Zo controleert u ons

Technische notitie voor DPO's, ondernemingsraden en auditors — versie juli 2026.

Scope

Deze notitie beschrijft de integriteits- en anonimiteitsmechanismen van het DIEP Cloud-platform (waarop Fairwind draait) en de verificatiestappen die een externe partij zelfstandig kan uitvoeren. Inhoudelijke audits (configuratie, verwerkingsbeschrijving, steekproeven) vallen onder de verwerkersovereenkomst met uw organisatie.

Architectuur van het auditspoor

  • Elke verwerkingsstap (ontvangst, verwerking, aggregatie, rapportgeneratie) schrijft een record naar een append-only auditlog. Records zijn cryptografisch geketend; wijziging of verwijdering achteraf breekt de keten.
  • Dagelijks wordt een checkpoint (keten-kop) berekend en ondertekend met een Ed25519-sleutelpaar; de publieke sleutel wordt aan klanten en hun auditors verstrekt.
  • Elk checkpoint krijgt een tijdstempel-token van een onafhankelijke Europese tijdstempelautoriteit conform RFC 3161.

Verificatieprocedure

Benodigd: de publieke sleutel, de checkpoint-reeks en de tijdstempel-tokens; verstrekking tijdens een auditafspraak.

  1. Verifieer de Ed25519-handtekening op elk checkpoint met standaardtooling.
  2. Valideer het RFC 3161-token tegen het certificaat van de tijdstempelautoriteit (o.a. openssl ts).
  3. Controleer dat opeenvolgende checkpoints op dezelfde keten aansluiten.

Een geslaagde verificatie toont aan dat het auditspoor bestond op het gestempelde tijdstip en nadien niet herschreven is.

Reikwijdte. Deze verificatie dekt het bestaan en de integriteit van het auditspoor sinds elk checkpoint. Zij dekt niet de semantische juistheid van individuele verwerkingsstappen; daarvoor bestaat de inhoudelijke audit onder de verwerkersovereenkomst.

Anonimiteitsmechanismen

  • Toelating zonder identiteit. Deelname verloopt via blinde handtekeningen (RFC 9474, blind-RSA): de uitgifte bewijst gerechtigdheid tot deelname; de inzending is cryptografisch niet aan het uitgiftemoment te koppelen.
  • Eén inzending per ronde. Een nullifier maakt dubbele inzendingen binnen dezelfde vraagronde detecteerbaar zonder de inzender te identificeren.
  • k-anonimiteitsdrempel. Aggregaties en rapporten onder de minimale groepsgrootte worden niet berekend en niet getoond; de drempel is afgedwongen in de code.
  • Tekstverwerking. De ruwe tekst van open antwoorden wordt na verwerking vernietigd. Opgeslagen afgeleiden zijn betekenisrepresentaties waaruit persoonsgegevens automatisch worden gefilterd (NER-scrubbing); omdat zulke filtering een restrisico kent, wordt ze aangevuld met de k-drempel op elke weergave.
  • Geen koppeling. Het systeem slaat geen naam, account of persoonsidentificator op bij een antwoord.

Auditafspraak

Voor inzage in checkpoints, publieke sleutels en de verwerkingsbeschrijving: plan een afspraak — wij lopen de verificatie samen met uw auditor door.

Referenties: RFC 3161 (Time-Stamp Protocol) · RFC 9474 (RSA Blind Signatures) · privacyverklaring.

How to verify us

Technical note for DPOs, works councils and auditors — version July 2026.

Scope

This note describes the integrity and anonymity mechanisms of the DIEP Cloud platform (on which Fairwind runs) and the verification steps an external party can perform independently. Content-level audits (configuration, records of processing, sampling) fall under the data processing agreement with your organisation.

Architecture of the audit trail

  • Every processing step (intake, processing, aggregation, report generation) writes a record to an append-only audit log. Records are cryptographically chained; later modification or removal breaks the chain.
  • Every day a checkpoint (chain head) is computed and signed with an Ed25519 key pair; the public key is provided to customers and their auditors.
  • Each checkpoint receives a timestamp token from an independent European timestamping authority, conforming to RFC 3161.

Verification procedure

Required: the public key, the checkpoint series and the timestamp tokens; provided during an audit appointment.

  1. Verify the Ed25519 signature on each checkpoint with standard tooling.
  2. Validate the RFC 3161 token against the timestamping authority's certificate (e.g. openssl ts).
  3. Check that consecutive checkpoints extend the same chain.

A successful verification shows that the audit trail existed at the stamped time and has not been rewritten since.

Reach. This verification covers the existence and integrity of the audit trail since each checkpoint. It does not cover the semantic correctness of individual processing steps; that is what the content-level audit under the processing agreement is for.

Anonymity mechanisms

  • Admission without identity. Participation uses blind signatures (RFC 9474, blind RSA): issuance proves entitlement to participate; the submission cannot be cryptographically linked to the issuance moment.
  • One submission per round. A nullifier makes duplicate submissions within the same question round detectable without identifying the submitter.
  • k-anonymity threshold. Aggregations and reports below the minimum group size are not computed and not shown; the threshold is enforced in code.
  • Text processing. The raw text of open answers is destroyed after processing. Stored derivatives are meaning representations from which personal data is filtered automatically (NER scrubbing); because such filtering carries a residual risk, it is complemented by the k-threshold on every display.
  • No linkage. The system stores no name, account or personal identifier with an answer.

Audit appointment

For access to checkpoints, public keys and the records of processing: book an appointment — we walk through the verification together with your auditor.

References: RFC 3161 (Time-Stamp Protocol) · RFC 9474 (RSA Blind Signatures) · privacy notice.

Comment nous vérifier

Note technique pour DPO, conseils d'entreprise et auditeurs — version juillet 2026.

Portée

Cette note décrit les mécanismes d'intégrité et d'anonymat de la plateforme DIEP Cloud (sur laquelle tourne Fairwind) et les étapes de vérification qu'une partie externe peut exécuter de manière autonome. Les audits de fond (configuration, registre des traitements, échantillonnage) relèvent du contrat de sous-traitance avec votre organisation.

Architecture de la piste d'audit

  • Chaque étape de traitement (réception, traitement, agrégation, génération de rapports) écrit un enregistrement dans un journal d'audit en append-only. Les enregistrements sont chaînés cryptographiquement ; toute modification ou suppression ultérieure rompt la chaîne.
  • Chaque jour, un checkpoint (tête de chaîne) est calculé et signé avec une paire de clés Ed25519 ; la clé publique est remise aux clients et à leurs auditeurs.
  • Chaque checkpoint reçoit un jeton d'horodatage d'une autorité d'horodatage européenne indépendante, conformément à la RFC 3161.

Procédure de vérification

Nécessaire : la clé publique, la série de checkpoints et les jetons d'horodatage ; fournis lors d'un rendez-vous d'audit.

  1. Vérifiez la signature Ed25519 de chaque checkpoint avec des outils standard.
  2. Validez le jeton RFC 3161 contre le certificat de l'autorité d'horodatage (p. ex. openssl ts).
  3. Contrôlez que les checkpoints successifs prolongent la même chaîne.

Une vérification réussie démontre que la piste d'audit existait au moment horodaté et n'a pas été réécrite depuis.

Portée. Cette vérification couvre l'existence et l'intégrité de la piste d'audit depuis chaque checkpoint. Elle ne couvre pas la justesse sémantique des étapes de traitement individuelles ; c'est l'objet de l'audit de fond prévu par le contrat de sous-traitance.

Mécanismes d'anonymat

  • Admission sans identité. La participation passe par des signatures aveugles (RFC 9474, blind RSA) : l'émission prouve le droit de participer ; la soumission ne peut pas être reliée cryptographiquement au moment d'émission.
  • Une soumission par tour. Un nullifier rend les soumissions en double détectables au sein d'un même tour de questions, sans identifier leur auteur.
  • Seuil de k-anonymat. Les agrégations et rapports sous la taille de groupe minimale ne sont ni calculés ni affichés ; le seuil est imposé dans le code.
  • Traitement du texte. Le texte brut des réponses ouvertes est détruit après traitement. Les dérivés conservés sont des représentations de sens dont les données personnelles sont filtrées automatiquement (NER scrubbing) ; ce filtrage comportant un risque résiduel, il est complété par le seuil k à chaque affichage.
  • Aucun couplage. Le système n'enregistre ni nom, ni compte, ni identifiant personnel avec une réponse.

Rendez-vous d'audit

Pour l'accès aux checkpoints, aux clés publiques et au registre des traitements : planifiez un rendez-vous — nous parcourons la vérification avec votre auditeur.

Références : RFC 3161 (Time-Stamp Protocol) · RFC 9474 (RSA Blind Signatures) · déclaration de confidentialité.