Koch Laboratory

Laborbuch — evidence-grade R&D time records

R&D time records for the German research allowance with a cryptographic chain of evidence: append-only, dual timestamping, self-hosted.

An electronic R&D journal designed to pass an audit — not merely survive one. Time records for the German research allowance (FZulG/BSFZ) with a cryptographic chain of evidence.

Why not a spreadsheet?

A spreadsheet can be rewritten yesterday — and the auditor knows it. In Laborbuch, every working week is closed cryptographically: the canonical record of entries is hashed (SHA-256) and timestamped through two channels at once — the BeatTime service (Ed25519 signature, Merkle tree) and OpenTimestamps anchored in the Bitcoin blockchain. BeatTime is our own service, and we say so plainly — which is why its log does not attest to itself: the root of every closed week is anchored externally, in the Bitcoin blockchain and in the reference line of a transfer booked by Swissquote Bank SA, and both anchors are published. Even the “own” channel therefore ends in registers that neither the vendor nor you control. Closed entries can be neither modified nor deleted; mistakes are corrected the way accountants do it — by storno, preserving the original. The proof of immutability is verifiable independently of the system and survives even its total loss.

Capabilities

Defensible records. Append-only entries separating work date from recording date, two recording regimes (same-day / marked reconstruction), hard limits following the FZulG methodology (a personal weekly cap — 40 h by default, adjustable per account to the contracted hours — and 20 hours per day), explicit demarcation of R&D from routine — non-research work is documented without inflating the records.

Records that cap themselves. R&D hours worked above the weekly cap are declared explicitly as not claimed: they stay in the journal with their anchors, but count towards neither the cap nor the basis of the application. Records that cut their own hours read differently from records where every week ends exactly at the maximum.

Chain of evidence. Anchors that substantiate entries: Git commits (synced automatically), evidence files with SHA-256 hashes (scans, measurement data, photos), or hash-only mode — the file never leaves your computer; the system stores only its fingerprint. Every anchor’s hash goes under the weekly timestamp.

Auditor-ready reports. Stundenaufzeichnung (with automatic translation of entries into German), the descriptive basis for a BSFZ application, PDF and CSV export. Colleagues’ hours are masked between users — including in exports.

Team work. An account per employee, each with its own weekly cap (contracted hours) and default project membership — a new person records from day one, with no configuration. The R&D lead gets the report broken down by person; between employees the hours stay masked, exports included.

Security. Per-user 2FA (app, hardware TOTP card, or e-mail code), AES-256-GCM encryption of evidence files, an append-only read-access journal (who viewed which reports and when), brute-force lockout, optional Tor access.

Privacy by design. Self-hosted: your data never leaves your infrastructure. Timestamping services see only hashes — never content. Public site with no cookies, no analytics, no third-party requests.

Laboratory profiles. IT (Git integration), wet-lab (evidence files), hardware (both) — switchable in the admin panel, no code changes.

Verifiable delivery. Every release image is published to two registries (ghcr.io and Docker Hub) and signed with cosign keyless — the signature is produced in a public GitHub Actions run, with no key in the vendor’s hands. You check it with a single command before starting the instance:

cosign verify ghcr.io/deiflagellum/laborbuch:X.Y.Z \n  --certificate-identity-regexp 'github.com/DeiFlagellum/laborbuch' \n  --certificate-oidc-issuer https://token.actions.githubusercontent.com

Operation without a console. Database backups — create, download, restore — from the admin panel (installations with the built-in database). An update is a new image tag and a container restart; the procedure is in the administrator manual.

Purchasing model

Pricing and terms

Plan Scope Net price / year
Solo up to 3 active accounts €590
Lab up to 10 active accounts €1,490
Institute unlimited accounts, priority support €2,990

Compliance and documents

Documentation for your compliance team (in German): TOM — technical and organisational measures (Art. 32 GDPR), DPA template (AVV), GoBD retention statement.

Contact

Advena Partners, Inh. Adam Koch, Weißensteinstr. 44, 58093 Hagen — info@dms-secure.de