Bonum Certa Men Certa

Sirius ‘Open Source’ Misleading the International Organization for Standardization (ISO) on Security

What if ISO knew the truth?

International Organization for Standardization (ISO) brag



Summary: There are no proper and truly compliance-driven procedures that are being followed, actively used, or even vaguely specified by poor leadership at Sirius ‘Open Source’; it's all improvised, hugely deficient, not even remotely compliant, and changes are sometimes made retroactively due to lapses and mistakes (compliance or merely appearance thereof, albeit only "after the act"); eventually there are attempts to shoot the messengers -- those who have actually cautioned about those concerning things for several years already

THE "Conclusion" part of the report (a document we'll publish tomorrow as PDF) is included at the bottom of this post. Worry not, it's not the end of the series, only the end of this report; we have plenty left to show and to explain after that. We're eager to show to the world what Sirius ‘Open Source’ Inc./Limited/Corporation truly is.



"We're eager to show to the world what Sirius ‘Open Source’ Inc./Limited/Corporation truly is."As a teaser of sorts, consider how poorly the company was handling data and information. It was getting worse over time because skilled people were leaving the company, making way for the "Google is your friend" mantra. This aforementioned mantra was something along the lines of, "trust big companies", you can give them any data we have. Trust them, they're big! Sure, they also spy for a government.

Data of high-profile clients, both past and present, was naturally left scattered all over the place, sometimes even outside the country. And to give just one example (there are so many; some will be covered later this month and next month), colleagues have cognition reports and incremental/full load reports on local -- as in personal and offsite -- machines (this is indirectly related to patients' data) with no protocol or guidelines for removing these. There's potentially sensitive data on people's machines at home and we've already witnessed mistakes made by the clients themselves (like patients' names or similar data showing up by mistake/accident).

THIS SHOULD NEVER HAPPEN!

"There are serious ramifications for data protection and adherence to law..."In a saner world, everything would be uploaded to a firewalled file server located on the client's own network, accessible in some secure fashion, without the data ever leaving the network, not even metadata. But when a company like Sirius handles its E-mail via AWS and AWS is also the host of OTRS (ticketing), one is expected to just upload files to AWS and transmit the stuff over E-mail (i.e. open relays). No encryption. I was repeatedly told off for using PGP in my E-mails.

There are serious ramifications for data protection and adherence to law, as there are unpatched old machines and perhaps backups that contain such files -- a ticking time bomb. And even way after they're no longer a client (years later), the example above serves to show that the problem does not go away. Not even when the contract ends (or gets terminated).

"Clients simply come to assume the reputation earned in past decades persists to date."The sad reality is that the company, Sirius (so-called 'open source'), is terrified about clients finding out how reckless and incompetent the company gradually became. Clients simply come to assume the reputation earned in past decades persists to date. They're trusting a company run by a person divorced twice, whose kids refuse to even speak to him. How can deep trust be established with people who (if they get caught) simply pretend nothing bad happened and instead of apologising would rather get aggressive, even combative, to cover up the abuse?

The text below mentions ISO, security incidents, and then the company's attempts to shoot the messenger (who cautioned about those issues along with many other issues). The in-depth analysis of the witch-hunt will follow after this report is published in full (some time tomorrow).




Conclusion



To summarise, Sirius should simply admit out in the open: "we've deviated away from our mission," and moreover Sirius ignores warnings about security (ISO deserves to know about phonies and posers at security).

Roy internally cautioned about this several times over the years. Later, when some providers suffers security breaches (as Roy predicted) Sirius neither reset the passwords nor left the compromised providers.

To reiterate what was stated at the start, what's alleged here is factually correct and evidence-backed. No URLs are provided, but URLs can be provided shall they be requested. Brevity still matters and much remains to be told.

In regards to the weak accusations leveraged to avoid paying compensation to Roy and Rianne, here again is the gist of the underlying issue/s:

1. no due process 2. no evidence presented (or claims merely alluded to without context/link) 3. gross accusation inflation 4. guilt by association (identical letter, too) 5. the company has a history doing this to couples, e.g. one blind colleague based in Germany; it was very serious and it went to court (cost the company or its Directors -- the founder and his wife -- a lot of money, went on for a long time, settled at the end)

The document is far from complete. Roy and Rianne have documents, have screenshots, links to official documents from Companies House etc.

Recent Techrights' Posts

Links 10/09/2026: Facebook Unsafe for Kids, Fake Songs (Against Right of Publicity, CG Forgeries Basically) a Growing Problem
Links for the day
Rust is Financially and Technically Controlled by Microsoft. Rust Foundation is a Front for Microsoft's Proprietary Software.
Rust is not and has never been about security
Gemini Links 10/09/2026: "I Don’t Want to Interact With Stochastic Parrots" and "ROOPHLOCH 2026!"
Links for the day
What the British School Closure (BSN Senior School Leidschenveen) Means to EPO Staff
The only European thing about the EPO is the staff
Standing in Solidarity With Matt Mullenweg
I don't trust the people and companies that want Mullenweg out. Neither should you.
Links 10/09/2026: "Smear Campaign Says Anti-Flock Movement Is Chinese Propaganda" and "Flock Employee Calls Cops on Reporter Filming Them"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Wednesday, September 09, 2026
IRC logs for Wednesday, September 09, 2026
IBM's Senior VP of Infrastructure is Out, Silent Layoffs Still Going On
Some people imagine the CEO will also "retire" very soon (and "ahead of time")
Gemini Links 09/09/2026: Mechanical Cameras, "Super App", and Prusa Issues
Links for the day
SLAPP Censorship - Part 177 Out of 200: Manosphere Without Financial Transparency
It has moreover replaced a female worker with a male
Deadline Tomorrow (10th of September) to Appeal the EPO's Fleecing of Staff (Union to Make Legal Challenges)
Join them. Fight the good fight.
linuxstans.com Died, Then Came Back as Slop (LLM Junk)
Don't make the mistake or the assumption that merely 'dabbling in' or 'experimenting with' LLMs can be forgivable as it is a trust destroyer
Links 09/09/2026: GAFAM Fatalities in Miami International Airport, "Britain’s Health Crisis Is Becoming a Political Crisis"
Links for the day
Gemini Links 09/09/2026: "Adjective Is Subjective" and Walled Gardens
Links for the day
Plagiarism is Hardly a New Problem, It Predates Mainstream Media Getting Paid to Whitewash It as "Training" or "Hey Hi", Then Conflate Plagiarism With "Intelligence" or Deferred "Value"
"Quantum" isn't new either; it's a 'circle-jerk' for companies without direction, only hype
Links 09/09/2026: Airport 'Down' (Glasgow and Edinburgh), 'Open' 'AI' Losses Rise to Pace of 50 Billion Dollars in Losses Per Year
Links for the day
Unsafe at Any Speed, "Modern" Appliances
Appliances have gotten worse
SLAPP Censorship - Part 176 Out of 200: The Sex-Obsessed Non-Experts
We heard some sexual stories
European Patent Office (EPO): No Transparency and No Paper Trail
The incompetence is that of the management, i.e. sheer incompetence of people who never examined a patent in their entire lifetime
Gemini Links 09/09/2026: Going Out, Smartphone Addiction, Mapping the Geminispace
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, September 08, 2026
IRC logs for Tuesday, September 08, 2026
Linux is Sabotaged by Botspam and Bloat (de Facto Denial of Service Attack in "Intelligence" Clothing After Rust in "Security" Clothing)
Linux is becoming orphaned, devalued and diluted by GAFAM slop
Switzerland No Longer Wants Microsoft's 'Swiss Cheese' (Back Doors)
Switzerland's patience with Microsoft is wearing thin
Debian is Not a Community, Many Debian Developers Work for Large Companies Including GAFAM (US)
"Community" sounds like friendship and amicability
Links 08/09/2026: Slop Companies Attack Some More Sites, Nvidia Bribes 'Linux' Foundation for Some More Openwashing and for Saying Slop is "Secure"
Links for the day
Gemini Links 08/09/2026: Ultra Introverts, BlackBerry Bold in 2026, and Laughing at LLMs
Links for the day
Microsoft Layoffs in October 2026
Microsoft is a market leader. In NDAs.
Links 08/09/2026: "The Green Revolution Has Failed Africa" and Palantir/Microsoft Harming NHS
Links for the day
Microsoft's Silent Layoffs Are the New Normal at Microsoft
Microsoft has a ton of layoffs all the time, but the media isn't mentioning those as no WARN notices get issued
SLAPP Censorship - Part 175 Out of 200: Implicit and Explicit Coalition Against the UK's SLAPP Industry
SRA recognises the problem
Further Transparency Problems at the EPO
The EPO was never meant to be profitable
Gemini Links 08/09/2026: "Everything Must Go", Announcing Perigee, and Presentations in a Browser
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, September 07, 2026
IRC logs for Monday, September 07, 2026