AI-Karma

Self-assessment v0.8 · 2026-09-26 · recomputed at every deployment

Our own KarmaScore, published

An assessment tool must accept being assessed — by itself, publicly, against the same 24 indicators as everyone else. Here are our score, our justified answers, our register of AI systems and our dated commitments. When we improve, this page changes; when it does not change, we have not made progress.

Global score72.5out of 100✓ Eligible for the label, at the “self-assessed” level only: for the “audited” level we are waiting for a third-party sincerity audit
T · Technology87.5
C · Compliance70.8
E · Environment54.2
S · Society62.5

Our 24 answers, justified

Sector applied: Digital & AI, with the following weighting: Technological 35 %, Compliance 30 %, Environmental 15 %, Societal 20 %. Every level is verifiable: the calculation can be reproduced from the formula and the weightings published on the methodology page.

IndicatorLevelJustification
Inventory of AI and digital systems4/4Our AI systems are publicly inventoried below, with an owner.
Explainability of automated decisions4/4The score is exactly decomposable; every report states whether it was written by AI or from a template.
Basic IT security3/4Security policy written and applied: inventory of the four secrets and their rotation, 2FA access, security headers and applied CSP, backups and a rehearsed restore. Two inventories are no longer declarative: the selftest refuses a secret read by the code that is missing from it, and an announced header that is not actually set. Dependency vulnerabilities are checked every Monday and on every proposed change. Breach procedure written, with the criterion for notifying the FDPIC and a prepared exercise (docs/EXERCICE_VIOLATION.md): it has not been run yet, and there is no external audit.
Data governance4/4Governance documented in docs/GOUVERNANCE_DONNEES.md: roles, quality criteria, lifecycle item by item, and default settings. Those are not merely written down: no cookie, consent box unticked, IP address never sent in the clear to the anti-abuse counter (Upstash) are checked by the selftest, which fails if any of them changes. Minimisation by design: assessments live in the browser, there is no database.
Human oversight4/4Product principle: the AI suggests, the human validates. No AI content is served without a guardrail.
Control over AI vendors2/4A 7-criteria grid (location, contract, use of data, certifications, retention, reversibility, footprint) applied to our five processors: Vercel, Anthropic, Resend, Upstash and Infomaniak (docs/FOURNISSEURS.md). Level lowered from 3 to 2 on 26.09.2026. Level 3 requires an applied grid and a verified handling of the data; the grid is applied, but location is not recorded everywhere (region of the Upstash database, place of the Resend log), Infomaniak was only assessed that day, and the data processing addenda are cited without version or reading date.
Record of processing activities3/4Exempt (Art. 12(5) FADP) but kept anyway: 6 documented processing activities, with a review cadence the selftest enforces. Automated checks block release if a processor from the register is engaged without an assessment sheet, if the content security policy opens a third-party origin, or if an entry exceeds its review cadence. They see neither an outbound call added on the server side nor a provider used outside the code: the e-mail service only entered the register on 26.09.2026, and business prospecting is still missing from it. Level lowered from 4 to 3 that day, because the register is not complete.
Informing data subjects2/4Policy published at /confidentialite which, since its revision of 26.09.2026, names the AI uses, every processor, the destination States and the basis of each transfer. Level lowered from 4 to 2 the same day: until then it left out the e-mail service, the technical logs and sending by e-mail, and several of its sentences were contradicted by the code. It remains incomplete: the retention periods of the Resend log and of the host's logs are not recorded, and people contacted by prospecting e-mails are not yet informed.
Impact assessments (DPIA)4/4The four criteria of Art. 22 FADP are applied to every processing activity in the register before release, with a date and a written rationale: six activities screened, none triggers a DPIA. An unscreened activity, or a positive screening left without follow-up, fails the integration gate.
AI Act applicability and classification4/4Applicability checked, use cases classified, legal monitoring versioned (see Methodology).
Data subject rights2/4Contact point identified (contact@ai-karma.ch) and written procedure: docs/DROITS_ET_RECOURS.md states, system by system, where to look for what we hold about a person, and what to answer when there is nothing. An automated check verifies that every processor in the register appears in it. Level lowered from 3 to 2 on 26.09.2026: the procedure did not cover prospecting data, added that day, and it has never been exercised, so no deadline has yet been met. Register of requests kept, empty to date.
Staff training2/4One-person structure: continuous monitoring and training of the founder, not formalised.
Low-footprint hosting2/4Energy profile of the host documented (Vercel/AWS, renewable through offset purchasing); migration to a certified Swiss cloud still to be decided (public page /empreinte).
Measuring the digital footprint2/4First estimate published with explicit method and assumptions (around 10-15 kg CO2e per year at prototype stage), public page /empreinte, updated quarterly.
Hardware life cycle2/4Hardware kept for a long time, without a written policy.
Digital sobriety3/4Frugality by design: template report without AI available, minimal audience measurement without cookies (aggregated statistics), static pages.
Responsible IT procurement2/4Footprint criterion built into the supplier grid and applied retroactively to current choices; decisive for the upcoming hosting choice.
Reduction targets2/4Dated targets: 100 % renewable hosting documented (Q4 2026), AI frugality ratio of at least 50 %, quarterly revision of the estimate.
Digital accessibility3/4axe-core audit (WCAG 2.1 AA) across all 78 public addresses in both themes, replayed on every proposed change and every Monday; zero violations as of 04.09.2026. Focus management and status announcements in place. What the tool cannot see — screen-reader journeys, end-to-end keyboard navigation — is still to be tested by hand.
Bias prevention2/4Bias control replayed on every proposed change: with identical answers, the verdict depends neither on the company name nor on its headcount, and the same score gives the same band whatever the sector. The only intended gap is the sector weighting, which the control displays rather than hides (up to 17.5 points between two sectors, at constant answers). Anti-fabrication guardrails tested. The text written by the model is not covered yet: it requires an API key and cannot run in continuous integration.
Transparency about AI use4/4Every report states its source; the pre-analysis cites its evidence; this score itself is public.
Impact on jobs and skills2/4One-person structure.
Inclusion and diversity1/4User feedback not yet structured; the pilots will change this level.
Avenues of recourse3/4A « Contest this report » link sits under every report produced, next to the note saying whether it came from a model or a template. It opens a message carrying the provenance and the date, nothing else. Commitment: human review, reasoned answer within 30 days, entry in the register. Previously the remedy existed only as prose on /confidentialite, so you had to guess it existed.

Our AI system register

The register we recommend to every company (Art. 26 AI Act / ISO 42001): here is ours, in full.

KarmaWriter — writing of assessment reportsDeployer · owner: Jaurès Adjamonsi

Tool: Claude API (Anthropic)

Classification: Transparency (Art. 50): generated content, systematically labelled “written by AI” or “template”

Measures: Tested anti-fabrication guardrail (any figure absent from the source data rejects the report), deterministic fallback without AI, no copy kept by AI-Karma; according to its documentation, Anthropic deletes API inputs and outputs no later than 30 days after receipt, except content flagged for breaching its usage rules (up to two years) and where the law requires it to be kept

Website pre-analysis — assessment suggestionsDeployer · owner: Jaurès Adjamonsi

Tool: Claude API (Anthropic)

Classification: Minimal risk: suggestions capped (level 3), evidence citation mandatory, human validation required

Measures: Tested anti-SSRF guard, missing evidence downgrades confidence, the user confirms or corrects every suggestion

Preliminary impact screening (Art. 22 FADP, the Swiss data protection act): none of these systems processes sensitive data on a large scale, profiles people or takes automated decisions about them, so no full impact assessment is required at this stage. We reassess with every new system.

Our dated commitments

  • Q4 2026Decide and carry out the definitive hosting (option: Swiss cloud with certified renewable energy, Infomaniak/Exoscale), supported by criterion 7 of the supplier grid.
  • Q4 2026Incorporate structured feedback from the pilot SMEs (inclusion, accessibility) and institute the periodic review of bias in generated content.
  • Q4 2026Tool-supported WCAG accessibility audit on all pages, corrections included.
  • Q4 2026Quarterly update of the footprint estimate with real volumes (public page /empreinte) and measurement of the AI frugality ratio.

History

DateVersionScoreNote
2026-09-26v0.872.5Four levels lowered after the FADP audit of 26.09.2026 and its cross-check, because the facts no longer supported them. Information of data subjects, from 4 to 2: the policy left out the e-mail service, the technical logs and sending by e-mail, and several of its sentences were contradicted by the code. Register, from 4 to 3: it ignored the e-mail service and still ignores business prospecting. Data subjects' rights, from 3 to 2: the procedure did not cover prospecting data and has never been exercised. Suppliers, from 3 to 2: location not recorded everywhere, Infomaniak never assessed. The policy, the register and the grid were corrected the same day; that is not enough to raise the levels again, as facts remain to be recorded with the providers and one processing activity remains to be registered. revised policy.
2026-09-04v0.779Three levels raised, on facts a third party can verify rather than on judgement: data governance documented with default settings the selftest refuses to let drift, register of processing activities embedded in the process by seven checks, two of which block release on an unregistered sub-processor or third-party origin, and dated, reasoned DPIA pre-screening for all six activities. Three further levels were NOT raised even though their wording would be defensible: the breach exercise has not been run, the rights procedure has not been tested, and the bias control does not cover the text written by the model. This revision also found and corrected a false claim: the site promised AA contrasts that the first tooled audit disproved on 39 pages. register of reviews.
2026-08-09v0.675Full inventory of the secrets and their rotation, four processors run through the grid (Resend and Upstash added), register of processing activities completed (email sending, anti-abuse counters), CSP applied and security headers, fingerprint of the IP address instead of the address. Levels unchanged: these are corrected facts, not maturity progress. published footprint.
2026-07-14v0.5.275Security policy, supplier grid applied, voluntary register of processing activities, first footprint estimate with targets, complaints procedure (docs/SECURITE, FOURNISSEURS, REGISTRE_TRAITEMENTS).
2026-07-10v0.563.8Privacy policy, legal notice and leading-by-example page published; our own AI register.
2026-07-10v0.454First self-assessment. Findings: no privacy policy (0/100), footprint not measured.

Feel like comparing? Run your own assessment, the same questions, the same engine, the same rules.