Skip to main content

Give the Board Results They Can Verify, Not a PDF They Must Trust

A consultant's survey findings normally arrive as a PDF the client has to take on trust. Signed results let their own security team check the numbers were not edited.

Your findings land as a slide deck. Somewhere in it is a chart saying 41% of one department does not feel safe raising concerns.

Everyone in the room takes that number on trust. Not because they doubt you, but because there is nothing else available to them: no way to tell your chart from a chart with a different number typed into it. That is fine right up until the finding is inconvenient, at which point "where did this come from" stops being a curious question.

Where the numbers usually come from

A survey tool the client did not choose, accessed through an account they do not control, exported by the firm being paid to produce the finding.

Nobody in that chain is behaving badly. It is just a chain with no independent link in it, and the person most exposed by that is you: when the finding is challenged, your credibility is the only thing backing it.

What a verifiable result looks like

Publish the results as a signed document instead of only a rendered chart. The document carries:

  • the counts, per question and per cohort;
  • the cohort definitions actually used;
  • the anonymity floors that were in force when it ran;
  • a signature made with a key belonging to the client's workspace.

The signature is the part that matters. Anyone can fetch the workspace's public key, and anyone can check that this exact set of numbers was signed by that workspace. Change one count, one percentage, one floor, and verification fails. Not "looks suspicious" - fails.

So the client's own security team can confirm the numbers in your report are the numbers the survey produced, without asking you, and without asking the vendor. They do not have to trust either of you. That is what makes it evidence rather than assertion.

Why the floors belong in the signed part

This is the detail people miss.

"41% of that department" is only meaningful alongside how many people were in it and what the minimum reportable group size was. A number over a cohort of four is not a finding, it is an accusation with a percentage sign. Signing the floors alongside the counts means the document states the conditions of its own validity, and nobody can quietly widen a cohort after the fact to make a number look better or worse.

If your tool shows small cohorts with a warning rather than sealing them, you cannot make this claim at all, because the underlying data was already reportable at a size where it should not have been.

What to do with it

Attach the document to the report. One line in the methodology section:

Results are published as a signed document. The counts, cohorts and anonymity thresholds above can be verified against the workspace's public key without reference to us.

Boards do not usually verify. Their security teams sometimes do, and the ones who do remember which supplier made it possible. The value is not in the checking, it is in being the firm whose numbers can be checked.

The thing underneath

None of this would mean much if the vendor could read individual answers, because then the aggregate is just their word about what they read.

Ours cannot. Answers are encrypted in each respondent's browser before upload, so what is stored is ciphertext and the aggregate is computed and decrypted in the browser of somebody the workspace gave a key to. The signature says this aggregate came from that workspace. The architecture says nobody, including us, saw the answers that went into it.

Together those are a claim about a survey that does not rest on trusting the people who ran it, which is a strange and useful thing to be able to hand a client.

FAQ

What does the client actually need to verify it? The signed document and the workspace's public key, which is served publicly. No account, no login, and nothing from us.

What if we edit the numbers for the report? Your report can say whatever you think it should. The signed document is the raw finding, and the point is that the two can be compared. Present a rounded figure by all means; do not present a different one.

Does this expose anything about individual respondents? No. The document contains counts and cohorts, and cohorts below the floor are not in it at all.

Is this a blockchain thing? No. It is an ordinary digital signature over the results, with the public half published so anyone can check it.

See how an engagement runs.

#consultants#verification#results