Secure Messaging
How Disclosurely supports secure two-way messaging between reporters and case handlers without overclaiming anonymity or encryption.
Secure messaging lets reporters and authorised case handlers continue a case conversation inside the reporting workflow.
What Disclosurely Supports
- Two-way follow-up between reporters and case handlers.
- Anonymous report follow-up using a tracking or access code rather than a reporter account.
- Confidential report follow-up where the reporter's identity is known to authorised users.
- Message history stored with the relevant case record.
- Encryption in transit and server-side encryption controls for stored messages.
- Audit history for relevant messaging and case activity.
What Disclosurely Does Not Claim
- Disclosurely does not claim end-to-end encrypted messaging.
- Disclosurely does not guarantee anonymity if a reporter includes identifying details in message content or attachments.
- Disclosurely does not claim messages are visible only to one named investigator; access depends on configured roles and permissions.
- Disclosurely does not replace customer duties around confidentiality, anti-retaliation, or investigation handling.
Procurement Checklist
- Confirm how anonymous reporters regain access to messages.
- Review which roles can view or reply to messages.
- Ask whether message access appears in audit history.
- Confirm how file attachments in messages are handled.
- Review retention settings for messages and related case data.
- Check how reporter notifications work for anonymous and confidential reports.
Related Concepts
- Anonymous Reporting Workflows
- Anonymous vs Confidential Reports
- How to Submit a Report
- Access Control & Permissions
- Encryption & Data Handling
- Secure Two-Way Conversations
FAQs
Can anonymous reporters receive follow-up questions?
Yes. Anonymous reporters can continue the conversation through the reporting workflow if they keep their tracking or access code.
Are messages end-to-end encrypted?
No. Messages are protected by encrypted transport, server-side encryption controls, and role-based access, but they are not described as end-to-end encrypted.
What happens if an anonymous reporter loses their code?
Access may not be recoverable without undermining anonymity. Organisations should tell reporters to store their code securely.
