Wiki source code of Transparency Policy

Last modified by Robert Schaub on 2025/12/22 14:32

Show last authors
1 = Transparency Policy =
2 == 1. Purpose and Scope ==
3 This Transparency Policy defines FactHarbor's commitment to openness in all aspects of operations, governance, and finances. It establishes what information is public by default, what may be kept private, and the processes for requesting information.
4 **This policy applies to:**
5 * FactHarbor Organisation (legal entity)
6 * All FactHarbor projects and services
7 * Governing Team, staff, and contractors
8 * All decision-making processes
9 == 2. Core Principle: Default to Public ==
10 **Default Rule:** All organisational information is public unless it meets a specific exception.
11 This principle reflects FactHarbor's mission: a project claiming to support well-grounded, manipulation-resistant judgments must itself be transparent and accountable.
12 == 3. What Must Be Public ==
13 === 3.1 Financial Information ===
14 Published annually (within 6 months of fiscal year end):
15 * **Complete financial statements** (audited where possible)
16 * **Tax filings** (Swiss tax filings per cantonal requirements)
17 * **Income statement** showing: * Grants and donations (aggregate) * Sponsorships and contracts (aggregate) * Other revenue sources
18 * **Expense statement** showing: * Program expenses by category * Administrative costs * Fundraising costs
19 * **Compensation ranges** by role (not individual salaries)
20 * **Major funding relationships** (>$50,000 per year or >10% of budget)
21 === 3.2 Governance Information ===
22 Published continuously (promptly of changes):
23 * **Governance documents**: * Verein statutes (bylaws) * Operating procedures * Decision-making authority matrix * Conflict of interest policy
24 * **Governing Team information**: * Current board composition * Governing Team member bios and affiliations * Meeting schedules * Governing Team meeting minutes (with limited exceptions - see section 4) * Governing Team decisions and resolutions
25 * **Policy changes**: * All policy updates with rationale * Effective dates * Community input periods
26 * **Organisational structure**: * Reporting relationships * Key staff roles (not individual names unless they choose) * Advisory bodies and committees
27 === 3.3 Operational Information ===
28 Published regularly:
29 * **Transparency Reports** (twice yearly): * Government requests for user data * Content moderation statistics * Takedown requests (DMCA, legal) * Policy violation reports * Security incident disclosures (after resolution)
30 * **Technical Performance**: * AKEL performance metrics * Quality gate pass rates * Risk tier distribution statistics * System uptime and availability
31 * **Content Statistics**: * Number of claims, scenarios, verdicts * Publication mode distribution * Review and audit rates
32 * **Partnership Information**: * Major partnerships and collaborations * Funding relationships * Technical dependencies
33 === 3.4 Source Code and Technical Specifications ===
34 Published continuously:
35 * All source code per open source licenses (MIT, AGPL, CC BY-SA)
36 * Technical architecture documentation
37 * Protocol and data model specifications
38 * API documentation
39 * Quality gate algorithms and parameters
40 * Risk tier assignment criteria
41 == 4. What May Be Private ==
42 Information may be withheld ONLY when disclosure would:
43 === 4.1 Individual Privacy (Highest Priority) ===
44 Private:
45 * User personal data (emails, IP addresses, phone numbers)
46 * Contributor real names (if pseudonymous)
47 * Personnel files and reviews
48 * Individual salaries (publish ranges only)
49 * Medical or family information
50 * Background checks
51 === 4.2 Security ===
52 Temporarily private (with time limits):
53 * Unpatched security vulnerabilities (public after patch + 30-90 days)
54 * Active security incidents (public after resolution)
55 * Penetration test results (sanitized version public after fixes)
56 * Authentication credentials and API keys
57 * Infrastructure-specific security configurations
58 === 4.3 Legal ===
59 Private while active:
60 * Ongoing litigation details (summary public, details after resolution)
61 * Attorney-client privileged communications
62 * Settlement negotiations
63 * Subpoenas with gag orders (challenge orders exceeding 1 year)
64 * Whistleblower identity (protected permanently unless they consent)
65 === 4.4 Operational ===
66 Private with conditions:
67 * Donor information (unless donor consents to publication)
68 * Abuse investigation details (protect victims)
69 * Governing Team discussions on personnel matters (outcomes public)
70 * Strategic plans that would create competitive disadvantage (time-limited: public after 12 months or execution)
71 == 5. Time Limits on Privacy ==
72 All private information has an expiration date:
73 * **Security vulnerabilities**: Public 30-90 days after patch
74 * **Security incidents**: Public immediately after resolution (sanitized)
75 * **Governing Team personnel discussions**: Outcomes public, process private for 1 year then reviewed
76 * **Strategic plans**: Public after execution or 12 months, whichever comes first
77 * **Legal matters**: Public after resolution
78 * **Donor information**: May be withheld permanently only with donor objection
79 **Annual Review:** All information marked "private" is reviewed annually. If exception no longer applies, information becomes public.
80 == 6. Transparency Reports ==
81 Published **twice yearly** (January and July):
82 === 6.1 Government Requests ===
83 * Number of requests for user data (by type)
84 * Number of requests complied with
85 * Number of requests challenged
86 * Number of users affected
87 * Types of data requested
88 === 6.2 Content Moderation ===
89 * Total moderation actions by category
90 * Publication mode changes (Mode 1 → 2, etc.)
91 * Quality gate failures by gate
92 * Community flags and expert reviews
93 * Takedown requests and responses
94 === 6.3 Security ===
95 * Security incidents (after resolution)
96 * Vulnerability reports received
97 * Bounties paid
98 * Patches deployed
99 * Audit findings (sanitized)
100 === 6.4 Performance ===
101 * AKEL performance metrics
102 * User growth and engagement
103 * Content growth
104 * Community contributions
105 * System availability
106 == 7. Information Request Process ==
107 === 7.1 Submitting a Request ===
108 Anyone may request organisational information:
109 1. **Email**: [Transparency contact to be established]
110 2. **Include**: * Specific information requested * Rationale for request * Preferred format (if applicable)
111 3. **Expect**: Initial response within 14 business days
112 === 7.2 Request Evaluation ===
113 Requests are evaluated against:
114 * Is information already public? (link provided)
115 * Does exception in Section 4 apply?
116 * Can information be disclosed with redactions?
117 * Is time limit on privacy expired?
118 === 7.3 Response Types ===
119 * **Granted**: Information provided promptly
120 * **Partially Granted**: Information with redactions provided, explanation of redactions
121 * **Denied**: Written explanation of which exception applies
122 * **Deferred**: If time-limited exception, date when information will become public
123 == 8. Appeals Process ==
124 If request is denied:
125 === 8.1 First Appeal ===
126 1. Submit appeal to **Transparency Committee** (if established) or Governing Team
127 2. Include: * Original request * Denial reason * Additional context or rationale
128 3. Decision promptly
129 === 8.2 Final Appeal ===
130 1. Appeal to **Full Governing Team** of Leads
131 2. Governing Team reviews at next scheduled meeting
132 3. Governing Team decision is final
133 4. Rationale published (unless it would disclose the private information)
134 == 9. Community Input ==
135 === 9.1 Policy Changes ===
136 Before making material changes to transparency commitments:
137 1. **Proposal published** with rationale
138 2. **Public comment period** (minimum 30 days)
139 3. **Community input** considered
140 4. **Decision rationale** published with final policy
141 === 9.2 Ongoing Input ===
142 Community may:
143 * Request additional transparency commitments
144 * Suggest improvements to reporting
145 * Identify information that should be public
146 * Challenge exceptions
147 Submit suggestions to: [Transparency contact to be established]
148 == 10. Compliance and Oversight ==
149 === 10.1 Internal Oversight ===
150 * **Transparency Officer** (staff or board designee): * Reviews all privacy classifications * Manages information requests * Prepares transparency reports
151 * **Annual Transparency Audit**: * Reviews all "private" classifications * Checks compliance with publication schedules * Assesses process effectiveness
152 === 10.2 Public Reporting ===
153 Annual transparency compliance report includes:
154 * Number of information requests received
155 * Request grant/deny statistics
156 * Exception usage (how often each applied)
157 * Privacy expiration reviews
158 * Improvements made to process
159 === 10.3 Independent Audit ===
160 When feasible (budget permitting):
161 * Independent third-party transparency audit
162 * Results published
163 * Recommendations implemented or explanations provided
164 == 11. Enforcement ==
165 === 11.1 Violations ===
166 Violation of this policy includes:
167 * Withholding information that should be public
168 * Failing to publish required reports on schedule
169 * Misclassifying public information as private
170 * Extending privacy beyond time limits without review
171 === 11.2 Consequences ===
172 * Internal violations: Performance review, retraining, or disciplinary action
173 * Governing Team violations: Governing Team review, potential removal
174 * Persistent violations: Independent investigation
175 === 11.3 Whistleblower Protection ===
176 Anyone may report transparency violations to:
177 * [Transparency contact to be established]
178 * Any board member directly
179 * External parties (regulators, media)
180 Whistleblowers are protected from retaliation. Reports may be anonymous.
181 == 12. Updates to This Policy ==
182 Changes to this Transparency Policy:
183 * Require Governing Team approval
184 * Must include 30-day public comment period
185 * Are published with rationale
186 * Take effect 30 days after final publication
187 **Version History:**
188 * 0.9.28 (2025-12-17): Initial policy based on best practices from Wikimedia Foundation and Mozilla Foundation
189 == 13. Contact ==
190 **Transparency Requests**: [Transparency contact to be established]
191 **Appeals**: [Governing Team contact to be established]
192 **Whistleblower Reports**: [To be established - secure channel]
193 == 14. Related Policies ==
194 * [[Open Source Model and Licensing>>FactHarbor.Organisation.Open Source Model and Licensing]]
195 * [[Privacy Policy>>FactHarbor.Organisation.How-We-Work-Together.Privacy-Policy]]
196 * [[Governance>>FactHarbor.Organisation.Governance.WebHome]]
197 * [[Finance & Compliance>>FactHarbor.Organisation.Finance-Compliance]]