Method. We model the architecture with fault tree analysis under IEC 61025. The top event is an undetected, unsupported assertion or fabricated diagnostic hypothesis reaching a released clinical case summary presented to a physician. The tree includes 23 independent barriers. We express the result per released case summary and treat each released summary as one demand.
Result. The figure we assert is a worst-case bound of 3.23 × 10−6 per released case summary. IEC 61508-1 associates SIL 4 in low-demand operation with a probability of failure on demand between 10−5 and 10−4. Our bound is 3.1 times lower than the most stringent edge of that range, 1 × 10−5. Where a 31-fold figure appears in our material, it is measured against the SIL-3 threshold of 1 × 10−4 and is stated as such.
Mode of operation. The software releases many case summaries in a day, so it does not operate in the low-demand mode that IEC 61508 defines. We therefore present SIL-4 as the class of our design target, derived by analogy per released case summary. We do not present it as conformity with the standard in its mode of operation.
Operating rate, and what the bound is in continuous operation. Our design case assumes up to two released case summaries per hour per physician seat. At the bound we assert, 3.23 × 10−6 per released summary, that is 6.46 × 10−6 per hour. For continuous and high-demand operation IEC 61508-1 uses a probability of dangerous failure per hour, and places SIL 1 between 10−6 and 10−5, SIL 2 between 10−7 and 10−6, SIL 3 between 10−8 and 10−7, and SIL 4 between 10−9 and 10−8. Expressed per hour at our design rate, the bound therefore falls in the SIL 1 band. Reaching the SIL 4 band per hour at the same per-summary bound would require fewer than one released summary in roughly three hundred hours, which is not how this software is used. We state this here rather than leave it to be derived: the SIL-4-class figure on this page is a per-demand statement measured against the low-demand band, and we make no SIL 4 claim in continuous or high-demand operation.
What this is, and what it is not. This is the Company's own engineering analysis of its own architecture. No accredited third party has certified it, and no independent functional safety assessment has been performed. A SIL level under IEC 61508 is assigned to a safety function through an assessment process that we have not undergone, which is why we describe the result as a SIL-4-class target rather than as a SIL 4 rating. The figure describes unsupported statements in the architecture. It is not a measure of diagnostic accuracy, and it is not a result for any individual product.
Scope, sensitivity and version. The analysis applies to one frozen software release, identified in the source monograph, and is re-run when the architecture changes. Under nominal operating conditions the model gives 1.69 × 10−7 per released summary; that nominal estimate is not used for safety claims, and only the worst-case bound is asserted. The bound moves with the common-cause factor: 2.24 × 10−6 at beta = 1.000, 3.23 × 10−6 at beta = 1.442, 4.48 × 10−6 at beta = 2.000, and 6.72 × 10−6 at beta = 3.000. Source: WP-001, sections 4.2, 5, 6 and 8. Analysis published 30 July 2026; the calculations were re-computed and verified internally on 27 July 2026. Full fault tree analysis: doi.org/10.5281/zenodo.21725747
Bands: IEC 61508-1:2010, Table 2 (low-demand mode, average probability of failure on demand) and Table 3 (high-demand or continuous mode, probability of dangerous failure per hour).
Version history
- Version 1.0, 28 September 2026: First publication.
