AI-Karma

Self-assessment v0.6 · 2026-08-09 · recomputed at every deployment

Our own KarmaScore, published

An assessment tool must accept being assessed — by itself, publicly, against the same 24 indicators as everyone else. Here are our score, our justified answers, our register of AI systems and our dated commitments. When we improve, this page changes; when it does not change, we have not made progress.

Global score75out of 100✓ Eligible for the label, at the “self-assessed” level only: for the “audited” level we are waiting for a third-party sincerity audit
T · Technology87.5
C · Compliance79.2
E · Environment54.2
S · Society62.5

Our 24 answers, justified

Sector applied: Digital & AI, with the following weighting: Technological 35 %, Compliance 30 %, Environmental 15 %, Societal 20 %. Every level is verifiable: the calculation can be reproduced from the formula and the weightings published on the methodology page.

IndicatorLevelJustification
Inventory of AI and digital systems4/4Our AI systems are publicly inventoried below, with an owner.
Explainability of automated decisions4/4The score is exactly decomposable; every report states whether it was written by AI or from a template.
Basic IT security3/4Written and applied security policy (docs/SECURITE.md): inventory and rotation of the four secrets, two-factor access, security headers and CSP applied, backups with restoration exercised, incident response. No external audit yet.
Data governance3/4Minimisation by design: assessments live in the browser, there is no database.
Human oversight4/4Product principle: the AI suggests, the human validates. No AI content is served without a guardrail.
Control over AI vendors3/4A 7-criteria grid (location, data processing agreement, use of data, certifications, reversibility, footprint) applied to our four processors: Anthropic, Vercel, Resend, Upstash (docs/FOURNISSEURS.md).
Record of processing activities3/4Exempt (Art. 12(5) FADP) but kept anyway: 6 documented processing activities, annual review (docs/REGISTRE_TRAITEMENTS.md).
Informing data subjects4/4Published, tailored policy, explicitly mentioning AI uses, processors and transfers (/confidentialite).
Impact assessments (DPIA)3/4Pre-screening documented and applied to every processing activity (4 criteria of Art. 22 FADP); trigger identified for future server-side persistence.
AI Act applicability and classification4/4Applicability checked, use cases classified, legal monitoring versioned (see Methodology).
Data subject rights3/4Process for exercising rights documented in the privacy policy (reply within 30 days).
Staff training2/4One-person structure: continuous monitoring and training of the founder, not formalised.
Low-footprint hosting2/4Energy profile of the host documented (Vercel/AWS, renewable through offset purchasing); migration to a certified Swiss cloud still to be decided (public page /empreinte).
Measuring the digital footprint2/4First estimate published with explicit method and assumptions (around 10-15 kg CO2e per year at prototype stage), public page /empreinte, updated quarterly.
Hardware life cycle2/4Hardware kept for a long time, without a written policy.
Digital sobriety3/4Frugality by design: template report without AI available, minimal audience measurement without cookies (aggregated statistics), static pages.
Responsible IT procurement2/4Footprint criterion built into the supplier grid and applied retroactively to current choices; decisive for the upcoming hosting choice.
Reduction targets2/4Dated targets: 100 % renewable hosting documented (Q4 2026), AI frugality ratio of at least 50 %, quarterly revision of the estimate.
Digital accessibility3/4Focus management, status announcements, AA contrasts, colour-blind-friendly palette; full WCAG audit still to be done.
Bias prevention2/4Anti-fabrication guardrails tested in the selftest; no periodic review of bias in generated content yet.
Transparency about AI use4/4Every report states its source; the pre-analysis cites its evidence; this score itself is public.
Impact on jobs and skills2/4One-person structure.
Inclusion and diversity1/4User feedback not yet structured; the pilots will change this level.
Avenues of recourse3/4Published procedure: report an erroneous AI output, human review, reasoned reply within 30 days (/confidentialite).

Our AI system register

The register we recommend to every company (Art. 26 AI Act / ISO 42001): here is ours, in full.

KarmaWriter — writing of assessment reportsDeployer · owner: Jaurès Adjamonsi

Tool: Claude API (Anthropic)

Classification: Transparency (Art. 50): generated content, systematically labelled “written by AI” or “template”

Measures: Tested anti-fabrication guardrail (any figure absent from the source data rejects the report), deterministic fallback without AI, no retention of data

Website pre-analysis — assessment suggestionsDeployer · owner: Jaurès Adjamonsi

Tool: Claude API (Anthropic)

Classification: Minimal risk: suggestions capped (level 3), evidence citation mandatory, human validation required

Measures: Tested anti-SSRF guard, missing evidence downgrades confidence, the user confirms or corrects every suggestion

Preliminary impact screening (Art. 22 FADP, the Swiss data protection act): none of these systems processes sensitive data on a large scale, profiles people or takes automated decisions about them, so no full impact assessment is required at this stage. We reassess with every new system.

Our dated commitments

  • Q3 2026Decide and carry out the definitive hosting (option: Swiss cloud with certified renewable energy, Infomaniak/Exoscale), supported by criterion 7 of the supplier grid.
  • Q4 2026Incorporate structured feedback from the pilot SMEs (inclusion, accessibility) and institute the periodic review of bias in generated content.
  • Q4 2026Tool-supported WCAG accessibility audit on all pages, corrections included.
  • Q4 2026Quarterly update of the footprint estimate with real volumes (public page /empreinte) and measurement of the AI frugality ratio.

History

DateVersionScoreNote
2026-08-09v0.675Full inventory of the secrets and their rotation, four processors run through the grid (Resend and Upstash added), register of processing activities completed (email sending, anti-abuse counters), CSP applied and security headers, fingerprint of the IP address instead of the address. Levels unchanged: these are corrected facts, not maturity progress. published footprint.
2026-07-14v0.5.275Security policy, supplier grid applied, voluntary register of processing activities, first footprint estimate with targets, complaints procedure (docs/SECURITE, FOURNISSEURS, REGISTRE_TRAITEMENTS).
2026-07-10v0.563.8Privacy policy, legal notice and leading-by-example page published; our own AI register.
2026-07-10v0.454First self-assessment. Findings: no privacy policy (0/100), footprint not measured.

Feel like comparing? Run your own assessment, the same questions, the same engine, the same rules.