Wiki source code of Transparency Policy

Last modified by Robert Schaub on 2025/12/24 21:53

Show last authors
1 = Transparency Policy =
2 == 1. Purpose and Scope ==
3 This Transparency Policy defines FactHarbor's commitment to openness in all aspects of operations, governance, and finances. It establishes what information is public by default, what may be kept private, and the processes for requesting information.
4 **This policy applies to:**
5 * FactHarbor Organisation (legal entity)
6 * All FactHarbor projects and services
7 * Governing Team, staff, and contractors
8 * All decision-making processes
9 == 2. Core Principle: Default to Public ==
10 **Default Rule:** All organisational information is public unless it meets a specific exception.
11 This principle reflects FactHarbor's mission: a project claiming to support well-grounded, manipulation-resistant judgments must itself be transparent and accountable.
12 == 3. What Must Be Public ==
13 === 3.1 Financial Information ===
14 Published annually (within 6 months of fiscal year end):
15 * **Complete financial statements** (audited where possible)
16 * **Tax filings** (Swiss tax filings per cantonal requirements)
17 * **Income statement** showing:
18 * Grants and donations (aggregate)
19 * Sponsorships and contracts (aggregate)
20 * Other revenue sources
21 * **Expense statement** showing:
22 * Program expenses by category
23 * Administrative costs
24 * Fundraising costs
25 * **Compensation ranges** by role (not individual salaries)
26 * **Major funding relationships** (>$50,000 per year or >10% of budget)
27 === 3.2 Governance Information ===
28 Published continuously (promptly of changes):
29 * **Governance documents**:
30 * Verein statutes (bylaws)
31 * Operating procedures
32 * Decision-making authority matrix
33 * Conflict of interest policy
34 * **Governing Team information**:
35 * Current board composition
36 * Governing Team member bios and affiliations
37 * Meeting schedules
38 * Governing Team meeting minutes (with limited exceptions - see section 4)
39 * Governing Team decisions and resolutions
40 * **Policy changes**:
41 * All policy updates with rationale
42 * Effective dates
43 * Community input periods
44 * **Organisational structure**:
45 * Reporting relationships
46 * Key staff roles (not individual names unless they choose)
47 * Advisory bodies and committees
48 === 3.3 Operational Information ===
49 Published regularly:
50 * **Transparency Reports** (twice yearly):
51 * Government requests for user data
52 * Content moderation statistics
53 * Takedown requests (DMCA, legal)
54 * Policy violation reports
55 * Security incident disclosures (after resolution)
56 * **Technical Performance**:
57 * AKEL performance metrics
58 * Quality gate pass rates
59 * Risk tier distribution statistics
60 * System uptime and availability
61 * **Content Statistics**:
62 * Number of claims, scenarios, verdicts
63 * Publication mode distribution
64 * Review and audit rates
65 * **Partnership Information**:
66 * Major partnerships and collaborations
67 * Funding relationships
68 * Technical dependencies
69 === 3.4 Source Code and Technical Specifications ===
70 Published continuously:
71 * All source code per open source licenses (MIT, AGPL, CC BY-SA)
72 * Technical architecture documentation
73 * Protocol and data model specifications
74 * API documentation
75 * Quality gate algorithms and parameters
76 * Risk tier assignment criteria
77 == 4. What May Be Private ==
78 Information may be withheld ONLY when disclosure would:
79 === 4.1 Individual Privacy (Highest Priority) ===
80 Private:
81 * User personal data (emails, IP addresses, phone numbers)
82 * Contributor real names (if pseudonymous)
83 * Personnel files and reviews
84 * Individual salaries (publish ranges only)
85 * Medical or family information
86 * Background checks
87 === 4.2 Security ===
88 Temporarily private (with time limits):
89 * Unpatched security vulnerabilities (public after patch + 30-90 days)
90 * Active security incidents (public after resolution)
91 * Penetration test results (sanitized version public after fixes)
92 * Authentication credentials and API keys
93 * Infrastructure-specific security configurations
94 === 4.3 Legal ===
95 Private while active:
96 * Ongoing litigation details (summary public, details after resolution)
97 * Attorney-client privileged communications
98 * Settlement negotiations
99 * Subpoenas with gag orders (challenge orders exceeding 1 year)
100 * Whistleblower identity (protected permanently unless they consent)
101 === 4.4 Operational ===
102 Private with conditions:
103 * Donor information (unless donor consents to publication)
104 * Abuse investigation details (protect victims)
105 * Governing Team discussions on personnel matters (outcomes public)
106 * Strategic plans that would create competitive disadvantage (time-limited: public after 12 months or execution)
107 == 5. Time Limits on Privacy ==
108 All private information has an expiration date:
109 * **Security vulnerabilities**: Public 30-90 days after patch
110 * **Security incidents**: Public immediately after resolution (sanitized)
111 * **Governing Team personnel discussions**: Outcomes public, process private for 1 year then reviewed
112 * **Strategic plans**: Public after execution or 12 months, whichever comes first
113 * **Legal matters**: Public after resolution
114 * **Donor information**: May be withheld permanently only with donor objection
115 **Annual Review:** All information marked "private" is reviewed annually. If exception no longer applies, information becomes public.
116 == 6. Transparency Reports ==
117 Published **twice yearly** (January and July):
118 === 6.1 Government Requests ===
119 * Number of requests for user data (by type)
120 * Number of requests complied with
121 * Number of requests challenged
122 * Number of users affected
123 * Types of data requested
124 === 6.2 Content Moderation ===
125 * Total moderation actions by category
126 * Publication mode changes (Mode 1 → 2, etc.)
127 * Quality gate failures by gate
128 * Community flags and expert reviews
129 * Takedown requests and responses
130 === 6.3 Security ===
131 * Security incidents (after resolution)
132 * Vulnerability reports received
133 * Bounties paid
134 * Patches deployed
135 * Audit findings (sanitized)
136 === 6.4 Performance ===
137 * AKEL performance metrics
138 * User growth and engagement
139 * Content growth
140 * Community contributions
141 * System availability
142 == 7. Information Request Process ==
143 === 7.1 Submitting a Request ===
144 Anyone may request organisational information:
145 1. **Email**: [Transparency contact to be established]
146 2. **Include**:
147 * Specific information requested
148 * Rationale for request
149 * Preferred format (if applicable)
150 3. **Expect**: Initial response within 14 business days
151 === 7.2 Request Evaluation ===
152 Requests are evaluated against:
153 * Is information already public? (link provided)
154 * Does exception in Section 4 apply?
155 * Can information be disclosed with redactions?
156 * Is time limit on privacy expired?
157 === 7.3 Response Types ===
158 * **Granted**: Information provided promptly
159 * **Partially Granted**: Information with redactions provided, explanation of redactions
160 * **Denied**: Written explanation of which exception applies
161 * **Deferred**: If time-limited exception, date when information will become public
162 == 8. Appeals Process ==
163 If request is denied:
164 === 8.1 First Appeal ===
165 1. Submit appeal to **Transparency Committee** (if established) or Governing Team
166 2. Include:
167 * Original request
168 * Denial reason
169 * Additional context or rationale
170 3. Decision promptly
171 === 8.2 Final Appeal ===
172 1. Appeal to **Full Governing Team** of Leads
173 2. Governing Team reviews at next scheduled meeting
174 3. Governing Team decision is final
175 4. Rationale published (unless it would disclose the private information)
176 == 9. Community Input ==
177 === 9.1 Policy Changes ===
178 Before making material changes to transparency commitments:
179 1. **Proposal published** with rationale
180 2. **Public comment period** (minimum 30 days)
181 3. **Community input** considered
182 4. **Decision rationale** published with final policy
183 === 9.2 Ongoing Input ===
184 Community may:
185 * Request additional transparency commitments
186 * Suggest improvements to reporting
187 * Identify information that should be public
188 * Challenge exceptions
189 Submit suggestions to: [Transparency contact to be established]
190 == 10. Compliance and Oversight ==
191 === 10.1 Internal Oversight ===
192 * **Transparency Officer** (staff or board designee):
193 * Reviews all privacy classifications
194 * Manages information requests
195 * Prepares transparency reports
196 * **Annual Transparency Audit**:
197 * Reviews all "private" classifications
198 * Checks compliance with publication schedules
199 * Assesses process effectiveness
200 === 10.2 Public Reporting ===
201 Annual transparency compliance report includes:
202 * Number of information requests received
203 * Request grant/deny statistics
204 * Exception usage (how often each applied)
205 * Privacy expiration reviews
206 * Improvements made to process
207 === 10.3 Independent Audit ===
208 When feasible (budget permitting):
209 * Independent third-party transparency audit
210 * Results published
211 * Recommendations implemented or explanations provided
212 == 11. Enforcement ==
213 === 11.1 Violations ===
214 Violation of this policy includes:
215 * Withholding information that should be public
216 * Failing to publish required reports on schedule
217 * Misclassifying public information as private
218 * Extending privacy beyond time limits without review
219 === 11.2 Consequences ===
220 * Internal violations: Performance review, retraining, or disciplinary action
221 * Governing Team violations: Governing Team review, potential removal
222 * Persistent violations: Independent investigation
223 === 11.3 Whistleblower Protection ===
224 Anyone may report transparency violations to:
225 * [Transparency contact to be established]
226 * Any board member directly
227 * External parties (regulators, media)
228 Whistleblowers are protected from retaliation. Reports may be anonymous.
229 == 12. Updates to This Policy ==
230 Changes to this Transparency Policy:
231 * Require Governing Team approval
232 * Must include 30-day public comment period
233 * Are published with rationale
234 * Take effect 30 days after final publication
235 **Version History:**
236 * 0.9.28 (2025-12-17): Initial policy based on best practices from Wikimedia Foundation and Mozilla Foundation
237 == 13. Contact ==
238 **Transparency Requests**: [Transparency contact to be established]
239 **Appeals**: [Governing Team contact to be established]
240 **Whistleblower Reports**: [To be established - secure channel]
241 == 14. Related Policies ==
242 * [[Open Source Model and Licensing>>FactHarbor.Organisation.Open Source Model and Licensing]]
243 * [[Privacy Policy>>FactHarbor.Organisation.How-We-Work-Together.Privacy-Policy]]
244 * [[Governance>>FactHarbor.Organisation.Governance.WebHome]]
245 * [[Finance & Compliance>>FactHarbor.Organisation.Finance-Compliance]]