| Onderwerp | Stand | Toelichting |
|---|
| Topic | Status | Notes |
| Bewijs zonder vertrouwen in EverStamp | ja | Elke foto en elk dossier is te controleren met open standaarden (C2PA, RFC 3161, de Europese vertrouwenslijst), ook als EverStamp niet meer bestaat. |
| Verification without trusting EverStamp | yes | Every photo and every file can be checked with open standards (C2PA, RFC 3161, the European trust list), including if EverStamp no longer exists. |
| Foto's op onze servers | nee, tenzij u deelt, een verzoek beantwoordt of uw organisatie bewaren aanzet | Foto's blijven op het toestel. Een deellink zet een versleuteld archief tijdelijk bij ons, met een sleutel die alleen in de link zit. Een levering (het antwoord op een verzoek) en bewaren bij EverStamp (een keuze van de organisatie, voor al haar dossiers) zetten het archief bij ons met de sleutel versleuteld in de kluis van het register: EverStamp kan het dan openen, doet dat alleen als een ingelogd lid erom vraagt, en elke opening staat in het logboek. |
| Photos on our servers | no, unless you share a file, answer a request, or your organisation turns on storage at EverStamp | Photos stay on the device. A share link places an encrypted archive with us temporarily, under a key that sits only in the link. A delivery (the answer to a request) and storage at EverStamp (a choice of the organisation, for all its files) place the archive with us with the key encrypted in the vault of the registry: EverStamp can then open it, does so only when a signed-in member asks for it, and every opening is logged. |
| Versleuteling onderweg en in rust | ja | TLS met HSTS; back-ups versleuteld met een sleutel die niet op de server staat; geheimen versleuteld in de database. |
| Encryption in transit and at rest | yes | TLS with HSTS; backups encrypted with a key that is not on the server; secrets encrypted in the database. |
| Signeersleutel in een HSM | ja | AWS KMS (Frankfurt); de sleutel verlaat de HSM nooit. |
| Signing key in an HSM | yes | AWS KMS (Frankfurt); the key never leaves the HSM. |
| Toestellen aantoonbaar echt | ja | Apple App Attest (iPhone) of Android Key Attestation bij elke registratie: alleen een ongewijzigde EverStamp-app op een echt toestel komt binnen. |
| Devices demonstrably genuine | yes | Apple App Attest (iPhone) or Android Key Attestation on every registration: only an unmodified EverStamp app on a real device gets in. |
| Logboek van handelingen | ja | Elke handeling op het dashboard en via de API, met wie en wanneer; plus een openbaar, gestempeld register. |
| Audit log of actions | yes | Every action in the dashboard and through the API, with who and when; plus a public, timestamped registry. |
| Monitoring en statuspagina | ja | Intern elke vijf minuten, extern onafhankelijk; everstamp.app/status. |
| Monitoring and status page | yes | Internally every five minutes, externally and independently; everstamp.app/status. |
| Back-ups en herstel | ja | Elk uur, op drie plekken bij twee leveranciers; herstelpunt hooguit een uur; een runbook met gemeten stappen. |
| Backups and recovery | yes | Hourly, in three places across two providers; recovery point at most one hour; a runbook with measured steps. |
| Gegevens in de EU | ja | Servers in Duitsland; opslag en database in EU-regio's. De lijst van subverwerkers staat onderaan. |
| Data in the EU | yes | Servers in Germany; storage and database in EU regions. The list of subprocessors is at the bottom. |
| Verwijderen op verzoek | ja | Een organisatie kan zichzelf opheffen: alles wordt gewist of ontdaan van namen en contactgegevens, tot in het register. |
| Deletion on request | yes | An organisation can close itself down: everything is erased or stripped of names and contact details, right into the registry. |
| Export van alle gegevens | ja | Een zip met alles van de organisatie, als json en csv, door een beheerder zelf te maken. |
| Export of all data | yes | A zip with everything belonging to the organisation, as JSON and CSV, generated by an administrator. |
| MFA voor uw gebruikers | deels | Inloggen gaat zonder wachtwoord via een link naar het e-mailadres; een tweede factor voor uw gebruikers volgt. |
| MFA for your users | partly | Sign-in is passwordless, through a link sent to the email address; a second factor for your users is to follow. |
| SSO en SCIM | nog niet | Op de roadmap voor Enterprise. |
| SSO and SCIM | not yet | On the roadmap for Enterprise. |
| ISO 27001, SOC 2 | nog niet | Geen certificering; deze pagina en de open verificatie zijn wat we nu kunnen laten zien. |
| ISO 27001, SOC 2 | not yet | No certification; this page and the open verification are what we can show you today. |
| Externe pentest | gepland | Voor de lancering; het rapport delen we onder NDA. |
| External penetration test | planned | Before launch; we will share the report under NDA. |