Security & Privacy Architecture

Confidentiality engineered into every layer

Whistleblowing software is only as good as the trust it commands. We treat privacy and security as non-negotiable architectural requirements.

Anonymous Reporting Without Accounts

Reporters can submit concerns completely anonymously or identified. No login credentials, personal email, or employee account required to submit or follow up.

Private Case References

Each submission generates a unique case reference (e.g. CASE-2026-0012) that allows whistleblowers to return and follow up safely via 'Check on a report'.

Strict Multi-Tenant Isolation

Every tenant workspace is strictly partitioned. Cross-tenant data access is prevented, ensuring organization data and cases remain private to authorized users.

Role-Based Access Control

Admin, Case manager, and Investigator roles enforce least-privilege scoping across your organization's compliance team.

Complete Audit Trail

Every case assignment, status change, and internal note is recorded with timestamped audit entries to maintain accountability.

EU Directive Compliance

Designed for EU Directive 2019/1937 requirements, providing the confidential intake channel, 7-day acknowledgement tracking, and 3-month feedback deadlines.

Have specific compliance or security questionnaires?

Our team regularly assists compliance and security officers with SOC2, GDPR, and ISO compliance assessments.