CRUSETRA
Appendix B · Dossier Security and data handling ← Back to the findings

What the Dossier reads, and what stays local.

A matte aluminium padlock; its shackle, closed, is the same polished onyx as the tool's accents.

The Dossier is the piece your regulator reads, so its rules are the strictest in the suite. It reads content hashes (a number computed from a file's bytes), dates, versions and answers from the other tools' reports. An answer is what one control returns. It reads no client value of yours and touches no network at all.

The network allowlist is empty and a test over each file checks it

Like Monitoring and Scoring, two other tools of the suite, the Dossier downloads nothing. The allowlist, the list of modules that may touch the network, is empty. A structural test reads each source file for network calls and fails the suite if one appears. Its detector proves it can see a planted call before its zero is believed.

Verify the empty allowlist

Run the suite. The test fails if any file gains a network call.

run it yourself
npm testfails if any module touches the network, and the allowlist is empty

Where it livessrc/frontiere.test.ts:30 · src/frontiere.test.ts:51

What the Dossier reads from a report

The Dossier reads the other tools' signed reports: their content hashes, dates, versions, rule settings and answer counts. It never reads, stores or reprints a client value, because no name, no amount, no account, no country of yours exists in any report of the suite. It cites a report by its content hash and its answers, and names the review by its identifier only.

The document the Dossier writes is saved next to your files and in no other place. Its content hash is computed like that of each tool's results file in the suite, and the command that checks it is printed on the page that presents it.

Verify on the results file itself

The public results file, releve-public.json, carries its own content hash and holds answers, content hashes, dates and counts. Search it for anything else.

run it yourself
python3 -c "import json; d=json.load(open('releve-public.json')); print(sorted(d), '/', sorted(d['questions']))"prints the file's top-level keys (controls, coverage, questions, settings, seal, the content hash) and its questions

Where it livessrc/dossier.ts:9 · src/empreinte.ts:58 · src/empreinte.ts:63

A signature is checked before it is trusted

A signature that cannot be checked is not treated as informally fine, and it does not count as valid. The control fails and its answer states the reason, which we call a refusal, one per report. On day one that produced a zero on signatures across the whole suite, printed on the public page.

Verify a refusal

Read any answer of the signed control in the public results file, listed under verdicts. It carries its reason.

run it yourself
python3 -c "import json; q=json.load(open('releve-public.json'))['questions']['screening']; print([v['detail'] for v in q['verdicts'] if v['controle']=='signed'][0])"prints the refusal text as the tool recorded it

Where it livessrc/controles/index.ts:15 · src/controles/fresh.ts:5