Skip to main content
Required by EU law for organizations with 50+ employees

Risk register #

Effective date: 2026-05-21 Last reviewed: 2026-09-23 Next review: 2027-05-21 Owner: Yaroslav Shmarov, operator Version: 1.4

This register lists the top information-security risks assessed against EthicsPortal, the treatment in place, and the residual position the operator has consciously accepted. It exists so that a controller, auditor, or procurement reviewer can verify that the most material risks have been thought about, not just the ones convenient to mention.

The register is a summary. The substantive treatment for each risk is documented on the Security page, in the Data Processing Agreement , in the Business continuity plan , or in the Information security policy . The register’s job is to make the trade-offs visible in one place.


Assessment scale #

LevelImpactLikelihood
LowSingle-customer inconvenience; no personal-data exposureNot expected during the review window
MediumMulti-customer service degradation, or personal-data exposure confined to operational metadataPlausible during the review window
HighConfidentiality breach of reporter identity or report content; or extended unavailability of a covered surfaceReasonably foreseeable in absence of treatment

The review window is twelve months from the effective date above.


Residual-position vocabulary #


Register #

R-01. Operator incapacity / single point of failure #

FieldValue
Inherent impactHigh
Inherent likelihoodMedium
TreatmentSelf-service PDF case export is available while the Service remains reachable. DPA §6.8 preserves the Controller’s deletion-and-return rights, but fulfilling an off-platform request currently depends on the sole operator. The deployment configuration is portable in principle, not a proven operator-incapacity handoff.
Residual positionIn treatment. A formal operator-incapacity protocol with a named legal contact is on the roadmap and not yet in place. See the Business continuity plan §8 for what is and is not in place today. Self-service in-product export requires no operator involvement and is the primary continuity control against operator unavailability.

R-02. Hetzner outage (primary infrastructure provider) #

FieldValue
Inherent impactHigh
Inherent likelihoodLow
TreatmentDaily database dumps to Hetzner Object Storage (separate from compute host), encrypted with GnuPG symmetric AES-256 before upload, plus server-level snapshots; monthly restore drill into a disposable environment that decrypts, restores and confirms the application can read the restored data (Security#backups-and-restore ). Off-provider recovery remains unverified.
Residual positionIn treatment. Cross-provider hot failover is absent. A provider-wide outage and sole-operator unavailability could prevent the published four-hour recovery objective; the current drill has not measured full-service recovery. Whole-dump encryption was established on 2026-09-23 and is exercised by the monthly drill; attachment-at-rest encryption remains outstanding, and both it and a measured off-provider recovery are required before this risk can be accepted as controlled.

R-03. Sub-processor personal-data breach #

FieldValue
Inherent impactMedium–High (varies by sub-processor and data category)
Inherent likelihoodLow
TreatmentDefined database fields use application encryption; supplier disclosures and the 30-day sub-processor notice/objection mechanism are published (Security#data-encryption , DPA §6.4 ). Mailjet receives reporter email and a case identifier/link when reporter notifications are chosen. AppSignal receives telemetry; the reporter-controller namespace exclusion was confirmed against AppSignal’s own action inventory on 2026-09-23, but sample contents and other paths remain to be checked (TP-01).
Residual positionIn treatment. An EU-based direct supplier does not prove an EU-only downstream chain. Mailjet’s sensitive-data permission, account DPAs, support access, restricted transfers, whole-object encryption and telemetry samples remain unverified. Do not assert that every supplier receives only non-identifying data.

R-04. Operator credential theft / account compromise #

FieldValue
Inherent impactHigh
Inherent likelihoodLow
TreatmentHardware-backed two-factor authentication on operator accounts with production access. Production database access requires the operator’s authenticated session; credentials are not embedded in code or shared. An append-only audit log records defined report and account events, not every read or action; a privileged database operator could still alter the database-level control (Security#audit-and-compliance ).
Residual positionMonitored. The risk is materially lower than typical SaaS because there are no employee credentials to compromise — the attack surface reduces to one identity. Monitored via AppSignal alerts for anomalous handler-portal authentication patterns. Trigger for re-treatment: a credible phishing attempt against the operator, or a CVE affecting the hardware-key path.

R-05. Restore failure during disaster recovery #

FieldValue
Inherent impactHigh
Inherent likelihoodLow
TreatmentTwo complementary backup layers (database dump and server-level snapshot) in independent retention scopes. Restore drill performed monthly, automated, into a disposable environment; it decrypts the dump, restores it, compares every table against production, and boots the application against the restored data to confirm an encrypted column still decrypts — row counts alone would not reveal a dump whose encryption key no longer matches. Restore procedure documented in the Business continuity plan §6 .
Residual positionAccepted. RPO 24 hours and RTO 4 hours are stated in the SLA . Data written within the 24 hours preceding a catastrophic failure may be lost; this trade-off is disclosed.

R-06. Reporter network-side attribution leak (outside processor boundary) #

FieldValue
Inherent impactMedium
Inherent likelihoodMedium
TreatmentThe Service does not store reporter IP addresses with reports, messages or audit records, and application logs for reporter routes contain no IP addresses; rate limiting uses a keyed, pseudonymous hash kept only for the rate-limit window. The TLS proxy’s own connection logs can include IP addresses and are not linked to reports. File uploads have metadata stripped (EXIF / GPS / author) server-side before storage. See Security#anonymity-and-privacy .
Residual positionAccepted. Network-side attribution (the reporter’s ISP, the reporter’s employer’s egress proxy, a man-in-the-middle, or a corporate-device endpoint agent) is outside the processor boundary and cannot be controlled by the Service. Reporters are informed of this on the portal and may choose to report from a personal device on an external network, or via Tor. This residual is disclosed to reporters at the point of submission, which is the only place the trade-off can be acted upon.

R-07. Critical vulnerability in upstream dependency #

FieldValue
Inherent impactMedium–High
Inherent likelihoodMedium
TreatmentContinuous SCA on every change: Brakeman for Rails-specific issues, bundler-audit for Ruby advisories, importmap audit for JavaScript imports, Dependabot for weekly grouped updates. End-of-life components are replaced before their upstream support window closes. See Security#secure-development-lifecycle and Security#dependency-and-patch-management . Documented vulnerability-response timelines: critical 7 days, high 30 days, medium 90 days.
Residual positionMonitored. The Rails ecosystem is well-staffed for security disclosures. Trigger for re-treatment: a zero-day affecting Rails request-handling, ActiveRecord encryption, or PostgreSQL with no available patch.

R-08. Audit-log integrity compromise #

FieldValue
Inherent impactHigh
Inherent likelihoodLow
TreatmentAudit-log entries are append-only and cannot be edited or selectively deleted by any application user, including organization administrators. PostgreSQL triggers reject changes to core audit content and table truncation even when Rails callbacks are bypassed; their presence is checked against the deployed database through the authenticated operational healthcheck. Required foreign-key nullification remains possible when a related record is erased, and entries are included in PDF case exports for regulatory review. See Security#audit-and-compliance .
Residual positionAccepted. The trail is not hash-chained, WORM-backed, or independently replicated. A privileged database operator could disable or drop the triggers, or issue a direct deletion outside the application-controlled retention and GDPR erasure paths. Production database access controls and the privileged-access procedure govern that residual risk; the public append-only claim is limited to application users and the protected database write paths described above.

R-09. Reporter passcode loss #

FieldValue
Inherent impactMedium
Inherent likelihoodMedium (reporters are anonymous and may not have password-recovery channels)
TreatmentThe 6-digit passcode is stored only as a bcrypt digest and cannot be recovered by the operator or by any handler. Reporters are informed at submission that the passcode is non-recoverable. Handlers may invite a reporter to re-submit or continue the conversation by an alternative channel.
Residual positionAccepted by design. Recoverability of the passcode is incompatible with the reporter-anonymity model: a recovery channel would require an identifier (email, phone) that defeats anonymity, or an operator-side reset that would allow the operator to impersonate the reporter. The trade-off is disclosed to reporters at the point of choosing the passcode.

R-10. Regulatory change requiring re-architecture #

FieldValue
Inherent impactMedium–High
Inherent likelihoodMedium (Member-State transpositions and AI-Act delegated acts continue to evolve)
TreatmentInterpretive positions on ambiguous Directive 2019/1937 provisions are documented openly in the Directive 2019/1937 interpretations , so a controller can verify alignment with their counsel’s reading before subscribing. Per-country law summaries are published in whistleblower laws by country and reviewed when national-law text changes. Material changes to processing (sub-processors, AI use, transfers) are notified to controllers under DPA §6.4 .
Residual positionMonitored. Trigger for re-treatment: ECJ judgment on a Directive 2019/1937 question that contradicts a published interpretation; CJEU judgment on international-transfer adequacy affecting an EU sub-processor; AI-Act delegated act extending obligations to AI-free processors.

Risks consciously not in this register #

The following are recognized risk categories that this register deliberately omits because they are eliminated by design rather than treated:

If any of these design constraints changes, the risk re-enters this register.


Treatment plan #

Clause 6.1.3 requires a risk treatment plan, and a residual position of In treatment means nothing without a date against it: an open item with no target is indistinguishable from one nobody intends to close. Every risk carrying that position appears below, with the control it moves and the date it is owned to.

RefRisk / controlActionTarget
TP-01R-03; A.5.14, A.8.12, A.8.16Verify the supplier chain at account level: executed DPAs, current sub-processor lists, transfer mechanisms, Mailjet’s sensitive-data permission, and a sample of the telemetry AppSignal actually receives. Part done 2026-09-23: AppSignal’s own records confirm no reporter-portal controller is instrumented; the contents of stored samples, and both other suppliers, remain outstanding2026-11-30
TP-02R-02; A.8.13Encryption at rest for file attachments, the remaining half of the backup gap now that database dumps are encrypted2027-01-31
TP-03R-01Operator-incapacity protocol with a named legal contact, replacing the present position that self-service export is the only control2027-03-31
TP-04R-02; A.5.30Restore into a provider other than Hetzner and measure it against the published four-hour RTO2027-03-31
TP-05A.5.35; Clause 9.2Commission an independent external security review, per management review MR-012027-06-30

All five are owned by the operator; there is nobody else to assign them to, which is the substance of R-01 and of the Clause 7.1 resourcing position.

When a target is missed. It is recorded as missed at the next management review , with the reason and a new date, and this table is updated to show both. A target that quietly moves is worse than no target, because it converts a commitment into a decoration.


Review cadence #

TriggerAction
AnnualFull review of every register row; residual positions re-affirmed or revised
Material architecture changeAffected rows reviewed and revised in the same change
Sub-processor added or replacedR-03 reviewed; new row added if the change introduces a category not already represented
Material incident in the incident registerRoot-cause-relevant rows reviewed; treatment updated if the incident revealed a control gap
Material change to the Information security policy or Business continuity planAffected rows reviewed for consistency
Finding raised at internal audit or management reviewAffected rows reviewed; a decision recorded against the register is actioned here

Review actions are recorded in the document-control section below.


Document control #

FieldValue
Document titleEthicsPortal Risk Register
Version1.4
Effective date2026-05-21
Last reviewed2026-09-23
Next scheduled review2027-05-21
OwnerYaroslav Shmarov, operator
DistributionPublished on ethicsportal.eu/policies/

Signed: Yaroslav Shmarov, on behalf of EthicsPortal — 2026-09-23.

Last updated: