Skip to main content
Required by EU law for organizations with 50+ employees

Information security policy #

Effective date: 2026-05-21 Last reviewed: 2026-09-23 Next review: 2027-05-21 Owner: Yaroslav Shmarov, operator Version: 1.1


1. Purpose #

This policy states the information-security objectives that govern EthicsPortal, the controls that satisfy them, and the responsibilities that maintain them. It exists so that customers, controllers under GDPR, regulators, and procurement reviewers can refer to a single named document for the security posture of the Service.

This policy is the parent document for the business continuity plan , the risk register , the internal audit record , the management review record , and the ISO/IEC 27001:2022 self-assessment .


2. Scope #

This policy applies to:

This policy does not extend to systems operated by the controller (the customer organization) outside the Service.


3. Objectives #

EthicsPortal commits to three primary security objectives, in order of priority:

  1. Confidentiality of reporter identity. Personal data identifying or reasonably capable of identifying a whistleblower is protected against unauthorized disclosure to any party — including controller-side personnel who are not designated handlers, sub-processors, and the operator’s own infrastructure providers — to the extent technically feasible.
  2. Integrity of the audit trail. Records of who did what, when, are preserved in an append-only form that cannot be altered by any user, including organization administrators.
  3. Availability of the whistleblowing channel. The reporter portal is available to whistleblowers under the SLA target so that the protected reporting right under EU Directive 2019/1937 is not silently degraded.

Confidentiality takes precedence over availability where the two conflict — the reporter portal will be taken offline in the event of a credible threat to reporter identity, with disclosure under the incident register .

Each objective carries a measure and a target, so that a management review can conclude whether it was met rather than only that work was done:

ObjectiveMeasureTargetRead from
Confidentiality of reporter identityConfirmed disclosures of reporter identity to any party outside the organization’s designated handlersZeroIncident register , which records every material security event and carries a 7-day disclosure obligation
Integrity of the audit trailPresence of the append-only triggers on the deployed audit_logs table, queried against the running database rather than inferred from migration historyPresent at every checkThe production check set published at secure.ethicsportal.eu/up , which runs continuously and fails the check if either trigger is absent
Availability of the whistleblowing channelMonthly uptime of the reporter and handler portals99.5%SLA#measurement ; monthly figures available to operators on request

These targets are reviewed annually alongside this policy. A missed target is a nonconformity, recorded and corrected under the internal audit programme, not a number quietly restated.


4. Roles and responsibilities #

EthicsPortal is operated by a single named individual, Yaroslav Shmarov, who holds all of the following responsibilities:

RoleResponsibility
Information security officerOwns this policy and its review
Data protection contactPrivacy and data-subject-rights inquiries; reachable at privacy@ethicsportal.eu
Incident response leadOwns the response process for events meeting the incident register scope
Authorized signatorySigns DPAs, security questionnaires, and commercial agreements
Sub-processor managerReviews sub-processor relationships and publishes the list on the subprocessors page

The single-operator structure is documented openly on the Trust page. Continuity arrangements that compensate for this structure are stated in the business continuity plan .


5. Control commitments #

The technical and organizational measures implementing this policy are documented on the Security page and are summarized below. Each commitment maps to one or more ISO/IEC 27001:2022 Annex A controls in the control map .

DomainCommitmentDetail
Encryption at restNon-deterministic encryption of defined report, identity and communication database fields; whole backups and attachments require separate verificationSecurity#data-encryption
Encryption in transitHTTPS/TLS for all connections; unencrypted HTTP is redirectedSecurity#data-encryption
Reporter anonymityNo reporter IP storage with reports or in application logs; keyed hashing for rate limiting; metadata stripped from uploadsSecurity#anonymity-and-privacy
Access controlRole-based access (admin/member/viewer) enforced at the controller boundary via Pundit policies; least-privilege defaults; opt-in two-factor authentication for handler accounts (recommended at onboarding); mandatory hardware-key 2FA on operator production accountsSecurity#access-control
Session management14-day idle timeout; per-session revocation; nightly sweepSecurity#access-control
Audit trailAppend-only, actor + action + timestamp, cannot be edited by any userSecurity#audit-and-compliance
RetentionCustomer-configurable 12/24/36/48/60-month retention with automatic deletion after closureSecurity#audit-and-compliance
Secure developmentDocumented lifecycle covering design review, change review, static analysis, dependency management, environment separation, vulnerability responseSecurity#secure-development-lifecycle
Vulnerability managementContinuous SCA in CI; weekly Dependabot; no end-of-life componentsSecurity#dependency-and-patch-management
Backup and restoreDaily database dumps encrypted with GnuPG AES-256 before upload, plus server-level snapshots, all in the EU; file attachments are not yet encrypted at rest; RPO 24h and RTO 4h are objectives; the monthly drill proves the restored database is readable by the application but does not prove full-service recoverySecurity#backups-and-restore
Sub-processor managementPublished list, 30-day change notice, controller objection rightSubprocessors , DPA §6.4
No AI / LLM processingPersonal data covered by the DPA is not transmitted to any LLM, generative-AI, or AI-classifier serviceDPA §6.10
No BYOKCustomer-managed encryption keys are not supported; deliberate architectural choiceDPA §6.11
Incident responseMaterial incidents recorded publicly within 7 days of containment; final report within 30 daysIncident register
Personal data breach notificationNotification to affected controllers without undue delay after awarenessDPA §6.6

6. Risk management, internal audit and management review #

Information-security risks are assessed against the Service annually and after any material change to architecture, sub-processors, or the threat landscape. The current assessment, treatment, and residual-position decisions are published in the risk register .

Risks accepted as residual are stated openly with a justification; risks not yet treated are stated openly with a target.

The management system is audited annually against ISO/IEC 27001:2022 and against the commitments published on this site. The programme, the audits performed, and every finding they raise are published in the internal audit record . Audit findings, monitoring results, and progress against the objectives in §3 are then reviewed by the operator as top management and recorded in the management review record .

Both are self-performed. A single-person organization cannot produce an impartial internal audit, and that limitation is stated on each page rather than worked around. It is the reason an independent external review remains the principal open item on the ISO/IEC 27001:2022 self-assessment .


7. Sub-processor management #

EthicsPortal engages sub-processors only where the function cannot reasonably be performed in-house and where the sub-processor materially improves availability, confidentiality, or compliance for the customer. The current list, the data each sub-processor receives, and the legal jurisdiction of each are published on the subprocessors page.

No large language model, generative-AI service, or AI-based classifier is engaged as a sub-processor. This is a documented product commitment (DPA §6.10 ) and a confidentiality-grade decision (Coverage map §5 ), not a configuration default.

Controllers are notified at least 30 days before any sub-processor is added or replaced. A controller that objects to a proposed change may terminate the agreement under DPA §6.4 without penalty.


8. Personnel security #

EthicsPortal has no employees or contractors. All personal data is processed exclusively by the named operator.

Having no employees removes a hiring process, not the operator. ISO/IEC 27001:2022 Clause 7.2 requires the competence of the people doing the work to be determined and recorded regardless of headcount, so screening (A.6.1) and awareness (A.6.3) are marked Compensating in the self-assessment rather than not applicable, and the compensating arrangements are these:

A.6.4 (disciplinary process) and the remaining employment-lifecycle controls stay Not applicable: there is no employment relationship for them to govern.

If EthicsPortal engages additional personnel in the future, this policy will be updated to state the screening, training, and offboarding procedures that apply.


9. Physical security #

EthicsPortal does not operate its own physical infrastructure. Server, database, and object-storage hosting are provided by Hetzner Online GmbH in Nuremberg, Germany. Physical security controls (data-center access, environmental controls, media destruction) are inherited from Hetzner and documented in their published certifications. See subprocessors .

The operator does not maintain a physical office that processes customer data. Operator workstations used for production access are protected by full-disk encryption and screen-lock controls.


10. Compliance #

EthicsPortal commits to compliance with:

EthicsPortal does not currently hold ISO/IEC 27001 certification. The platform publishes a structured self-assessment at /iso-27001/ covering both the mandatory Clause 4–10 requirements and all 93 Annex A controls, in the form of a Statement of Applicability. When accreditation is obtained, the certificate scope and date will be published on /trust/ .


11. Policy violations and enforcement #

A violation of this policy by the operator is a violation of the contractual commitments to controllers and may trigger:

Where a violation is suspected or reported, the operator is required to record, investigate, remediate, and disclose under the same process as any other security incident.


12. Document control #

FieldValue
Document titleEthicsPortal Information Security Policy
Version1.1
Effective date2026-05-21
Last reviewed2026-09-23
Next scheduled review2027-05-21
Review trigger (interim)Any material change to architecture, sub-processors, regulatory obligations, or the risk register
OwnerYaroslav Shmarov, operator
DistributionPublished on ethicsportal.eu/policies/

This policy is reviewed annually and after any of the interim triggers above. The effective date and version are incremented when the policy is materially revised.

Signed: Yaroslav Shmarov, on behalf of EthicsPortal — 2026-09-23.

Last updated: