Safety
DiveSuite is life-critical software. Incorrect decompression calculations can cause serious injury or death. This section documents our safety architecture, principles, and practices.
Safety Principles
Section titled “Safety Principles”- Deco Engine Isolation – All decompression calculations happen in one isolated Rust crate with a 95%+ test coverage target. Rust becomes the only deco engine with D27 (planned); today a TypeScript plan fallback still computes plans on every platform, within its refusal scope
- AI Never Overrides – AI is advisory only. AI cannot generate, modify, or override decompression schedules
- Disclaimers Always Accessible – Every plan output carries the safety disclaimer. It may use progressive disclosure (a compact hint with expandable detail, or a one-time acknowledgment stored in settings), but it is never removed
- Warnings Are Never Dismissible – Gas reserve, ppO2, ICD and other active safety warnings are always visible
- Refuse Instead of Guessing – The fallback refuses every input it cannot model. Planned (D27): if no Rust engine runs, DiveSuite shows a persistent “engine unavailable” card and no plan, value or warning
- Validation Required – Deco calculations are validated against Subsurface and the published tables before release
- Offline Must Work – Core safety features work without internet. AI features degrade gracefully when offline
Documents
Section titled “Documents”| Document | Description |
|---|---|
| Safety Principles | Core safety architecture and rules |
| Deco Engine | Buhlmann implementation, engine availability, validation |
| AI Boundaries | What AI can and cannot do |
| Disclaimers | Required disclaimer text and placement |
Safety Architecture
Section titled “Safety Architecture”graph TB subgraph "User Input" UI[User Interface] AI[AI Suggestions] end
subgraph "Validation Layer" V[Parameter Validation] end
subgraph "Deco Engine" DE[Rust engine<br/>Buhlmann ZHL-16C] end
subgraph "Output" D[Disclaimer] P[Plan Output] end
UI --> V AI -->|"treated as<br/>unverified input"| V V -->|"validated params"| DE DE --> D D --> P
style AI fill:#fff3cd style DE fill:#d4edda style D fill:#f8d7daRisk Register (Safety-Related)
Section titled “Risk Register (Safety-Related)”| Risk | Severity | Status |
|---|---|---|
| RISK-01: Deco calculation incorrectness | Critical | Open |
| RISK-04: AI safety boundary violation | High | Partial |
| RISK-09: No independent deco review | High | Open |
Testing Requirements
Section titled “Testing Requirements”Deco Engine (Mandatory)
Section titled “Deco Engine (Mandatory)”- 95%+ branch coverage
- Property-based tests (proptest) for invariants:
- NDL never grows with depth
- Gas consumption is always positive
- No-fly time is never negative
- Hostile input is refused and the solver always terminates
- Validation against Subsurface (same algorithm): deco schedules within 1 min per stop and 2 min total runtime, no-stop limits within 1 min
- Published tables (PADI RDP, US Navy, NOAA) as an upper bound: the engine’s NDL is never longer than the shortest published value at the same depth
AI Safety (Mandatory)
Section titled “AI Safety (Mandatory)”- AI cannot suggest exceeding MOD
- AI cannot suggest exceeding NDL
- AI cannot suggest ppO2 > limits
- All AI output includes disclaimer
- Kill switch (CC-15) completely disables AI