For organizations

A reporting channel starts with people ready to respond.

Give reporters a way to raise concerns and return for encrypted follow-up. Start with a small pilot, a designated recipient team, and a tested response process.

Prepare your pilot

Setup is currently assisted. A reporting link becomes available only after your organization provides its public encryption key, configures recipient access, and verifies a complete test conversation.

Contact us about setup

This email is for general setup questions. Do not send sensitive reports, evidence, return codes, or private keys.

What you need to put in place

  1. Choose the people and the process

    Name the recipients who will review reports. Decide who covers absences, how you handle conflicts of interest, and what response expectations you will publish. The service does not set response deadlines for your team.

  2. Keep control of your encryption key

    Have your technical administrator generate an RSA-3072 key pair for RSA-OAEP with SHA-256. Export the public and private keys as separate JWK files. Share only the public JWK and its key identifier for setup.

    Keep the private JWK with your authorized recipients, backed up in a location they control. Recipients select that file locally to unlock the inbox; the application does not upload it. Losing a private key means losing recipient access to the conversations encrypted for it.

  3. Configure recipient sign-in

    Set a Cloudflare Access policy for your recipient inbox and API, with access limited to your designated team. Provide the application's Access audience identifier and have your administrator verify the sign-in configuration. A decryption key alone does not grant inbox access.

  4. Publish clear reporting and retention information

    Choose your organization name, reporting channel slug, guidance, and a retention period between 1 and 365 days. The default is 90 days from case creation. Explain which concerns you receive, who reviews them, and where reporters can find your policies.

  5. Test the entire conversation before launch

    Send a non-sensitive test report, save its return code, and verify that a recipient can unlock it. Reply from the inbox, reopen follow-up with the code, and test an attachment download, status change, and deletion. Verify unauthorized recipients cannot access the case.

    Once setup is verified, publish your organization-specific reporting link where your employees and other reporters can confirm it is authentic.

Manage a case through to completion

Authorized recipients can read and reply to reports, download encrypted evidence after local decryption, and mark a case as received, under review, or closed. Closing stops new replies; deletion removes access. Expiration is measured from case creation and is not extended by replies.

Keep older private keys when rotating to a new key: existing cases remain encrypted for the key used when they were created. Disabling new intake does not remove follow-up access to existing conversations before they are deleted or expire.

Open the recipient inbox

Agree on the limits

Encryption protects message and evidence contents in transit through application storage. It does not remove delivery metadata, guarantee anonymity, or prevent recipients from making copies. Your organization remains responsible for how reports and downloaded evidence are handled.

Review privacy, access, and retention with your recipient team before opening a channel.

Technical administrators can use the implementation and setup guide for provisioning, key generation, and verification.