Self-assessment v0.8 · 2026-09-26 · recomputed at every deployment
Our own KarmaScore, published
An assessment tool must accept being assessed — by itself, publicly, against the same 24 indicators as everyone else. Here are our score, our justified answers, our register of AI systems and our dated commitments. When we improve, this page changes; when it does not change, we have not made progress.
Our 24 answers, justified
Sector applied: Digital & AI, with the following weighting: Technological 35 %, Compliance 30 %, Environmental 15 %, Societal 20 %. Every level is verifiable: the calculation can be reproduced from the formula and the weightings published on the methodology page.
| Indicator | Level | Justification |
|---|---|---|
| Inventory of AI and digital systems | 4/4 | Our AI systems are publicly inventoried below, with an owner. |
| Explainability of automated decisions | 4/4 | The score is exactly decomposable; every report states whether it was written by AI or from a template. |
| Basic IT security | 3/4 | Security policy written and applied: inventory of the four secrets and their rotation, 2FA access, security headers and applied CSP, backups and a rehearsed restore. Two inventories are no longer declarative: the selftest refuses a secret read by the code that is missing from it, and an announced header that is not actually set. Dependency vulnerabilities are checked every Monday and on every proposed change. Breach procedure written, with the criterion for notifying the FDPIC and a prepared exercise (docs/EXERCICE_VIOLATION.md): it has not been run yet, and there is no external audit. |
| Data governance | 4/4 | Governance documented in docs/GOUVERNANCE_DONNEES.md: roles, quality criteria, lifecycle item by item, and default settings. Those are not merely written down: no cookie, consent box unticked, IP address never sent in the clear to the anti-abuse counter (Upstash) are checked by the selftest, which fails if any of them changes. Minimisation by design: assessments live in the browser, there is no database. |
| Human oversight | 4/4 | Product principle: the AI suggests, the human validates. No AI content is served without a guardrail. |
| Control over AI vendors | 2/4 | A 7-criteria grid (location, contract, use of data, certifications, retention, reversibility, footprint) applied to our five processors: Vercel, Anthropic, Resend, Upstash and Infomaniak (docs/FOURNISSEURS.md). Level lowered from 3 to 2 on 26.09.2026. Level 3 requires an applied grid and a verified handling of the data; the grid is applied, but location is not recorded everywhere (region of the Upstash database, place of the Resend log), Infomaniak was only assessed that day, and the data processing addenda are cited without version or reading date. |
| Record of processing activities | 3/4 | Exempt (Art. 12(5) FADP) but kept anyway: 6 documented processing activities, with a review cadence the selftest enforces. Automated checks block release if a processor from the register is engaged without an assessment sheet, if the content security policy opens a third-party origin, or if an entry exceeds its review cadence. They see neither an outbound call added on the server side nor a provider used outside the code: the e-mail service only entered the register on 26.09.2026, and business prospecting is still missing from it. Level lowered from 4 to 3 that day, because the register is not complete. |
| Informing data subjects | 2/4 | Policy published at /confidentialite which, since its revision of 26.09.2026, names the AI uses, every processor, the destination States and the basis of each transfer. Level lowered from 4 to 2 the same day: until then it left out the e-mail service, the technical logs and sending by e-mail, and several of its sentences were contradicted by the code. It remains incomplete: the retention periods of the Resend log and of the host's logs are not recorded, and people contacted by prospecting e-mails are not yet informed. |
| Impact assessments (DPIA) | 4/4 | The four criteria of Art. 22 FADP are applied to every processing activity in the register before release, with a date and a written rationale: six activities screened, none triggers a DPIA. An unscreened activity, or a positive screening left without follow-up, fails the integration gate. |
| AI Act applicability and classification | 4/4 | Applicability checked, use cases classified, legal monitoring versioned (see Methodology). |
| Data subject rights | 2/4 | Contact point identified (contact@ai-karma.ch) and written procedure: docs/DROITS_ET_RECOURS.md states, system by system, where to look for what we hold about a person, and what to answer when there is nothing. An automated check verifies that every processor in the register appears in it. Level lowered from 3 to 2 on 26.09.2026: the procedure did not cover prospecting data, added that day, and it has never been exercised, so no deadline has yet been met. Register of requests kept, empty to date. |
| Staff training | 2/4 | One-person structure: continuous monitoring and training of the founder, not formalised. |
| Low-footprint hosting | 2/4 | Energy profile of the host documented (Vercel/AWS, renewable through offset purchasing); migration to a certified Swiss cloud still to be decided (public page /empreinte). |
| Measuring the digital footprint | 2/4 | First estimate published with explicit method and assumptions (around 10-15 kg CO2e per year at prototype stage), public page /empreinte, updated quarterly. |
| Hardware life cycle | 2/4 | Hardware kept for a long time, without a written policy. |
| Digital sobriety | 3/4 | Frugality by design: template report without AI available, minimal audience measurement without cookies (aggregated statistics), static pages. |
| Responsible IT procurement | 2/4 | Footprint criterion built into the supplier grid and applied retroactively to current choices; decisive for the upcoming hosting choice. |
| Reduction targets | 2/4 | Dated targets: 100 % renewable hosting documented (Q4 2026), AI frugality ratio of at least 50 %, quarterly revision of the estimate. |
| Digital accessibility | 3/4 | axe-core audit (WCAG 2.1 AA) across all 78 public addresses in both themes, replayed on every proposed change and every Monday; zero violations as of 04.09.2026. Focus management and status announcements in place. What the tool cannot see — screen-reader journeys, end-to-end keyboard navigation — is still to be tested by hand. |
| Bias prevention | 2/4 | Bias control replayed on every proposed change: with identical answers, the verdict depends neither on the company name nor on its headcount, and the same score gives the same band whatever the sector. The only intended gap is the sector weighting, which the control displays rather than hides (up to 17.5 points between two sectors, at constant answers). Anti-fabrication guardrails tested. The text written by the model is not covered yet: it requires an API key and cannot run in continuous integration. |
| Transparency about AI use | 4/4 | Every report states its source; the pre-analysis cites its evidence; this score itself is public. |
| Impact on jobs and skills | 2/4 | One-person structure. |
| Inclusion and diversity | 1/4 | User feedback not yet structured; the pilots will change this level. |
| Avenues of recourse | 3/4 | A « Contest this report » link sits under every report produced, next to the note saying whether it came from a model or a template. It opens a message carrying the provenance and the date, nothing else. Commitment: human review, reasoned answer within 30 days, entry in the register. Previously the remedy existed only as prose on /confidentialite, so you had to guess it existed. |
Our AI system register
The register we recommend to every company (Art. 26 AI Act / ISO 42001): here is ours, in full.
Tool: Claude API (Anthropic)
Classification: Transparency (Art. 50): generated content, systematically labelled “written by AI” or “template”
Measures: Tested anti-fabrication guardrail (any figure absent from the source data rejects the report), deterministic fallback without AI, no copy kept by AI-Karma; according to its documentation, Anthropic deletes API inputs and outputs no later than 30 days after receipt, except content flagged for breaching its usage rules (up to two years) and where the law requires it to be kept
Tool: Claude API (Anthropic)
Classification: Minimal risk: suggestions capped (level 3), evidence citation mandatory, human validation required
Measures: Tested anti-SSRF guard, missing evidence downgrades confidence, the user confirms or corrects every suggestion
Preliminary impact screening (Art. 22 FADP, the Swiss data protection act): none of these systems processes sensitive data on a large scale, profiles people or takes automated decisions about them, so no full impact assessment is required at this stage. We reassess with every new system.
Our dated commitments
- Q4 2026Decide and carry out the definitive hosting (option: Swiss cloud with certified renewable energy, Infomaniak/Exoscale), supported by criterion 7 of the supplier grid.
- Q4 2026Incorporate structured feedback from the pilot SMEs (inclusion, accessibility) and institute the periodic review of bias in generated content.
- Q4 2026Tool-supported WCAG accessibility audit on all pages, corrections included.
- Q4 2026Quarterly update of the footprint estimate with real volumes (public page /empreinte) and measurement of the AI frugality ratio.
History
| Date | Version | Score | Note |
|---|---|---|---|
| 2026-09-26 | v0.8 | 72.5 | Four levels lowered after the FADP audit of 26.09.2026 and its cross-check, because the facts no longer supported them. Information of data subjects, from 4 to 2: the policy left out the e-mail service, the technical logs and sending by e-mail, and several of its sentences were contradicted by the code. Register, from 4 to 3: it ignored the e-mail service and still ignores business prospecting. Data subjects' rights, from 3 to 2: the procedure did not cover prospecting data and has never been exercised. Suppliers, from 3 to 2: location not recorded everywhere, Infomaniak never assessed. The policy, the register and the grid were corrected the same day; that is not enough to raise the levels again, as facts remain to be recorded with the providers and one processing activity remains to be registered. revised policy. |
| 2026-09-04 | v0.7 | 79 | Three levels raised, on facts a third party can verify rather than on judgement: data governance documented with default settings the selftest refuses to let drift, register of processing activities embedded in the process by seven checks, two of which block release on an unregistered sub-processor or third-party origin, and dated, reasoned DPIA pre-screening for all six activities. Three further levels were NOT raised even though their wording would be defensible: the breach exercise has not been run, the rights procedure has not been tested, and the bias control does not cover the text written by the model. This revision also found and corrected a false claim: the site promised AA contrasts that the first tooled audit disproved on 39 pages. register of reviews. |
| 2026-08-09 | v0.6 | 75 | Full inventory of the secrets and their rotation, four processors run through the grid (Resend and Upstash added), register of processing activities completed (email sending, anti-abuse counters), CSP applied and security headers, fingerprint of the IP address instead of the address. Levels unchanged: these are corrected facts, not maturity progress. published footprint. |
| 2026-07-14 | v0.5.2 | 75 | Security policy, supplier grid applied, voluntary register of processing activities, first footprint estimate with targets, complaints procedure (docs/SECURITE, FOURNISSEURS, REGISTRE_TRAITEMENTS). |
| 2026-07-10 | v0.5 | 63.8 | Privacy policy, legal notice and leading-by-example page published; our own AI register. |
| 2026-07-10 | v0.4 | 54 | First self-assessment. Findings: no privacy policy (0/100), footprint not measured. |
Feel like comparing? Run your own assessment, the same questions, the same engine, the same rules.