Self-assessment v0.6 · 2026-08-09 · recomputed at every deployment
Our own KarmaScore, published
An assessment tool must accept being assessed — by itself, publicly, against the same 24 indicators as everyone else. Here are our score, our justified answers, our register of AI systems and our dated commitments. When we improve, this page changes; when it does not change, we have not made progress.
Our 24 answers, justified
Sector applied: Digital & AI, with the following weighting: Technological 35 %, Compliance 30 %, Environmental 15 %, Societal 20 %. Every level is verifiable: the calculation can be reproduced from the formula and the weightings published on the methodology page.
| Indicator | Level | Justification |
|---|---|---|
| Inventory of AI and digital systems | 4/4 | Our AI systems are publicly inventoried below, with an owner. |
| Explainability of automated decisions | 4/4 | The score is exactly decomposable; every report states whether it was written by AI or from a template. |
| Basic IT security | 3/4 | Written and applied security policy (docs/SECURITE.md): inventory and rotation of the four secrets, two-factor access, security headers and CSP applied, backups with restoration exercised, incident response. No external audit yet. |
| Data governance | 3/4 | Minimisation by design: assessments live in the browser, there is no database. |
| Human oversight | 4/4 | Product principle: the AI suggests, the human validates. No AI content is served without a guardrail. |
| Control over AI vendors | 3/4 | A 7-criteria grid (location, data processing agreement, use of data, certifications, reversibility, footprint) applied to our four processors: Anthropic, Vercel, Resend, Upstash (docs/FOURNISSEURS.md). |
| Record of processing activities | 3/4 | Exempt (Art. 12(5) FADP) but kept anyway: 6 documented processing activities, annual review (docs/REGISTRE_TRAITEMENTS.md). |
| Informing data subjects | 4/4 | Published, tailored policy, explicitly mentioning AI uses, processors and transfers (/confidentialite). |
| Impact assessments (DPIA) | 3/4 | Pre-screening documented and applied to every processing activity (4 criteria of Art. 22 FADP); trigger identified for future server-side persistence. |
| AI Act applicability and classification | 4/4 | Applicability checked, use cases classified, legal monitoring versioned (see Methodology). |
| Data subject rights | 3/4 | Process for exercising rights documented in the privacy policy (reply within 30 days). |
| Staff training | 2/4 | One-person structure: continuous monitoring and training of the founder, not formalised. |
| Low-footprint hosting | 2/4 | Energy profile of the host documented (Vercel/AWS, renewable through offset purchasing); migration to a certified Swiss cloud still to be decided (public page /empreinte). |
| Measuring the digital footprint | 2/4 | First estimate published with explicit method and assumptions (around 10-15 kg CO2e per year at prototype stage), public page /empreinte, updated quarterly. |
| Hardware life cycle | 2/4 | Hardware kept for a long time, without a written policy. |
| Digital sobriety | 3/4 | Frugality by design: template report without AI available, minimal audience measurement without cookies (aggregated statistics), static pages. |
| Responsible IT procurement | 2/4 | Footprint criterion built into the supplier grid and applied retroactively to current choices; decisive for the upcoming hosting choice. |
| Reduction targets | 2/4 | Dated targets: 100 % renewable hosting documented (Q4 2026), AI frugality ratio of at least 50 %, quarterly revision of the estimate. |
| Digital accessibility | 3/4 | Focus management, status announcements, AA contrasts, colour-blind-friendly palette; full WCAG audit still to be done. |
| Bias prevention | 2/4 | Anti-fabrication guardrails tested in the selftest; no periodic review of bias in generated content yet. |
| Transparency about AI use | 4/4 | Every report states its source; the pre-analysis cites its evidence; this score itself is public. |
| Impact on jobs and skills | 2/4 | One-person structure. |
| Inclusion and diversity | 1/4 | User feedback not yet structured; the pilots will change this level. |
| Avenues of recourse | 3/4 | Published procedure: report an erroneous AI output, human review, reasoned reply within 30 days (/confidentialite). |
Our AI system register
The register we recommend to every company (Art. 26 AI Act / ISO 42001): here is ours, in full.
Tool: Claude API (Anthropic)
Classification: Transparency (Art. 50): generated content, systematically labelled “written by AI” or “template”
Measures: Tested anti-fabrication guardrail (any figure absent from the source data rejects the report), deterministic fallback without AI, no retention of data
Tool: Claude API (Anthropic)
Classification: Minimal risk: suggestions capped (level 3), evidence citation mandatory, human validation required
Measures: Tested anti-SSRF guard, missing evidence downgrades confidence, the user confirms or corrects every suggestion
Preliminary impact screening (Art. 22 FADP, the Swiss data protection act): none of these systems processes sensitive data on a large scale, profiles people or takes automated decisions about them, so no full impact assessment is required at this stage. We reassess with every new system.
Our dated commitments
- Q3 2026Decide and carry out the definitive hosting (option: Swiss cloud with certified renewable energy, Infomaniak/Exoscale), supported by criterion 7 of the supplier grid.
- Q4 2026Incorporate structured feedback from the pilot SMEs (inclusion, accessibility) and institute the periodic review of bias in generated content.
- Q4 2026Tool-supported WCAG accessibility audit on all pages, corrections included.
- Q4 2026Quarterly update of the footprint estimate with real volumes (public page /empreinte) and measurement of the AI frugality ratio.
History
| Date | Version | Score | Note |
|---|---|---|---|
| 2026-08-09 | v0.6 | 75 | Full inventory of the secrets and their rotation, four processors run through the grid (Resend and Upstash added), register of processing activities completed (email sending, anti-abuse counters), CSP applied and security headers, fingerprint of the IP address instead of the address. Levels unchanged: these are corrected facts, not maturity progress. published footprint. |
| 2026-07-14 | v0.5.2 | 75 | Security policy, supplier grid applied, voluntary register of processing activities, first footprint estimate with targets, complaints procedure (docs/SECURITE, FOURNISSEURS, REGISTRE_TRAITEMENTS). |
| 2026-07-10 | v0.5 | 63.8 | Privacy policy, legal notice and leading-by-example page published; our own AI register. |
| 2026-07-10 | v0.4 | 54 | First self-assessment. Findings: no privacy policy (0/100), footprint not measured. |
Feel like comparing? Run your own assessment, the same questions, the same engine, the same rules.