Κέντρο ασφαλείας
Το Disclosurely είναι σχεδιασμένο για ευαίσθητες ροές whistleblowing με κρυπτογράφηση σε μεταφορά, κρυπτογράφηση διακομιστή σε ηρεμία, απομόνωση πελατών, ελέγχους πρόσβασης βάσει ρόλου, καταγραφή ελέγχου, διαχειριζόμενες λειτουργίες και σχεδιασμό με γνώμονα το GDPR.
Αυτή η σελίδα απευθύνεται σε IT, προμήθειες, νομικούς και υπεύθυνους ασφαλείας. Περιγράφει την τρέχουσα πλατφόρμα παραγωγής, εκτός αν ένα στοιχείο σημειώνεται ρητά ως σε εξέλιξη, προγραμματισμένο ή διαθέσιμο κατόπιν αιτήματος.
Εκτελεστική σύνοψη
Το Disclosurely είναι πλατφόρμα πολλαπλών πελατών για whistleblowing και διαχείριση υποθέσεων. Τα δεδομένα πελατών οργανώνονται ανά οργανισμό, προστατεύονται σε μεταφορά με TLS, αποθηκεύονται με ελέγχους κρυπτογράφησης διακομιστή και είναι προσβάσιμα μέσω ρόλων οριοθετημένων στον οργανισμό και ροών με ίχνος ελέγχου.
Το περιβάλλον παραγωγής φιλοξενείται σε διαχειριζόμενη υποδομή στο ΗΒ/ΕΕ. Οι έλεγχοι ασφαλείας εξελίσσονται μέσω εσωτερικών επισκοπήσεων, συνεχούς ενίσχυσης παραγωγής και σχολίων από πραγματικές επισκοπήσεις ασφαλείας και προμηθειών.
Αξιολόγηση προμηθευτή
Το Disclosurely είναι σχεδιασμένο ώστε οι επισκοπήσεις ασφαλείας προμηθευτή να είναι απλές. Αυτή η σελίδα παρέχει επισκόπηση των ελέγχων ασφαλείας, της υποδομής και των επιχειρησιακών πρακτικών. Επικοινωνήστε αν χρειάζεστε πρόσθετη τεκμηρίωση.
Κέντρο ασφαλείας
Αυτή η σελίδα — έλεγχοι, αρχιτεκτονική και επιχειρησιακές πρακτικές.
ΆνοιγμαΠολιτική απορρήτου
Ρόλοι υπευθύνου/εκτελούντος την επεξεργασία, διατήρηση και επαφές απορρήτου.
ΆνοιγμαΣύμβαση επεξεργασίας δεδομένων
Υλικό DPA για νομική επισκόπηση και προμήθειες.
ΆνοιγμαΥπεργολάβοι
Υπηρεσίες υποστήριξης που χρησιμοποιεί η πλατφόρμα παραγωγής.
ΆνοιγμαΑντιμετώπιση περιστατικών
Σύνοψη αντιμετώπισης περιστατικών για αξιολογήσεις προμηθευτή.
ΆνοιγμαΕπιχειρησιακή συνέχεια
Σύνοψη συνέχειας και ανάκτησης για due diligence.
ΆνοιγμαΕπικοινωνία ασφαλείας
Ερωτήματα προμηθειών και ασφαλείας.
ΆνοιγμαΕπισκόπηση ασφαλείας
Συνοπτική επισκόπηση του τρέχοντος μοντέλου ασφαλείας παραγωγής.
Σχεδιασμός προϊόντος με προτεραιότητα την ασφάλεια
Το Disclosurely είναι σχεδιασμένο για ροές whistleblowing και διαχείρισης υποθέσεων όπου η εμπιστευτικότητα, ο ελεγχόμενος έλεγχος πρόσβασης και οι ανιχνεύσιμες ενέργειες έχουν σημασία από την πρώτη υποβολή έως το κλείσιμο.
Κρυπτογράφηση σε μεταφορά και σε ηρεμία
Η μεταφορά προστατεύεται με TLS και το περιεχόμενο αναφορών μαζί με σχετικά τεκμήρια αποθηκεύονται με ελέγχους κρυπτογράφησης διακομιστή. Το ευαίσθητο περιεχόμενο υπόθεσης δεν αποθηκεύεται ως απλό κείμενο στους κύριους πίνακες υποθέσεων.
Πολλαπλοί πελάτες εξ ορισμού
Τα δεδομένα πελατών είναι λογικά απομονωμένα ανά οργανισμό. Οι διαδρομές πρόσβασης είναι οριοθετημένες στον οργανισμό, με υποστήριξη Row Level Security και ελέγχους δικαιωμάτων βάσει ρόλου.
Ελέγξιμες λειτουργίες
Η δραστηριότητα υπόθεσης, χρηστών, ροών και γεγονότων ασφαλείας καταγράφεται ώστε οι πελάτες να μπορούν να επισκοπήσουν τον κύκλο ζωής μιας αναφοράς και τις ενέργειες γύρω από αυτήν.
Διαχειριζόμενες λειτουργίες πλατφόρμας
Η πλατφόρμα παραγωγής βασίζεται σε διαχειριζόμενες υπηρεσίες παράδοσης, δεδομένων και αποθήκευσης ώστε οι βασικοί έλεγχοι να μπορούν να επισκοπούνται και να ενισχύονται χωρίς υποδομή που λειτουργεί ο πελάτης.
Χειρισμός με προτεραιότητα το απόρρητο
Η ανώνυμη αναφορά δεν απαιτεί λογαριασμό, τα μεταδεδομένα αρχείων αφαιρούνται όπου ισχύει και οι πελάτες δεν μπορούν να ταυτοποιήσουν ανώνυμους καταγγέλλοντες μέσω της ίδιας της πλατφόρμας.
Οδικός χάρτης ασφαλείας
Τρέχουσα ωριμότητα ελέγχων και συνεχής επένδυση. Οι ετικέτες κατάστασης περιγράφουν εργασία ετοιμότητας, όχι ολοκληρωμένες πιστοποιήσεις.
Ολοκληρώθηκε
- MFA
- Κρυπτογράφηση σε ηρεμία και σε μεταφορά
- Καταγραφή ελέγχου
- Κέντρο ασφαλείας
- Πρόσβαση βάσει ρόλου
- Ασφαλή αντίγραφα
Σε εξέλιξη
- Ετοιμότητα SOC 2 (με υποστήριξη Delve)
- Ετοιμότητα ISO 27001 (με υποστήριξη Delve)
Προγραμματισμένο
- Cyber Essentials
Διαδρομή συμμόρφωσης
Προγράμματα διασφάλισης σε εξέλιξη ή προγραμματισμένα. Κανένα από τα παρακάτω δεν πρέπει να θεωρείται ολοκληρωμένη πιστοποίηση.
Εργασία ετοιμότητας σε εξέλιξη. Δεν δημοσιεύεται σήμερα αναφορά SOC 2.
Εργασία ετοιμότητας σε εξέλιξη. Δεν ισχυριζόμαστε πιστοποίηση ISO 27001 σήμερα.
Καταχωρημένο για μελλοντική εργασία διασφάλισης. Δεν έχει ξεκινήσει ως τρέχων ισχυρισμός.
Πόροι Κέντρου εμπιστοσύνης
Αναφορές προμηθειών, ασφαλείας, νομικών και συμμόρφωσης ομαδοποιημένες κατά τη διαδρομή επισκόπησης που συνήθως ακολουθούν οι αγοραστές.
Security
Identity, access, session, encryption, and monitoring references for IT security review.
Compliance
GDPR, EU Directive, retention, audit, and regulatory context for legal and compliance review.
Reporting
Anonymous reporting, secure messaging, report types, and reporter journey references.
Cases
Investigation workflow, evidence, and file-handling references for case management review.
Αρχιτεκτονική
Το Disclosurely λειτουργεί ως διαχειριζόμενη διαδικτυακή εφαρμογή με προαιρετική επεξεργασία AI εκτός της βασικής διαδρομής αναφοράς.
Request flow
- 1. A reporter or case manager reaches the reporting portal through the managed web application.
- 2. The application uses managed identity, storage, and core data services for authentication and organisation-scoped operations.
- 3. Core case data is stored in UK/EU-hosted PostgreSQL tables tied back to the relevant organisation and permission model.
- 4. Audit records, workflow events, and related security-relevant actions are recorded alongside the case lifecycle.
- 5. Optional AI processing is invoked only when a user requests supported AI functionality. It is not part of the default reporting path.
Application delivery
Runs the public-facing application through managed delivery infrastructure with HTTPS, request handling, and web-layer protections for the reporting portal.
Core platform services
Supports authentication, organisation-scoped data handling, encrypted storage, and the core data services used by the production platform.
Transactional email
Used for platform notifications and verification-related delivery only. It is not presented as a reporting-data workspace.
Billing systems
Handles billing and subscription events only. It is separate from the reporting and case-handling path.
Operational monitoring
Supports production issue investigation with masking controls so faults can be reviewed without treating operational telemetry as a reporting-data export channel.
Έλεγχος ταυτότητας
Το Disclosurely χρησιμοποιεί μοντέλο ελέγχου ταυτότητας βάσει email σχεδιασμένο να μειώνει την έκθεση διαπιστευτηρίων διατηρώντας την πρόσβαση οριοθετημένη στον σχετικό οργανισμό.
- Single-use email verification codes are used for account access.
- One-time verification codes and one-time sign-in codes are issued during authentication flows.
- Έλεγχος ταυτότητας codes and related sign-in tokens are short-lived and limited to the requested verification or session-establishment step.
- Secure session management tracks active sessions and related activity after sign-in.
- Organisation-based permissions determine the data and actions available to each user.
- Role-based authorisation is enforced through organisation-aware role and permission records.
- MFA is available in the current production platform.
Disclosurely uses single-use email verification codes for authentication. Magic-link sign-in is intentionally avoided to maximise compatibility with enterprise email security gateways that inspect links before users interact with them.
MFA is available in production. SSO remains planned for future enterprise tiers and is not represented here as a currently available control.
Κρυπτογράφηση
Το Disclosurely χρησιμοποιεί ελέγχους κρυπτογράφησης μεταφοράς και διακομιστή για να προστατεύει δεδομένα αναφορών και σχετικά τεκμήρια. Η πλατφόρμα δεν πρέπει να περιγράφεται ως κρυπτογραφημένη από άκρο σε άκρο.
- TLS is used for communication between browsers, the frontend, and platform services.
- Report content is stored using server-side encryption controls rather than plain-text report bodies in the primary case table.
- Encrypted report handling is organisation-scoped, with access tied back to organisation permissions and case roles.
- Uploaded documents are handled through encrypted storage references and linked case metadata.
- For anonymous submissions, metadata stripping is applied where applicable to reduce identifying information in uploaded files.
- Authorised users within an organisation can decrypt and view reports according to their permissions and assigned access.
Κρυπτογράφηση in Disclosurely protects data in motion and at rest, but it does not prevent authorised users inside the relevant organisation from decrypting and working on reports when their role allows it.
Απομόνωση πελατών
Οι οργανισμοί πελατών είναι λογικά απομονωμένοι εντός κοινής πλατφόρμας παραγωγής.
- Organisations are logically isolated inside a multi-tenant architecture.
- Row Level Security is enabled on core customer data tables, including organisations, reports, profiles, and related operational records.
- Organisation-scoped queries are used throughout the production data model to keep access bound to the relevant tenant.
- Πρόσβαση βάσει ρόλου enforcement sits alongside tenant boundaries so users only see the cases and records their role permits.
- Recent tenant-isolation hardening work has strengthened production organisation boundaries without exposing sensitive implementation detail.
- Isolation controls continue to be reviewed as part of ongoing security improvement work.
Ανώνυμη αναφορά
Το Disclosurely περιλαμβάνει διαδρομή ανώνυμης αναφοράς σχεδιασμένη ώστε οι καταγγέλλοντες να υποβάλλουν και να συνεχίζουν αναφορές χωρίς δημιουργία λογαριασμού.
- A dedicated anonymous reporting portal supports account-free submission.
- Optional file uploads are supported for evidence and supporting material.
- Metadata stripping is applied where applicable to reduce identifying file metadata on anonymous submissions.
- Anonymous two-way messaging allows follow-up questions and clarifications without requiring identity disclosure.
- Reporters use a tracking ID together with a private access secret to return to their report.
- Organisations cannot identify anonymous reporters through the platform itself.
Έλεγχος και συμμόρφωση
Ο χειρισμός υποθέσεων και η επιχειρησιακή λογοδοσία υποστηρίζονται από δομημένο ιστορικό ελέγχου και παρακολούθηση κύκλου ζωής.
- Case lifecycle events are recorded from submission through review, investigation, and closure states.
- Audit history captures user activity, workflow activity, and related operational metadata.
- Audit records are designed to support change detection and integrity review, including chained record fields in the core audit table.
- Exportable audit history supports legal, governance, and customer review requirements.
- Workflow logs, security events, and related audit records help preserve operational traceability around sensitive cases.
- Internal Disclosurely support activity is kept separate from customer audit records through dedicated internal audit logging.
Customer audit history is distinct from internal founder or support activity. That separation helps preserve a cleaner customer-facing record during investigations and reviews.
Υποδομή
Η υποδομή παραγωγής βασίζεται σε διαχειριζόμενες υπηρεσίες για παράδοση, υπολογισμό, λειτουργία βάσης δεδομένων, αποθήκευση και υποστηρικτικούς ελέγχους.
Managed application delivery
The web application is delivered through managed hosting with HTTPS, request handling, and network-layer protections for the public-facing service.
Core data services
Managed database, authentication, encrypted storage, and organisation-scoped access controls support the production data model.
Web-layer protections
HTTPS is used across the platform, and the web layer applies controls such as CSP, frame restrictions, referrer policy, and MIME-type protections.
Webhook verification
Internal webhook handling verifies provider signatures before events are processed.
Rate limiting and lockouts
Sensitive authentication flows apply throttling and lockout controls to reduce abuse and repeated verification attempts.
Ongoing hardening
Production security improvements are made continuously as the platform evolves and controls are reviewed.
Διαμονή δεδομένων και υποδομή
Πώς σχετίζονται τα δεδομένα πελατών με την πλατφόρμα Disclosurely και τις υπηρεσίες υποστήριξης.
- Customer data is hosted within the UK/EU.
- Disclosurely uses a small number of trusted subprocessors for delivery, billing, email, optional AI, and operations.
- Appropriate contractual safeguards are in place where applicable.
- Υπεργολάβοι do not receive unrestricted access to customer data.
- Category-level service roles are listed in Υπηρεσίες υποστήριξης below for procurement review.
Αντίγραφα ασφαλείας και ανάκτηση
Τα αντίγραφα και η ανάκτηση βασίζονται σε δυνατότητες διαχειριζόμενης υποδομής και όχι σε στοιχεία πλατφόρμας που λειτουργεί ο πελάτης.
- Managed database backups are used for the production data layer.
- High availability is supported through managed frontend, database, and storage services.
- Disaster recovery planning follows the managed-service model used by the platform.
- Recovery objectives are not stated here unless they are contractually agreed and operationally documented.
AI και επεξεργασία δεδομένων
Η υποστήριξη AI είναι διαθέσιμη για επιλεγμένες ροές υποθέσεων, αλλά είναι προαιρετική και εκτός της προεπιλεγμένης διαδρομής υποβολής.
- AI features are optional.
- AI is used only when requested by an authorised user.
- Reports are not automatically processed by AI as part of the core reporting flow.
- Supported AI functionality currently covers summarisation, categorisation, and analysis assistance.
- Customer data remains encrypted at rest in the core platform data layer.
- AI processing relies on approved third-party providers when enabled.
- Current service categories are listed in the Υπηρεσίες υποστήριξης section.
- Customer data is not used to train public AI models.
- AI processing is limited to the requested functionality and routed through logged, organisation-scoped request handling.
AI output is designed to assist case handling, not replace human judgement, legal review, or governance decisions.
GDPR και απόρρητο
Το Disclosurely λειτουργεί με γνώμονα το UK GDPR και το EU GDPR, με ελέγχους που στοχεύουν στην ελαχιστοποίηση, υπεύθυνη επεξεργασία και έλεγχο του πελάτη επί των δεδομένων αναφορών.
- Privacy by design informs product decisions for sensitive reporting workflows.
- Customer report data is handled with export and deletion request workflows in the production data model.
- Organisation-level retention controls are available through retention policy records.
- Privacy handling is described alongside controller and processor roles in the Πολιτική απορρήτου.
- UK GDPR and EU GDPR considerations are reflected in hosting, retention, deletion, export, and access-control design.
For controller and processor roles, retention details, international transfer handling, and contact information, review the Πολιτική απορρήτου.
Υπηρεσίες υποστήριξης
Τρέχουσες κατηγορίες υπηρεσιών που χρησιμοποιεί η πλατφόρμα παραγωγής και ο δημόσιος ιστότοπος.
| Service Area | Purpose |
|---|---|
| Core platform services | Authentication, organisation-scoped data handling, object storage, and core server-side platform operations. |
| Application delivery | Public web application hosting, delivery, and runtime support. |
| Transactional email | Verification-related and operational email delivery. |
| Billing systems | Subscription and billing processing. |
| Optional AI services | Supported AI-assisted summaries, categorisation, and analysis flows when enabled. |
| Operational monitoring | Error monitoring and production issue investigation. |
| Site analytics | Website usage analytics for the public site. |
Τεκμηρίωση
Βασικά έγγραφα που χρησιμοποιούνται κατά τις επισκοπήσεις ασφαλείας προμηθευτή. Τα PDF μπορούν να προστεθούν εδώ όταν είναι διαθέσιμα.
Αντιμετώπιση περιστατικών Summary
Summary of incident response practices for supplier due diligence.
Διαθέσιμο κατόπιν αιτήματος.Επιχειρησιακή συνέχεια Summary
Summary of continuity and recovery practices for procurement review.
Διαθέσιμο κατόπιν αιτήματος.Σύμβαση επεξεργασίας δεδομένων
DPA materials for legal and procurement review.
Διαθέσιμο κατόπιν αιτήματος.Πολιτική απορρήτου
Current privacy terms, controller and processor roles, data handling, and contact details.
ViewΕπαγγελματική ασφάλιση
Κάλυψη ασφάλισης που διατηρεί η επιχείρηση. Πληροφορίες συμβολαίου διαθέσιμες κατόπιν αιτήματος.
Professional Indemnity Insurance
Professional indemnity cover is in place. Policy details are available upon request.
Διαθέσιμο upon request. Cover values are not published on this page.
Public Liability Insurance
Public liability cover is in place. Policy details are available upon request.
Διαθέσιμο upon request. Cover values are not published on this page.
Επαφή ασφαλείας
Ερωτήματα προμηθειών και ασφαλείας μπορούν να απευθύνονται στη διεύθυνση παρακάτω.
security@disclosurely.com
Use this contact for supplier questionnaires, security reviews, procurement due diligence, and related trust documentation requests.
Υπεύθυνη αποκάλυψη
Δεσμευόμαστε να προστατεύουμε το Disclosurely και τους οργανισμούς που βασίζονται σε αυτό. Εκτιμούμε την υπεύθυνη, ιδιωτική αναφορά ζητημάτων ασφαλείας.
How to report a vulnerability
Please email security@disclosurely.com with a clear description of the issue, steps to reproduce where possible, and any relevant impact assessment. You can also reach us via our contact page.
We aim to acknowledge reports within 2 business days and will keep you updated as we investigate and remediate.
Υπεύθυνη αποκάλυψη guidance
- Give us a reasonable opportunity to investigate and fix the issue before public disclosure.
- Do not access, modify, or exfiltrate customer data, or attempt to disrupt the availability of Disclosurely services.
- Avoid privacy violations, destruction of data, and interruption or degradation of service.
- Act in good faith and only interact with systems you are authorised to test as part of a coordinated report.
We appreciate researchers who help us improve security. Provided you follow this guidance, we will not pursue legal action for good-faith reports.
PGP encryption for vulnerability reports will be supported soon. Until then, email security@disclosurely.com directly.
Ενημερώσεις ασφαλείας
Πρόσφατη εργασία ενίσχυσης που καταγράφεται σε αυτό το Κέντρο εμπιστοσύνης.
- Recorded2026-07-13Note 01
Tenant isolation hardening
Production organisation boundaries were tightened to reinforce organisation-scoped access paths and strengthen isolation controls across sensitive workflows.
Impact: Reduces the risk of cross-organisation access and improves confidence in tenant boundary enforcement. - Recorded2026-07-13Note 02
Anonymous messaging hardening
Anonymous follow-up flows were reviewed and tightened so reporters can continue two-way communication without creating an account or exposing their identity.
Impact: Improves protection around anonymous follow-up without changing the core reporting workflow. - Recorded2026-07-13Note 03
Attachment integrity validation
Evidence handling was improved around encrypted attachment storage, access tracing, and related upload controls.
Impact: Strengthens confidence that uploaded evidence remains intact and tied to the correct report context. - Recorded2026-07-13Note 04
Webhook signature verification
Internal webhook processing was updated to verify provider signatures before events are accepted and processed.
Impact: Reduces the chance of unauthorised or spoofed webhook traffic being processed by the platform. - Recorded2026-07-13Note 05
Founder Console isolation
Internal support and founder activity was separated more clearly from customer tenant records and audit history.
Impact: Improves separation between internal operational activity and customer-visible audit records. - Recorded2026-07-13Note 06
Role-based authorisation improvements
Role definitions and permission handling were refined to keep access closer to job function and organisation scope.
Impact: Narrows access to the actions and records needed for each role, supporting least-privilege handling. - Recorded2026-07-13Note 07
Authentication flow improvements
Email-based sign-in flows, verification handling, and session-related controls were reviewed and improved in production.
Impact: Improves reliability and control around verification, sign-in, and active session handling. - Recorded2026-07-13Note 08
Security review programme
Security changes are reviewed continuously, with production improvements informed by internal reviews and customer feedback.
Impact: Creates a repeatable path for hardening work instead of treating security changes as one-off tasks.
Συχνές ερωτήσεις
Σύντομες απαντήσεις σε συχνές ερωτήσεις επισκόπησης ασφαλείας.