":"/tools/finance/incident-notification-pack?sample=2&autorun=0"},{"n":3,"id":"cra-exploited-vuln","title":"Cra exploited vuln","deep_link":"/tools/finance/incident-notification-pack?sample=3&autorun=0"},{"n":4,"id":"clean-pack","title":"Clean pack","deep_link":"/tools/finance/incident-notification-pack?sample=4&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/incident-notification-pack-hosted.md","selfhost":"/prompts/incident-notification-pack-selfhost.md","assemble":"/prompts/incident-notification-pack-assemble.md","mac":null},"rehearsal":{"bundle":"/samples/incident-notification-pack.zip","bundle_url":"https://decosa.ai/samples/incident-notification-pack.zip","folder":"/samples/incident-notification-pack/","expected":"/samples/incident-notification-pack/expected.json","files":["/samples/incident-notification-pack/expected.json","/samples/incident-notification-pack/inputs/entity.json","/samples/incident-notification-pack/inputs/incident.json","/samples/incident-notification-pack/inputs/log.json","/samples/incident-notification-pack/inputs/notices.json"],"bytes":4802,"checks":["the pack needs attention","the wrong detection time is held as a time mismatch","the held time names the logged one","the no-exfiltration claim is held","the 8-K lacks a sentence on the financial impact","the two notices give different host counts","the NIS2 early warning was late by 7 hours","the 8-K is due at 17:30 Eastern on the fourth business day","the signed report verifies","the report matches the log it was run on","the hash-chained timeline verifies","a report with its status changed no longer verifies","every model call has a signed receipt"],"licence":"Synthetic: Brightwater Payroll Cloud, its people, customers, IP addresses (RFC 5737 documentation ranges) and forensic firm are fictional (decosa_api/verticals/incident/synth.py). Part of decosa-api, AGPL-3.0-or-later.","about":"A synthetic incident log (VPN, EDR, chat, forensics, disclosure committee), the entity fields, and two supplied notices: a Form 8-K Item 1.05 draft and a NIS2 incident notification. Planted: the 8-K gives the detection time an hour late and a stale host count, and has no sentence on the financial impact; the NIS2 notification says no personal data was exfiltrated while the log records a 38 GB upload of HR exports; the NIS2 early warning went out 31 hours after awareness. The pack must hold both sentences, name the right time, list the missing element and the contradictions between the notices, show the early-warning clock as late, and the signed report and the hash-chained timeline must verify.","run":{"containers":"docker compose exec api python scripts/rehearse.py incident-notification-pack","checkout":"python scripts/rehearse.py incident-notification-pack --bundle incident-notification-pack.zip --base-url http://127.0.0.1:8445","mac":".venv/bin/python scripts/rehearse.py incident-notification-pack"},"guidance":"Set up with a coding agent (we recommend Claude Code with Claude Opus 5.5; any capable coding agent works) on mock data only, run the rehearsal until every check passes, then run your own data locally yourself. Never give the agent real data during setup."},"hardware_fit":{"check":"/self-host/hardware?use=incident-notification-pack","data":"/api/hardware.json","tiers":[{"id":"lite","gpu_gb":0,"basis":null,"unknown":[]},{"id":"standard","gpu_gb":57.6,"basis":"stack","unknown":[]}],"mac":null},"links":{"page":"/tools/finance/incident-notification-pack","json":"/use-cases/incident-notification-pack.json","metrics":"/metrics/incident-notification-pack","console":"/tools/finance/incident-notification-pack","console_sample":"/tools/finance/incident-notification-pack?sample=1&autorun=0","stack":"/tools/finance/incident-notification-pack#stack","try_live":"/tools/finance/incident-notification-pack","watch":"/tools/finance/incident-notification-pack","build":"/tools/finance/incident-notification-pack#build","self_host":"/tools/finance/incident-notification-pack#self-host","prompts":{"hosted":"/prompts/incident-notification-pack-hosted.md","selfhost":"/prompts/incident-notification-pack-selfhost.md","assemble":"/prompts/incident-notification-pack-assemble.md","mac":null}}}