{"schema_version":"1","site":"https://decosa.ai","id":"signed-lab-notebook","num":"44","name":"Signed lab notebook","tool_name":"Keep a signed lab notebook","short":"Lab notebook","blurb":"A tamper-evident lab notebook with an AI-analysis log. Entries hold text and instrument files by SHA-256, amendments point at the original and give a reason, and witnesses and approvers sign with their own keys. When a model analyses data, the prompt, the exact data files, the model and its signed receipt go on the record, so a reviewer sees which conclusions were AI-assisted. RFC 3161 timestamps from an independent authority, an audit-trail export and a verify page anyone can run.","status":"live","labels":{"industry":["science-research","compliance-trust"],"job":["attest","review"],"input":["text","files"],"deploy":["hosted","selfhost"],"status":"live","output":["record","data"],"data":["confidential"],"hardware":"gpu-96","licence":"permissive"},"industries":["science-research","compliance-trust"],"runs_in":["hosted","selfhost"],"part_of":[],"built_from":["signed-record"],"models":"Qwen3.8-27B (AI analyses)","where":"Hosted for synthetic or public data; self-host for unpublished results","hardware":"1× RTX PRO 6000 (96 GB) or 1× RTX 5090 (32 GB) for the analysis model; the notebook, signatures and verification run on CPU","final_artifact":"A signed notebook export (JSON) with an audit-trail CSV for an inspector, checkable in the browser, with RFC 3161 timestamps.","self_host_first":true,"verification":{"receipt_coverage":"full","summary":"Receipt per AI analysis; signed hash chain, personal e-signatures, RFC 3161 timestamps","manual_qa":{"hosted":{"date":"2026-09-26","result":"pass (pre-release server)","p50_ms":23700,"p95_ms":null,"runs":null,"receipts_per_run":1,"cost_per_run_usd":0.00105},"selfhost":{"date":"2026-09-26","result":"pass","method":"Fresh clone of the branch into a clean directory on our server, image built from docker/api/Dockerfile, api started with compose (named volume, python healthcheck), then the assemble prompt's smoke steps 1-9; torn down afterwards.","notes":"Ran against the already-running Qwen3.8-27B vLLM on 127.0.0.1:8114 instead of the compose llm service; model-server startup not re-verified. Analysis receipt attested, FreeTSA token in 159 ms, export verified, altered export rejected. Host networking and port 8438 because other services held the default ports."},"known_limits":["Hosted check ran on the pre-release server (decosa-api the pre-release branch on our server, gateway route): console flow with personal keys, own entry with a file, AI analysis, self-witness refused, timestamp rate limit, export, audit CSV, tamper buttons, verify page, Watch replay, Build example as written, 390 px layout. Production runs it once merged and deployed.","The server signs exports with its own key: an operator could rebuild a notebook that has only account signatures and no surviving TSA token. Personal keys and export copies kept by others catch that.","Signer identity is the name the key-holder sends unless the signer enrolled a personal key; no SSO or two-component sign-in (21 CFR 11.200) yet.","AI analyses are receipted, not graded; the number check only points at numbers not in the data.","FreeTSA is a free service with no SLA; TSA certificate revocation is not checked (the issuer is pinned).","POST /notebook/verify takes 8 MB by default; larger exports are checked in the browser (a 17 MB, 10,000-entry export took 4.7 s)."],"nightly_covers":null},"nightly":"https://api.decosa.ai/verify/status"},"eval_summary":{"metrics":[{"name":"Genuine synthetic exports that verify","value":"300 / 300","unit":null,"n":300,"split":"synthetic","note":"Median check 4.4 ms in Python."},{"name":"Outsider alterations caught (editing the export without keys)","value":"1,400 / 1,400","unit":null,"n":1400,"split":"synthetic","note":null},{"name":"Insider alterations caught, personal keys + TSA, export alone","value":"515 of 520","unit":null,"n":520,"split":"synthetic","note":"All caught when checked against an earlier export (1,400 / 1,400 across configurations)."},{"name":"Insider edits caught, account signatures + TSA, export alone","value":"29/200","unit":null,"n":200,"split":"synthetic","note":"Deletes 2/40, reorders 14/40, backdates 40/80, forged signatures 40/80."},{"name":"Real recorded export, insider alterations caught on the export alone","value":"10 of 12","unit":null,"n":12,"split":"synthetic","note":"All 12 outsider alterations caught."},{"name":"Python and TypeScript verifiers agree","value":"219 / 219","unit":null,"n":219,"split":"synthetic","note":null}],"dataset":"Synthetic notebooks from the vertical's test kit (entries, attachments by SHA-256, amendments, AI analyses with receipts, signatures, RFC 3161 tokens from an offline test TSA), attacked by an outsider and an insider holding the server key across 13 alterations in three configurations; plus one real recorded demo export with a FreeTSA token.","held_out":false,"caveats":["Synthetic notebooks only; no personal or real lab data.","No dev/test split: the verifier's rules were written first and not tuned to pass cases; only the attacker was changed after a run.","Against the operator, account signatures alone catch few changes: an insider can delete timestamp tokens that stop matching.","The quality of the AI analyses is not measured; the product records and receipts them, it does not grade them.","Real-world clock drift against the TSA and TSA certificate revocation are not measured."],"date":"2026-09-26","doc_url":"https://decosa.ai/metrics/evals/signed-lab-notebook"},"stack":{"summary":"Every entry, amendment and e-signature goes on an append-only hash chain. Instrument files are hashed in the browser, so only their SHA-256 is recorded; a correction is a new entry that points at the original and gives a reason. Witnesses and approvers sign one exact version with their own Ed25519 key, with a meaning (authored, witnessed, reviewed, approved). When a scientist asks the open model to analyse data, the exact prompt, the hash of every data file it saw (which must match a file already attached), the model and its signed receipt go on the record. RFC 3161 timestamps from an independent authority bound when each part existed. The export is a signed record plus an audit-trail CSV, and a verify page checks it in the inspector's browser. It is for academic labs, biotech and CROs that use AI on their data and need to show what it did; it is a signing and provenance layer with a small notebook, not a full ELN.","tagline":"A tamper-evident lab notebook that shows which conclusions an AI model helped with, and lets an inspector check it without trusting you.","deployment":"hosted-or-self-host","regulatory_note":"Checked 26 Sep 2026. 21 CFR Part 11 sets when FDA treats electronic records and signatures as equivalent to paper for records other FDA rules require (the predicate rules). The notebook supports the audit-trail requirement of 11.10(e) (secure, computer-generated, time-stamped records of who created or changed what, without obscuring earlier entries), the signature manifestation of 11.50 (printed name, date and time, and meaning) and the signature/record linking of 11.70. Compliance also needs the lab's validation, written procedures, training, access control and signature controls under 11.100 to 11.300 (for example two distinct identification components for non-biometric signatures); software alone does not make anyone compliant. FDA's guidance Part 11, Electronic Records; Electronic Signatures: Scope and Application (August 2003) narrowed enforcement (validation, audit trails, record retention and copying) while the predicate rules still apply; the final guidance Electronic Systems, Electronic Records, and Electronic Signatures in Clinical Investigations: Questions and Answers (October 2024, docket FDA-2017-D-1105) covers clinical investigations. The trusted timestamps follow RFC 3161; their weight depends on the Time-Stamp Authority (FreeTSA, the default, is free with no SLA; an eIDAS-qualified or commercial TSA can be configured). AI analyses are recorded and receipted, not validated: a person must still check them. Model licence: Apache-2.0 (Qwen3.8-27B). Not legal or regulatory advice.","components":[{"id":"notebook","role":"Notebook: hash chain, members, amendments, e-signature rules, RFC 3161 client, export, audit CSV and verification (no model; CPU)","name":"decosa-api notebook module (decosa_api/verticals/notebook)","hf_repo":null,"license":"AGPL-3.0-or-later","params":null,"quant":null,"vram_gb":0,"memory_gb_estimate":null,"engine":"Python 3.12, FastAPI; append-only JSONL; Ed25519 and ECDSA/RSA verification via cryptography; a small DER reader for RFC 3161 tokens","receipt_coverage":"partial","in_hosted_demo":null,"tiers":["lite","standard"],"alternative_to":null},{"id":"qwen","role":"Writes the AI analysis note from the selected entries and attached data files","name":"Qwen3.8-27B (NVFP4)","hf_repo":"nvidia/Qwen3.8-27B-NVFP4","license":"Apache-2.0","params":"27.8B","quant":"NVFP4 (MLP NVFP4, GDN/attention FP8) + FP8 KV cache; MTP head, 3 draft tokens","vram_gb":20,"memory_gb_estimate":null,"engine":"vLLM 0.29.0, temperature 0, thinking off, 700 tokens max; called through our gateway's metered route (hosted) or directly (self-host)","receipt_coverage":"strong","in_hosted_demo":true,"tiers":["standard"],"alternative_to":null}],"tiers":[{"id":"lite","label":"Lite · notebook, signatures and timestamps on CPU (self-host)","summary":"Everything except AI analyses: entries, amendments, personal e-signatures, RFC 3161 timestamps, the signed export and the verify page. Analyses you run elsewhere can be recorded as ordinary entries, without a receipt.","components":["notebook"],"hardware":"Any CPU","quality_evidence":[{"metric":"Genuine exports verified","value":"300 / 300","source":"docs/evals/signed-lab-notebook.md"},{"metric":"Alterations caught, file edited without keys (13 kinds in 5 groups, 3 configurations)","value":"1,400 / 1,400","source":"docs/evals/signed-lab-notebook.md"},{"metric":"Alterations caught, insider with the server key, personal keys + TSA","value":"515 / 520 on the export alone; 520 / 520 with an earlier export","source":"docs/evals/signed-lab-notebook.md"},{"metric":"Verify a 10,000-entry notebook (17,107 chain entries)","value":"2.6 s Python; 4.7 s browser code (Node)","source":"docs/evals/signed-lab-notebook.md"}],"latency_note":"measured: entries, signatures and exports take milliseconds; a timestamp adds one round trip to the TSA","in_hosted_demo":false,"receipt_coverage":"none","receipt_note":"No model call, so no receipts: the export is signed by your box, and personal keys and TSA tokens are the outside signatures.","hosting":null},{"id":"standard","label":"Standard · Qwen3.8-27B writes receipted AI analyses (hosted demo)","summary":"Adds the AI-analysis log: the model writes a note from the selected entries and attached data, with a signed receipt, the exact prompt and the data hashes on the record. This is what the hosted API runs.","components":["notebook","qwen"],"hardware":"1× RTX PRO 6000 96 GB (measured) or 1× RTX 5090 32 GB (estimate)","quality_evidence":[{"metric":"AI analyses with a signed receipt covering the stored output","value":"5 / 5 end-to-end runs (smoke, recorder, self-host, two console analyses)","source":"scripts/smoke/signed-lab-notebook.py; docs/evals/signed-lab-notebook.md"},{"metric":"Insider edit of an AI output with a gateway receipt (real export)","value":"caught: the gateway receipt covers a different output","source":"docs/evals/signed-lab-notebook.md"},{"metric":"Sample analysis: outlier named, numbers checked","value":"named well F7 in the run recorded; 7 of 13 numbers in the data, 4 rounded, 2 flagged (one run, not an accuracy measure)","source":"docs/evals/signed-lab-notebook.md"},{"metric":"Tamper detection and 10k performance","value":"as the lite tier (same code)","source":"docs/evals/signed-lab-notebook.md"}],"latency_note":"measured on a shared, busy GPU: one analysis in under half a minute; the rest of the notebook is milliseconds","in_hosted_demo":true,"receipt_coverage":"strong","receipt_note":"Each AI analysis carries a gateway-signed receipt embedded in the signed export.","hosting":null}],"alternates":[],"services":[{"name":"decosa-api (notebook routes)","port":8445,"image":"${DECOSA_REGISTRY}/decosa-api:<tag>","purpose":"POST /notebook/books, /members, /entries, /amend, /analysis (SSE or JSON), /sign, /timestamp; GET /notebook/books/<id>, /export, /audit.csv; POST /notebook/verify; GET /notebook/info, /notebook/samples."},{"name":"vLLM (AI analyses)","port":8114,"image":"vllm/vllm-openai@sha256:c2914767605584b6d8f45686b82de173ecc99e781897aa3d0a66dacd72c51ae1","purpose":"Qwen3.8-27B NVFP4 behind our gateway (hosted) or called directly (self-host). Not needed on the lite tier."}],"tools":[{"name":"FreeTSA (freetsa.org), RFC 3161 Time-Stamp Authority","url":"https://freetsa.org/index_en.php","license":"Free public service; no written terms of service or SLA","purpose":"Signs the chain head and Merkle root with an ECDSA P-384 certificate issued by the FreeTSA root, which is pinned in the API and the site (PEM sha256 2151b611…e044438, fetched 25 Sep 2026). Chosen as the cheapest honest outside anchor; DigiCert and Sectigo's public TSAs also answered, and any RFC 3161 TSA can be set with DECOSA_NOTEBOOK_TSA_URL."},{"name":"Verify page (/notebook/verify) and POST /notebook/verify","url":null,"license":"Apache-2.0","purpose":"Checks an export in the inspector's browser: hashes, links, the server signature, personal e-signatures, AI analyses against the data they cite and their receipts, and RFC 3161 tokens; optionally that a later export still contains an earlier one unchanged."},{"name":"GET /notebook/books/<id>/audit.csv","url":null,"license":"Apache-2.0","purpose":"Who, what, when and why for every chain entry, with hashes, for an inspector's spreadsheet."},{"name":"scripts/notebook_eval.py and docs/evals/signed-lab-notebook.md","url":null,"license":"Apache-2.0","purpose":"Genuine exports, 13 alterations by an outsider and by an insider holding the server key, and a 10,000-entry notebook (decosa-api)."}],"hardware":[{"tier":"Any CPU, no GPU","fits":true,"notes":"Lite tier: notebook, signatures, timestamps, export and verification. A 10,000-entry notebook verifies in 2.6 s on one core."},{"tier":"1× RTX 5090 32 GB","fits":true,"notes":"Qwen3.8-27B NVFP4 needs about 20 GB of weights plus KV cache. Estimate: same model stack as the other Qwen verticals, not run here for this one."},{"tier":"1× RTX PRO 6000 Blackwell 96 GB","fits":true,"notes":"Measured on our server: the hosted demo ran on this card, shared with other services."}],"latency":[{"lane":"AI analysis of the sample (about 1,080 prompt and 480 generated tokens), hosted gateway route","typical_ms":22200,"source":"measured on our server 2026-09-26: 22.2 s in the smoke run while the shared gateway was busy with other evaluation jobs"},{"lane":"RFC 3161 timestamp from FreeTSA, including verification","typical_ms":159,"source":"measured on our server 2026-09-26: 159 ms in the self-host run (one request)"},{"lane":"whole sample notebook: 2 members, 3 entries, 1 AI analysis, 3 signatures, 1 timestamp, export","typical_ms":23700,"source":"measured on our server 2026-09-26: 22.4 s (smoke) and 23.7 s (recorder), nearly all of it the model call"},{"lane":"verify a 10,000-entry export (17,107 chain entries, 17 MB)","typical_ms":4700,"source":"measured 2026-09-26: 2.6 s in Python on our server, 4.7 s for the site's browser code under Node 26 on a Mac"}],"benchmark":null,"notes":["All 300 genuine synthetic exports verified. Every alteration by someone editing the file without keys was caught (1,400 of 1,400: edits, deletions, reordering, backdating, forged signatures), naming the entry.","An insider holding the server key, who repairs every hash and re-signs, was caught on the export alone in 515 of 520 cases when signers used personal keys and TSA timestamps, and in 1,400 of 1,400 when compared with an earlier export a witness kept. With account signatures only, most such rewrites pass on their own: keep export copies.","Python and the browser verifier agree on 219 of 219 exports.","The number check lists numbers in an AI analysis that are not in its data (calculated, thresholds or wrong) for the reviewer; it does not grade the analysis.","What it cannot show: that the science is right, that a named person without a personal key really signed, or that the lab's procedures meet Part 11."]},"buyer_facts":[{"label":"What you send","value":"Entry text, file hashes (files are hashed in your browser), members and their public keys, signatures, and the data text for an AI analysis (up to 60,000 characters)."},{"label":"What you get","value":"A signed export (JSON) with every entry, amendment, AI analysis, e-signature and RFC 3161 token; an audit-trail CSV; a verify page an inspector runs in their browser."},{"label":"Typical cost","value":"One model call per AI analysis: a fraction of a cent at the gateway list price. Entries, signatures, timestamps and exports are CPU."},{"label":"Retention (hosted)","value":"Demo notebooks expire after 14 days. Self-host keeps notebooks as append-only files in your data volume for as long as you set."},{"label":"What leaves the box (self-host)","value":"Only the timestamp request: a 32-byte digest of the chain head, sent to the TSA. On the hosted route the entries and analysis data reach our server and the gateway."},{"label":"Part 11","value":"Supports the audit-trail, signature-manifestation and signature/record-linking requirements. Validation, SOPs, SSO and two-component sign-in are yours to provide."}],"data_handling":{"page":"/data#signed-lab-notebook","self_host":{"level":"confidential","leaves":"identifiers","summary":"Runs on your machine; by default only short identifiers or a digest go to the public services listed in external_calls."},"hosted":{"level":"operator-processed","demo_only":false,"summary":"TLS to Decosa's server, then decrypted and processed by Decosa's API server, with the open models run by NEAR AI through OpenRouter, with Reka AI as the only fallback under Decosa's account.","gpus":"operator-contracted","third_parties":[],"retention":"Demo notebooks expire after 14 days. Self-host keeps notebooks as append-only files in your data volume for as long as you set.","used_for_training":false,"encrypted_while_processed":false},"sealed_tier":{"applies":false,"note":"The sealed tier (raw chat only, never use-case pipelines) is paused at launch (/docs/sealed-tier)."},"external_calls":[{"to":"FreeTSA (freetsa.org), or the RFC 3161 time-stamp authority you set","route":"both","sends":"digest","what":"A 32-byte digest of the notebook's chain head, never the entries, to get a trusted timestamp.","default":"on","off":"Set DECOSA_NOTEBOOK_TSA_URL to your own time-stamp authority."}]},"console":{"href":"/tools/life-sciences/signed-lab-notebook","input":"notebook","lanes":[{"id":"entries","title":"Entries, amendments and files by hash","kind":"list"},{"id":"analysis","title":"AI analysis log","kind":"markdown"},{"id":"export","title":"Signatures, timestamp and signed export","kind":"json"}],"samples":[{"n":1,"id":"enzyme-kinetics","title":"Enzyme kinetics","deep_link":"/tools/life-sciences/signed-lab-notebook?sample=1&autorun=0"}],"deep_link_params":{"sample":"1-based index into samples, or a sample id","autorun":"1 = start the run once the sample is loaded; 0 (default) = only preselect","reduce-motion":"1 = turn off animations"}},"api":{"base":"https://api.decosa.ai","contract":"/api/contract.json","contract_markdown":"/api/contract.md","reference":"/docs/api","keys":"/account/keys"},"prompts":{"hosted":"/prompts/signed-lab-notebook-hosted.md","selfhost":"/prompts/signed-lab-notebook-selfhost.md","assemble":"/prompts/signed-lab-notebook-assemble.md","mac":"/prompts/signed-lab-notebook-mac.md"},"rehearsal":{"bundle":"/samples/signed-lab-notebook.zip","bundle_url":"https://decosa.ai/samples/signed-lab-notebook.zip","folder":"/samples/signed-lab-notebook/","expected":"/samples/signed-lab-notebook/expected.json","files":["/samples/signed-lab-notebook/expected.json","/samples/signed-lab-notebook/inputs/amendment-attachments.json","/samples/signed-lab-notebook/inputs/amendment-reason.txt","/samples/signed-lab-notebook/inputs/amendment.txt","/samples/signed-lab-notebook/inputs/analysis-question.txt","/samples/signed-lab-notebook/inputs/entry-1-protocol.json","/samples/signed-lab-notebook/inputs/entry-2-plate-run.json","/samples/signed-lab-notebook/inputs/member-1.json","/samples/signed-lab-notebook/inputs/member-2.json","/samples/signed-lab-notebook/inputs/notebook.json","/samples/signed-lab-notebook/inputs/rates-corrected.csv","/samples/signed-lab-notebook/inputs/rates.csv"],"bytes":6489,"checks":["the AI analysis flags the planted outlier well F7","the analysis records the SHA-256 of the rates file it read","the amendment points at the original run entry, which stays in the record","the exported record verifies","the record holds 1 amendment and 3 e-signatures","a copy with the amendment reason changed no longer verifies","every model call has a signed receipt"],"licence":"Synthetic: the lab, people, instrument and data are invented for Decosa; the rates come from a Michaelis-Menten curve (Vmax 118, Km 0.42 mM) with small noise and one deliberate outlier. Part of decosa-api, AGPL-3.0-or-later.","about":"A fictional lab records a protocol and a plate-reader run with its rates file attached by SHA-256, asks the model to analyse the data (receipted), amends the run to exclude the planted outlier well F7 with a reason, and collects witness, review and approval signatures and an RFC 3161 timestamp. The exported record must verify, and a copy with one entry changed must not. The timestamp comes from FreeTSA, a free third-party authority: if it is down that step is skipped and nothing checks it.","run":{"containers":"docker compose exec api python scripts/rehearse.py signed-lab-notebook","checkout":"python scripts/rehearse.py signed-lab-notebook --bundle signed-lab-notebook.zip --base-url http://127.0.0.1:8445","mac":".venv/bin/python scripts/rehearse.py signed-lab-notebook"},"guidance":"Set up with a coding agent (we recommend Claude Code with Claude Opus 5.5; any capable coding agent works) on mock data only, run the rehearsal until every check passes, then run your own data locally yourself. Never give the agent real data during setup."},"hardware_fit":{"check":"/self-host/hardware?use=signed-lab-notebook","data":"/api/hardware.json","tiers":[{"id":"lite","gpu_gb":0,"basis":null,"unknown":[]},{"id":"standard","gpu_gb":57.6,"basis":"stack","unknown":[]}],"mac":{"fit":"full","memory_gb":32}},"links":{"page":"/tools/life-sciences/signed-lab-notebook","json":"/use-cases/signed-lab-notebook.json","metrics":"/metrics/signed-lab-notebook","console":"/tools/life-sciences/signed-lab-notebook","console_sample":"/tools/life-sciences/signed-lab-notebook?sample=1&autorun=0","stack":"/tools/life-sciences/signed-lab-notebook#stack","try_live":"/tools/life-sciences/signed-lab-notebook","watch":"/tools/life-sciences/signed-lab-notebook","build":"/tools/life-sciences/signed-lab-notebook#build","self_host":"/tools/life-sciences/signed-lab-notebook#self-host","prompts":{"hosted":"/prompts/signed-lab-notebook-hosted.md","selfhost":"/prompts/signed-lab-notebook-selfhost.md","assemble":"/prompts/signed-lab-notebook-assemble.md","mac":"/prompts/signed-lab-notebook-mac.md"}}}