Security Overview
High-level overview of Disclosurely's current security posture, including encryption, access controls, audit history, and buyer review limitations.
Disclosurely's security model combines encrypted data handling, organisation-scoped access controls, and audit history to support safer whistleblowing workflows.
What Disclosurely Supports
- TLS-protected connections for data in transit.
- Server-side encryption controls for stored report and case data.
- Role-based access controls for case handlers and administrators.
- Session management for authenticated users.
- Audit history for case activity, workflow changes, and review events.
- Secure file upload and evidence handling workflows.
- Optional AI features that should be reviewed separately before use.
What Disclosurely Does Not Claim
- Disclosurely does not claim end-to-end encryption or a zero-knowledge architecture.
- Disclosurely does not claim ISO 27001 certification, SOC 2 reporting, or third-party security attestation on this public page.
- Disclosurely does not make a customer automatically compliant with GDPR, the EU Whistleblowing Directive, SOX, or employment law.
- Disclosurely does not replace customer policies, legal review, access governance, or internal investigation procedures.
Procurement Checklist
- Confirm which security controls are live today and which are planned.
- Review role design, least-privilege access, and case visibility controls.
- Ask how encryption, backups, retention, and deletion are handled in the current production environment.
- Review audit history coverage for case activity and administrative changes.
- Confirm whether AI features are enabled, optional, or excluded from the intended deployment.
- Request current legal, privacy, and supplier diligence materials where required.
Related Concepts
- Encryption & Data Handling
- Access Control & Permissions
- Authentication & SSO
- Session Management
- Audit Trail & Case Activity Records
- Security Centre
FAQs
Is this page a security certification?
No. It is a public overview of Disclosurely's current security posture and should not be treated as a certification, attestation, or contractual security schedule.
Is Disclosurely end-to-end encrypted?
No. Disclosurely uses encrypted transport and server-side encryption controls, but authorised users can access report data according to their permissions.
What should buyers verify during security review?
Buyers should verify current controls, contractual terms, data-processing arrangements, retention settings, user access governance, and any assurance material supplied during procurement.
