For organizations
Register your organization
Set up your reporting channel with Basic. €10/month or €100/year.
Loading your account…
Setup help
Administrator setup and verification
Registration creates a recovery kit containing your private key and recipient credential. Save and verify it during setup. Email sign-in cannot recover your private key.
For assisted setup, use the steps below with your platform administrator.
What you need to put in place
Choose the people and the process
Name the recipients who will review reports. Decide who covers absences, how you handle conflicts of interest, and what response expectations you will publish. The service does not set response deadlines for your team.
Keep control of your encryption key
Generate your encryption keys in the browser: an RSA-3072 key pair for RSA-OAEP with SHA-256. Download the public and private keys as separate JWK files. Share only the public JWK and its key identifier for setup.
Keep the private JWK with your authorized recipients, backed up in a location they control. Recipients select that file locally to unlock the inbox; the application does not upload it. Losing a private key means losing recipient access to the conversations encrypted for it.
Configure recipient sign-in
Have your administrator generate a recipient access token in the dashboard and share it securely with your designated team. Recipients enter this token to access the inbox and select their private JWK locally to decrypt reports. Replace the token when team access changes.
Publish clear reporting and retention information
Have your platform administrator add your organization in the administration dashboard with its public key, recipient access token, name, reporting channel slug, and guidance. Choose a retention period between 1 and 365 days; the default is 90 days from case creation. Explain which concerns you receive, who reviews them, and where reporters can find your policies.
Test the entire conversation before launch
Send a non-sensitive test report, save its return code, and verify that a recipient can unlock it. Reply from the inbox, reopen follow-up with the code, and test an attachment download, status change, and deletion. Verify unauthorized recipients cannot access the case.
Once setup is verified, publish your organization-specific reporting link where your employees and other reporters can confirm it is authentic.
Manage a case through to completion
Authorized recipients can read and reply to reports, download encrypted evidence after local decryption, and mark a case as received, under review, or closed. Closing stops new replies; deletion removes access. Expiration is measured from case creation and is not extended by replies.
Keep older private keys when rotating to a new key: existing cases remain encrypted for the key used when they were created. Disabling new intake does not remove follow-up access to existing conversations before they are deleted or expire.
Agree on the limits
Encryption protects message and evidence contents in transit through application storage. It does not remove delivery metadata, guarantee anonymity, or prevent recipients from making copies. Your organization remains responsible for how reports and downloaded evidence are handled.
Review privacy, access, and retention with your recipient team before opening a channel.
Generate keys for assisted setup
Registration generates keys as part of your recovery kit. Use this separate tool only when coordinating assisted setup or a key change with your administrator.
For organizations
Generate your encryption keys.
Create a public key for your reporting channel and a private key for your recipients. Key generation happens entirely in this browser. Neither key is sent to our servers.
One pair, two different roles
Share the public JWK and its key identifier with your platform administrator. Keep the private JWK with your authorized recipients to unlock reports in the recipient inbox.
Save your private key before leaving. Keys are held only in this page's memory until you copy or download them. Refreshing, leaving, or clearing this page removes its copy; we cannot recover it.
The downloaded private JWK is not password protected. Store it in a secure location with a backup your recipients control. Never send it to support or upload it to organization setup.
RSA-3072 · RSA-OAEP · SHA-256
Your key pair is ready
The exported keys passed an encryption and decryption check in this browser.
Public key identifier
Use this identifier with the public JWK in organization setup. It is also included as kid in both files.
Public key
Share this file with your platform administrator for organization setup.
Private key
Keep this file confidential. Anyone with this key and access to your encrypted reports can decrypt them. Keep older private keys when creating a new pair.
Copying puts the private key on your clipboard, where other apps or clipboard sync may retain it. Clearing this page does not remove downloaded files or clipboard copies.
Generating keys does not register or change your reporting channel. Continue with organization setup after saving both files.