Effective date: 2026-05-21
Last reviewed: 2026-09-23
Next review: 2027-05-21
Owner: Yaroslav Shmarov, operator
Version: 1.4
This register lists the top information-security risks assessed against EthicsPortal, the treatment in place, and the residual position the operator has consciously accepted. It exists so that a controller, auditor, or procurement reviewer can verify that the most material risks have been thought about, not just the ones convenient to mention.
R-01. Operator incapacity / single point of failure
#
Field
Value
Inherent impact
High
Inherent likelihood
Medium
Treatment
Self-service PDF case export is available while the Service remains reachable. DPA §6.8
preserves the Controller’s deletion-and-return rights, but fulfilling an off-platform request currently depends on the sole operator. The deployment configuration is portable in principle, not a proven operator-incapacity handoff.
Residual position
In treatment. A formal operator-incapacity protocol with a named legal contact is on the roadmap and not yet in place. See the Business continuity plan §8
for what is and is not in place today. Self-service in-product export requires no operator involvement and is the primary continuity control against operator unavailability.
Daily database dumps to Hetzner Object Storage (separate from compute host), encrypted with GnuPG symmetric AES-256 before upload, plus server-level snapshots; monthly restore drill into a disposable environment that decrypts, restores and confirms the application can read the restored data (Security#backups-and-restore
). Off-provider recovery remains unverified.
Residual position
In treatment. Cross-provider hot failover is absent. A provider-wide outage and sole-operator unavailability could prevent the published four-hour recovery objective; the current drill has not measured full-service recovery. Whole-dump encryption was established on 2026-09-23 and is exercised by the monthly drill; attachment-at-rest encryption remains outstanding, and both it and a measured off-provider recovery are required before this risk can be accepted as controlled.
Medium–High (varies by sub-processor and data category)
Inherent likelihood
Low
Treatment
Defined database fields use application encryption; supplier disclosures and the 30-day sub-processor notice/objection mechanism are published (Security#data-encryption
, DPA §6.4
). Mailjet receives reporter email and a case identifier/link when reporter notifications are chosen. AppSignal receives telemetry; the reporter-controller namespace exclusion was confirmed against AppSignal’s own action inventory on 2026-09-23, but sample contents and other paths remain to be checked (TP-01).
Residual position
In treatment. An EU-based direct supplier does not prove an EU-only downstream chain. Mailjet’s sensitive-data permission, account DPAs, support access, restricted transfers, whole-object encryption and telemetry samples remain unverified. Do not assert that every supplier receives only non-identifying data.
Hardware-backed two-factor authentication on operator accounts with production access. Production database access requires the operator’s authenticated session; credentials are not embedded in code or shared. An append-only audit log records defined report and account events, not every read or action; a privileged database operator could still alter the database-level control (Security#audit-and-compliance
).
Residual position
Monitored. The risk is materially lower than typical SaaS because there are no employee credentials to compromise — the attack surface reduces to one identity. Monitored via AppSignal alerts for anomalous handler-portal authentication patterns. Trigger for re-treatment: a credible phishing attempt against the operator, or a CVE affecting the hardware-key path.
Two complementary backup layers (database dump and server-level snapshot) in independent retention scopes. Restore drill performed monthly, automated, into a disposable environment; it decrypts the dump, restores it, compares every table against production, and boots the application against the restored data to confirm an encrypted column still decrypts — row counts alone would not reveal a dump whose encryption key no longer matches. Restore procedure documented in the Business continuity plan §6
.
Residual position
Accepted. RPO 24 hours and RTO 4 hours are stated in the SLA
. Data written within the 24 hours preceding a catastrophic failure may be lost; this trade-off is disclosed.
The Service does not store reporter IP addresses with reports, messages or audit records, and application logs for reporter routes contain no IP addresses; rate limiting uses a keyed, pseudonymous hash kept only for the rate-limit window. The TLS proxy’s own connection logs can include IP addresses and are not linked to reports. File uploads have metadata stripped (EXIF / GPS / author) server-side before storage. See Security#anonymity-and-privacy
.
Residual position
Accepted. Network-side attribution (the reporter’s ISP, the reporter’s employer’s egress proxy, a man-in-the-middle, or a corporate-device endpoint agent) is outside the processor boundary and cannot be controlled by the Service. Reporters are informed of this on the portal and may choose to report from a personal device on an external network, or via Tor. This residual is disclosed to reporters at the point of submission, which is the only place the trade-off can be acted upon.
R-07. Critical vulnerability in upstream dependency
#
Field
Value
Inherent impact
Medium–High
Inherent likelihood
Medium
Treatment
Continuous SCA on every change: Brakeman
for Rails-specific issues, bundler-audit
for Ruby advisories, importmap audit for JavaScript imports, Dependabot
for weekly grouped updates. End-of-life components are replaced before their upstream support window closes. See Security#secure-development-lifecycle
and Security#dependency-and-patch-management
. Documented vulnerability-response timelines: critical 7 days, high 30 days, medium 90 days.
Residual position
Monitored. The Rails ecosystem is well-staffed for security disclosures. Trigger for re-treatment: a zero-day affecting Rails request-handling, ActiveRecord encryption, or PostgreSQL with no available patch.
Audit-log entries are append-only and cannot be edited or selectively deleted by any application user, including organization administrators. PostgreSQL triggers reject changes to core audit content and table truncation even when Rails callbacks are bypassed; their presence is checked against the deployed database through the authenticated operational healthcheck. Required foreign-key nullification remains possible when a related record is erased, and entries are included in PDF case exports for regulatory review. See Security#audit-and-compliance
.
Residual position
Accepted. The trail is not hash-chained, WORM-backed, or independently replicated. A privileged database operator could disable or drop the triggers, or issue a direct deletion outside the application-controlled retention and GDPR erasure paths. Production database access controls and the privileged-access procedure govern that residual risk; the public append-only claim is limited to application users and the protected database write paths described above.
Medium (reporters are anonymous and may not have password-recovery channels)
Treatment
The 6-digit passcode is stored only as a bcrypt digest and cannot be recovered by the operator or by any handler. Reporters are informed at submission that the passcode is non-recoverable. Handlers may invite a reporter to re-submit or continue the conversation by an alternative channel.
Residual position
Accepted by design. Recoverability of the passcode is incompatible with the reporter-anonymity model: a recovery channel would require an identifier (email, phone) that defeats anonymity, or an operator-side reset that would allow the operator to impersonate the reporter. The trade-off is disclosed to reporters at the point of choosing the passcode.
Medium (Member-State transpositions and AI-Act delegated acts continue to evolve)
Treatment
Interpretive positions on ambiguous Directive 2019/1937 provisions are documented openly in the Directive 2019/1937 interpretations
, so a controller can verify alignment with their counsel’s reading before subscribing. Per-country law summaries are published in whistleblower laws by country
and reviewed when national-law text changes. Material changes to processing (sub-processors, AI use, transfers) are notified to controllers under DPA §6.4
.
Residual position
Monitored. Trigger for re-treatment: ECJ judgment on a Directive 2019/1937 question that contradicts a published interpretation; CJEU judgment on international-transfer adequacy affecting an EU sub-processor; AI-Act delegated act extending obligations to AI-free processors.
The following are recognized risk categories that this register deliberately omits because they are eliminated by design rather than treated:
AI / LLM exposure of report content. No LLM, generative-AI, or AI-classifier service is engaged as a sub-processor. Report content is not transmitted to such services for any purpose. The attack surface (prompt injection, hallucinated compliance evidence, unauthorized retention by third parties) is therefore not present. Source: DPA §6.10
.
Reporter PII shared with handlers without justification. The Service does not surface reporter IP, browser fingerprint, or device identifiers to handlers, because none of these are collected or stored.
Cross-tenant data leakage at the application layer. Pundit-policy authorization is checked on every controller action; multi-tenant isolation is enforced at the request boundary, not via row-level visibility filters that can be bypassed.
If any of these design constraints changes, the risk re-enters this register.
Clause 6.1.3 requires a risk treatment plan, and a residual position of In treatment means nothing without a date against it: an open item with no target is indistinguishable from one nobody intends to close. Every risk carrying that position appears below, with the control it moves and the date it is owned to.
Ref
Risk / control
Action
Target
TP-01
R-03; A.5.14, A.8.12, A.8.16
Verify the supplier chain at account level: executed DPAs, current sub-processor lists, transfer mechanisms, Mailjet’s sensitive-data permission, and a sample of the telemetry AppSignal actually receives. Part done 2026-09-23: AppSignal’s own records confirm no reporter-portal controller is instrumented; the contents of stored samples, and both other suppliers, remain outstanding
2026-11-30
TP-02
R-02; A.8.13
Encryption at rest for file attachments, the remaining half of the backup gap now that database dumps are encrypted
2027-01-31
TP-03
R-01
Operator-incapacity protocol with a named legal contact, replacing the present position that self-service export is the only control
2027-03-31
TP-04
R-02; A.5.30
Restore into a provider other than Hetzner and measure it against the published four-hour RTO
All five are owned by the operator; there is nobody else to assign them to, which is the substance of R-01 and of the Clause 7.1 resourcing position.
When a target is missed. It is recorded as missed at the next management review
, with the reason and a new date, and this table is updated to show both. A target that quietly moves is worse than no target, because it converts a commitment into a decoration.