Release, state, journey
No finding floats free of software version, operating system, choice state or moment.
The unit of testing is not “the app” in the abstract. It is one exact release, in one exact state, following one exact journey, on one exact date. The method also preserves what it cannot establish.
No finding floats free of software version, operating system, choice state or moment.
The stock device shows ordinary reality; the instrumented device can explain a request, with checks for instrumentation effects.
Unique values establish transmission without collecting unsuspecting residents’ data.
An observed connection, readable field and confirmed role permit different sentences.
The actor receives the release, journey, evidence, proposed wording and exact question before publication.
The original result remains visible; change is credited only after the appropriate verification.
The level is part of every URL, card, export and API response.
Public metadata. No package or runtime claim.
Preserved release, documents, manifest, SDKs, journeys and two lanes.
Authentication, payment/location, withdrawal, deletion, language, accessibility and retest.
Synthetic scenario or reference app; never evidence about a real institution.
The public site summarises the method. These documents are the operating source of truth used before, during and after each test.
The protocol creates a dated, contestable public record for one exact mobile-app release, one device state, one defined service journey and one choice state. It does not certify an application as “safe”, “private”, “GDPR compliant” or “illegal”.
Its core comparison has three independently sourced tracks:
A fourth track records the practical service outcome: whether a resident could complete the public task after refusing an optional choice or permission.
Every publishable observation must identify:
The report is never about “the app” in every possible condition. It is about the recorded release and journeys.
Public metadata only. No package preservation or runtime claim.
Minimum publication package:
R1 plus, where safe and relevant:
A synthetic or purpose-built scenario used to test the laboratory and interface. It must never be presented as evidence about a real institution.
Publish the selection method before testing. Use a matrix rather than suspicion or prominence alone:
The sample should contain good, ambiguous and discrepant results. A laboratory that can only produce accusations is not calibrated.
For every release:
Do not silently replace an unavailable historical policy with the current one.
Use a stock, non-rooted device representing an ordinary resident:
Question answered: What did an ordinary device appear to contact?
Use a matched research-configured device:
Question answered: Can the laboratory associate request contents with a specific app event?
A behaviour seen only under instrumentation must be narrowed, repeated and checked for instrumentation effects before publication.
Never use unsuspecting residents’ traffic. Maintain dedicated research artefacts:
A unique token supports stronger wording than a generic field name. It still does not by itself establish legal roles, retention or later use.
Each journey has:
Minimum state sequence where applicable:
Do not grant every permission automatically. The point is to test the resident’s actual choice architecture.
Record at minimum:
Raw captures are restricted. Public traces are derived, sanitised and minimised.
Use a provenance hierarchy:
Label every relationship as documented, confirmed, observed, inferred, unresolved or disputed. A CDN, cloud region, IP geolocation or shared hostname does not prove an independent recipient or data-residency conclusion.
| Evidence | Maximum public wording |
|---|---|
| SDK signature found | The tested package contains SDK X. The test did not establish that all its functions were active. |
| Domain connection observed | The tested release contacted X during this journey. |
| Encrypted destination only | The destination was observed; transmitted fields were not established. |
| Readable field category | A request contained device-model information. |
| Exact synthetic token | The request contained the synthetic email or token used only for this test. |
| No connection observed | This connection was not observed in the tested journeys. |
| Infrastructure association inferred | The destination appears associated with X; its role was not independently confirmed. |
| Institution confirms role | The institution identified X as its contracted processor. |
| Repair passes retest | The original behaviour was not reproduced in the stated retest; this is not a guarantee about all future states. |
Prohibited shortcuts include “spies”, “sells data”, “secretly tracks”, “sends everything”, “GDPR compliant” and “illegal” unless a separate, appropriately sourced investigation establishes the precise proposition.
Use one or more claim-level classes:
“Observed but not clearly described” is not a legal conclusion. “Declared but not observed” is not proof that the declaration is false.
A consequential runtime claim normally requires:
Use three clean runs for a verified repair or a claim whose force depends on repeated non-observation.
Narrow or withhold a claim when:
For every deep receipt, record:
Do not collapse these facts into a coercion score.
Send claim-level notices containing:
Allow a normal response window of ten working days, with extensions for technically complex or security-sensitive issues. This is an editorial practice, not a claimed statutory deadline.
Statuses:
documented → sent for response → acknowledged → repair promised → updated → retest due → verified
Alternative statuses:
disputed → unable to reproduce → no response → superseded
Preserve the original result after repair. Display the verified repair prominently. Reward correction without erasing history.
Retest quarterly and after:
This is a transparency audit, not a vulnerability scanner. Do not:
Potential vulnerabilities leave the public receipt workflow and enter responsible disclosure.
A public receipt contains:
Raw captures, credentials, unredacted payloads and exploitable details remain outside the public package.