PHA — Tool Qualification Pack
IEC 61508-3 §7.4.4 evidence-first pack. Recomputed live from the pinned engine. Indicative / screening — formal tool-qualification duty sits with the end user.
WORK PROJECT NAME:
Customer's Logo
Customer's NAME
PHA QUANTITATIVE-ANALYSIS
TOOL QUALIFICATION PACK
DOCUMENT NO. :
REVISION :
BY
DEKENGINEER.COM
GB R&D
APPROVAL NOTE
ReviewedAccepted as qualification evidence
RESUBMIT FOR APPROVAL BY
Indicative / screening analyses only — not certification-grade. Competent-person review per IEC 61882 / IEC 61511 is required prior to issue; SIL/LOPA outputs must not be relied upon as a system of record for credited-IPL or SIS decisions without validated device FMEDA data and independent assessment.
DATE
OWNER NAME
| 0 | IFR | ||||
| REVISION | ISSUE DATE | PREPARED BY | CHECKED BY | APPROVED BY | REVISION STATUS |
DekEn Page 2 / 5 | PHA QUANTITATIVE-ANALYSIS — TOOL QUALIFICATION PACK IEC 61508-3 §7.4.4 (tool classes) · IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61025 · IEC 62502 · ISA-TR84.00.02 | Rev.0 | |
| TOOL IDENTIFICATION | |||
| Tool name | DekEn PHA Quantitative-Analysis Engine | ||
| Publisher | dekengineer.com | ||
Version source The release version is the git tag of the build; the live page reflects the running application build (the served bundle), so the printed pack tracks whatever version is deployed. No version is hard-coded into this evidence pack. | |||
Scope Offline support/analysis tool for low-demand SIFs: SIL verification (PFDavg + the IEC 61508-2 Route 1H architectural cap), fault-tree analysis and event-tree analysis. It computes and presents analysis results; it does not actuate or control any safety function. | |||
| CLASSIFICATION STATEMENT (IEC 61508-3 §7.4.4) | |||
Classification Self-classified as a T2-ANALOGOUS offline support/analysis tool per IEC 61508-3:2010 §7.4.4 (software tool classes T1 / T2 / T3; the ed.3 draft Annex H "TIC2" concept). A T2 tool supports verification/analysis and cannot directly introduce a fault into the safety function, but an undetected error in its output could fail to reveal one — hence this justification evidence. | |||
Honest caveat §7.4.4 literally scopes software tools used in the DEVELOPMENT of SIS software, and the formal tool-qualification duty sits with the END USER (the organisation deploying the tool in its safety lifecycle). This pack does NOT assert that the tool is qualified, certified or compliant — it supplies the evidence the end user needs to make that justification. | |||
Sources IEC 61508-3:2010 §7.4.4 (Tool support and programming languages — software tool classes T1/T2/T3); IEC 61508-3 ed.3 draft Annex H (tool-confidence concept, "TIC"). | |||
DekEn Page 3 / 5 | PHA QUANTITATIVE-ANALYSIS — TOOL QUALIFICATION PACK IEC 61508-3 §7.4.4 (tool classes) · IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61025 · IEC 62502 · ISA-TR84.00.02 | Rev.0 | |
| TOOL BEHAVIOUR SPECIFICATION | |||
PFDavg method IEC 61508-6 Annex B B.3.2.2 — SIL verification — PFDavg by voted architecture (1oo1/1oo2/1oo2D/2oo3). λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD; tCE/tGE are the channel/voted-group equivalent mean downtimes (IEC 61508-6 Annex B). | |||
1oo1 PFDavg = λ_DU·(TI/2 + MTTR) + λ_DD·MRT
• Low-demand mode; rare-event regime (λ·T1 ≪ 1) — the simplified-equation linearisation.
• Identical channels within a voted group; a single periodic proof test at interval TI.
• λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD.
• Single channel — no redundancy, so no common-cause (β) credit. | |||
1oo2 PFDavg = 2·λ′²·tCE·tGE + β·λ_DU·(TI/2 + MTTR) + β_D·λ_DD·MRT
• Low-demand mode; rare-event regime (λ·T1 ≪ 1) — the simplified-equation linearisation.
• Identical channels within a voted group; a single periodic proof test at interval TI.
• λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD.
• A common-cause event defeats the redundancy, so the β-floor terms are voting-independent. | |||
2oo2 PFDavg = 2·(λ_DU·(TI/2 + MTTR) + λ_DD·MRT) — two independent 1oo1 channels summed
• Low-demand mode; rare-event regime (λ·T1 ≪ 1) — the simplified-equation linearisation.
• Identical channels within a voted group; a single periodic proof test at interval TI.
• λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD.
• Both channels must function → a dangerous fault in EITHER defeats the group; no CCF credit (β does not help a system that needs both). | |||
1oo2D PFDavg = 2·λ′²·tCE·tGE + β·λ_DU·(TI/2 + MTTR) + β_D·λ_DD·MRT (Hokstad-corrected; coincides with 1oo2 at the same λ split)
• Low-demand mode; rare-event regime (λ·T1 ≪ 1) — the simplified-equation linearisation.
• Identical channels within a voted group; a single periodic proof test at interval TI.
• λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD.
• A lone DETECTED dangerous fault degrades the voted group to a working 1oo1 (repaired online within MRT) and does not by itself fail the function → no standalone (1−β_D)·λ_DD·MRT residual.
• HFT taken conservatively as 0 (HFT counting excludes diagnostics, IEC 61508-2 §7.4.4.1.1).
• Cross-checked against an independent numerical-integration + Markov reference; conservativeBound1oo2D gives a pessimistic upper envelope. | |||
2oo3 PFDavg = 6·λ′²·tCE·tGE + β·λ_DU·(TI/2 + MTTR) + β_D·λ_DD·MRT
• Low-demand mode; rare-event regime (λ·T1 ≪ 1) — the simplified-equation linearisation.
• Identical channels within a voted group; a single periodic proof test at interval TI.
• λ_DU = λ_D·(1−DC), λ_DD = λ_D·DC; λ′ = (1−β)·λ_DU + (1−β_D)·λ_DD.
• A common-cause event defeats the redundancy, so the β-floor terms are voting-independent. | |||
Architectural cap IEC 61508-2:2010 Route 1H (Tables 2 & 3): the achieved SIL is capped by the hardware architecture — achieved = min(PFDavg-band SIL, architectural-constraint SIL) over element Type A/B, Safe Failure Fraction and Hardware Fault Tolerance. | |||
Spurious-trip rate STR(KooN) from the safe failure rate λ_S — ISA-TR84.00.02 / IEC 61508-6 Annex B simplified forms (1oo1 = λ_S; 1oo2 = 2·λ_S; 2oo2/2oo3 CCF-dominated). MTTF_spurious = 1 / STR. | |||
Fault-tree analysis IEC 61025 — Fault Tree Analysis — top-event probability + minimal cut sets. AND = ∏pᵢ, OR = 1 − ∏(1 − pᵢ); minimal cut sets by Boolean expansion. | |||
Event-tree analysis IEC 62502 — Event Tree Analysis — outcome frequencies from pivotal events. f_IE × ∏ branch probabilities over 2ᵏ paths. | |||
| USE MODELS & CONSTRAINTS (VALIDITY DOMAIN) | |||
Rare-event regime (LIVE) The simplified IEC 61508-6 Annex B equations are first-order (rare-event, λ·T1 ≪ 1). At λ_D = 5e-5/h, TI = 8760 h (λ·T1 ≈ 0.44, 1oo1) the closed form gives PFDavg = 2.19e-1 versus the independent numerical integral 1.90e-1 — a divergence of ≈ 15%. Pushed further, at λ_D = 2.5e-4/h (λ·T1 ≈ 2.2) the closed form returns PFDavg = 1.10e+0 — which EXCEEDS 1 and is therefore unphysical. Inputs in this regime are out of scope and require competent-person review. | |||
Demand mode Low-demand mode only. High-demand / continuous-mode PFH is out of scope (deferred — see §8). | |||
ETA pivotals Event trees are limited to ≤ 12 pivotal events (2¹² outcome paths); independent branches assumed. | |||
Identical channels The voted-architecture PFDavg forms assume IDENTICAL channels within a group (IEC 61508-6 Annex B). Non-identical channels are out of scope (deferred — see §8). | |||
Failure-rate data Indicative typical rates (ISA-TR84 / OREDA / exida public ranges). Starting values only — replace with the device’s certified FMEDA / safety-manual data before any SIL claim. | |||
1oo2D modelling scope The 1oo2D closed form uses the documented degrade-to-1oo1 (Hokstad) modelling choice — a lone detected dangerous fault does not by itself fail the function, so there is no standalone (1−β_D)·λ_DD·MRT residual. The audited cross-check validates the linearisation UNDER this assumption, not the choice itself; `conservativeBound1oo2D` provides a deliberately pessimistic upper envelope (always ≥ the production form and the independent reference) for over-claim-proofing, and 1oo2D’s HFT is taken conservatively as 0. | |||
DekEn Page 4 / 5 | PHA QUANTITATIVE-ANALYSIS — TOOL QUALIFICATION PACK IEC 61508-3 §7.4.4 (tool classes) · IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61025 · IEC 62502 · ISA-TR84.00.02 | Rev.0 | |
| VALIDATION RECORDS SUMMARY | |||
Cross-check (LIVE) Eight representative cells recomputed live: the production closed form vs the INDEPENDENT reference (numerical Simpson integration of the real exponential channel unavailability — a different computational method, not the same algebra), with |Δ%|. | |||
| 1oo1 · DC 0% · β 0% · TI 8760h · MTTR 8h | prod 4.39e-3 · ref 4.37e-3 · |Δ| 0.48% | ||
| 1oo1 · DC 60% · β 0% · TI 8760h · MTTR 8h | prod 1.76e-3 · ref 1.75e-3 · |Δ| 0.30% | ||
| 1oo2 · DC 0% · β 2% · TI 8760h · MTTR 8h | prod 1.12e-4 · ref 1.12e-4 · |Δ| 0.39% | ||
| 1oo2 · DC 60% · β 5% · TI 17520h · MTTR 24h | prod 1.92e-4 · ref 1.90e-4 · |Δ| 0.64% | ||
| 1oo2D · DC 0% · β 2% · TI 4380h · MTTR 24h | prod 5.06e-5 · ref 4.99e-5 · |Δ| 1.34% | ||
| 1oo2D · DC 90% · β 5% · TI 8760h · MTTR 8h | prod 2.24e-5 · ref 2.23e-5 · |Δ| 0.25% | ||
| 2oo3 · DC 0% · β 2% · TI 8760h · MTTR 8h | prod 1.62e-4 · ref 1.60e-4 · |Δ| 0.81% | ||
| 2oo3 · DC 60% · β 5% · TI 17520h · MTTR 8h | prod 2.21e-4 · ref 2.19e-4 · |Δ| 0.98% | ||
Sampled max |Δ%| 1.34% across these 8 cells. | |||
Full grid (jest-pinned) The complete 48-cell PFDavg cross-check grid (max divergence ~1.34%) is pinned in `silVerification.test.ts` as jest evidence. Anti-circularity: the reference module uses TWO genuinely independent derivations — a Simpson numerical integrator and a discrete-time Markov solve — and neither imports the production engine (a test asserts the file text never names that module). The Route 1H architectural-cap tables are separately pinned by a 24-cell grid in the same suite. | |||
Test execution — as of 2026-06-11 / 7f9af733 POINT-IN-TIME release evidence (not live). Frontend: 1933 / 1937 passed across 172 suites (0 failed). Backend: 2107 / 2113 passed (0 failed). SIL cross-check drift pin: pass. | |||
| KNOWN ISSUES / ERRATA | |||
Register Append-only known-issues / documented-limitations register. Published entries are never edited or removed; a correction is made by appending a new entry that supersedes a prior one. | |||
ERR-2026-001 — PFDavg accuracy is bounded to the rare-event regime (λ·T1 ≪ 1) The engine implements the IEC 61508-6 Annex B simplified (first-order, rare-event) PFDavg equations. Cross-checked against an independent numerical-integration oracle over the documented 48-cell grid, agreement is within ~1.34% in the normal low-demand design regime, but the simplified form's divergence grows with λ·T1: ~15% at λ·T1 ≈ 0.44, and the linearisation becomes unphysical (PFDavg can exceed 1) near λ·T1 ≈ 2.2.
Disposition: Documented validity domain — the tool targets low-demand SIFs where λ·T1 ≪ 1 (the design intent of the simplified equations). Inputs outside this regime are out of scope and require competent-person review. See the Validation & Methodology dossier and docs/validation §1b. | |||
ERR-2026-002 — 1oo2D PFDavg reflects a documented modelling choice (degrade-to-1oo1) The 1oo2D closed form uses the Hokstad-corrected degrade-to-1oo1 assumption — a lone DETECTED dangerous fault degrades the voted group to a working 1oo1 (repaired online within MRT) and does not by itself fail the function, so there is no standalone (1−β_D)·λ_DD·MRT residual. The audited cross-check validates the simplified-equation linearisation UNDER this assumption; it does not adjudicate between it and the alternative textbook standalone-DD interpretation, which reads materially higher at high diagnostic coverage (the dropped term is ~5% / 31% / 322% of PFDavg at DC 0.6 / 0.9 / 0.99).
Disposition: By design, with a conservative alternative available — conservativeBound1oo2D gives a deliberately pessimistic upper envelope (always ≥ the production form and ≥ the independent reference) for over-claim-proofing, and 1oo2D's HFT is taken conservatively as 0. See docs/validation §1b. | |||
ERR-2026-003 — Audit-trail capture scope is unit-of-work operations The always-on audit trail records create/update/delete on study content via the ORM-flush interceptor. Capture scope is unit-of-work operations: Core-level bulk operations (query.update()/query.delete()) and DB-cascade child deletes are not individually recorded — they are evidenced by the parent record's delete event.
Disposition: Documented honest-by-design scope. Application mutations flow through the ORM unit-of-work (captured); the few Core-level/cascade paths are evidenced at the parent. See the dossier "Records & Electronic Signatures" section. | |||
ERR-2026-004 — 21 CFR Part 11 §11.10(a) system validation is the deploying organisation's responsibility The platform implements Part 11-ALIGNED technical controls (HMAC-chained tamper-evident audit trail; multi-signer e-signatures with password re-authentication and signing manifests). Part 11 also requires procedural controls and §11.10(a) validation of the system in the deploying organisation's operational environment, plus operator SOPs — these sit outside the software and remain the customer's responsibility.
Disposition: By design — a documented split between vendor-provided technical controls and customer-side procedural/validation duties. No "certified" or "compliant" claim is made. See the dossier "Records & Electronic Signatures" section. | |||
DekEn Page 5 / 5 | PHA QUANTITATIVE-ANALYSIS — TOOL QUALIFICATION PACK IEC 61508-3 §7.4.4 (tool classes) · IEC 61508-6 · IEC 61508-2 (Route 1H) · IEC 61025 · IEC 62502 · ISA-TR84.00.02 | Rev.0 | |
| REQUALIFICATION POLICY | |||
Policy Every release re-runs the full frontend gate (TypeScript type-check · ESLint · jest · production build) and the backend gate (pytest), AND the drift pins. This pack and the cross-check grid recompute LIVE from the engine; the validation grids are jest-pinned. The release gate therefore IS the requalification — the tool cannot ship if any pinned behaviour or boundary number has drifted. | |||
| DEFERRED CAPABILITIES | |||
Deferred Out of current scope, documented for completeness: IEC 61508-2 Route 2H (reliability-data route); high-demand / continuous-mode operation (PFH); non-identical channels within a voted group; proof-test-coverage variants beyond the modelled perfect/partial-stroke split; reliability block diagrams (RBD); and certified third-party failure-rate data (e.g. SERH-class datasets) pending licensing. | |||