Trust Centre

Security, privacy and assurance.

Updated 20 September 2026 · Publication copy v4

WhistleHub OÜ is the processor; the customer organisation is the controller. This page describes how the service is built and operated. Our Terms of Service, Privacy Policy, Data Processing Agreement and sub-processor list are public and linked below.

How reports are protected

Encryption. Report content and attachments are encrypted at the application layer with AES-256-GCM, under a key generated per report and wrapped by a hardware-backed key in Google Cloud KMS. Google encrypts the database and storage layer independently.

Reporter anonymity. A reporter can submit without an account, an email address or a phone number. No IP address, browser data or name reaches any organisation-facing surface, and attachment metadata is stripped.

Isolation between organisations. Each organisation’s data is separated. Attempts to reach another organisation’s data fail without revealing whether anything exists.

Audit trail. Every action that creates, accesses, modifies or closes a report is written to a hash-chained log. Alteration and deletion are blocked at database level, and hashes are anchored periodically to a public blockchain with an independent verifier. Only hashes are written to the chain — never report content or personal data.

Attachments. Files are scanned for malware inside the platform. They never leave the platform for scanning, and downloads are blocked until scanning completes.

Transport. TLS 1.2 or higher on every connection, HSTS, strict Content-Security-Policy.

Where the data is

Application containers, database, attachments, encryption keys and runtime secrets run in Google Cloud’s europe-west1 region (Belgium, EU). Transactional email is sent through Zone Media OÜ (Estonia).

Optional message translation sends only the message text — never account data, contact details or attachments. It runs only when a user asks for it, and the input is not used to train Google’s models.

The full sub-processor list is public.

We run in a single EU region, with recovery from encrypted daily backups and point-in-time restore.

Our infrastructure provider Google Cloud holds ISO/IEC 27001, 27017, 27018 and SOC 2/3 certifications.

Operations

Availability. Our Terms of Service commit to 99.5% monthly availability, excluding announced maintenance. A synthetic reporter-to-handler-to-response journey runs every six hours, with alerting on crashes, key-wrapping failures and audit-write failures.

Backup and recovery. Encrypted daily backups, fourteen days retained, with point-in-time restore across a seven-day window. Recovery point objective is minutes; our target for database restoration is one hour.

Incident response. Triage within one business hour of detection. Affected controllers are notified without undue delay and within 48 hours of our becoming aware of a personal data breach — within 24 hours where reporter identity or report content may have been exposed. Root cause report within seven days.

Security testing. Our system is reviewed against a documented programme covering tenant isolation, reporter anonymity, authentication, authorisation, encryption, audit-trail integrity and infrastructure configuration. Reviews run regularly and after significant changes; eight were carried out between February and August 2026.

Retention and deletion. Each organisation configures its own retention and auto-archiving periods. Expired records are crypto-shredded by destroying the encryption key and deleting attachment objects. Reporter data export and anonymisation are supported.

Responsible disclosure. We accept reports of suspected vulnerabilities at security@whistlehub.eu and respond within two business days.

Documents

Available during security review. Request from security@whistlehub.eu:

  • Security Whitepaper v1.0
  • Key management and tenant isolation documentation — under NDA
  • Signed DPA and registry extract — for contracting

Request the security pack

Security contact

Security questions or responsible disclosure: security@whistlehub.eu. We respond within two business days.

Commercial and privacy enquiries: info@whistlehub.eu.

WhistleHub OÜ · Registry code 16567393 · Estonia · whistlehub.eu

We use essential cookies and local storage to keep our service running securely. No tracking or advertising cookies are used. Learn more