Encryption & Data Handling
Public reference for how Disclosurely describes encryption, data handling, access controls, and the limits of the current security model.
Disclosurely uses encryption and access controls to protect sensitive reports, case history, and related evidence. This page describes the current public posture only.
Further Reading
- Why Encryption Matters in Whistleblowing Systems explains how buyers should evaluate encryption claims alongside access control, workflow, and auditability.
Current wording standard
- Use encryption in transit for TLS-protected connections.
- Use encryption at rest for stored case and report data.
- Use server-side encryption controls for the platform model.
- Do not describe Disclosurely as end-to-end encrypted or zero-knowledge.
What this means in practice
- Report and case data are protected while stored in the production environment.
- Access to case content is controlled through organisation-scoped permissions.
- Audit records support traceability for workflow changes and review activity.
- Messaging and follow-up remain inside the platform workflow rather than external email threads where possible.
Reporting encryption model
For reporting workflows, Disclosurely protects report data through encrypted transport, encrypted storage, and access-controlled case handling.
- In transit: Connections to the platform are protected with TLS.
- At rest: Stored report and case data use server-side encryption controls.
- Access: Authorised case handlers view reports according to organisation-scoped permissions.
- Follow-up: Reporter messaging is kept inside the reporting workflow where possible.
Anonymous and confidential reporting both rely on the same platform security model. Disclosurely should not be described as end-to-end encrypted, because authorised users within an organisation can view reports through the application according to their permissions.
What this page does not claim
- No claim of hardware security modules, customer-managed keys, or BYOK.
- No claim that Disclosurely staff can never access any customer data under any circumstance.
- No claim of ISO 27001 certification or SOC 2 reporting today.
