Verifying Feishu identity

One session covers every module.

experiment

Platform reference

Platform Guide

What changed, how decisions are made, and how the system is built

Release Notes

Platform updates, feature documentation, and verification records

v0.22.02026-08-09

Fixed-Context Ionizable Lipid Efficacy

Introduced one bounded efficacy product: assess an ionizable-lipid structure in a declared AGILE HeLa assay, persist the result, and expose measured position, local chemical support, nearest experimental analogs and the next confirmation experiment without implying universal lipid quality.

Features

deployed

Assay-Declared Prediction

Every result is tied to HeLa, firefly luciferase mRNA, the released 35:16:46.5:2.5 formulation and 24-hour mTP readout; in-vivo, tropism and safety claims remain out of scope.

deployed

Measured Neighborhood

The result shows its position in 1,100 measured lipids, count-based Morgan local support and five nearest measured analogs instead of collapsing evidence into a generic composite score.

deployed

Immutable Result History

Canonical structure, checkpoint version and assay context form a Program-scoped persistence key; stored analysis reopens without losing its model, benchmark or evidence provenance.

Smoke Test Report

2026-08-09 | Pinned Modal model, FastAPI persistence gateway and production Next.js build
PASS1. Reproducible Model Contractdeployment gate

Verify checkpoint, scaler, dataset, split, fingerprints and RDKit before serving

The endpoint serves the pinned LANTERN commit under RDKit 2024.09.1 and fails closed on artifact or contract drift.

PASS2. Support-Domain Audit110 released test rows

Calibrate local support from released test-to-training nearest-neighbor behavior

Count-fingerprint p05 and p25 boundaries are frozen, while the 28.2% exact-neighbor rate is disclosed as a combinatorial-library limitation.

PASS3. Product Release Gate13 focused tests + production smoke

Validate API contracts, deterministic persistence and optimized production rendering

The efficacy route, authenticated gateway, Program history and production page compiled and passed live health checks.

Changelog (6 changes)
  • Added /efficacy as the single fixed-context ionizable-lipid efficacy workspace
  • Deployed the pinned LANTERN checkpoint in the genprime-ai Modal workspace
  • Added fail-closed model, RDKit, artifact-hash, assay and interpretation validation
  • Added immutable Program-scoped result persistence and saved-result history
  • Added assay ruler, nearest measured analogs, random-versus-scaffold benchmark and paper trail
  • Replaced saturated bit-fingerprint support with count-based Morgan support and explicit collision disclosure
v0.21.02026-08-06

Reference-calibrated Scientific Profile

Replaced the interim radar-first analysis with an evidence-led benchmark workbench that explains position, score construction and evidence quality separately.

Features

deployed

Reference Distribution Lanes

Each rank-driving dimension now shows the candidate against every protected reference observation, the reference range, interquartile band and median.

deployed

Auditable Score Construction

Per-dimension weights and weighted contributions reconstruct the current rank score instead of asking the reader to infer meaning from radar area.

deployed

Evidence and Scenario Semantics

Evidence type, authority eligibility and context-only dimensions are explicit; assumption scenarios are labeled as stress tests rather than calibrated uncertainty.

Changelog (4 changes)
  • Added protected-reference min, quartiles, median, max and empirical percentile
  • Added per-dimension contribution reconstruction and evidence provenance
  • Replaced five competing metric hues with neutral surfaces and one institutional accent
  • Retained the radar release in history while removing it from the primary scientific interaction
v0.20.12026-08-06

Evidence Profile Visualization

Refined the benchmark board's visual hierarchy and restored the seven-axis evidence profile as a governed comparison, pairing the selected entry with the protected reference median.

Features

deployed

Reference-Calibrated Radar

The selected candidate now overlays the median of the protected reference panel across all seven historical dimensions, with ranking axes visually distinguished from context-only defaults.

deployed

Scientific Metric Rail

The top summary was rebuilt as one restrained instrument rail using cobalt, mineral teal and warm-neutral state cues instead of five heavy gray cards.

Changelog (4 changes)
  • Restored the historical spider-chart interaction without restoring legacy ranking semantics
  • Compared every selected profile with the live protected-reference median
  • Marked the four rank-driving axes separately from three context-only axes
  • Reduced border weight and replaced the gray metric-card cast with a controlled scientific palette
v0.20.02026-08-06

Persistent Benchmark Board

Replaced transient cohort-first comparison with a versioned benchmark board. Retained results now open as a persisted ranking with stored analysis; new structures are evaluated once, inserted into the board and safely editable without mutating their score artifacts.

Features

deployed

Evaluate Once, Reuse Deterministically

Canonical structure, evaluation profile and scorer version form the cache key. Existing artifacts load immediately and repeat submissions reuse the original report.

deployed

Persistent Ranked Inventory

Historical cohorts are deduplicated into one inspectable board with protected literature anchors, stored dimension analysis, provenance and current-version ranking.

deployed

Recoverable Curation

Names, notes, tags and ranking inclusion are editable. Archive is a soft delete, restore is explicit, reference anchors are protected and computed scores are immutable.

Smoke Test Report

2026-08-06 | SQLite persistence harness, icl-discovery test environment and production web build
PASS1. Deterministic Persistence26.7s first run; 0.02s repeat

Materialize unique retained structures and reuse the same scorer-version artifacts

104 unique local artifacts were created on the first pass; the second pass evaluated zero structures and returned the persisted board.

PASS2. Curation Integrity20 focused tests

Edit metadata, archive and restore without changing calculated scores

Score immutability, cache reuse, deduplication and protected references passed alongside preflight and score-integrity coverage.

PASS3. Product Buildlocal release gate

Lint, type validation and optimized route generation

The benchmark board, single preflight, CandidateSystem contract and cohort replay compile as one assessment surface.

Changelog (6 changes)
  • Made the persistent Benchmark Board the default assessment interaction
  • Added versioned SQLite score artifacts and an auditable event log
  • Added evaluate-and-rank input with canonical-SMILES cache reuse
  • Added search, role filtering, metadata editing, rank exclusion, archive and restore
  • Changed board order to the four candidate-varying dimensions while retaining the legacy composite for traceability
  • Kept cohort replay and single-candidate preflight as explicit secondary tasks
v0.19.22026-08-06

Visible Cohort Entry

Corrected the product entry point for retained candidate cohorts. Preflight and cohort comparison now sit in the visible Program workflow, cohort selection is the default assessment view, and Candidates exposes the retained inventory before the empty Program registry.

Features

deployed

Program-Level Entry

Moved Preflight & Cohorts out of the collapsed capability drawer and into the always-visible Program workflow without adding another module.

deployed

Cohort-First Assessment

The assessment page now opens on cohort comparison by default, while explicit links preserve single-structure preflight as a separate task.

deployed

Historical Inventory

Candidates now shows selectable cohort, retained structure, reference-anchor and completed-run counts above the Program registry.

Changelog (4 changes)
  • Promoted Preflight & Cohorts into Program Workspace
  • Made cohort comparison the default assessment view
  • Added a direct cohort action and visible retained-data inventory to Candidates
  • Removed the redundant historical-record footer
v0.19.12026-08-06

Candidate Cohorts and Historical Replay

Restored the useful comparison capability of the former Validator without restoring its all-purpose decision semantics. Candidate Preflight can now select Program candidates or retained historical run cohorts and compare them against a fixed literature anchor panel.

Features

beta

Direct Cohort Selection

A compact sample tray selects an entire candidate set or individual structures, searches within the set and runs a bounded comparison for up to 32 candidates.

beta

Historical Run Recovery

Retained score-stage structures from prior molecular-design runs are exposed as read-only cohorts instead of remaining hidden in filesystem artifacts. Active Program CandidateSystems appear as their own cohort when present.

beta

Governed Comparison Boundary

The comparison preserves legacy dimensions, composite and Grade for inspection, but the contract is always DEMO_ONLY/BLOCKED and cannot write a rank, task, CandidateSystem or synthesis decision.

Smoke Test Report

2026-08-06 | Standalone production build and icl-discovery test environment
PASS1. Cohort Contract17 focused tests

Catalog, fixed anchors, bounded batch comparison and fail-closed authority

Candidate Preflight and score-integrity suites passed, including six reference anchors and historical cohort replay.

PASS2. Production Buildlocal release gate

ESLint, TypeScript validation and optimized static generation

All 35 routes compiled and generated successfully; /validator includes the candidate-set tray and comparison table.

Changelog (5 changes)
  • Added candidate-set-catalog.v1 and candidate-cohort-benchmark.v1
  • Exposed retained historical score-stage cohorts without mutating them into Program records
  • Added direct set selection, individual candidate selection and fixed reference anchors
  • Kept single-candidate candidate-preflight.v2 unchanged and non-decision
  • Documented the separation between readiness, historical comparison and governed scientific review
v0.19.02026-08-04

Program-Centered Research Workspace

Rebuilt the product interaction model around one persistent Program context, one five-state decision spine, and one visible next action. Redundant global routes, repeated Program ID entry and always-visible future governance controls are removed from the canonical workflow.

Features

deployed

Persistent Program Context

The application shell now owns the active Program. Context is normalized, remembered locally, propagated through canonical links and consumed across evidence, candidates, experiments, decisions, governance, model evaluation and prospective validation.

deployed

Decision Control Room

Dashboard no longer acts as a module directory. It reads Program records, identifies the current stage, states blockers and routes the user to the next valid action without converting unavailable data into a passed gate.

deployed

Progressive Governance

The work queue reveals review, revocation, scoped application and rollback controls only when server state makes each operation valid. Digest materialization remains available as a collapsed advanced control.

deployed

Canonical Product Surface

Review, Legacy Curation, separate Validation Registry and Agent are retired as product destinations. Stable compatibility routes redirect into Work Queue, Evidence, Prospective Validation and Dashboard.

Smoke Test Report

2026-08-04 | Standalone production build, Next.js 15.5.21
PASS1. Production Build~11s local

ESLint, type validation and optimized static generation

All 35 routes compiled and generated successfully with no lint or type errors.

PASS2. Product Surface Audit16-route DOM gate

Inspect canonical desktop and mobile workspaces for overflow, raw icons, personal context and server errors

Every canonical route passed at 1440 px; Dashboard and Program passed at 390 px with zero horizontal overflow. Compatibility routes return their intended redirects.

PASS3. Program Context and Asset Reliabilityproduction browser gate

Verify deep links, selector changes, reload persistence, navigation propagation and standalone static assets

Program context remained stable through change and reload; the 13.9 KB local icon subset loaded from the standalone image and every rendered symbol resolved as a ligature.

Changelog (7 changes)
  • Replaced the ten-step global pipeline directory with Program Workspace and Capabilities
  • Introduced a responsive application shell and mobile navigation
  • Consolidated candidate review around complete CandidateSystems
  • Moved molecular-generation results into contextual execution history
  • Collapsed compatibility forms and advanced controls behind progressive disclosure
  • Self-hosted a minimal icon subset and added the asset to deployment smoke tests
  • Published Product Information Architecture v2 and updated architecture and methodology guidance
v0.18.42026-08-03

Candidate Preflight Product Naming

Unified the core readiness workflow under one user-facing name: Candidate Preflight. The former Validator label is retired from current navigation and the Dashboard while the existing /validator route and API paths remain stable for compatibility.

Features

deployed

One Product Name

Navigation, Dashboard, page chrome and current documentation now describe one core capability: Candidate Preflight. candidate-preflight.v2 remains the scientific contract behind that product surface.

deployed

Explicit Non-Decision Boundary

The Dashboard labels the capability NON_DECISION instead of presenting Validator as a second module. Preflight checks readiness for review; it does not rank, approve or recommend synthesis.

deployed

Route Compatibility

The /validator browser route and /api/v1/validator/preflight endpoint remain unchanged, preserving bookmarks and integrations without exposing the legacy product vocabulary.

Smoke Test Report

2026-08-03 | Local release gate, Next.js 15.5.21
PASS1. Product Vocabulary Auditstatic contract audit

Verify current navigation and Dashboard use Candidate Preflight

The sidebar exposes Candidate Preflight as the Core destination; the Dashboard no longer presents Validator as a separate capability.

PASS2. Frontend Production Buildlocal release gate

ESLint, type validation and optimized static generation

All routes build with /validator preserved as the compatibility path and Candidate Preflight retained in page chrome.

PASS3. Contract Boundaryroute and documentation audit

Preserve the v2 non-decision API contract

candidate-preflight.v2 and POST /api/v1/validator/preflight are unchanged; only the product vocabulary is consolidated.

Changelog (4 changes)
  • Renamed the Core sidebar destination from Validator to Candidate Preflight
  • Reframed the Dashboard card around Candidate Preflight and its NON_DECISION boundary
  • Kept /validator and /api/v1/validator/preflight as stable compatibility paths
  • Documented the separation between product name, scientific contract and compatibility route
v0.18.32026-08-03

Candidate Preflight Contract

Rebuilt Validator around the platform's current scientific chain: it now verifies molecular input, computation readiness, complete CandidateSystem context, evidence lineage, and the next governed handoff without producing a universal score or synthesis recommendation.

Features

deployed

Five-Gate Readiness Rail

The default Validator experience now presents molecular identity, computation readiness, developability review, CandidateSystem context, and evidence lineage as separate inspectable gates. A failed heuristic remains a review signal rather than silently becoming a scientific decision.

deployed

CandidateSystem-Native Input

Users can start with a quick structure intake or validate the full candidate-system.v1 object, including formulation, payload, biology, assay, operating constraints, metrics, and provenance.

deployed

Non-Decision API Contract

POST /api/v1/validator/preflight returns candidate-preflight.v2 with explicit NON_DECISION authority, fail-closed blockers, evidence gaps, descriptors, checks, and governed handoff actions. It never returns Grade, rank, composite score, or synthesis decision fields.

deployed

Calmer Navigation and Account Surface

The sidebar returns to a 200-pixel workbench width with a more generous row rhythm. The bottom account surface follows the compact avatar/name/settings pattern; sign-out moves into Account settings instead of competing with navigation.

Smoke Test Report

2026-08-03 | Local release gate, Next.js 15.5.21 and project conda environment
PASS1. Preflight Contract Regression2.47s focused suite

Validate incomplete, complete, and invalid CandidateSystem inputs

15/15 focused Validator and scoring-integrity tests passed; the v2 payload contains no grade, rank, composite-score, or synthesis-decision keys.

PASS2. Frontend Production Buildlocal release gate

ESLint, type validation, and optimized static generation

All 35 routes built successfully, including the rebuilt /validator and updated Settings account surface.

PASS3. Compatibility Boundarystatic contract audit

Retain old integrations without exposing them in the current workflow

Legacy /validate, /benchmark, /references, and /grading routes remain available for historical replay; the default page calls only /preflight.

Changelog (6 changes)
  • Replaced the default score-and-grade Validator UI with Candidate Preflight
  • Added candidate-preflight.v2 and a fail-closed five-gate readiness contract
  • Added quick structure and complete CandidateSystem JSON input paths
  • Removed legacy benchmark, radar, composite, Grade, rank, and synthesis actions from the default Validator
  • Added governed handoffs to Program, Onboarding, Evidence, and Review
  • Relaxed sidebar density and moved sign-out into Account settings
v0.18.22026-08-03

Compact Pipeline Navigation

Reframed the application as a compact research workbench: the scientific lifecycle is now one ordered Pipeline, Validator is promoted as the current core operational capability, platform documentation is consolidated, and administrator oversight lives inside Settings.

Features

deployed

Ordered Pipeline Rail

Ten workflow pages now sit behind one collapsible Pipeline entry and open automatically around the active step. The 01–10 rail communicates the real sequence without presenting every route as a separate top-level product.

deployed

Validator as Core Capability

Validator is promoted immediately below Pipeline as a persistent first-level destination with a Core marker, reflecting its current evidence strength and day-to-day utility.

deployed

Consolidated Platform and Admin Navigation

Release Notes, Methodology and Architecture are available through one Platform Guide with Updates, Method and System sections. Admin access and activity records move into a protected Settings section while /admin remains a compatibility redirect.

deployed

Research-Workbench Density

Sidebar width, navigation rhythm, top bar, page gutters, large headings, cards, tables and form controls use a tighter shared density tuned for information-heavy scientific work.

Smoke Test Report

2026-08-03 | Release gate, Next.js 15.5.21
PASS1. Frontend Production Build~12s local

ESLint, type validation and optimized static generation

All 35 routes built successfully, including Platform Guide and the /admin compatibility redirect.

PASS2. Navigation and Access Boundarystatic gate

Verify hierarchy, deep-link compatibility and administrator visibility

Pipeline, Analysis and Design Tools retain every route; the sidebar contains no Admin link; Settings mounts the audit ledger only for the live Feishu super administrator.

PASS3. Feishu RBAC Regression3.39s

Re-run the focused identity, role and administrator boundary suite

7/7 focused tests passed in the project environment; moving the audit UI did not alter the server-enforced super-admin boundary.

Changelog (6 changes)
  • Collapsed ten lifecycle workspaces into one numbered Pipeline rail
  • Promoted Validator to a first-level Core destination
  • Collapsed Analysis and Design Tools into contextual navigation groups
  • Merged release, method and system references into Platform Guide
  • Moved administrator oversight into Settings and retained /admin as a redirect
  • Reduced global navigation, typography, spacing, card and table density
v0.18.12026-08-03

Admin Audit Ledger and Runtime Cutover

Closed the post-OAuth session verification loop, made the Feishu allowlist the sole production administrator authority, added cross-user login and task records, and moved TransMA serving to the genprime-ai Modal workspace.

Features

deployed

Feishu Super-admin Boundary

The sidebar and dedicated Admin workspace appear only for the configured Feishu super administrator. The API revalidates the live platform role, demotes password-era admin rows, and returns 403 for every other identity.

deployed

Login and Task Audit Ledger

Admin now combines an expandable per-user Feishu login history, failed-login review, and cross-user pipeline and retained historical task records with status, owner, source and timestamps.

deployed

genprime-ai GPU Runtime

The TransMA default and persisted platform setting now target the verified genprime-ai Modal endpoint. Known legacy workspace values migrate automatically while unrelated custom endpoints remain unchanged.

deployed

Simplified Navigation

The sidebar uses tighter vertical rhythm and aligned horizontal padding, removes the Agent entry, and gives the administrator a dedicated audit destination.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21 + Modal
PASS1. Backend Regression17.62s

Complete API, RBAC, run ownership and scientific workflow suite

347/347 tests passed, including worker-thread OAuth session verification, allowlist reconciliation, non-admin 403 boundaries, task aggregation and GPU URL migration.

PASS2. Frontend Production Build~15s local

ESLint, type validation and optimized build

All 34 routes built successfully, including the guarded Admin workspace; Settings and the sidebar expose no administrator controls to regular users.

PASS3. Modal Runtimelive probe

Verify the genprime-ai TransMA health endpoint

The genprime-ai endpoint returned HTTP 200 with model_loaded=true before the production setting was migrated.

Changelog (6 changes)
  • Allowed FastAPI SQLite dependencies to cross worker threads safely
  • Added a guarded /admin workspace with login and task records
  • Restricted platform settings writes and LLM tests to the super administrator
  • Reconciled super-admin rows against the configured Feishu allowlist
  • Migrated TransMA serving to the genprime-ai workspace
  • Removed Agent from the sidebar and tightened navigation spacing
v0.18.02026-08-03

Unified Feishu Identity Boundary

Replaced the route-by-route password wall with one verified Feishu session for the complete platform, retired local password entry points, and added explicit ownership rules for current and historical work.

Features

deployed

One Session Across Every Module

The frontend establishes one host-scoped Feishu session and every protected API revalidates it against the live user and tenant boundary. There is no per-module password prompt or proxy-supplied demo identity.

deployed

Historical Work Preserved Read-Only

Runs, agent threads and plans created before trusted ownership are visible to signed-in members as legacy shared records, but cannot be resumed, cancelled, renamed, deleted or continued through normal routes.

deployed

Private Ownership for New Work

New runs, conversations and plans are bound server-side to the verified Feishu user. Owners and super admins can access them; unrelated users receive a non-disclosing not-found response.

deployed

Fail-Closed Cutover

Production refuses missing or default signing secrets, OAuth state is browser-bound and single-use, password login is retired, and deployment verifies the public edge before reporting success.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Backend Regression18.67s

Complete test suite including identity and legacy ACL cases

345/345 tests passed. The cutover suite covers password retirement, anonymous API denial, browser-bound OAuth state, safe redirects, live user revocation, private ownership and legacy read-only behavior.

PASS2. Frontend Production Build~8s local

ESLint, type validation and optimized production build

All 33 routes built successfully with the shared identity bootstrap and Feishu-only login surface.

PASS3. Credential Hygienestatic scan

Remove reusable password material from the active release

The active tree contains no historical plaintext credential or tracked htpasswd file; deployment retires the server copy after nginx switches successfully.

PASS4. Privacy Boundarystatic scan

Keep identity cutover generic and presentation-independent

No visitor, meeting, institution or preparation-specific identity is encoded in the product or access policy.

Changelog (6 changes)
  • Added Feishu-required production policy and live identity revalidation
  • Retired password login, registration, Basic Auth and proxy demo identity
  • Added owner-bound pipeline runs, agent threads and plans
  • Classified unowned historical work as legacy shared read-only
  • Added OAuth state binding, tenant enforcement, audit logging and edge rate limiting
  • Added secret-safe provisioning and deployment smoke gates
v0.17.02026-08-03

Mechanism-Boundary Product Semantics

Made the evidence-governed system path the only actionable path, isolated historical molecule-only scores as a non-decision replay, and expanded external admission with the actual commercial-license and endpoint boundaries for COMET/LANCE and Helix-mRNA.

Features

deployed

Legacy Replay, Not a Candidate Leaderboard

The results workspace now labels historical triage DEMO ONLY · NON-DECISION, hides legacy Grade, composite and rank, and removes score-derived seed/synthesis actions. Current work routes to Program definition and complete CandidateSystem onboarding.

deployed

Twenty-Capability Admission Registry

COMET/LANCE and Helix-mRNA join the registry with pinned source revisions, model/artifact roles and explicit blockers. The current boundary is 15 supporting-only, 5 rejected and zero decision-grade external capabilities.

deployed

License Truth at Time of Use

COMET is rejected because its custom agreement prohibits commercial R&D, redistribution and most modification; Helix-mRNA is rejected because the published weights are non-commercial and the task is payload representation, not LNP delivery.

deployed

Mechanism Endpoint Method

Methodology v6 and architecture v17 define independent formation, exposure, uptake, escape, damage/recovery, inflammation, function, repeat-dose and process endpoints, with hard gates, conservative bounds, Pareto and information gain instead of a universal score.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression16.73s

pytest across the complete release snapshot

336/336 tests passed, including registry schema, role/license gates, remote-input blocking, evidence custody, permanent blind and activation dossier replay.

PASS2. External Admission Snapshot<1s

Machine-validate exact registry counts and authority

20 capabilities: 15 supporting only, 5 rejected and zero authoritative candidates. COMET and Helix-mRNA preserve empty allowed-role sets.

PASS3. Frontend Production Build~12s local

ESLint, type validation, optimized build and dependency audit

33 routes built successfully; npm audit reported zero vulnerabilities; /results contains no legacy Grade/composite/rank action path.

PASS4. Privacy Boundarystatic scan

Scan the release diff for isolated research identity or preparation context

No person name, institutional identity, meeting context or preparation marker entered product, documentation, tests or registry changes.

Changelog (5 changes)
  • Renamed the historical results card to Legacy Triage Replay and removed Grade/composite/rank from its current UI
  • Removed every legacy score-derived action and routed users to Program and CandidateSystem workflows
  • Added pinned COMET/LANCE and Helix-mRNA registry entries with fail-closed non-commercial licensing
  • Expanded registry assertions to 20 capabilities and 5 rejected entries
  • Added methodology v6 and architecture v17
v0.16.02026-08-03

Evidence-Custodied Model Promotion

Connected the previously separate activation cards, permanent-blind result, dataset custody, candidate/rollback artifacts and serving identity into one append-only, time-of-use reverified promotion dossier—without moving activation authority into the web API or training process.

Features

deployed

Eight-Source Activation Dossier

A strict Program-scoped request binds five JSON cards, an activation-grade dataset package, candidate and rollback artifacts, plus one completed permanent-blind result. Every role requires a distinct Evidence source and the final fingerprint covers source/artifact attestations, exact bytes, blind receipt and logical card hashes.

deployed

Isolated Physical Gate Replay

The server ignores caller filesystem locations, safely materializes current custody in a private environment and invokes the existing activation-v2 gate. Duplicate keys, NaN, unknown card fields, unsafe ZIPs, artifact drift and a hand-authored blind slice fail closed.

deployed

Large Artifact Streaming Custody

An admin-only route streams candidate and rollback artifacts up to a configurable 2 GiB ceiling, limits bytes during transfer, fsyncs staging, computes server SHA-256 and atomically adopts content. Dossier verification rehashes large files with bounded reads instead of loading model weights into memory.

deployed

Append-Only Handoff and Replay

Only a fully passing physical preview can be registered as READY_FOR_INDEPENDENT_ACTIVATION. Every list operation rebuilds the blind result and activation gate from current custody; drift becomes BLOCKED without rewriting history. READY remains NON_DECISION and NOT ACTIVATED.

deployed

Promotion Control Plane

The /models workspace now separates external capability admission from model promotion. A custody rail exposes Evidence → Blind → Artifacts → Policy → Handoff, supports real source assembly and large artifact staging, and never seeds a fake dossier or metric.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression14.29s

pytest across the complete release snapshot

336/336 tests passed, including real activation-grade dataset/card/artifact verification, exact blind-slice binding, duplicate-card-key and malicious-ZIP rejection, custody tamper blocking, streaming upload limits, append-only triggers and final-approver separation.

PASS2. Frontend Production Build~11s local

ESLint, type validation and optimized Next build

33 routes built successfully; /models now includes the operational promotion-dossier workspace, current integrity ledger and explicit NON_DECISION · NOT ACTIVATED boundary.

PASS3. Physical and Authority Boundarytest-gated

No preview or registration can issue activation

Only verified custody can reach READY_FOR_INDEPENDENT_ACTIVATION; the API has no attestation writer, blocked previews are zero-write, and the final approver must differ from trainer, calibration executor and evaluation executor.

PASS4. Deployment Contractworkflow-gated

Persistent custody, page and OpenAPI smoke gates

Deployment preserves host runtime custody and now requires /models plus dossier preview/import/list and admin streaming-artifact contracts before reporting success.

Changelog (9 changes)
  • Added strict activation-dossier request, preview, registration and current-view contracts
  • Added safe isolated dataset/model materialization and exact reuse of activation policy v2
  • Bound EvaluationCard permanent-blind evidence to the current server recomputation receipt
  • Added append-only dossier storage with unique evidence fingerprint and no-update/no-delete triggers
  • Added admin-only bounded streaming custody for large candidate and rollback artifacts
  • Strengthened core activation approval independence from calibration/evaluation executors
  • Added Program-scoped preview, import, list and artifact upload APIs
  • Expanded /models with separate external-admission and promotion-dossier control planes
  • Added methodology v5, architecture v16 and the Activation Dossier v1 operating contract
v0.15.02026-08-03

Permanent-Blind Evaluation Control Plane

Added an executable one-shot path from a pretraining truth commitment to nine-model prediction freeze, controlled reveal, independent server recomputation and an append-only result receipt—without allowing a passing blind slice to activate a model.

Features

deployed

Pre-Reveal Truth Commitment

An independent custodian freezes the exact truth-file SHA-256 before candidate training. Plan creation binds holdout, endpoint, unit, candidate code/config/artifact, all eight registered baselines and policy thresholds while keeping truth bytes outside platform custody.

deployed

Exact Nine-Model Prediction Freeze

The server requires the candidate plus eight registered baselines to predict the identical blind sample set with point and interval estimates. Unknown fields, duplicate keys, missing pairs, identity drift and early truth reveal fail closed.

deployed

Three-Party Reveal and Evaluation

Truth can be attached only after predictions and only by the preregistered custodian. Finalization requires a third identity that is neither custodian, trainer nor prediction submitter, and no client-provided metric is accepted.

deployed

Server Metrics and Blind-Slice Adapter

The server computes nine-model RMSE, MAE, Spearman, tie-conservative top-k enrichment, interval coverage and calibration with deterministic 95% structure-group bootstrap intervals. The candidate is compared with the strongest frozen traditional baseline.

deployed

Custody Rail Workbench

The /evaluations workspace now separates development and permanent-blind evidence. Its commit → freeze → reveal → recompute rail performs real operations, exposes identity boundaries and shows no metric until an actual immutable result exists.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression14.69s

pytest across the complete release snapshot

326/326 tests passed, including a real eight-baseline archive registration followed by truth commitment, 270-row prediction freeze, controlled reveal, 200-replicate group bootstrap, immutable finalization, policy-floor enforcement and read-time recomputation.

PASS2. Frontend Production Build~11s local

ESLint, type validation and optimized Next build

33 routes built successfully; /evaluations includes both evidence classes, the custody rail, operational forms, integrity blockers and a real empty state.

PASS3. Dependency and Privacy Gates<4s

Production audit and restricted-identity scan

npm reported zero production vulnerabilities; scoped source, UI, documentation and workflow scans found zero restricted-person or preparation-context references.

PASS4. Authority Gatetest-gated

Blind result cannot self-activate a candidate model

PASS/FAIL emits one activation-compatible permanent-blind slice while the stored result remains NON_DECISION, activation_allowed=false and subject to distinct external/scaffold/time/calibration/governance gates.

Changelog (9 changes)
  • Added strict permanent-blind plan, prediction, truth, result and workflow contracts
  • Added append-only plan/submission/result storage with one-shot uniqueness and no-update/no-delete triggers
  • Added truth-custodian, trainer, prediction-submitter and independent-evaluator separation
  • Added exact nine-model matrix validation and time-of-use Evidence custody replay
  • Added deterministic server metrics, group-bootstrap intervals and conservative best-baseline comparison
  • Added permanent-blind plan, submission, finalization and reverified list APIs
  • Added a canonical truth/prediction manifest preparation CLI
  • Expanded /evaluations with development/permanent-blind views and a four-stage custody rail
  • Added methodology v4, architecture v15 and the permanent-blind operating contract
v0.14.02026-08-03

Verified Same-Split Evaluation Registry

Connected the strict eight-model CPU baseline evaluator to evidence custody and the visible platform: complete run archives can now be safely verified, immutably registered to a Program and fully replayed at read time without granting model authority.

Features

deployed

Complete Archive Verification

A deterministic ZIP must contain the exact 8 × 5 run file set. The server rejects traversal, symbolic links, encrypted or duplicate members, unsafe compression and extra files before recomputing nested hashes, folds, predictions, metrics, intervals, code and runtime identity.

deployed

Append-Only Evaluation Registration

A zero-write Program preview verifies current Evidence custody. Import replays the archive and records source, archive, run, dataset and all eight model identities in an immutable SQLite record fixed to UNVALIDATED, NON_DECISION and activation_allowed=false.

deployed

Time-of-Use Integrity

Every registry read reopens the current custody artifact and repeats full bundle verification. Missing bytes, digest drift, code/runtime mismatch or registration-binding drift becomes a visible BLOCKED state without rewriting history.

deployed

Same-Split Evaluation Workbench

The new /evaluations workspace places all eight baselines on one frozen dataset rail, exposes selected metrics and immutable bindings, and keeps activation blockers visible. Empty Programs show no synthetic metrics.

deployed

Durable Evidence Custody

Production now host-mounts runtime evidence artifacts and protects the directory from deployment deletion. The API image includes the shared read-only frozen-package reader while Modal training code remains excluded.

Smoke Test Report

2026-08-03 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression15.85s

pytest across the complete release snapshot

315/315 tests passed, including deterministic packaging, safe extraction, full verifier replay, Evidence custody, API preview/import/list, append-only storage and digest mismatch blocking.

PASS2. Frontend Production Build~12s local

ESLint, type validation and optimized Next build

33 routes built successfully, including the new /evaluations registry and updated model-admission/dashboard navigation.

PASS3. Authority and Empty-State Gatetest-gated

No development baseline can become decision-grade

Preview and registration contracts force UNVALIDATED, NON_DECISION and activation_allowed=false; the UI reports zero activation-eligible models and renders no placeholder metrics.

PASS4. Deployment Contractworkflow-gated

Persistent custody, production page and OpenAPI smoke gates

Deployment preserves host runtime artifacts and requires /evaluations plus baseline preview, import and list contracts before reporting success.

Changelog (8 changes)
  • Added deterministic baseline-run ZIP packaging and defensive archive extraction
  • Reused the full evaluator verifier to recompute file, fold, metric, interval, config, code and runtime identities
  • Added Program-scoped preview, append-only import and time-of-use reverified list contracts
  • Added immutable baseline evaluation storage with source/archive/run/dataset/model bindings
  • Added the /evaluations same-split comparison rail and real empty/blocked states
  • Connected model admission, dashboard navigation and release documentation to evaluation evidence
  • Persisted Evidence custody under the production runtime host mount
  • Added architecture v14 and baseline evaluation registry documentation
v0.13.02026-08-02

Model & API Admission with Prediction Lineage

Connected the external capability registry, model activation governance and real CandidateSystem intake: every external tool now has a visible role boundary, and every admitted predicted metric must replay to an immutable run, an independently issued activation and the exact candidate value and uncertainty.

Features

deployed

Visible Capability Admission

The new /models workspace exposes the reviewed 18-capability registry, current tier counts, exact licenses, deployment/input policies, permitted roles and declared blockers. It reports the current zero decision-grade external model boundary without turning the registry into a model leaderboard.

deployed

Intended-Use Preflight

A deterministic API assesses capability, intended role, input classification and endpoint/unit. Remote non-public data, disallowed roles, rejected licenses and non-authoritative candidate-ranking attempts fail closed.

deployed

Prediction-Run Lineage

Candidate batch preflight now replays prediction-run.v1 artifacts and verifies run/model/activation/capability identity, endpoint, unit, per-candidate value and uncertainty, canonical activation hash, policy and independent issuer binding.

deployed

Proposal Admission Boundary

Production ExperimentProposal creation derives admission from append-only batch receipts and re-verifies current prediction/activation bytes at time of use. Manual drafts and candidates whose activation artifact later disappears are excluded.

Smoke Test Report

2026-08-02 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression15.25s

pytest across the complete release snapshot

313/313 tests passed, including registry policy, intended-use assessment, remote-input boundaries, prediction/activation replay, external authority blocking and time-of-use proposal enforcement.

PASS2. Frontend Production Build~12s local

ESLint, type validation and optimized Next build

32 routes built successfully, including the new /models admission matrix and updated onboarding/experiment boundaries.

PASS3. Dependency and Privacy Gates<1s

Production dependency audit and restricted-identity scan

npm reported zero production vulnerabilities; the tracked platform and documentation scan found zero restricted identity references.

PASS4. Deployment Contractworkflow-gated

Production page and OpenAPI smoke gates

Deployment requires /models plus registry snapshot, intended-use assessment and existing candidate batch/proposal contracts before reporting success.

Changelog (8 changes)
  • Added external-capability snapshot and intended-use assessment contracts
  • Added a searchable /models admission matrix with current evidence boundaries and exact blockers
  • Added prediction-run.v1 with per-candidate values, uncertainty and canonical record digest
  • Bound predicted batch metrics to current activation schema/policy, independent issuer and serving-identity hash
  • Blocked non-authoritative external capability outputs from Pilot-eligible candidate metrics
  • Blocked unreceipted manual predictions from the production ExperimentProposal path
  • Re-verified current prediction and activation artifact custody whenever a proposal is created
  • Added architecture v13, model/API admission documentation and deployment smoke gates
v0.12.02026-08-02

Custody-Bound Candidate Data Onboarding

Closed the gap between a pilot-ready control plane and real candidate data: complete CandidateSystems can now enter through an immutable JSON artifact, receive a zero-write deterministic preflight, and be imported atomically only when every row and metric evidence source passes.

Features

deployed

Deterministic Batch Preflight

The server replays the custody artifact and reports every schema, context, formulation, evidence, uncertainty, duplicate-ID and duplicate-semantics blocker by row. A preview never writes CandidateSystems.

deployed

Evidence-Bound Candidate Metrics

Every Pilot-eligible measured or predicted metric must carry uncertainty and point to a physically verified, reviewed source with a matching evidence class. Predictions must also bind a registered model or run identity.

deployed

Atomic Append-Only Import

An administrator submits the preview digest; the server replays the source and writes all CandidateSystems, members and the batch receipt in one transaction. Any conflict rolls the full import back.

deployed

Round 1 Execution Funnel

The new /onboarding workspace exposes live custody-batch, READY-system, frozen-proposal and blinded-pack state, plus a neutral JSON template and row-level correction guidance.

Smoke Test Report

2026-08-02 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression12.71s

pytest across the complete release snapshot

305/305 tests passed, including zero-write preflight, custody replay, reviewer/admin separation, evidence-class review, concurrent conflict rollback, append-only receipts and member-lineage tamper detection.

PASS2. Frontend Production Build~11s local

ESLint, type validation and optimized Next build

31 routes built successfully, including the new /onboarding workspace and live Round 1 execution funnel.

PASS3. Dependency and Privacy Gates<1s

Production dependency audit and restricted-identity scan

npm reported zero production vulnerabilities; the scoped platform, web, docs, workflows and README scan found zero restricted identity references.

PASS4. Deployment Contractworkflow-gated

Production page and OpenAPI smoke gates

Deployment requires /onboarding plus batch preview and atomic-import contracts before reporting success.

Changelog (6 changes)
  • Added candidate-system-batch.v1 source, preview, import-result and immutable receipt contracts
  • Added server-side source-digest replay, complete row blockers and metric evidence/review checks
  • Added duplicate semantic detection, post-preview conflict rollback and receipt/member integrity verification
  • Added the /onboarding workspace, neutral JSON template and live Round 1 readiness funnel
  • Recorded the legacy-data readiness audit without fabricating missing formulation, process, payload, assay or endpoint values
  • Extended methodology, blueprint and deployment smoke gates for real candidate batch onboarding
v0.11.02026-08-02

Blinded Prospective Pilot Execution

Turned prospective validation from a control-plane contract into an operational pilot workflow: the server now replays five equal-budget selection policies, freezes role-separated plate packs, ingests custody-bound blind observations and derives round aggregates without client-entered hit counts.

Features

deployed

Deterministic Five-Arm Pilot Pack

A complete ExperimentProposal can now be replayed into platform, random, diversity-only, uncertainty-only and preregistered human arms. Every policy receives a canonical digest and must fill the same N within the same cost ceiling.

deployed

Role-Separated Blinding

Authorized lab custody sees real sample mappings; analysts receive wells, sample type, replicates and blind IDs only. Controls remain blinded in the observation contract.

deployed

Server-Derived Results

The independent evaluator uploads a complete blinded JSON artifact. The server verifies physical custody, coverage, controls, QC, units and actual cost before unblinding and generating the immutable result manifest.

deployed

Visible Pilot Operations

The new /pilot workspace covers replay, preregistration, pack freeze, role-specific downloads, observation custody and result recording. /validation is now a read-only registry with no placeholder hashes or manual aggregate entry.

Smoke Test Report

2026-08-02 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression14.74s

pytest across the complete release snapshot

297/297 tests passed, including five-arm replay, blinding, append-only storage, evidence custody, server projection and independent evaluator enforcement.

PASS2. Frontend Production Build~12s local

ESLint, type validation and optimized Next build

30 routes built successfully, including the new /pilot workspace and read-only /validation registry.

PASS3. Dependency and Privacy Gates<1s

Production dependency audit and public-surface identity scan

npm reported zero production vulnerabilities; the scoped platform, web, docs and workflow scan found no restricted identity terms.

PASS4. Deployment Contractworkflow-gated

Production page and OpenAPI smoke gates

Deployment requires /pilot plus preview, pack and result contracts before reporting success.

Changelog (7 changes)
  • Added ProspectivePilotPreview, ProspectivePilotPack, analyst view, observation manifest and result receipt contracts
  • Added deterministic equal-budget selection replay and canonical policy hashes for all five arms
  • Added seeded union plate allocation with separate lab-custody and blind analyst views
  • Added physical raw-observation custody and server-generated prospective result manifests
  • Blocked planner self-evaluation, endpoint-direction conflicts, missing blind coverage, failed controls, deviations and actual-cost overruns
  • Added the /pilot product workspace and converted /validation into a read-only registry
  • Extended methodology, blueprint and production smoke gates for executable prospective pilots
v0.10.02026-08-02

Prospective Policy Validation & Governed Target Heads

Added a fail-closed prospective validation contract for testing whether a frozen selection policy improves real decisions under equal budgets, plus an atomic reference adapter that turns approved learning receipts into observable version-head transitions and exact rollbacks.

Features

deployed

Complete Five-Arm Preregistration

Every plan freezes the platform policy, random, diversity-only, uncertainty-only and human baselines against the same candidate pool, candidate count, endpoint and cost ceiling.

deployed

Independent Two-Round Evaluation

The planner cannot evaluate their own plan. Both immutable rounds require a server-verified machine-readable result manifest; material deviations, missing custody, digest drift or aggregate mismatch block evaluation.

deployed

Predeclared Increment Gate

A plan passes only when the platform arm exceeds every baseline by the preregistered hit-rate delta in each of two evaluable rounds. The summary remains NON_DECISION.

deployed

Atomic Governed Target Adapter

Approved application receipts can now create immutable JSON snapshots and atomically advance a real current head. Rollback restores only the exact recorded prior snapshot and preserves append-only history.

deployed

Visible Validation & Transition Surfaces

The new /validation workspace manages preregistration, rounds and summaries; /governance now exposes server-side payload hashing, bootstrap, materialization and transition history.

Smoke Test Report

2026-08-02 | Release gate, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression11.69s

pytest across the release snapshot

290/290 tests passed, including prospective evidence custody, two-round threshold logic, governed target head transitions and exact rollback.

PASS2. Frontend Production Build~11s local

ESLint, type validation and optimized Next build

29 routes built successfully, including /validation and the expanded /governance surface.

PASS3. Fail-Closed Target Transition<1s

Actor, payload, current-head and lineage checks

Wrong actors and payload digests are rejected; snapshots and transitions cannot be updated or deleted; rollback restores the exact prior version.

PASS4. Deployment Contractworkflow-gated

Production page and OpenAPI smoke gates

Deployment now requires /validation plus prospective plan/round and governed apply/rollback contracts before success.

Changelog (8 changes)
  • Added immutable ProspectiveValidationPlan, ProspectiveValidationRound and deterministic summary contracts
  • Added equal-budget five-arm enforcement, two-round pass criteria and planner/evaluator separation
  • Bound prospective values to a server-parsed result manifest held in physical evidence custody
  • Added the /validation product workspace and navigation entry
  • Added immutable governed-target snapshots, atomic current heads and append-only transitions
  • Connected LearningApplication and LearningRollback records to authenticated physical target transitions
  • Added server-side target payload digest binding and visible transition history
  • Extended production smoke gates for the new page and API families
v0.9.02026-08-02

Independent Governance, Scoped Learning & Rollback

Closed the gap between review-ready research artifacts and controlled action. Decision and learning packets now enter explicit review queues, require independent authenticated identities, produce immutable authority records, and preserve revocation or exact prior-version rollback paths.

Features

deployed

Independent DecisionReview

A DecisionPacket can be approved or rejected only by an authenticated identity distinct from its preparer. The immutable review binds the packet digest, recommendation, rationale and conditions.

deployed

Revocation & Rollback Authority

Approved decisions can be revoked without deleting history. Revocation records the reason, affected targets and mandatory rollback actions, and makes the previous approval non-effective.

deployed

Scoped LearningReview

LearningUpdates enter a separate review queue. Approval grants only explicit evidence, dataset, model-evaluation or experiment-backlog scopes; unapproved target classes fail closed.

deployed

Version-Bound Application Receipts

Learning application requires a third identity, target ID, prior/applied version IDs and SHA-256 digests, plus a rollback reference. Rollback can restore only the exact recorded prior version and digest.

Changelog (5 changes)
  • Added the /governance review, authorization, application and rollback surface
  • Added DecisionReview, DecisionRevocation, LearningReview, LearningApplication and LearningRollback contracts
  • Added append-only SQLite governance tables, digest verification and current-state projections
  • Added separation-of-duties, scope and exact-version rollback fail-closed gates
  • Added deployment smoke checks for the governance page and API contracts
v0.8.02026-08-02

Program-First Evidence, Experiment & Learning Control Plane

Reframed the platform around auditable research programs rather than standalone molecule scores. The new control plane preserves source custody, freezes complete candidate systems and experiment proposals, separates execution facts from evaluation, and prepares human-review decision and learning packets without auto-approving scientific actions.

Features

deployed

Program Design

A neutral ProgramBrief defines the decision, context, competing hypotheses, constraints, evidence needs and required outputs before candidate selection begins.

deployed

Evidence Backbone & Artifact Custody

Program-scoped sources, claims, contexts, evidence edges and citation packs are persisted with digest checks and server-verified physical artifacts.

deployed

CandidateSystem & Frozen ExperimentProposal

Candidates are evaluated as complete context-bound systems. Fixed-budget selection, plate layout, controls, replicates, metrics and success criteria are frozen into a replayable proposal.

deployed

Execution, Decision & Learning

Immutable execution records feed NON_DECISION evaluations. DecisionPackets require human review, while LearningUpdates remain review-only and cannot automatically mutate evidence, datasets or models.

deployed

Data & Model Governance

Partner onboarding, blind custody, traditional baselines, artifact integrity, activation attestations and external capability admission now fail closed when lineage or evidence is incomplete.

Smoke Test Report

2026-08-02 | GCP production, FastAPI + Next.js 15.5.21
PASS1. Full Backend Regression~12s

pytest across the release snapshot

274/274 tests passed, including evidence, experiment design, decision-learning, data contracts, model activation and baseline evaluation.

PASS2. Frontend Production Build~20s local

Fresh npm install, security audit and next build

27 routes built; npm audit reported zero vulnerabilities after upgrading Next.js, PostCSS and sharp to patched versions.

PASS3. Production Route Smoke<5s

Internal checks for the new control-plane pages

/, /program, /evidence, /experiments and /decisions each returned HTTP 200 from the production web container.

PASS4. API Contract Check<2s

Production OpenAPI and blueprint verification

Program blueprint v3 and the execution, decision-packet and learning-update route families are present in production.

PASS5. Privacy & Database Boundary<1s

Identity denylist and runtime database isolation

No private research identity markers entered the application tree; deployment preserved the existing runtime database file.

Changelog (6 changes)
  • Added /program, /evidence, /experiments and /decisions product surfaces
  • Added Program, Evidence, CandidateSystem, ExperimentProposal, ExecutionRecord, EvaluationResult, DecisionPacket and LearningUpdate contracts
  • Added immutable SQLite persistence, digest revalidation and physical artifact custody
  • Added partner v2 onboarding, blinded custody, traditional baselines and model activation governance
  • Separated execution facts, rule evaluation, human approval authority and review-only learning
  • Added production database isolation, dependency security upgrades and route-level deployment smoke checks
v0.7.02026-07-09

Privacy-Safe Curation, Review Harness & Model Lifecycle Gates

Added the in vivo CAR-T curation cockpit and the first decision-review backend. Raw source links, local paths, and candidate-origin names are kept internal; the UI now exposes only internalized technical signals, evidence class, decision value, blockers, and next actions.

Features

deployed

Privacy-Safe Curation Page

New Curation entry for in vivo CAR-T delivery intelligence. The page presents target-hypothesis context, internalized prior work, competitive benchmarks, technical literature, review-harness status and upgrade decisions without exposing raw source locations.

deployed

Operational Review Workbench

Curation now includes an interactive candidate review console and model lifecycle gate. Users can submit a neutral candidate intake, run the ICL/verification/panel harness, and check whether calibration, adapters, fine-tuning or retraining are allowed.

deployed

Candidate Review Harness

New pipeline/review/ package with CandidateIntake, Claim Ledger, ICL gate wrapper, verification gates and static multi-agent review panel. APIs: /api/v1/review/intake/validate, /icl-gate, /verify, /run, /eval/run.

deployed

Verification & Eval Gates

Hard gates now catch uncited material claims, predicted-as-measured language, target-finality overclaim, in vivo CAR-T delivery overclaim, weak benchmark context and duplicate-source double counting.

deployed

Model Lifecycle Readiness

New pipeline/model_lifecycle/ package and /api/v1/model-lifecycle/* endpoints. Blocks premature fine-tuning or retraining when sample size, endpoint consistency, split strategy, formulation metadata or calibration reports are insufficient.

deployed

Architecture v6

New architecture_overview_v6.md documents the decision architecture, privacy-safe curation rules, review harness, eval suite and model lifecycle gate.

Smoke Test Report

2026-07-09 | Local FastAPI + Next.js production preview, Python 3.13, Next.js 15.5.14
PASS1. Review Infrastructure Tests<1s

pytest review and model-lifecycle test suites

9 tests passed across tests/test_review_infrastructure.py and tests/test_model_lifecycle.py.

PASS2. Review Eval API<1s

POST /api/v1/review/eval/run

5/5 deterministic eval cases passed: target uncertainty, evidence class, delivery overclaim, benchmark hygiene and source duplication.

PASS3. Model Lifecycle API<1s

GET /policy and POST /retrain/readiness

Policy endpoint returns calibration, adapter, ensemble retrain, AGILE fine-tune and formulation-model thresholds. Small AGILE fine-tune dataset is correctly blocked.

PASS4. Frontend Build~10s

next build

All 20 routes compiled successfully, including /curation, /architecture and /releases.

PASS5. Curation Exposure Scan<1s

Rendered /curation HTML checked for raw source exposure

No raw external source link, local filesystem path, or candidate-origin name appears in the rendered page.

Changelog (10 changes)
  • Added pipeline/review/ — intake schema, ICL gate, claim ledger, verification gates, static panel and eval suite
  • Added pipeline/api/review_routes.py — /api/v1/review endpoints
  • Added pipeline/model_lifecycle/ — dataset/model/calibration cards and retraining-readiness policy gates
  • Added pipeline/api/model_lifecycle_routes.py — /api/v1/model-lifecycle endpoints
  • Added tests/test_review_infrastructure.py and tests/test_model_lifecycle.py
  • Added web/src/app/curation/page.tsx with interactive candidate review and model lifecycle controls
  • Added review/model-lifecycle API client types and calls to web/src/lib/api.ts
  • Updated homepage navigation with Review Console, Model Lifecycle and Architecture entry points
  • Added architecture_overview_v6.md with privacy-safe decision architecture
  • Updated curation page to hide raw source links, local file paths and candidate-origin names
v0.6.02026-04-14

Safety Assessment, Multi-Tissue Tropism & AGILE Fine-Tuning

Added two new science modules: 4-dimensional safety/immunogenicity assessment (cytotoxicity, hepatotoxicity, hemolytic, immunogenicity) and multi-tissue tropism prediction (liver, spleen, lung, T-cell, DC) based on SORT mechanism and published SAR rules. Prepared AGILE GNN fine-tuning infrastructure with 2,219 ICL-specific training samples.

Features

deployed

Safety & Immunogenicity Assessment

New pipeline/safety/ module with 4-dimensional scoring: cytotoxicity (reactive groups, permanent charge), hepatotoxicity (biodegradability, CYP liability), hemolytic activity (amphiphilicity, charge density), immunogenicity (TLR motifs, complement activation). API: POST /api/v1/safety/assess.

deployed

Multi-Tissue Tropism Prediction

New pipeline/tropism/ module predicting organ selectivity (liver, spleen, lung, T-cell, DC) based on SORT mechanism (Cheng/Dilliard 2020-2021), pKa-driven charge ratio, PEG shielding, particle size, and tail saturation. Returns probability distribution + selectivity index. API: POST /api/v1/tropism/predict.

beta

AGILE Fine-Tuning Infrastructure

Data preparation pipeline extracting 2,219 ICL-specific training samples from lipid_master.db (80/10/10 split). Fine-tuning script ready for GPU execution. Activity range: -2.35 to 15.96 log RLU across HeLa + Raw264 assays.

Changelog (8 changes)
  • Created pipeline/safety/assessor.py — SafetyAssessor with 4 scoring dimensions + SMARTS-based structural analysis
  • Created pipeline/api/safety_routes.py — POST /assess and POST /batch endpoints
  • Created pipeline/tropism/predictor.py — TropismPredictor with Henderson-Hasselbalch charge model + organ-specific scoring
  • Created pipeline/api/tropism_routes.py — POST /predict endpoint with optional formulation params
  • Created scripts/finetune_agile.py — prepare/train/evaluate CLI with RDKit SMILES validation
  • Generated pipeline/screener/finetune/ — train.csv (1,775), val.csv (221), test.csv (223), metadata.json
  • Registered safety_router and tropism_router in pipeline/api/main.py
  • Added assessSafety() and predictTropism() to web/src/lib/api.ts
v0.5.02026-04-13

pKa Prediction v2, SISSO Validation & Lin Conformation Data

Science-depth upgrade: improved pKa estimation using RDKit descriptors (MAE 0.32 vs ~1.3), validated SISSO 6-model reproduction (<5% RMSE deviation), and imported Lin et al. 121 lipid conformation density maps with 22-dimensional SISSO features. Architecture document v4 with version switching.

Features

deployed

pKa Prediction v2

Replaced linear heuristic with RDKit-based model using LogP, TPSA, MW, Gasteiger partial charges, and EWG counting. Calibrated against SM-102 (6.44 vs 6.68), MC3 (6.61 vs 6.44), KC2 (6.61 vs 6.70). MAE reduced from ~1.3 to 0.32.

deployed

SISSO Feature Extraction — Validated

sisso_repro module fully functional: 22-dimensional geometric features from XZ/YZ density maps, 6 symbolic regression models (Model 7/8/9/12/15/17). All models reproduce within <5% RMSE of Lin et al. published results.

deployed

Lin 121 Conformation Data Import

Imported 121 lipid conformation records (XZ/YZ density map file paths), 121 transfection activity values (RLU), and 121 SISSO 22-dimensional feature vectors into descriptors table. Database: 1,338 lipids, 121 conformations.

deployed

Architecture v4 + Version Switcher

New architecture_overview_v4.md with closed-loop pipeline, pKa v2, SISSO, and deployment sections. Frontend version dropdown defaults to latest, preserves all previous versions (v1–v4).

deployed

JWT Auth Removal

Removed all JWT Bearer token references from frontend (agent, formulation, conjugation, validator, settings, mRNA pages). Platform uses HTTP Basic Auth exclusively.

Smoke Test Report

2026-04-13 | GCP VM, Docker stack, conda icl-discovery, RDKit 2024.03
PASS1. pKa Validation<1s

Test pKa predictions against 4 FDA benchmark lipids

SM-102: 6.44 (lit 6.68, err -0.24), MC3: 6.61 (lit 6.44, err +0.17), KC2: 6.61 (lit 6.70, err -0.09). MAE 0.32.

PASS2. SISSO Feature Extraction3s

Extract 22 features from 121 density maps

121 lipids x 22 features extracted. Output matches sisso_features.csv (pre-validated).

PASS3. SISSO Model Reproduction2s

6 symbolic regression models predict pKa within literature RMSE

All 6 models: max RMSE deviation 4.2% (Model 8). Models 9/12/15/17 at 0.0% deviation.

PASS4. Conformation Data Import5s

121 conformations, activities, and SISSO features into DB

DB: 1,338 lipids (+122), 121 conformations (was 0), 121 SISSO features (was 0), ~4,700 activities.

PASS5. Agent Mode (JWT cleanup)2s

Agent chat works without JWT token after auth cleanup

All pages use browser basic auth. No Bearer null headers. Agent streaming functional.

Changelog (7 changes)
  • Rewrote pipeline/scoring/validator.py _estimate_pka() — RDKit descriptors + Gasteiger charges
  • Created scripts/import_lin_conformations.py — bulk import 121 lipids + conformations + SISSO features
  • Validated pipeline/sisso_repro/ — feature_extractor.py (22 features) + predictor.py (6 models)
  • Created architecture_overview_v4.md with closed-loop, pKa v2, SISSO, deployment sections
  • Removed JWT Bearer token from all frontend pages: agent, formulation, conjugation, validator, settings, mrna
  • Replaced login/page.tsx with basic auth info page
  • Cleaned api.ts — removed getToken, login, register, getMe, logout functions
v0.4.02026-04-13

Closed-Loop Discovery Pipeline & GCP Deployment

Major platform upgrade: closed-loop ICL discovery with automatic seed extraction from scored candidates, synthesis candidate triage (validator grade B+ threshold), and wet-lab data feedback integration. Migrated deployment from ECS to GCP VM with Docker 3-service stack. Comprehensive science audit with reference lipid data seeding.

Features

deployed

Closed-Loop Seed Extraction

New API endpoint GET /exports/{run_id}/seeds extracts top-scored SMILES from completed runs. Pipeline page 'Seed from Previous Run' selector lets users load candidates from any prior run as seeds for the next iteration — closing the generate→score→seed loop.

deployed

Synthesis Candidate Triage

Results page now includes a 'Synthesis Candidates' section. Runs the 7-dimension validator on scored candidates and shows those graded B+ or above with composite score, predicted pKa, and synthesis action. Direct links to seed next run or inject wet-lab data.

deployed

Discovery Loop Visualization

Results page shows the full closed-loop flow: Score → Triage → Synthesize → Validate → Next Iteration. Each step links to the relevant platform action.

deployed

GCP Docker Deployment

Migrated from ECS to GCP VM (iaso-research-platform) with 3-service Docker stack (FastAPI API, Next.js frontend, nginx reverse proxy) on port 8090. System nginx proxies lnp.iaso-research.com with Let's Encrypt SSL.

deployed

FDA Reference Lipid Data

Seeded published activity data for SM-102, ALC-0315, DLin-MC3-DMA, DLin-KC2-DMA: pKa, particle size, PDI, encapsulation efficiency, zeta potential from Hassett 2019, Schoenmaker 2021, Jayaraman 2012, Semple 2010.

deployed

Science Audit Fixes

Chemical Space page: replaced mock SAR data with proper awaiting-data state. Library page: removed disabled enumerate button, show real reagent inventory. Basic auth user display in sidebar.

Smoke Test Report

2026-04-13 | GCP VM us-west1-b, Docker (micromamba + node:20-alpine + nginx:alpine), Next.js 15.5.14
PASS1. Docker Stack Health35s

All 3 containers running, health check returns 200

lnp-api (healthy), lnp-web (running), lnp-nginx (running). curl http://127.0.0.1:8090/health → {status: ok}.

PASS2. SSL & Auth<1s

HTTPS with Let's Encrypt cert, basic auth working

Certificate and the historical password boundary were verified without publishing credential material.

PASS3. Seed Extraction API<1s

GET /exports/{run_id}/seeds returns SMILES from scored CSV

Returns top candidates with scores, sorted descending. Supports min_score filter and max_count.

PASS4. Synthesis Triage API~20s

GET /exports/{run_id}/synthesis-candidates validates and grades candidates

Runs 7-dimension validator on each candidate. Caches results to synthesis_candidates.json. Returns grade, composite, pKa, synthesis action.

PASS5. Reference Data Seeding<1s

4 FDA benchmark lipids with full characterization data in DB

SM-102 (pKa=6.68, EE=93%), ALC-0315 (pKa=6.09, EE=97%), MC3 (pKa=6.44, EE=95%), KC2 (pKa=6.70, EE=90%).

PASS6. Port Isolation<1s

All VM services on separate ports, no conflicts

antibody:8080, lnp:8090, system nginx:80/443. All health checks pass independently.

Changelog (12 changes)
  • Added pipeline/api/exports.py — GET /{run_id}/seeds and GET /{run_id}/synthesis-candidates endpoints
  • Updated web/src/app/pipeline/page.tsx — 'Seed from Previous Run' dropdown with auto-load from URL param
  • Updated web/src/app/results/page.tsx — Synthesis Candidates triage table + Discovery Loop visualization
  • Updated web/src/lib/api.ts — extractSeeds(), getSynthesisCandidates() functions
  • Created scripts/seed_reference_activities.py — FDA reference lipid data seeding
  • Migrated .github/workflows/ from ECS to GCP IAP tunnel deploy (rsync + docker compose)
  • Created deploy/ — nginx.conf (3-upstream proxy), htpasswd (basic auth)
  • Created web/Dockerfile.web — multi-stage Next.js standalone build
  • Rewrote docker-compose.prod.yml — 3-service stack (api, web, nginx) on 127.0.0.1:8090
  • Fixed Chemical Space page — removed mock SAR data, clear ensemble prerequisite messaging
  • Fixed Library page — removed disabled enumerate button, show real reagent names
  • Fixed nginx HTTPS redirect loop — separated 443/80 server blocks
v0.3.02026-04-08

Full-Stack Smoke Test & Deployment Pipeline

Comprehensive smoke test across all 15 pages. Fixed critical bugs including CSV upload (422 error), missing library endpoints, auth state masking, and CSV parsing for SMILES with commas. Established CI/CD pipeline for ECS deployment with IAP tunnel pattern.

Features

deployed

15-Page Smoke Test — All Pass

Complete page-by-page verification: Overview, Pipeline, Runs, Results, Formulation, mRNA, Conjugation, Iterations, Chemical Space, Library, Agent, Architecture, Settings, Login, 404. 0 TypeScript errors, 0 build warnings.

deployed

Library Endpoints

New GET /api/v1/library/stats and GET /api/v1/library/reagents endpoints. Queries lipid_master.db for real-time stats (1,216 lipids, ~4,600 activities). Previously returned 404.

deployed

CSV Upload Fix (Iterations)

Rewrote /inject-data from JSON body to multipart/form-data UploadFile. Frontend sends CSV via FormData — old endpoint returned 422 on every attempt. Critical for active learning loop.

deployed

CI/CD Deployment Pipeline

GitHub Actions workflow with IAP tunnel to GCP VM. SSH key-based deploy, docker-compose.prod.yml with localhost-only port binding, nginx reverse proxy with SSL.

deployed

Release Notes Page

This page — platform update documentation with feature descriptions, smoke test reports, and verification records for each release.

Smoke Test Report

2026-04-08 | Next.js 15.5.14, React 19.1.0, Tailwind CSS 4.1, SQLite WAL
PASS1. Build & Compile12s

next build — all 15 pages compile with 0 errors

0 TypeScript errors. 0 build warnings. All static + dynamic pages generated successfully.

PASS2. API Health Check<1s

GET /health returns {status: ok}

FastAPI startup complete. Users table auto-created. 37 endpoints registered across 12 modules.

PASS3. Auth Flow1s

Register, login, JWT token, /me endpoint

JWT issued with 30-day expiry. Sidebar correctly shows username when authenticated, 'Sign in' when not.

PASS4. Pipeline Submit2s

SMILES input, parameter config, run submission

Run created with unique ID. Progress streaming via polling. Cancel and resume functional.

PASS5. CSV Upload (Iterations)1s

File upload via multipart/form-data to /inject-data

Previously returned 422. Fixed: endpoint now accepts UploadFile. CSV parsed correctly including SMILES with commas.

PASS6. Library Stats<1s

GET /api/v1/library/stats and /reagents

Returns real DB stats: 1,216 lipids, 4,600+ activities. Reagent inventory with type filter. Previously 404.

PASS7. Agent Chat3s

Thread create, message send, markdown response

Requires API key configured in Settings. Thread persistence in SQLite. Suggested prompts functional.

Changelog (9 changes)
  • Added pipeline/api/library_routes.py — GET /api/v1/library/stats and /reagents endpoints
  • Fixed pipeline/api/iteration_routes.py — /inject-data now accepts multipart/form-data UploadFile
  • Fixed web/src/app/results/page.tsx — proper CSV parser for quoted fields (SMILES with commas)
  • Fixed web/src/components/sidebar.tsx — removed hardcoded fallback user, proper auth state display
  • Fixed web/src/app/formulation/page.tsx — validation preventing submission when percentages != 100%
  • Fixed web/src/app/architecture/page.tsx — TypeScript JSX union type error
  • Added CI/CD: GitHub Actions workflow with IAP tunnel, docker-compose.prod.yml
  • Added python-multipart dependency for FastAPI Form() handlers
  • Unignored web/src/lib/ for CI build to resolve @/lib/api imports
v0.2.02026-04-05

Next.js Frontend & TransMA Training Complete

Migrated frontend from Streamlit to Next.js 15 + React 19 with full-featured UI. Completed TransMA model training for lipid property prediction. Built 15 pages covering the complete ICL discovery workflow from pipeline submission to formulation design.

Features

deployed

Next.js 15 Frontend

Complete migration from Streamlit to Next.js 15 + React 19 + Tailwind CSS 4. 15 pages with consistent design system, sidebar navigation, JWT authentication, and responsive layout.

deployed

TransMA Model Training

3D Transformer + Mamba architecture trained for lipid property prediction. Ensemble of 5 models for uncertainty quantification. CPU-only inference strategy for 16GB RAM.

deployed

AI Agent Chat

Claude-powered chat interface with thread persistence, suggested prompts, and markdown rendering. Integrated at /agent with animated gradient border effect.

deployed

Architecture Documentation

Comprehensive v3 architecture document served via API endpoint. TOC sidebar with intersection observer for scroll-tracking, collapsible sections, anchor navigation.

deployed

Formulation DOE Module

LNP formulation design-of-experiments with component percentage sliders, validation, prediction, and optimization suggestions.

deployed

mRNA Design Module

Protein-to-FASTA workflow with tissue selector, modification options, poly(A) configuration, quality metrics, and downloadable FASTA output.

Changelog (7 changes)
  • Built web/ directory: Next.js 15 + React 19 + Tailwind CSS 4 + TypeScript
  • Created 15 page components: Overview, Pipeline, Runs, Results, Iterations, Chemical Space, Library, Validator, Formulation, mRNA, Conjugation, Agent, Architecture, Settings, Login
  • Built pipeline/api/ with FastAPI: 37 endpoints across 12 route modules
  • Completed TransMA training — 5-model ensemble for uncertainty quantification
  • Added lipid_db/lipid_master.db with 1,216 lipids and ~4,600 activities
  • Created architecture_overview_v3.md (76KB comprehensive platform documentation)
  • Configured Next.js rewrite proxy for API calls in development
v0.1.02026-04-03

Platform Foundation & ML Pipeline

Initial scaffold of the ICL Discovery Platform. 5-stage ML pipeline (SISSO → Generate → Screen → Conformer → Score) with LSTM generation, AGILE GNN screening, RDKit conformer generation, and TransMA scoring. FastAPI backend with SQLite database.

Features

deployed

5-Stage ML Pipeline

DAG-based pipeline: SISSO feature extraction → LSTM molecular generation → AGILE GNN screening (top 500) → RDKit ETKDG conformer generation → TransMA scoring (top 20).

deployed

External Model Integration

Integrated 4 external models: SISSO (Fortran, symbolic regression), AGILE (PyTorch GNN, 60k compound pretrained), TransMA (3D Transformer + Mamba), REINVENT4 (generative). Bootstrap script for automated setup.

deployed

FastAPI Backend

REST API with JWT authentication, run management (CRUD + progress + cancel/resume), exports (CSV/SDF), and system status monitoring.

deployed

SQLite Database

WAL-mode SQLite at lipid_db/lipid_master.db. Tables: lipids, activities, sources, conformations, iterations, iteration_results, users, settings, agent_plans, agent_threads.

deployed

Conda Environment

Reproducible icl-discovery conda env: Python 3.11, PyTorch CPU, PyTorch Geometric, RDKit, OpenBabel, gfortran, openmpi. Single environment.yml for all dependencies.

Changelog (9 changes)
  • Initial project scaffold with pipeline/, web/, lipid_db/, external/ structure
  • Created pipeline_config.yaml — 5-stage DAG definition with model configs
  • Built pipeline stages: sisso_stage, generate_stage, screen_stage, conformer_stage, score_stage
  • Integrated SISSO, AGILE, TransMA, REINVENT4 as git submodules/externals
  • Created FastAPI backend (pipeline/api/main.py) with auth, runs, exports, status
  • Set up SQLite database with comprehensive schema for lipid data
  • Created environment.yml and setup_env.sh for reproducible environment setup
  • Added Dockerfile and docker-compose.yml for containerized deployment
  • Created Makefile with dev, api, web, stop, restart targets