Features¶
User Features¶
Multi-user system with customizable user roles (whistleblower, recipient, administrator)
Entirely manageable from a web administration interface
Support for more than 90 languages with support for Right-to-Left (RTL)
Let whistleblowers decide if and when to confidentially declare their identity
Exchange multimedia files with whistleblower
Secure management of files’ access and visualization
Chat with Whistleblower to discuss the report
Unique 16-digit receipt for the whistleblower to log back in anonymously
Simple recipient interface for receiving and analyzing reports
Support for the categorization of the reports with labels
Support for the user search of reports
Support for assigning and creating case management statuses
Customizable look and feel (logo, colour, styles, font, text)
Define multiple reporting channels (e.g. per-topic, per-department)
Create and manage multiple whistleblowing site (e.g for subsidiaries or third party clients)
Advanced questionnaire builder
Whistleblowing system statistics
Legal Features¶
Designed in adherence with ISO 37002:2021 and EU Directive 2019/1937
Bidirectional anonymous communication (comments/messages)
Customizable case management workflow (statuses/sub-statuses)
Whistleblower identity conditional reporting workflow
Manage conflict of interest in the reporting workflow
Custodian functionality to authorize access to whistleblower identity
GDPR privacy by design and by default
GDPR configurable data retention policies
GDPR compliant subscriber module for new users of SaaS services
No logs of IP addresses
Audit log
Integratable with existing enterprise case management platform
Free Software OSI Approved AGPL 3.0 License
Security Features¶
Designed in adherence with ISO 27001:2022
Full data encryption of whistleblower reports and recipient communication
Digital anonymity support with Tor integration
Built-in HTTPS support with TLS 1.3 standard (SSLabs A+ rating)
Automatic free digital certificate enrollment (Let’s Encrypt)
Multiple penetration tests with full public reports
Conform to industry standards and best practices for application security (OWASP)
Two-Factor authentication (2FA) support compliant with standard TOTP RFC 6238
Integrated network sandboxing with iptables
Integrated application sandboxing with AppArmor
Complete protection against automated submissions (spam prevention)
Subject to continuous peer-review and periodic security audits
PGP support for encrypted email notifications and encrypted file downloads
Does not leave traces in browser cache
Technical Features¶
Multi-site support enabling to run multiple virtual site on the same setup
Responsive user interfaces made with Boostrap CSS Framework
Built-in Accessibility Support with WAI-ARIA compliance
Automated Software Quality Measurement and Continuous Integration Testing
Long-Term Support plan (LTS)
Built with lightweight framework technologies (AngularJS and Python Twisted)
Integrated SQLite database
Automatic setup of Tor Onion Services Version 3
Support for self-service signup for whistleblowing SaaS service setup
Debian packaging with repository for update/upgrades
Fully self-contained application
Easy integration of the platform with existing websites
Rest API