← all projects

Confidential Reporting System

A platform for anonymous wrongdoing reports — employees report without revealing their identity while organisations meet European whistleblower-protection obligations.

Project

Confidential Reporting System

A platform through which employees report wrongdoing safely — fully anonymously if they choose — while organisations meet their European whistleblower-protection obligations.

Client / Industry

Compliance and internal reporting — the system serves multiple organisations.

Platform

An anonymous channel for submitting reports, case follow-up without revealing identity, and a workspace for the authorised people who handle the cases.

Role

Full development and ongoing care — from the first version through recurring security reviews.

Problem

European rules require organisations to run an internal channel for reporting wrongdoing — but a channel on paper is not the same as a channel people trust. If an employee suspects their identity could be exposed, the reports simply never come. The system has to protect the reporter from exposure, let the organisation handle cases within legal deadlines, and leave a verifiable trail of it all — at the same time.

Solution

Trust is built by design, not by promise: the system is arranged so that an anonymous reporter’s identity exists nowhere inside it — so neither the organisation, nor we, nor a potential attacker can uncover it.

  • Reporting without an account and without identity — the reporter alone chooses whether to introduce themselves or stay fully anonymous.
  • Case follow-up through a one-time access code: the reporter returns, reads responses and adds to the report without ever logging in or revealing themselves.
  • A workspace for authorised handlers: case processing, communication with the reporter and legal deadlines in one place.
  • Every action on a case leaves a trail — who did what and when, without any view into the reporter’s identity.

Anonymity by Design, Not by Promise

The system has twice undergone independent security testing modelled on real attacks, with every finding fixed and re-verified. Data is kept to the minimum necessary: what the system does not store cannot leak.

Results

0

pieces of identity data about an anonymous reporter in the system — anonymity is built into the foundations, not added later.

independent security testing; every finding fixed and re-verified.

EU

aligned with European rules on whistleblower protection and personal-data protection.

Need a similar project?