Skip to content
scopal affairs
software 10.2026

Sicherlich: aluta continua

The blockchain version stopped at the regulator. The door version runs on my desk. What it still cannot do is the part that needs a law.

In March I wrote that sicherlich was paused. The blockchain went to sleep. The project didn't.

→ see also: Sicherlich, the first post

where it stands

What exists now is the door I promised at the end of the last post. It runs on my own machine and on my own data, the only test subject I am allowed to experiment on.

There is a local vault: keys derived with Argon2id, records encrypted with AES-256-GCM in a local SQLite file. There is a relay design that only ever sees ciphertext, forgets it after a set time and can be self-hosted. There are letter templates for the GDPR rights that matter here: access, erasure, portability. And there is PhotoFlow, which feeds the vault.

Figure 1 marks every part as operational, specified or merely designed. The medical vault is live, but getting documents into it is still a manual step. The finance vault exists on paper.

Fig. 1: Current state of sicherlich and PhotoFlow. Patient's device, ciphertext-only relay, optional external extraction API and data controllers, with status marks per component.

dark processing

While researching my own data I went through the history my health insurer keeps on me and learned a word: Dunkelverarbeitung. Dark processing. It sounds like something you do in a cellar. It is what insurers call a claim that runs from intake to payout without a person touching it. Nobody looks, the lights stay off.

I found that slightly rich. The one party in the chain without such machinery was me. Paper arrives, and I sort it by hand or I don't.

PhotoFlow is my answer, pointed the other way. A scan goes in. Local OCR reads it, a deterministic classifier sorts it, a model extracts the fields. Then it stops at a gate: I confirm each document before anything is filed. It is dark until the last step, where I turn the light on. That seems like the right amount of dark.

One caveat, which the figure makes visible: if I switch on the extraction step, the page image goes to an external model. That is a boundary crossing. I would rather draw it than hide it.

the missing half

What is not built is the part I started sicherlich for. Data leaves the vault toward the practice, the insurer, the next doctor, without a station in between that can read it, and with a grant the patient can end.

Figure 2 draws it. Each recipient gets its own envelope. Intermediaries carry ciphertext. A ledger on my device records who may see what, and until when. Nothing in it is exotic; envelope encryption is old. The open question is who is allowed to send one.

Fig. 2: Target architecture. Patient-issued revocable grants, per-recipient envelopes, ciphertext-only intermediaries and four open legal questions.

the dog is buried in § 630f

Take the revocation arrow in Figure 2. Technically it means: no new key, blob withdrawn. It cannot make anyone unread a page. That limit is physics. The other limit is law, and it is harder.

§ 630f BGB makes the practitioner the keeper of the record and obliges them to keep it for ten years after treatment ends. § 630g gives me the right to inspect it and to get copies. Read together: the practice keeps the file, and I have a right to look at it. The GDPR agrees. Article 17(3)(b) sets aside my right to erasure wherever a legal retention duty applies. A patient with perfect key management is still a guest in their own file.

I want that inverted, and I want it written into the BGB. The patient is the data holder. The practice works on a copy that the patient grants, for as long as the treatment needs it. The ten years stay, because they protect patients: a record that can be quietly shortened cannot prove a treatment error. The duty just has to attach to a record the patient holds, not to a filing cabinet in the practice.

That is a political position, not an architecture. I am an engineer, not a lawyer, and I know it compresses years of legislation into two sentences. There is also the exception from last time: § 630g lets a practitioner refuse inspection for significant therapeutic reasons, which is how the psychiatric restriction works. A patient-held record has to be able to carry that. I don't have a clean answer yet.

The architecture in Figure 2 is this argument, made in running code instead of a position paper. There are two ways it can go. The law changes, which I am not counting on this year. Or someone builds the mechanism and uses it, and whether it is allowed becomes a question about something that exists. I lean toward the second, with legal advice before anything touches a real practice's data.

the glass patient

"Gläserner Patient" is meant as a warning, and in the German-speaking world it is usually read as one. I think the warning points at the wrong thing. The patient is not transparent because data gets shared. The patient is transparent because everyone except the patient holds the data and decides where it goes.

Line it up and it gets strange. Doctors are criticised for holding on to records, and they remain the keepers. Insurers hold the most complete picture, and are trusted with it. The one party not trusted to hold and pass on their own record is the person it describes. When I asked for my own file, it came slowly, and then it came complete, from the insurer.

That is where I understood that sicherlich would have to grow into something the size of an insurer to carry any legal weight at all. What it promises is trust in the individual, and that is exactly what the system does not give. The risk model underneath is a doctoral thesis, and I won't pretend a paragraph settles it.

what happens next

  1. Close the manual step between PhotoFlow and the medical vault.
  2. Build the envelope between two of my own devices. With no third party involved there is no legal question yet, only a technical one.
  3. Write the grant ledger, including revocation, and find out what "revoked" means once the blob has already left.
  4. Find a data protection lawyer and one practice willing to talk.

The struggle continues. I wouldn't have used that phrase in March, when the project had a whitepaper's worth of architecture and no running code. Now it has a vault, a pipeline and a list of things it cannot do. That is a better place to argue from.

So these are the questions I cannot stop asking.

Why does the system trust everyone with my record except me?

Why is a patient who holds their own data a risk, and an insurer that holds all of it a safeguard?

Why do the better paid pay higher contributions? Are they more prone to illness? In the statutory system you pay by income, in the private one by risk. Neither asks you. If it was never about risk, it is not mathematics. It is redistribution, and that is a political question in a lab coat. If it is solidarity, say so. If it is risk, show the arithmetic.

I would like to hear it said out loud, by someone with a vote. Until then I will keep building the door.

Aluta continua.