Technical audit · 2026-05-29

bamf.de

German Federal Office for Migration and Refugees

Federal Office for Migration and Refugees — the body that processes asylum applications. 58 requests, 1 domain. BundesSans and BundesSerif served locally. Matomo is documented in the policy with opt-out — entirely absent from the HAR. Not a single external domain. Full compliance.

Timeline of the leak

+77 ms · load
All CSS, JS, icons, and images load from www.bamf.de. Leichte Sprache (easy language) and Gebärdensprache (sign language) symbols — SVG icons, local.
+166 ms · fonts
www.bamf.de/static/fonts/BundesSchrift — BundesSansWeb (Regular, Bold, BoldItalic, Italic) and BundesSerifWeb (Regular, Bold). The state font standard, fully local.
No external domains
Not a single request outside www.bamf.de. No Matomo, no YouTube, no Google. Set-Cookie — zero.

Declared versus actual

Matomo — documented in the policy with an opt-out mechanism — заявлен
YouTube — mentioned in the policy for embedded videos — заявлен
Session cookies — documented as strictly necessary — заявлен

Context

BAMF (Bundesamt für Migration und Flüchtlinge) is the federal agency that decides asylum applications, manages integration programs, and maintains records of foreign nationals. Sensitivity is high: the site’s visitors include asylum seekers, refugees, and migrants. HAR: 58 requests, 1 domain.

Architectural discipline

All 58 requests are directed exclusively to www.bamf.de. BundesSans and BundesSerif — the state Bundesdesign font standard — are hosted locally at /static/fonts/BundesSchrift/. Leichte Sprache and Gebärdensprache icons are SVG files on the proprietary server. No Google Fonts, no CDN, no external JS libraries.

Matomo in the policy — not in the HAR

BAMF’s privacy policy describes Matomo (formerly Piwik) as an anonymous visit-statistics tool: “Rückschlüsse auf die Identität der Nutzer und Teilnehmer sind nicht möglich.” An opt-out is provided — the user can decline. Legal basis: Art. 6(1)(f) DS-GVO (legitimate interest). In the HAR from May 2026, Matomo is entirely absent: no matomo.js, no piwik.php, no requests of any kind to a Matomo domain. It is possible the audit was conducted in an opt-out state carried over from a previous session, or that Matomo was disabled during the audit period.

YouTube — in the policy, not in the HAR

The policy mentions embedded YouTube videos using the enhanced data protection mode (erweiterter Datenschutzmodus). No YouTube embeds were recorded on the homepage at the time of the audit.

Easy language and sign language

The homepage offers links to versions of the site in Leichte Sprache (easy language for people with cognitive differences) and Gebärdensprache (sign language). For an agency working with refugees from various countries with varying levels of German proficiency, this is a critically important feature. The corresponding SVG icons are implemented with no external dependencies.

Conclusion

bamf.de — an agency serving one of the most vulnerable categories of visitors to state websites — demonstrates an architecture with zero external domains. This is the second zero result in the German series, after bundespolizei.de. Both are federal law-enforcement and security bodies. A pattern is already emerging in the German series: the more sensitive the data being processed, the cleaner the architecture.

Evidence
Original (audit)
HAR file: de/bamf-de-2026-05-29.har
SHA-256: 23a0f305c719d7ed146d37dbe576db824208e081dc3f02df79b13961f3549f12
HAR files are stored on EU infrastructure (Proton Drive). SHA-256 is published for integrity verification.