CRUSETRA
Appendix B · Scoring Security and data handling ← Back to the findings

Where Scoring runs, and what stays on your machine.

A matte aluminium padlock; its shackle, closed, is the same deep amethyst as the tool's accents.

Customer risk scoring reads the most personal table a bank holds. Its public data was written and generated with no real person in it, and no official risk list was copied anywhere. No module is allowed to reach the network.

No module may touch the network, and a test checks each source file

Like its sister tools Monitoring and the Dossier, Scoring downloads nothing. The allowlist, the modules allowed to touch the network, is empty. A structural test reads each source file as text and fails the suite if a line touches the network. It first plants a network call and checks that it sees it, so its zero can be trusted.

Verify nothing touches the network

Run the suite, which fails if any file gains such a line.

run it yourself
npm testfails if any module touches the network, and the allowlist is empty

Where it livessrc/frontiere.test.ts:30 · src/frontiere.test.ts:51

The public data holds no real person and no official list

Our public test set is a file we no longer change. Each customer file was written for the typology it illustrates, a named pattern of risk, or generated from those files under a seed. It holds no customer data, anonymised or otherwise.

No official risk list was copied in either. A test requires the suspect files and the retained ones, those not escalated, to share their countries. So the test set cannot bring a list in by its examples. The geography factor, which reads the country, is zero here, and the tool prints that zero as a finding.

Check the data's source

The data file states its source, and a test checks that no official list was copied in.

run it yourself
python3 -c "import json; d=json.load(open('src/dossiers-etiquetes.json')); print(d['provenance'], len(d['dossiers']), 'dossiers, each with a written reason')"prints: authored 84 dossiers, each with a written reason (source, then customer files)

Where it livessrc/dossiers-etiquetes.json:2 · src/dossiers-etiquetes.test.ts:65

Your two files stay yours, and the outputs carry no value from them

The measurement is a local process at your desk, reading your two CSV files. It loads the reviews your analysts already closed and your customer attributes into memory and writes its outputs next to your files and nowhere else. They are counts, rates, confidence intervals (the range the true rate is likely to sit in) and one answer per review, keyed by review id. Your customer ids, countries and amounts do not leave the machine. Your review ids survive as those keys, so choose opaque ids.

The tool has no callback and no telemetry, so it opens no connection to us and sends no usage data. There is no account to create.

Check the test set offline

Cut the network, run everything, then recompute the content hash (the fingerprint of its bytes) of our public test set.

run it yourself
CRUSETRA_OFFLINE=1 npm testthe whole suite with the network cutnpm run sceller -- releve-public.json --checkprints "already sealed, and the seal matches" and the content hash

Where it livessrc/sceller.ts:60 · src/dossier.ts:11