Vivodepot GmbH · Berlin
Technische ValidierungTechnical Validation
Vivodepot ist eine Single-File-HTML-Anwendung, die offline im Browser läuft. Diese Seite dokumentiert, wie und womit sie geprüft wird — automatisch bei jedem Code-Commit und manuell auf externen Plattformen. Wo eine externe Plattform eine Report-ID vergibt, ist sie hier verlinkt; sonst sind Werkzeug, Version und Datum angegeben. Geprüft wird gegen öffentliche Referenzen: Gazelle (IHE Europe), Matchbox, HL7 FHIR Validator, NIST-CAVP- und Wycheproof-Testvektoren, RFC 5869, OSV.dev, W3C Nu Html Checker, axe-core, Google Lighthouse und einem eigenen, unabhängigen Krypto-Harness.
Vivodepot is a single-file HTML application that runs offline in the browser. This page documents how and with what it is verified — automatically at every code commit and manually on external platforms. Where an external platform issues a report ID, it is linked here; otherwise tool, version and date are given. Testing is against public references: Gazelle (IHE Europe), Matchbox, the HL7 FHIR Validator, NIST CAVP and Wycheproof test vectors, RFC 5869, OSV.dev, the W3C Nu Html Checker, axe-core, Google Lighthouse and an independent in-house crypto harness.
Vier Prüf-Schichten. Automatische Tests laufen bei jedem Code-Commit ohne manuellen Eingriff und decken Logik, Kryptographie und Datenmodell ab. Vor jeder Veröffentlichung laufen zusätzlich Freigabe-Prüfungen: Konformität, Krypto-Testvektoren, Offline-Garantie, Barrierefreiheit und ein Abgleich der eingebundenen Bibliotheken gegen bekannte Schwachstellen. Die Geräte-Abnahme prüft, was sich ohne Browser nicht prüfen lässt — Änderungen an der Bedienoberfläche werden im Browser und auf dem Gerät gegen eine verschlüsselte Referenzdatei geführt, mit Nachweis aus dem gespeicherten Datensatz statt aus der Anzeige. Validierung auf externen Plattformen prüft, ob die Implementierung mit dem übereinstimmt, was externe Stellen als korrekt definieren; Testmaterial wird dafür von uns eingereicht. Regulatorische Einordnungen — DSGVO, Ausfuhrrecht, CRA, CE — sind als eigene Einschätzung gekennzeichnet und nicht behördlich bestätigt. Der Quellcode ist öffentlich, alle vier Schichten sind damit von außen nachvollziehbar. Ein externes Sicherheits-Audit hat bisher nicht stattgefunden.
Four validation layers. Automated tests run at every code commit without manual intervention, covering logic, cryptography and the data model. Before any release, additional gate checks run: conformance, cryptographic test vectors, the offline guarantee, accessibility, and a comparison of bundled libraries against known vulnerabilities. Device acceptance covers what cannot be verified without a browser — changes to the user interface are exercised in the browser and on the device against an encrypted reference file, with evidence taken from the stored record rather than from the display. Validation on external platforms checks whether the implementation matches what external bodies define as correct; the test material is submitted by us. Regulatory assessments — GDPR, export control, CRA, CE — are marked as our own and are not confirmed by any authority. The source code is public, so all four layers can be followed from outside. No external security audit has taken place to date.
FHIR-KonformitätFHIR Conformance
Gazelle EHDS Continuous Testing Platform
IHE Europe · Matchbox 4.0.20 · ProfilProfile Bundle-uv-ips 2.0.0
BESTANDENPASSED
Externe PlattformExternal platform
ErgebnisResult
0 Errors · 6 Warnings (nicht-blockierendnon-blocking)
DatumDate
21. Mai 202621 May 2026
Bundle
13 Einträge inkl. 4 LOINC-Lab-Observations13 entries incl. 4 LOINC lab observations
Gazelle EHDS — bewertete KonformitätstestsAssessed Conformance Tests
IHE Europe · Continuous Testing Session für EHDS-Profile · Testtiefe ThoroughIHE Europe · Continuous Testing Session for EHDS profiles · testing depth Thorough
4 × VERIFIZIERT4 × VERIFIED
Externe PlattformExternal platform
LaborbefundLaboratory report
Content Creator · ProfilContent Creator · profile Bundle-eu-lab|0.1.1 · Testinstanz 448 · verifizierttest instance 448 · verified
PatientenkurzaktePatient summary
Content Creator · EU Patient Summary / IPS · Testinstanz 450 · verifiziertContent Creator · EU Patient Summary / IPS · test instance 450 · verified
EntlassbriefDischarge report
Content Creator · EU Hospital Discharge Report · Testinstanz 449 · verifiziertContent Creator · EU Hospital Discharge Report · test instance 449 · verified
Yellow-Button-DownloadYellow Button download
vollständiger Bürgerweg: Anmeldung, Auswahl, Download, Wiedereinlesen · Testinstanz 568 · verifiziertthe full citizen path: sign-in, selection, download, re-import · test instance 568 · verified
Geprüft mitVerified with
Gazelles eigenem Konformitätsprüfer; die Bewertung nimmt eine Monitorin der Plattform vorGazelle’s own conformance checker; the assessment is made by a platform monitor
StandAs of
23. September 2026 · weitere Instanzen sind eingereicht und noch nicht bewertet23 September 2026 · further instances are submitted and not yet assessed
Gazelle EHDS — Einmal-Freigabe (SMART Health Links)One-Time Share (SMART Health Links)
Yellow Button One-Time Share · Senden und EmpfangenYellow Button One-Time Share · sending and receiving
EINGEREICHT · BEWERTUNG OFFENSUBMITTED · ASSESSMENT PENDING
Externe PlattformExternal platform
SendenSending
SHL Holder · Manifest-Weg · Testinstanz 727 · Belege eingereicht, Bewertung offenSHL Holder · manifest route · test instance 727 · evidence submitted, assessment pending
EmpfangenReceiving
SHL Receiver · Manifest mit Passcode, Auflösung über location · Testinstanz 751 · Belege eingereichtSHL Receiver · manifest with passcode, resolution via location · test instance 751 · evidence submitted
NachweisEvidence
das bei der Gegenstelle entschlüsselte Dokument war mit dem abgeschickten byte-genau identisch — gleiche SHA-256, gleiche Längethe document decrypted at the counterpart was byte-for-byte identical to the one sent — same SHA-256, same length
EinordnungScope
Der Freigabe-Link wird im Gerät erzeugt, der Schlüssel steckt im Link und verlässt es nicht. Ablegen und Abholen laufen auf eigenen Seiten; die Anwendung selbst macht zu keinem Zeitpunkt einen Netzaufruf.The sharing link is produced on the device; the key is carried in the link and never leaves it. Depositing and retrieving run on separate pages; the application itself never makes a network call.
StandAs of
23. September 202623 September 2026
Matchbox FHIR Validator
ahdis · Matchbox 4.1.17 · ProfilProfile Bundle-uv-ips 2.0.0
BESTANDENPASSED
Externe PlattformExternal platform
ErgebnisResult
0 Errors · 4 Warnings (die EU-EPS-Profile sind auf dem Server nicht geladenthe EU EPS profiles are not loaded on the server)
DatumDate
24. September 2026 (zuvor 28. Mai 2026)24 September 2026 (previously 28 May 2026)
Bundle
vom heutigen Erzeuger, Beispieldepot · 9 Ressourcen, darunter Allergie, Medikation, Diagnose, Eingriff und Implantatfrom the current generator, sample depot · 9 resources, including allergy, medication, condition, procedure and implant
HL7 FHIR Validator
HL7 validator_cli, fest eingestellt und per SHA-256 geprüft · läuft vor jedem Push, wenn sich der FHIR-Export ändertHL7 validator_cli, pinned and checked by SHA-256 · runs before every push when the FHIR export changes
BESTANDENPASSED
AutomatischAutomated
ErgebnisResult
0 Errors · jedes Erzeugnis mit dem erwarteten Urteil · ein absichtlich kaputtes Bundle wird abgelehnt0 errors · every generated bundle gets the expected verdict · a deliberately broken bundle is rejected
Letzter LaufLast run
24. September 2026 · validator_cli 6.9.1224 September 2026 · validator_cli 6.9.12
ProfilProfile
Bundle-uv-ips 2.0.0 · EU EPS
KryptographieCryptography
AES-256-GCM · Authentifizierte VerschlüsselungAuthenticated Encryption
WebCrypto API · SubtleCrypto · keine externen Krypto-Bibliothekenno external crypto libraries
BESTÄTIGTCONFIRMED
AutomatischAutomated
AlgorithmusAlgorithm
AES-256-GCM · 256-Bit-Schlüsselkey · 12-Byte-IV zufälligrandom · 16-Byte-Authentication-Tag
GarantieGuarantee
Vertraulichkeit und Integrität in einem Vorgang — manipulierter Ciphertext wird mit Auth-Tag-Fehler abgewiesen. Die Vertraulichkeit hängt am Passwort der Bürgerin: Aus einem schwachen Passwort folgt ein schwacher Schlüssel, unabhängig von Algorithmus und Iterationszahl.Confidentiality and integrity in one operation — tampered ciphertext is rejected with auth tag error. Confidentiality rests on the citizen's password: a weak password yields a weak key, regardless of algorithm or iteration count.
AAD-BindungBinding
PBKDF2-Iterations-Zahl als Additional Authenticated Data eingebunden — Header-Manipulation erkennbarPBKDF2 iteration count bound as Additional Authenticated Data — header manipulation detectable
IV-Kollisions-Schätzungcollision estimate
P ≈ 6,3 × 10⁻²² bei 10.000 Speicher-Vorgängen unter demselben Schlüssel — praktisch null für Bürgerinnen-NutzungP ≈ 6.3 × 10⁻²² for 10,000 storage operations under the same key — practically zero for citizen use
PBKDF2-SHA-256 · SchlüsselableitungKey Derivation
OWASP Password Storage Cheat Sheet · NIST SP 800-132
KONFORMCONFORMANT
AutomatischAutomated
ErgebnisResult
600.000 Iterationen · OWASP-Empfehlung 2024 erfülltiterations · OWASP 2024 recommendation met
Salt
32 Byte kryptographisch zufällig · verhindert Rainbow-Table-Angriffebytes cryptographically random · prevents rainbow table attacks
Konstanten-DisziplinConstant Discipline
Eine einzige KonstanteOne single constant PBKDF2_ITERATIONS = 600.000 · alle Pfade einheitlich · Legacy-Konstanten bereinigt (Cluster Krypto-2.1)all paths consistent · legacy constants cleaned (cluster Crypto-2.1)
HKDF · Funktionale SchlüsseltrennungFunctional Key Separation
HMAC-based Key Derivation · RFC 5869
BESTÄTIGTCONFIRMED
AutomatischAutomated
ZweckPurpose
Aus PBKDF2-Ausgabe werden zwei funktional getrennte Schlüssel abgeleitet: AES-Verschlüsselungs-Schlüssel und HMAC-Signatur-SchlüsselTwo functionally separated keys are derived from PBKDF2 output: AES encryption key and HMAC signature key
Externe VektorenExternal Vectors
RFC-5869-Vektoren · Wycheproof-HKDF-Vektoren — alle grünRFC 5869 vectors · Wycheproof HKDF vectors — all green
Cross-Use-SchutzProtection
Test 5.2-A-13: HKDF-Key wirftHKDF key throws InvalidAccessError bei AES-decrypt — kein Key-Misuse möglichon AES-decrypt — no key misuse possible
Authentifizierte Krypto-Versions-AchseAuthenticated Crypto Version Axis
kryptoVersion-Feldfield · Allowlist · kein stilles Fallbackno silent fallback
BESTÄTIGTCONFIRMED
AutomatischAutomated
ErgebnisResult
Iterations-Zahl kryptographisch gebunden · Manipulation erkennbar · 15 automatische Tests (K22-01 bis K22-15)Iteration count cryptographically bound · tampering detectable · 15 automated tests (K22-01 to K22-15)
MechanismusMechanism
Iterations-Zahl als AAD in AES-GCM — Manipulation im Header führt zu Authentication-Tag-Fehler · kein schweigendes Zurückfallen auf schwächere KryptoIteration count as AAD in AES-GCM — header manipulation leads to auth tag failure · no silent fallback to weaker crypto
Allowlist
UnbekannteUnknown kryptoVersion-Werte werden explizit abgelehnt · Legacy-Container werden beim nächsten Schreib-Vorgang transparent migriertvalues are explicitly rejected · legacy containers are transparently migrated on the next write
JWS Ed25519 · Provider-ZertifikateProvider Certificates
RFC 7515 · W3C Verifiable Credentials · Trust Authority
BESTÄTIGTCONFIRMED
AutomatischAutomated
AlgorithmusAlgorithm
Ed25519 primär · ES256 (ECDSA P-256) als Fallbackprimary · ES256 (ECDSA P-256) as fallback
Header-ValidierungValidation
Algorithmus-AllowlistAlgorithm allowlist ["EdDSA", "ES256"] — alg=none, alg-Verwirrung und kid-Injection ausgeschlossenconfusion and kid injection excluded
Trust Authority
Public Key statisch eingebettetPublic key statically embedded · kid: vivodepot-trust-authority-v2-22082026 · Vertrauen läuft nach 18 Monaten ab · Sperrliste widerrufener Anbieterschlüssel im Programm, bei jedem Import geprüft, derzeit ohne Eintragtrust expires after 18 months · revocation list of withdrawn provider keys built into the program, checked on every import, currently empty
Externe Test-VektorenExternal Test Vectors
150 Wycheproof-Vektorenvectors (88 valid, 62 invalid) · 0 Fundefindings · Laufrun 14.09.2026
NIST CAVP + Wycheproof · Externe Test-VektorenExternal Test Vectors
Unabhängige kryptographische Referenz-VektorenIndependent cryptographic reference vectors
BESTÄTIGTCONFIRMED
Externe VektorenExternal vectors
ErgebnisResult
419 externe Vektoren · alle grün · Implementation stimmt mit publizierten Referenzen übereinexternal vectors · all green · implementation matches published references
VektorenVectors
RFC-5869-HKDF: 3 · NIST-CAVP-AES-256-GCM: 30 (20 Encrypt, 5 Decrypt-PASS, 5 Decrypt-FAIL) · Wycheproof-AES-GCM: 66 (39 valid, 27 invalid) · Wycheproof-HKDF: 86 (83 valid, 3 invalid) · Wycheproof-HMAC-SHA-256: 174 (66 valid, 108 invalid) · Wycheproof-PBKDF2-HMAC-SHA-256: 60 (60 valid)
BedeutungMeaning
Nicht nur interne Tests — externe, von Vivodepot unabhängig publizierte Vektoren belegen die korrekte AES-GCM- und HKDF-ImplementationNot only internal tests — external, independently published vectors confirm the correct AES-GCM and HKDF implementation
Unabhängiger Krypto-HarnessIndependent Crypto Harness
Eigener Code, eigener Prozess, eigene Engine-Kreuzprobe — läuft NICHT in der normalen SuiteOwn code, own process, own cross-engine check — does NOT run in the normal suite
59/59
Eigenständiger LaufStandalone run
ErgebnisResult
59/59 grün · 0 rot · Lauf 23.09.2026green · 0 red · run 23 September 2026
AbdeckungCoverage
RFC 5869 HKDF-SHA256 · RFC 4231 HMAC-SHA256 (zwei Enginestwo engines) · AES-256-GCM (Node-OpenSSL ↔ WebCrypto) · Zerfall in Feld-Einheiten (Krypto-Generation 4)decay into field units (crypto generation 4)
Warum eigenständigWhy standalone
Eigener vm-Kontext, lädt ausschließlichOwn vm context, loads only vivodepot-krypto-kern-PORT-VERBATIM.js — trägt bewusst nicht dieselben Annahmen wie die Suite, die er prüftdeliberately does not share the assumptions of the suite it checks
AufrufHow it runs
von Handby hand · npm run krypto:harness → tools/independent-krypto-harness.js
extractable: false · Schlüssel-Export-SchutzKey Export Protection
WebCrypto CryptoKey · kein programmatischer Schlüssel-Exportno programmatic key export
BESTÄTIGTCONFIRMED
AutomatischAutomated
ErgebnisResult
10/10 geheime/private Schlüssel runtime-verifiziert · +1 öffentlicher (legitim) · 0 Ausnahmen · 20.06.2026secret/private keys runtime-verified · +1 public (legitimate) · 0 exceptions · 20 June 2026
BedeutungMeaning
Alle WebCrypto-Schlüssel mitAll WebCrypto keys with extractable: false — kein JavaScript-Code kann Schlüssel-Material aus dem Browser exportierenno JavaScript code can export key material from the browser
VdCrypto-Block-IntegritätVdCrypto Block Integrity
Krypto-Kern byte-identisch über alle TrägerCrypto core byte-identical across all carriers
BESTÄTIGTCONFIRMED
AutomatischAutomated
ErgebnisResult
Block-Hash byte-identisch · 0 Abweichungen · 20.06.2026block hash byte-identical · 0 deviations · 20 June 2026
Hash (SHA-256)
732ff4b0…a8a6282 · Kern und Lese-App identischcore and reader app identical
BedeutungMeaning
Der kryptographische Kern ist über alle Auslieferungen byte-genau derselbe — keine stille Änderung möglichthe cryptographic core is byte-exact identical across all deliveries — no silent change possible
SicherheitSecurity
OSV.dev Schwachstellen-ScanVulnerability Scan
Open Source Vulnerabilities · Google · gegen SBOM CycloneDX 1.4against SBOM CycloneDX 1.4
CLEAN
AutomatischAutomated
ErgebnisResult
0 bekannte Schwachstellen · 2 Bibliotheken mit Paket-Kennung geprüft (von 8 SBOM-Komponenten)0 known vulnerabilities · 2 libraries with package identifier checked (of 8 SBOM components)
DatumDate
7. August 20267 August 2026
Geprüfte BibliothekenLibraries checked
jsPDF 4.2.1 · qrcode-generator 1.4.4
Offline-Garantie-TestOffline Guarantee Test
Kein Netzwerk-Zugriff zur Laufzeit · Playwright-VerifikationNo network access at runtime · Playwright verification
BESTÄTIGTCONFIRMED
AutomatischAutomated
ErgebnisResult
0 externe Netzwerk-Requests zur Laufzeit · CSP connect-src 'none'0 external network requests at runtime · CSP connect-src 'none'
MethodeMethod
Netzwerk-Interceptions-Test · alle Requests müssen lokal oderNetwork interception test · all requests must be local or ./data/ sein
Barrierefreiheit und HTML-QualitätAccessibility and HTML Quality
W3C Nu Html Checker
vnu 26.5.21 · HTML5 undand WAI-ARIA Konformitätconformance
MIT 2 ERRORS2 ERRORS REMAINING
Externe PlattformExternal platform
ErgebnisResult
2 strukturell bedingte Errors (Limit L28) · 5 strukturelle Warnings · 2 Warnings behoben2 structurally caused errors (limit L28) · 5 structural warnings · 2 warnings resolved
DatumDate
28. Mai 202628 May 2026
CheckerChecker
vnu 26.5.21
axe-core · WCAG 2.2 Level AA
Barrierefreiheits-Prüfung · Kontrast, Tastatur-Navigation, ARIAAccessibility check · contrast, keyboard navigation, ARIA
TEILGEPRÜFTPARTIALLY TESTED
AutomatischAutomated
ErgebnisResult
0 Violations · 33 Sichten gescannt0 violations · 33 views scanned
DatumDate
28. Mai 202628 May 2026
CheckerChecker
axe-core 4.11.4
Google Lighthouse
Zweite, unabhängige Barrierefreiheits- und QualitätsmessungSecond, independent accessibility and quality measurement
A11Y 100 · BEST PRACTICES 96 · SEO 82A11Y 100 · BEST PRACTICES 96 · SEO 82
Lokal geprüftChecked locally
ErgebnisResult
Accessibility 100 · Best Practices 96 · SEO 82 · Performance 55Accessibility 100 · Best Practices 96 · SEO 82 · Performance 55
DatumDate
30. August 202630 August 2026
CheckerChecker
Lighthouse 13.4.1
Performance-Zahl eingeordnetPerformance figure in context
55 ist eine Artefaktzahl, keine reale Nutzungserfahrung: Lighthouse simuliert eine gedrosselte mobile CPU/Verbindung beim Laden einer 4,3-MB-Einzeldatei über einen lokalen Dev-Server. Vivodepot wird in der Praxis einmalig lokal/offline geöffnet, ohne Netzabruf — das Szenario, das die Drosselung misst, tritt real nicht ein. Nicht als Performance-Problem zu lesen, ohne echte PWA-Nutzung nachzumessen (installiert, aus dem Service-Worker-Cache).55 is an artefact of the measurement, not a real usage experience: Lighthouse simulates a throttled mobile CPU/connection while loading a 4.3 MB single file over a local dev server. In practice Vivodepot is opened once, locally/offline, with no network fetch — the scenario the throttling measures never actually occurs. Not to be read as a performance problem without re-measuring real PWA usage (installed, served from the service worker cache).
Übrige FundeRemaining findings
Best Practices: CSP-Direktive frame-ancestors wird über ein <meta>-Tag ignoriert (strukturelle Grenze des Ein-Datei-Modells ohne Server, kein Datenfehler) · SEO: keine Meta-Description/kein robots.txt (irrelevant für eine offline genutzte persönliche Anwendung, kein indexierbares Web-Dokument)Best Practices: the CSP directive frame-ancestors is ignored when delivered via a <meta> tag (a structural limit of the server-less single-file model, not a data error) · SEO: no meta description/robots.txt (irrelevant for a personal application used offline, not an indexable web document)
PWA-KategoriePWA category
In Lighthouse 13 entfallen (vom Hersteller entfernt) — PWA-Installierbarkeit wird seither über Chrome DevTools direkt geprüft, nicht mehr über einen eigenen Lighthouse-Score.Removed in Lighthouse 13 (dropped by the maintainers) — PWA installability is now checked directly via Chrome DevTools, no longer via a dedicated Lighthouse score.
veraPDF · PDF/A-KonformitätConformance
Langzeit-Archivierungs-Tauglichkeit der Export-PDFsLong-term archival suitability of exported PDFs
143 VON 146 REGELN143 OF 146 RULES
Lokaler LaufLocal run
ErgebnisResult
noch nicht PDF/A-konform · 143 von 146 Regeln des Profils PDF/A-3b bestanden, 3 offennot yet PDF/A conformant · 143 of 146 rules of the PDF/A-3b profile passed, 3 open
OffenOpen
XMP-Metadaten am Dokumentkatalog (ISO 19005-3, Klausel 6.6.2.1-1) · PDF/A-OutputIntent für DeviceRGB und DeviceGray (Klauseln 6.2.4.3-2 und 6.2.4.3-4)XMP metadata on the document catalog (ISO 19005-3, clause 6.6.2.1-1) · PDF/A OutputIntent for DeviceRGB and DeviceGray (clauses 6.2.4.3-2 and 6.2.4.3-4)
GeschlossenResolved
eingebettete Schriften (Inter ist in die Export-PDFs eingebettet)embedded fonts (Inter is embedded in the exported PDFs)
DatumDate
14. September 202614 September 2026
ValidatorValidator
veraPDF 1.30.0 · Profilprofile PDF/A-3b
Lizenz und LieferketteLicence and Supply Chain
SBOM CycloneDX 1.4
Software Bill of Materials · alle Dritt-Bibliotheken dokumentiertall third-party libraries documented
VOLLSTÄNDIGCOMPLETE
AutomatischAutomated
Software-KomponentenSoftware components
jsPDF 4.2.1 — MIT · qrcode-generator 1.4.4 — MIT · Inter (Schrift) — OFL-1.1 · alle eingebetteten Komponenten unter permissiven LizenzenjsPDF 4.2.1 — MIT · qrcode-generator 1.4.4 — MIT · Inter (font) — OFL-1.1 · all embedded components under permissive licences
Standard-Code-Listen (Daten)Standard code lists (data)
ICD-10-GM — BfArM, amtlich frei · LOINC — LOINC-Lizenz · ATC — ATC-GM des WIdO, amtlich veröffentlicht durch das BfArM · SNOMED CT — Affiliate-Lizenz über das NRC (BfArM), gehalten, deckt Endnutzer-Sublizenzen · je eigene Nutzungsbedingungen, nicht MITICD-10-GM — BfArM, official and free · LOINC — LOINC licence · ATC — ATC-GM by WIdO, officially published by BfArM · SNOMED CT — Affiliate licence via the NRC (BfArM), held, covers end-user sublicences · each with its own terms of use, not MIT
NachweisEvidence
THIRD_PARTY_LICENSES + vivodepot.sbom.cdx.json (CycloneDX 1.4)(CycloneDX 1.4)
Kein Laufzeit-CDN-RisikoNo Runtime CDN Risk
Alle Bibliotheken inline · kein externer JavaScript-Abruf zur LaufzeitAll libraries inline · no external JavaScript fetched at runtime
BESTÄTIGTCONFIRMED
AutomatischAutomated
ErgebnisResult
Kein Supply-Chain-Angriff über CDN möglichNo supply-chain attack via CDN possible
MethodeMethod
@vd-lib-Annotationen in VIVODEPOT.html · SBOM-Abgleich bei jedem Commit@vd-lib annotations in VIVODEPOT.html · SBOM reconciliation at every commit
Regulatorische EinordnungRegulatory Classification
CRA — Cyber Resilience Act
Verordnung (EU) 2024/2847 · Pflichten ab Dezember 2027Regulation (EU) 2024/2847 · obligations from December 2027
VORBEREITETPREPARED
Eigene EinordnungOwn assessment
EinordnungClassification
Vivodepot ist ein Produkt mit digitalen Elementen im Sinne des CRA — Software auf USB-Stick. Default-Kategorie (kein kritisches Produkt Klasse I oder II).Vivodepot is a product with digital elements under the CRA — software on a USB stick. Default category (not a critical product Class I or II).
SBOM
CycloneDX 1.4 · alle Dritt-Bibliotheken dokumentiertall third-party libraries documented · vivodepot.sbom.cdx.json (im öffentlichen Repo)(in the public repository)
Vulnerability Disclosure
SECURITY.md im Repository · PGP-Fingerprintin the repository · PGP fingerprint 30FB 9B42 7F12 095D 317B 4485 F527 3B32 959A 7D42 · Meldeprozess dokumentiertdisclosure process documented
Vollständige Pflichten abFull obligations from
Dezember 2027 · Vorbereitungs-Stand bereits jetzt: SBOM, Vulnerability Disclosure, Open Source unter EUPL-1.2December 2027 · current readiness: SBOM, vulnerability disclosure, open source under EUPL-1.2
UnterstützungszeitraumSupport period
Mindestens fünf Jahre Sicherheitsaktualisierungen ab dem Tag, an dem eine Fassung herauskommt, jede Aktualisierung mindestens zehn Jahre abrufbar (Mindestzusage), Produktende mit zwölf Monaten Vorlauf angekündigt — Depot-Dateien bleiben danach lesbar und exportierbar, der Quellcode steht unter EUPL-1.2At least five years of security updates from the day each version is released, every update retrievable for at least ten years (minimum commitment), product end announced with twelve months' notice — depot files remain readable and exportable afterwards, the source code is under EUPL-1.2
DSGVO — Datenschutz-GrundverordnungGeneral Data Protection Regulation
Privacy by Design · keine serverseitige Gesundheitsdaten-Verarbeitungno server-side processing of health data
KEINE VERARBEITUNGNO PROCESSING
Eigene EinordnungOwn assessment
Kern-Argumentargument
Vivodepot GmbH verarbeitet keine Gesundheitsdaten der Bürgerinnen — die Anwendung läuft vollständig lokal auf dem Gerät der Bürgerin. Keine Übermittlung, keine Cloud, kein Server.Vivodepot GmbH does not process citizens' health data — the application runs entirely locally on the citizen's device. No transmission, no cloud, no server.
Shop und WebsiteShop and website
Datenschutzerklärung auf vivodepot.de · IONOS-Hosting Deutschland · Odoo als Bestell-Verarbeiter · keine Tracking-CookiesPrivacy notice on vivodepot.de · IONOS hosting Germany · Odoo as order processor · no tracking cookies
Besondere Kategorien (Art. 9)Special categories (Art. 9)
Gesundheitsdaten verbleiben ausschließlich auf dem Gerät der Bürgerin — kein Zugriff durch Vivodepot GmbH möglich, technisch oder organisatorischHealth data remains exclusively on the citizen's device — no access by Vivodepot GmbH possible, technically or organisationally
WEEE / Stiftung EAR
Elektro- und Elektronikgerätegesetz · Vertreiberin, keine eigene RegistrierungElectrical Equipment Act · distributor, no own registration
ÜBER LIEFERKETTEVIA SUPPLY CHAIN
Eigene EinordnungOwn assessment
Status
Keine eigene Herstellerpflicht — WEEE-Nummer des Lieferanten angegebenNo own manufacturer obligation — supplier's WEEE number provided
EinordnungClassification
Vivodepot ist nicht Herstellerin im Sinne des ElektroG (§ 3 Nr. 9 lit. b): Der Vivodepot-Aufdruck auf dem Stick tritt neben die weiterhin lesbare Herstellermarke SanDisk, nicht an ihre Stelle. Als Vertreiberin gibt Vivodepot deshalb die WEEE-Registrierungsnummer des Lieferanten an.Vivodepot is not a manufacturer under the German Electrical Equipment Act (§ 3 no. 9 lit. b): the Vivodepot engraving on the stick sits alongside the still-legible SanDisk manufacturer mark, not in its place. As a distributor, Vivodepot therefore states the supplier's WEEE registration number.
WEEE-NummerNumber
DE 31310269 (SanDisk / Western Digital)(SanDisk / Western Digital)
CE / RoHS — Hardware-KonformitätHardware Conformance
Über Lieferkette · SanDisk als HerstellerThrough supply chain · SanDisk as manufacturer
ÜBER LIEFERKETTEVIA SUPPLY CHAIN
Eigene EinordnungOwn assessment
EinordnungClassification
CE-Kennzeichnung und RoHS-Konformität liegen beim Hersteller der USB-Sticks.CE marking and RoHS conformance rest with the USB stick manufacturer.
SoftwareSoftware
Nach eigener Einschätzung unterliegt Vivodepot als reine Software-Datei keiner eigenständigen CE-KennzeichnungspflichtBy our own assessment, as a pure software file Vivodepot is not subject to its own CE marking obligation
Export Control · EU-Dual-Use-VerordnungRegulation
Verordnung (EU) 2021/821 · Krypto-SoftwareRegulation (EU) 2021/821 · cryptographic software
AUSGENOMMENEXEMPTED
Eigene EinordnungOwn assessment
EinordnungClassification
Krypto-Software (AES-256, PBKDF2, Ed25519) fällt grundsätzlich unter Kategorie 5.2 der Dual-Use-Verordnung — jedoch greift die Mass-Market-Exemption (Note 3) sowie die Open-Source-Ausnahme für öffentlich verfügbare Software. Diese Einordnung ist unsere eigene; eine Auskunft des BAFA ist nicht eingeholt.Cryptographic software (AES-256, PBKDF2, Ed25519) generally falls under category 5.2 of the Dual-Use Regulation — however, the mass-market exemption (Note 3) and the open-source exemption for publicly available software apply. This is our own assessment; no ruling has been obtained from the German export authority.
Open Source
EUPL-1.2 · Quellcode öffentlich auf GitHub · keine Exportbeschränkung nach Note 3 i.V.m. EUPL-FreiheitEUPL-1.2 · source code public on GitHub · no export restriction under Note 3 in conjunction with EUPL freedoms
Grenzen der automatischen PrüfungLimits of Automated Verification
Die automatische Schicht läuft ohne Browser. Verhalten, das an Ereignissen auf Dokumentebene, an Layout, Scroll-Position oder Plattform-Eigenheiten hängt, ist dort nicht ausführbar und damit nicht prüfbar. Ein grüner Testlauf ist eine Aussage über die geprüfte Fläche, nicht über die gesamte Anwendung — die Zahl der Tests sagt nichts darüber, was außerhalb ihrer Reichweite liegt.
Diese Grenze ist erhoben und benannt. Sie ist der Grund für die Geräte-Abnahme als eigene Schicht: Jede Änderung an der Bedienoberfläche wird im Browser und auf dem Gerät gegen eine verschlüsselte Referenzdatei geprüft, und der Nachweis wird aus dem gespeicherten Datensatz geführt, nicht aus der Anzeige.
The automated layer runs without a browser. Behaviour that depends on document-level events, layout, scroll position or platform specifics cannot be executed there and therefore cannot be verified. A green test run is a statement about the surface that was tested, not about the application as a whole — the number of tests says nothing about what lies beyond their reach.
This limit has been surveyed and named. It is the reason device acceptance exists as a separate layer: every change to the user interface is verified in the browser and on the device against an encrypted reference file, with evidence taken from the stored record rather than from the display.
11821
Automatische TestsAutomated tests
Schicht 1: 11341 Tests, 0 Fehler · dazu 480 Browser-Tests · Stand 23.09.2026Layer 1: 11341 tests, 0 failures · plus 480 browser tests · as of 23 September 2026
0
Bekannte SchwachstellenKnown vulnerabilities
OSV.dev · 2 von 8 SBOM-Komponenten abfragbar2 of 8 SBOM components queryable
0
FHIR-Errors
Gazelle PASSED · 2 Reports
MIT · OFL
Software-LizenzenSoftware licences
jsPDF + qrcode-generator (MIT) · Inter (OFL-1.1) · permissive LizenzenjsPDF + qrcode-generator (MIT) · Inter (OFL-1.1) · permissive licences