Apps · Signet

Consent that survives the claim

Paper consent gets signed in the chair thirty seconds before treatment, scanned late, or lost — which is exactly the consent that collapses when it is questioned. Signet turns it into a ceremony: the wording is pinned to a version, the patient reads it on their own phone, answers two questions about it, and both signatures are sealed into a receipt before anything begins.

v7 wording, pinned by hash the receipt hashes the text, not the version number — edit the template tomorrow and yesterday's receipt still names what was read
2 comprehension answers marked in the clinician's browser against a key the phone is never sent
0 readable bytes on our servers the record is encrypted in the clinic's browser; the key never leaves it
ECDSA signed chain the receipt verifies offline, years later, against a published key
How it works

Four steps, in that order, enforced

The order is the product. A signature collected before the wording was pinned, or a seal written while a question was still wrong, would be a worse record than paper.

  • Admit. A phone that reaches the chair sees nothing until the clinician admits it, and a second phone is refused — one chair, one patient, so a receipt is never ambiguous about whose consent it is.
  • Offer. The template travels with its wording. What the patient reads is what gets hashed.
  • Sign. Answers and signature go from the phone to the clinician's browser over their own connection — addressed, never broadcast to the room.
  • Seal. Only when every answer is right and the clinician has countersigned. A wrong answer is not a fail — it is "explain it again", and the button says so.
What the patient holdstheir own phone, no app
  Bright Smile Dental
  Wisdom tooth extraction, lower left

  Consent template v7
  ─────────────────────────────────
  Risks include prolonged bleeding,
  dry socket, and temporary or —
  rarely — permanent numbness of
  the lip or tongue.

  Which of these is a known risk?
   ( ) A change in eye colour
   (•) Numbness that can persist

  ┌──────────────────────────────┐
  │   sign with your finger      │
  └──────────────────────────────┘

        [     I consent      ]
The split that makes it work

A receipt anyone can check, over a record nobody can read

Two different things happen when a ceremony is sealed, and keeping them apart is the whole design.

Sealingone tap, two destinations
The recordname, answers, both signatures — encrypted in the clinic's browser and stored as ciphertext. The key is never sent anywhere, so the platform holds bytes it cannot read.
The receiptthe hash of that record, the template version and hash, and the counts — written into a signed, append-only chain. It carries no patient data and can be handed to anybody.
The key filedownloaded separately, on purpose. A receipt that carried the decryption key would hand over the record with it.

Why it wins the claim, not just the signature

Generic e-signature proves that somebody signed something. When consent is disputed the questions are different: which version of the wording was in front of them, did they understand the risk they are now complaining about, and was the clinician actually there. The sealed record answers all three, and the chain says it has not been edited since — including by us.

Weakest point, stated

E-signature is a brutal commodity, and no insurer has tested this receipt format. The party who decides what counts as adequate consent evidence is the indemnity insurer, so the route to market runs through them rather than around them. The claim here is "better evidence" — never "insurer-approved" until one has said so.

And encryption cuts both ways: a clinic that loses its record key loses the record. The key file is offered the moment a ceremony is sealed for exactly that reason, and key recovery is a first-class feature on the roadmap rather than a footnote.

Pricing

What it costs

Commercial — per clinician, per month

A seat per clinician. The licence is checked at the chair and a seat is taken when the console opens; re-opening a seat you already hold always succeeds, so closing a laptop never locks a colleague out.

Without a licence the ceremony still runs and every receipt it writes is stamped licensed:false — a trial that produced receipts indistinguishable from paid ones would be worth less than no trial.

How it's built

The part that matters, in the open

The record is encrypted into Vault; only its hash goes on the Attest chain. The receipt is shareable, the record is not readable — by anyone, us included.

js/console.js
async storeRecord(record) {
    const text = SG.canonical(record);
    const blob = new Blob([text], { type: 'application/json' });
    const put = await this.channel.vaultPut(blob, { ttlSeconds: 30 * 24 * 3600 });
    return { blobId: put.blobId, key: put.key, bytes: text.length };
}

Taken from this app's source, not written for the page. Built on the Messaging Platform SDK.