Open Source · Mission · KonzeptOpen Source · Mission · Concept

Bürgerdaten gehören den Bürgern.

Personal data should be personal.

Vivodepot ist quelloffen. Das macht diesen Satz nachprüfbar, nicht nur behauptet. Diese Seite zeigt das Konzept dahinter, die regulatorische Einbettung und was Open Source hier konkret bedeutet.

Vivodepot is open source. That makes this claim verifiable, not just asserted. This page sets out the concept behind it, its regulatory frame, and what open source means here in concrete terms.

AusgangslageStarting point

Was die Institutionen wissen — und was Sie nicht wissen

What institutions know about you — and what you do not

Ein Mensch im Jahr 2026 hinterlässt seine digitale Repräsentation in Dutzenden Systemen gleichzeitig. Das Krankenhaus führt eine Patientenakte. Die Krankenkasse kennt seine Versicherungshistorie. Die Bank kennt seine Finanzen. Das Einwohnermeldeamt kennt seine Adresse. Keine dieser Institutionen kennt den ganzen Menschen. Jede kennt nur das Fragment, das für sie relevant ist — definiert aus ihrer eigenen Perspektive, in ihrem eigenen Format, für ihre eigenen Zwecke. Der Mensch selbst hat dieses Bild nicht — jedenfalls nicht zusammengeführt.

A person in 2026 leaves a digital trace in dozens of systems at once. The hospital keeps a patient record. The health insurer knows the insurance history. The bank knows the finances. The registration office knows the address. None of these institutions knows the whole person. Each knows only the fragment relevant to it — defined from its own perspective, in its own format, for its own purposes. The person themselves does not have this picture — at least not in one place.

Diese Fragmentierung hat einen strukturellen Grund. Die digitale Welt ist um Institutionen herum gebaut, nicht um den Menschen: Institutionen sammeln und ordnen das, was sie für ihre Aufgaben brauchen. Der Mensch erscheint darin als Datenpunkt, nicht als jemand, dem die Daten gehören.

The fragmentation is structural, not accidental. The digital world is built around institutions, not around people: institutions collect and organise what they need for their tasks. The person shows up there as a data point, not as the one to whom the data belongs.

Seit dem Volkszählungsurteil des Bundesverfassungsgerichts 1983 ist das Recht auf informationelle Selbstbestimmung grundrechtlich verankert. Seit der DSGVO 2018 hat jeder EU-Bürger ein Recht auf Datenübertragbarkeit nach Art. 20. Die rechtliche Grundlage steht. Was zur praktischen Umsetzung gehört — Werkzeuge, mit denen die Person ihre Daten aus mehreren Systemen zusammenführen und gebündelt weitergeben kann — fehlt bis heute in den meisten Lebensbereichen.

Since the German Federal Constitutional Court’s 1983 census ruling, the right to informational self-determination has been constitutionally anchored. Since the GDPR in 2018, every EU citizen has had a right to data portability under Article 20. The legal foundation is there. What is needed to make it real in everyday life — tools with which a person can bring their data together from several systems and hand it over in one piece — is still missing in most areas of life.

Das Grundrecht gewährleistet insoweit die Befugnis des Einzelnen, grundsätzlich selbst über die Preisgabe und Verwendung seiner persönlichen Daten zu bestimmen.
The fundamental right guarantees the individual the authority to decide, in principle, for themselves on the disclosure and use of their personal data. Working translation — no official English version exists.
Bundesverfassungsgericht · BVerfGE 65,1 · Volkszählungsurteil · 15. Dezember 1983 German Federal Constitutional Court · BVerfGE 65,1 · Census Decision · 15 December 1983
Maksym Kaharlytskyi
KonzeptConcept

Der Citizen Digital Twin

The Citizen Digital Twin

Der Begriff des Digital Twin ist in der Industrie geläufig: die vollständige digitale Entsprechung eines physischen Objekts, gehalten und betrieben von Institutionen. Vivodepot überträgt dieses Konzept auf den Menschen, der über seine Daten selbst verfügt.

The idea of the digital twin is familiar from industry: the complete digital counterpart of a physical object, held and operated by institutions. Vivodepot carries this concept across to the person, who has authority over their own data.

Der Citizen Digital Twin ist die digitale Repräsentation eines Menschen — Identität, Beziehungen, Vollmachten, Lebenskontext aus den Bereichen, die für die Person zählen. Der industrielle Twin gehört dem Hersteller. Der Citizen-Twin gehört der Person, deren Leben er darstellt. Ein zweiter Unterschied ist die Reichweite: Wo Sektor-Apps eine Domäne abbilden — Gesundheit, Finanzen, Behörde —, deckt der Twin den ganzen Lebenskontext einer Person ab. Vorsorge, Pflege, Familie, biografische Übergänge gehören dazu, ohne dass die Person sie in fünf verschiedene Apps verteilen muss.

The Citizen Digital Twin is the digital representation of a person — identity, relationships, powers of attorney, life context across the areas that matter to them. The industrial twin belongs to its manufacturer. The citizen twin belongs to the person whose life it represents. A second difference is reach: where sector apps cover one domain — health, finance, public administration — the twin covers a person's entire life context. Advance care, nursing, family, biographical transitions all belong, without the person having to distribute them across five different apps.

Aus dieser Eigentumslogik folgt eine technische Konsequenz, die das Konzept gegen die übliche Datenarchitektur abgrenzt: Daten überleben das Werkzeug. Wenn eine Institution, mit der eine Person verbunden war, einmal nicht mehr existiert — ein Pflegeheim schließt, ein Anbieter stellt seine Dienste ein, ein Vertragsverhältnis endet — bleiben die Daten der Person in ihrer Vivodepot-Datei erhalten. Lesbar, editierbar, exportierbar. Was wegfällt, ist die institutionelle Schnittstelle, nicht der Inhalt.

From this ownership logic follows a technical consequence that sets the concept apart from the standard data architecture: data outlives the tool. When an institution a person was connected to no longer exists — a care home closes, a provider discontinues their service, a contractual relationship ends — the person's data remains in their Vivodepot file. Readable, editable, exportable. What disappears is the institutional interface, not the content itself.

Abgrenzung zu verwandten Ansätzen

Demarcation from related approaches

Verwandte Konzepte haben Teile der Frage der Bürgerdatensouveränität aufgenommen — stets jedoch fragmentiert oder mit Kompromissen, die den Begriff der Souveränität einschränken.

Related concepts have taken on parts of the question of citizen data sovereignty — but always in a fragmented way, or with compromises that narrow what sovereignty means.

Deutschland-App (BMDS)

Deutschland-App (Federal Ministry for Digital and State Modernisation)

Die geplante Deutschland-App ist der Bürger-zu-Behörde-Kanal: Anträge stellen, Termine buchen, Bescheide empfangen — über ein zentrales Konto, mit der EUDIW als Authentifizierungs-Schicht. Vivodepot ist der Bürger-eigene Inhalts-Container, der die Daten vorhält, die in solche Anträge eingehen. Beide Architekturen sind komplementär: die Deutschland-App ist die Plattform, Vivodepot ist das persönliche Werkzeug. Vivodepot hält die Daten strukturiert vor, die in solche Anträge eingehen — als FHIR-IPS-Bundles und als eigener, dokumentierter Datensatz mit an FIM angelehnter Feldbenennung —, und gibt sie maschinenlesbar heraus.

The planned Deutschland-App is the citizen-to-administration channel: submit applications, book appointments, receive notices — via a central account, with the EUDIW as authentication layer. Vivodepot is the citizen-owned content container that holds the data flowing into such applications. The architectures are complementary: the Deutschland-App is the platform, Vivodepot is the personal tool. Vivodepot holds the data structured that flows into such applications — as FHIR-IPS bundles and as its own, documented record with field naming aligned to FIM — and makes it available in machine-readable form.

Cloud-basierte Anbieter und proprietäre Stacks

Cloud-based providers and proprietary stacks

Souveränität entsteht erst, wenn kein Anbieter ungefragt auf die Daten zugreifen kann — auch Vivodepot nicht. Deshalb gibt es keinen Vivodepot-Server: Die Datei liegt beim Bürger, der Schlüssel auch. Zum Hintergrund — US Cloud Act, „Sovereignty Washing" — siehe EU und Regulatorik →

Sovereignty only arises when no provider can access the data without being asked — including Vivodepot. That is why there is no Vivodepot server: the file stays with the citizen, and so does the key. For the background — US Cloud Act, "sovereignty washing" — see EU & regulation →

Elektronische Patientenakte (ePA)

The German electronic health record (ePA)

Die ePA macht den Patienten im Gesundheitssystem sichtbar. Vivodepot macht den Menschen hinter der Akte sichtbar — wer für ihn entscheiden darf, was seine Pflegewünsche sind, wie seine Biografie geprägt ist. Das ist klinisch relevant, aber nicht klinisch erzeugt.

The ePA makes the patient visible within the health system. Vivodepot makes the person behind the record visible — who may decide for them, what their care wishes are, how their biography has shaped them. This is clinically relevant, but not clinically produced.

Verwandte Ansätze aus Forschung und Standardisierung — EU Digital Identity Wallet, Self-Sovereign Identity, Solid/MyData, Vendor Relationship Management — mit Quellen unter Weiterlesen →

Related approaches from research and standardisation — EU Digital Identity Wallet, Self-Sovereign Identity, Solid/MyData, Vendor Relationship Management — with sources under Resources →

Christopher Echols
ReferenzimplementierungReference implementation

Vivodepot zeigt, dass es geht

Vivodepot shows that it is possible

Ein europäischer Vertragspartner allein ist noch keine Souveränität. Sie kann erst entstehen, wenn kein Anbieter — auch Vivodepot nicht — zwischen dem Bürger und seinen Daten steht. Das Konzept ist nicht utopisch. Eine Single-File-HTML-Anwendung ohne Server, ohne Cloud, ohne Konto kann das leisten — Vivodepot zeigt es konkret.

A European contractual partner alone is not yet sovereignty. It can only arise when no provider — including Vivodepot — stands between the citizen and their data. The concept is not utopian. A single-file HTML application without a server, without a cloud, without an account can deliver on it — Vivodepot shows it in practice.

Technische GrundlageTechnical foundation

Wie Vivodepot das Konzept umsetzt

How Vivodepot realises the concept

Jede dieser Entscheidungen folgt aus dem Souveränitätsprinzip.

Each of these choices follows from the sovereignty principle.

Träger und Format

Carrier and format

Eine verschlüsselte Single-File-HTML-Anwendung, die ohne Installation in jedem Browser läuft — vom USB-Stick, vom Laptop, vom lokalen Laufwerk. Die Anwendung bindet sich an keinen bestimmten Gerätetyp, sondern an die Person, die sie nutzt. Damit entfallen zwei Bindungen, die plattform-gebundene Apps mit sich bringen: Vivodepot funktioniert auf jeder Hardware-Plattform und in jedem gängigen Betriebssystem, und es ist nicht von einem App-Store abhängig, der die Distribution oder Funktion einschränken könnte.

An encrypted single-file HTML application that runs without installation in any browser — from a USB stick, from a laptop, from a local drive. The application binds itself to no particular device type, but to the person who uses it. This removes two ties that platform-bound apps bring with them: Vivodepot works on any hardware platform and any common operating system, and it does not depend on an app store that could restrict distribution or functionality.

Verschlüsselung

Encryption

AES-256-GCM. Ohne das Passwort der Person gibt es keinen Zugang — nicht für Institutionen, nicht für Dritte, nicht für Vivodepot selbst. Das ist bauartbedingt so, nicht eine Einstellung.

AES-256-GCM. Without the person’s password, there is no access — not for institutions, not for third parties, not for Vivodepot itself. This is how the software is built; it is not a setting.

Identitätsverankerung

Identity anchoring

SD-JWT-VC-Export nach dem Format der eIDAS-2.0-Implementierungsakte — experimentell, das Format kann sich noch ändern. Kein PID-Import — die EUDI-Architektur sieht keine Credential-Datei vor, die eine Anwendung ohne Netzzugriff entgegennehmen könnte.

SD-JWT-VC export following the format of the eIDAS-2.0 implementing acts — experimental, the format may still change. No PID import — the EUDI architecture provides no credential file that an application without network access could receive.

Beziehungs- und Sorgestruktur

Relationship and care structure

Eine Anker-Person mit Sub-Depots für Angehörige, verbunden durch HL7-V3-RoleCode-kodierte Beziehungstypen. Ein optionales Freitextfeld kann die Vollmachts-Grundlage benennen (z. B. Vorsorgevollmacht oder Betreuungsvollmacht) — kein Pflichtfeld, kein Beleg-Upload, kein Beginn-Datum.

An anchor person with sub-depots for family members, connected through relationship types coded with HL7-V3-RoleCode. An optional free-text field can name the basis for authority (e.g. power of attorney or care authorisation) — not required, no proof upload, no start date.

Interoperabilität

Interoperability

Import- und Export-Kanäle zu institutionellen Datenquellen. Bidirektional (Ein- und Auslesen): FHIR R4/IPS für Gesundheitsdaten, SD-JWT-VC für verifizierbare Nachweise, EDCI/Europass für Bildungsnachweise. Nur Einlesen: CAMT/ISO 20022 für Bankdaten, XMeld für Meldedaten, ein eigenes, dokumentiertes Format für Steuerdaten. SMART Health Links sind geplant (xShare).

Import and export channels to institutional data sources. Bidirectional (read and write): FHIR R4/IPS for health data, SD-JWT-VC for verifiable credentials, EDCI/Europass for educational records. Import only: CAMT/ISO 20022 for banking data, XMeld for registration data, an own, documented format for tax data. SMART Health Links are planned (xShare).

Vorinstallierte Standard-Vorlagen

Pre-installed standard templates

Vier amtliche Standard-Vorlagen auf Basis amtlicher Werke nach §5 UrhG (BMJ-Patientenverfügung, -Vorsorgevollmacht, -Betreuungsverfügung, BZgA-Organspende). Sie sind in jeder Vivodepot-HTML vorhanden, von Vivodepot treuhänderisch signiert. Eine Person braucht keine Institution, um anzufangen — der Stick aus der Schublade trägt die Vorlagen mit.

Four official standard templates based on official works under §5 of the German Copyright Act (BMJ advance directive, power of attorney, care directive; BZgA organ donation card). They are present in every Vivodepot HTML, signed by Vivodepot in trust. A person needs no institution to get started — the stick from the drawer carries the templates with it.

Trust-Authority-Architektur

Trust authority architecture

Institutionen können eigene Vorlagen für ihre Übergabe-Kontexte beisteuern. Vivodepot signiert deren Provider-Zertifikate als Verifiable Credentials nach W3C-Standard (JWS RFC 7515, Ed25519 primär, ES256 als Fallback). Der Trust-Authority-Public-Key ist statisch in jeder Vivodepot-HTML eingebettet — jede Anwendung verifiziert offline, ohne Server-Verbindung. Vivodepot ist nicht in der Übertragungs-Leitung. Vorlagen fließen vom Anbieter zum Bürger direkt; die Daten bleiben lokal beim Bürger und werden nur auf seine Entscheidung hin geteilt.

Institutions can contribute their own templates for their handover contexts. Vivodepot signs their provider certificates as Verifiable Credentials per the W3C standard (JWS RFC 7515, Ed25519 as primary, ES256 as fallback). The trust authority public key is statically embedded in every Vivodepot HTML — each instance verifies offline, without a server connection. Vivodepot is not in the transmission path. Templates flow directly from provider to citizen; the data stays locally with the citizen and is shared only at their discretion.

Fünf technische Eigenschaften sind gegen externe Referenzen geprüft und dokumentiert — FHIR-Konformität, Krypto-Parameter, Schwachstellen-Scan, Lizenz-Sauberkeit, Offline-Verhalten. Was die Prüfungen nicht abdecken, steht dort ebenfalls. Technische Validierung →

Five technical properties are verified against external references and documented — FHIR conformance, cryptographic parameters, vulnerability scan, licence cleanliness, offline behaviour. What the tests do not cover is stated there as well. Technical validation →

Vom Inhalt zur ÜbergabeFrom content to handover

Wie Daten zwischen Person und Institution übergeben werden

How data is handed over between person and institution

Die vier vorinstallierten amtlichen Vorlagen lassen sich ohne institutionelle Beteiligung ausfüllen. Ob eine Verfügung im Einzelfall hält, klärt Beratung — Vivodepot ersetzt sie nicht. Wo eine Institution dazukommt — eine Klinik, ein Pflegeheim, eine Bank, ein Notariat — bringt sie ihre eigene Vorlage mit, die in das vorhandene Vivodepot der Person eingelesen wird. Die Architektur kennt drei Rollen und einen Ablauf.

The four pre-installed official templates can be completed without any institutional involvement. Whether a directive holds in an individual case is a matter for advice — Vivodepot does not replace it. Where an institution comes in — a clinic, a care home, a bank, a notary — it brings its own template, which is loaded into the person's existing Vivodepot. The architecture has three roles and one workflow.

Vivodepot GmbH als Trust Authority

Vivodepot GmbH as trust authority

Stellt Provider-Zertifikate für Institutionen aus, signiert die Verifiable Credentials mit dem Trust-Authority-Schlüssel. Ist nicht in der Übertragungs-Leitung. Vorlagen fließen vom Anbieter zum Bürger direkt; die Daten bleiben lokal beim Bürger.

Issues provider certificates to institutions, signs the Verifiable Credentials with the trust authority key. Is not in the transmission path. Templates flow directly from provider to citizen; the data stays locally with the citizen.

Institution als Anbieter

Institution as provider

Erstellt eigene Vorlagen für ihre Übergabe-Kontexte, signiert sie mit dem eigenen Schlüssel — dessen Public Key in einem von Vivodepot ausgestellten Zertifikat verankert ist. Geltungsdauer pro Zertifikat: 18 Monate.

Creates its own templates for its handover contexts, signs them with its own key — the public key anchored in a certificate issued by Vivodepot. Validity per certificate: 18 months.

Person als Eigentümerin

Person as owner

Lädt Vorlagen per Datei-Import oder Stick aus dem Begrüßungs-Paket. Aktiviert sie für ein Sub-Depot oder lehnt sie ab. Behält die Daten, auch wenn der Anbieter nicht mehr existiert.

Loads templates via file import or stick from a welcome package. Activates them for a sub-depot, or declines. Keeps the data, even when the provider no longer exists.

Die Übergabe selbst

The handover itself

In jedem der elf Bereiche — Identität & Person, Meine Menschen, Mobilität & Reise, Finanzen & Zahlungen, Gesundheit, Bildung & Beruf, Sozialversicherung, Vorsorge & Recht, Verwaltung & Behörden, Wohnen & Eigentum, Persönliches — kann die Person eine Übergabe auslösen. Sie wählt die Felder aus, die sie übergeben will, bestätigt die Auswahl, wählt dann das Format: PDF zum Drucken oder JSON-Export zur Datei-Übergabe. Für den Notfall steht zusätzlich ein QR-Code mit den wichtigsten Notfallkontakten bereit. Kein stiller Export, keine Hintergrund-Übertragung. Übergaben lassen sich mit Datum in einem Protokoll vermerken, das die Person jederzeit einsehen kann — freiwillig, kein Zwangsprotokoll.

In each of the eleven areas — Identity & person, My people, Mobility & travel, Finance & payments, Health, Education & work, Social insurance, Advance care & law, Administration & authorities, Home & property, Personal — the person can initiate a handover. They select the fields they want to hand over, confirm the selection, then choose the format: PDF for printing or JSON export for file handover. For emergencies there is also a QR code with the most important emergency contacts. No silent export, no background transfer. Handovers can be logged with date in a record the person can review at any time — voluntary, never mandatory.

Auf der Empfangsseite — Klinik, Pflegekraft, Notar, Angehörige — wird kein Vivodepot benötigt. Eine schmale Lese-Begleitdatei (vivodepot-lesen.html) öffnet übergebene Dateien im Browser, speichert nichts, verbindet sich mit nichts. Nur wer die Daten besitzt, braucht das volle Werkzeug. Details zur Empfangsseite: Für Institutionen →

On the receiving side — clinic, carer, notary, family member — no Vivodepot is needed. A slim companion read-only file (vivodepot-lesen.html) opens handed-over files in the browser, stores nothing, connects to nothing. Only those who own the data need the full instrument. Details on the receiving side: For institutions →

Carlos Ibáñez
Werkzeug, nicht BeraterTool, not adviser

Wir vermitteln nichts und beraten nicht

We neither broker nor advise

Vivodepot verdient am Werkzeug. Die Erlöse kommen aus dem, was wir an Institutionen liefern — Hardware, Whitelabel, Servicevertrag, Vorlagen-Integration, Trust-Authority-Zertifikate. Versicherungs- oder Finanzprodukt-Vermittlung gehört nicht dazu.

Vivodepot earns from the tool. Revenue comes from what we deliver to institutions — hardware, white-label, service agreement, template integration, trust authority certificates. Insurance or financial product brokerage is not part of it.

Die Inhalte der Vorlagen verantworten die, die sie ausstellen — öffentliche Stellen für die Basis-Vorlagen, Institutionen für ihre eigenen. Rechts-, Finanz- oder medizinische Beratung bleibt bei denen, die sie auch erbringen dürfen. Diese Trennung hat einen architektonischen Grund: Eine Trust Authority, die am Vermittlungs-Geschäft der von ihr zertifizierten Anbieter mitverdient, kann nicht unabhängig zertifizieren.

The content of the templates is the responsibility of those who issue them — public authorities for the basic templates, institutions for their own. Legal, financial or medical advice stays with those who are permitted to provide it. There is an architectural reason for this separation: a trust authority that earns from the brokerage business of the providers it certifies cannot certify independently.

Vitaly Gariev
Über den NamenAbout the name

Vivo — ich lebe

Vivo — I live

Vivo heißt: ich lebe. Depot ist der Speicher. Vivodepot ist ein Lebensspeicher — der Ort, an dem zusammenkommt, was ein Leben ausmacht und was es braucht.

Zwei Fragen stecken in Vivodepot: vi wie wie, vo wie wo. Wie sollen die Dinge geregelt sein, die mir wichtig sind — und wo liegen die Unterlagen, wenn sie gebraucht werden. Das Wichtige und das Praktische, im selben Wort.

Vivo means: I live. A depot is where things are kept. Vivodepot is a place for everything a life holds — and everything it calls for, in one place.

Two questions live inside the name: how do I want the things that matter to me handled — and where will the papers be when they're needed. What matters and what's practical, in a single word.

Regulatorischer RahmenRegulatory framework

Warum jetzt

Why now

Europäische und deutsche Regulierung schaffen erstmals politische Anreize und rechtliche Anforderungen für genau das, was das Konzept beschreibt.

European and German regulation are putting in place, for the first time, political incentives and legal requirements for exactly what the concept describes.

Lizenz & StandardsLicence & standards

Offenheit als Designprinzip

Openness as a design principle

Vivodepot ist quelloffen, damit die Idee — Bürgerdaten gehören den Bürgern — auch dann noch gilt, wenn dieses Unternehmen einmal nicht mehr existiert.

Vivodepot is open source so that the idea — that personal data should be personal — still holds when this company one day no longer exists.

Die Anwendung steht unter EUPL-1.2 — frei für alle. Der Template-Übergabe-Mechanismus steht unter BUSL-1.1 mit automatischer Konversion zu EUPL-1.2 nach vier Jahren. Damit ist die Anwendung sofort frei verfügbar, und auch der Mechanismus wird vollständig offen — nur zeitlich versetzt, damit die Weiterentwicklung finanziert werden kann. Details siehe LICENSING.md.

The application is licensed under EUPL-1.2 — free for everyone. The template handover mechanism is licensed under BUSL-1.1 with automatic conversion to EUPL-1.2 after four years. The application is freely available immediately, and the mechanism becomes fully open as well — just on a delay that allows continued development. For details see LICENSING.md.

Vivodepot bildet zahlreiche offene Standards in vier Domänen ab: medizinische Codierungen, Identitäts- und Signaturformate, Verwaltungs- und Bürger-Formate, Kryptographie. Vollständige Liste: STANDARDS.md.

Beyond the licences, Vivodepot implements numerous open standards across four domains: medical coding, identity and signature formats, administrative and citizen-facing formats, and cryptography. For the full list, see STANDARDS.md.

AnwendungApplication

EUPL-1.2

European Union Public Licence mit Copyleft. Wer eine veränderte Fassung weitergibt, muss den Quellcode mitgeben — unter der EUPL oder einer der in Art. 5 genannten kompatiblen Lizenzen.

European Union Public Licence with copyleft. Anyone distributing a modified version must pass on the source code — under the EUPL or one of the compatible licences listed in Art. 5.

Übergabe-MechanismusHandover mechanism

BUSL-1.1 → EUPL-1.2

Business Source Licence für den Template- und Trust-Authority-Mechanismus. Die Lizenzpflicht greift bei drei Nutzungsarten: Eigenmarke/White-Label, Service-Level-Zusage oder kommerzielle Weiterverbreitung. Als zusätzlicher Auffang-Boden gegen unmarkiertes Massen-Deployment: ab 100.000 ausgegebenen Vivodepot-Instanzen. Nach vier Jahren konvertiert jede Version automatisch zu EUPL-1.2.

Business Source Licence for the template and trust authority mechanism. The licence obligation attaches to three uses: white-label branding, a service-level commitment, or commercial redistribution. As an additional backstop against unmarked mass deployment: from 100,000 issued Vivodepot instances. After four years, each version converts automatically to EUPL-1.2.

GesundheitsdatenHealth data

FHIR R4 / IPS

HL7 FHIR Release 4, International Patient Summary. Bidirektionaler Import und Export.

HL7 FHIR Release 4, International Patient Summary. Bidirectional import and export.

IdentitätIdentity

SD-JWT · eIDAS 2.0

Selective Disclosure JWT als Export-Format nach dem Stand der eIDAS-2.0-Implementierungsakte — experimentell, kein PID-Import.

Selective Disclosure JWT as export format, following the current state of the implementing acts — experimental, no PID import.

VerschlüsselungEncryption

AES-256-GCM

Alle Daten werden lokal im Browser verschlüsselt. Kein Zugang ohne Schlüssel der Person.

All data is encrypted locally in the browser. No access without the person’s key.

Medizinische CodierungMedical coding

SNOMED-CT · ICD-10 · ATC · LOINC

Internationale und deutsche Codierungs-Systeme für Diagnosen, Wirkstoffe, Impfungen, Prozeduren und Devices. Vorschlagslisten plus Freitext.

International and German coding systems for diagnoses, active substances, immunisations, procedures and devices. Suggestion lists plus free text.

VerwaltungsdatenAdministrative data

Behördendatensatz (FIM-angelehnt) · XMeld · eigenes Steuerformat

Ein eigener, dokumentierter Behördendatensatz mit an das Föderale Informationsmanagement angelehnter Feldbenennung — kein XÖV-konformes Format. Dazu XMeld sowie ein eigenes, dokumentiertes Format für Steuerdaten mit dem v1.0-Release.

Vivodepot's own, documented public-authority record with field naming aligned to the federal information management standard (FIM) — not an XÖV-conformant format. Plus XMeld and an own, documented format for tax data with the v1.0 release.

Bürger-FormateCitizen formats

vCard 4.0

Kontakte als vCard nach RFC 6350.

Contacts as vCard per RFC 6350.

Templates und ÜbergabeTemplates and handover

JWS RFC 7515 · Ed25519 · W3C VC

Signierte Template-Übergaben von Pilotpartnern an Bürger-Vivodepots. Vivodepot als Trust Authority. Ed25519 primär, ES256 als Fallback.

Signed template handovers from pilot partners to citizen Vivodepots. Vivodepot as trust authority. Ed25519 as primary, ES256 as fallback.

KontaktContact

Für den fachlichen Austausch

For technical and scientific exchange

Rückmeldungen, Kooperationsanfragen, wissenschaftliches Interesse oder ein Hinweis auf einen blinden Fleck im Konzept — wir antworten persönlich.

Feedback, cooperation enquiries, scientific interest or a pointer to a blind spot in the concept — we reply personally.

Kontakt

Contact

Für Forschungsinteresse, Kooperation und konzeptionelle Rückfragen:

For research interest, cooperation and conceptual questions:

forschung@vivodepot.de

Quellcode

Source code

Vivodepot steht unter EUPL-1.2 (Anwendung) und BUSL-1.1 mit Konversion zu EUPL-1.2 nach vier Jahren (Template-Mechanismus). Der Quellcode ist bei OpenCode (ZenDiS) zur Aufnahme hochgeladen.

Vivodepot is licensed under EUPL-1.2 (application) and BUSL-1.1 with conversion to EUPL-1.2 after four years (template mechanism). The source code has been uploaded to OpenCode (ZenDiS) for inclusion.

OpenCode
ImpressumLegal notice

AnbieterProviderVivodepot GmbH
Körnerstraße 7-10
10785 Berlin
Germany

Vertretung und VerantwortlichkeitRepresentation and responsibilityVertretungsberechtigte Geschäftsführerin und verantwortlich nach §18 Abs. 2 MStV: Carola Klessen, Anschrift wie oben.Managing director and responsible for content under §18 para. 2 MStV: Carola Klessen, address as above.

KontaktContactkontakt@vivodepot.de
Tel.: +49 30 200 092 24

RegistereintragRegistrationAmtsgericht Charlottenburg (Berlin)
HRB 289273 B
EUID: DEF1103R.HRB289273B
Charlottenburg Local Court (Berlin)
HRB 289273 B
EUID: DEF1103R.HRB289273B

Umsatzsteuer-IdentifikationsnummerVAT identification numberUSt-IdNr. gemäß §27a UStG: DE463929000VAT ID under §27a German VAT Act: DE463929000

LizenzenLicencesAnwendung: EUPL-1.2. Template-Übergabe-Mechanismus: BUSL-1.1 mit Konversion zu EUPL-1.2 nach vier Jahren. Details: LICENSING.md.Application: EUPL-1.2. Template handover mechanism: BUSL-1.1 with conversion to EUPL-1.2 after four years. Details: LICENSING.md.