Security Overview

High-level overview of Disclosurely's current security posture, including encryption, access controls, audit history, and buyer review limitations.

Disclosurely's security model combines encrypted data handling, organisation-scoped access controls, and audit history to support safer whistleblowing workflows.

What Disclosurely Supports

  • TLS-protected connections for data in transit.
  • Server-side encryption controls for stored report and case data.
  • Role-based access controls for case handlers and administrators.
  • Session management for authenticated users.
  • Audit history for case activity, workflow changes, and review events.
  • Secure file upload and evidence handling workflows.
  • Optional AI features that should be reviewed separately before use.

What Disclosurely Does Not Claim

  • Disclosurely does not claim end-to-end encryption or a zero-knowledge architecture.
  • Disclosurely does not claim ISO 27001 certification, SOC 2 reporting, or third-party security attestation on this public page.
  • Disclosurely does not make a customer automatically compliant with GDPR, the EU Whistleblowing Directive, SOX, or employment law.
  • Disclosurely does not replace customer policies, legal review, access governance, or internal investigation procedures.

Procurement Checklist

  • Confirm which security controls are live today and which are planned.
  • Review role design, least-privilege access, and case visibility controls.
  • Ask how encryption, backups, retention, and deletion are handled in the current production environment.
  • Review audit history coverage for case activity and administrative changes.
  • Confirm whether AI features are enabled, optional, or excluded from the intended deployment.
  • Request current legal, privacy, and supplier diligence materials where required.

FAQs

Is this page a security certification?

No. It is a public overview of Disclosurely's current security posture and should not be treated as a certification, attestation, or contractual security schedule.

Is Disclosurely end-to-end encrypted?

No. Disclosurely uses encrypted transport and server-side encryption controls, but authorised users can access report data according to their permissions.

What should buyers verify during security review?

Buyers should verify current controls, contractual terms, data-processing arrangements, retention settings, user access governance, and any assurance material supplied during procurement.

Related Trust Centre pages

Commercial review paths

Disclosurely Security Overview