New Feature: Multi Rater Feedback and 360 Appraisals
Κέντρο εμπιστοσύνης

Κέντρο ασφαλείας

Το Disclosurely είναι σχεδιασμένο για ευαίσθητες ροές whistleblowing με κρυπτογράφηση σε μεταφορά, κρυπτογράφηση διακομιστή σε ηρεμία, απομόνωση πελατών, ελέγχους πρόσβασης βάσει ρόλου, καταγραφή ελέγχου, διαχειριζόμενες λειτουργίες και σχεδιασμό με γνώμονα το GDPR.

Αυτή η σελίδα απευθύνεται σε IT, προμήθειες, νομικούς και υπεύθυνους ασφαλείας. Περιγράφει την τρέχουσα πλατφόρμα παραγωγής, εκτός αν ένα στοιχείο σημειώνεται ρητά ως σε εξέλιξη, προγραμματισμένο ή διαθέσιμο κατόπιν αιτήματος.

Εκτελεστική σύνοψη

Το Disclosurely είναι πλατφόρμα πολλαπλών πελατών για whistleblowing και διαχείριση υποθέσεων. Τα δεδομένα πελατών οργανώνονται ανά οργανισμό, προστατεύονται σε μεταφορά με TLS, αποθηκεύονται με ελέγχους κρυπτογράφησης διακομιστή και είναι προσβάσιμα μέσω ρόλων οριοθετημένων στον οργανισμό και ροών με ίχνος ελέγχου.

Το περιβάλλον παραγωγής φιλοξενείται σε διαχειριζόμενη υποδομή στο ΗΒ/ΕΕ. Οι έλεγχοι ασφαλείας εξελίσσονται μέσω εσωτερικών επισκοπήσεων, συνεχούς ενίσχυσης παραγωγής και σχολίων από πραγματικές επισκοπήσεις ασφαλείας και προμηθειών.

Κρυπτογράφηση σε μεταφορά
Κρυπτογράφηση σε ηρεμία
Απομόνωση πελατών
Πρόσβαση βάσει ρόλου
Περιβάλλον παραγωγής στο ΗΒ/ΕΕ
Καταγραφή ελέγχου
Υπεύθυνη αποκάλυψη
Προφίλ πλατφόρμας
Τεχνική επισκόπηση
Τρέχουσα κατάσταση
Τοποθεσία δεδομένων
ΗΒ / ΕΕ
Έλεγχος ταυτότητας
Email OTP + MFA
Κρυπτογράφηση
TLS + διακομιστής σε ηρεμία
Αρχεία ελέγχου
Διαθέσιμα
AI
Προαιρετικό και κατόπιν αιτήματος
Ενημερώθηκε
Αύγουστος 2026

Αξιολόγηση προμηθευτή

Το Disclosurely είναι σχεδιασμένο ώστε οι επισκοπήσεις ασφαλείας προμηθευτή να είναι απλές. Αυτή η σελίδα παρέχει επισκόπηση των ελέγχων ασφαλείας, της υποδομής και των επιχειρησιακών πρακτικών. Επικοινωνήστε αν χρειάζεστε πρόσθετη τεκμηρίωση.

Επισκόπηση ασφαλείας

Συνοπτική επισκόπηση του τρέχοντος μοντέλου ασφαλείας παραγωγής.

Σχεδιασμός προϊόντος με προτεραιότητα την ασφάλεια

Το Disclosurely είναι σχεδιασμένο για ροές whistleblowing και διαχείρισης υποθέσεων όπου η εμπιστευτικότητα, ο ελεγχόμενος έλεγχος πρόσβασης και οι ανιχνεύσιμες ενέργειες έχουν σημασία από την πρώτη υποβολή έως το κλείσιμο.

Κρυπτογράφηση σε μεταφορά και σε ηρεμία

Η μεταφορά προστατεύεται με TLS και το περιεχόμενο αναφορών μαζί με σχετικά τεκμήρια αποθηκεύονται με ελέγχους κρυπτογράφησης διακομιστή. Το ευαίσθητο περιεχόμενο υπόθεσης δεν αποθηκεύεται ως απλό κείμενο στους κύριους πίνακες υποθέσεων.

Πολλαπλοί πελάτες εξ ορισμού

Τα δεδομένα πελατών είναι λογικά απομονωμένα ανά οργανισμό. Οι διαδρομές πρόσβασης είναι οριοθετημένες στον οργανισμό, με υποστήριξη Row Level Security και ελέγχους δικαιωμάτων βάσει ρόλου.

Ελέγξιμες λειτουργίες

Η δραστηριότητα υπόθεσης, χρηστών, ροών και γεγονότων ασφαλείας καταγράφεται ώστε οι πελάτες να μπορούν να επισκοπήσουν τον κύκλο ζωής μιας αναφοράς και τις ενέργειες γύρω από αυτήν.

Διαχειριζόμενες λειτουργίες πλατφόρμας

Η πλατφόρμα παραγωγής βασίζεται σε διαχειριζόμενες υπηρεσίες παράδοσης, δεδομένων και αποθήκευσης ώστε οι βασικοί έλεγχοι να μπορούν να επισκοπούνται και να ενισχύονται χωρίς υποδομή που λειτουργεί ο πελάτης.

Χειρισμός με προτεραιότητα το απόρρητο

Η ανώνυμη αναφορά δεν απαιτεί λογαριασμό, τα μεταδεδομένα αρχείων αφαιρούνται όπου ισχύει και οι πελάτες δεν μπορούν να ταυτοποιήσουν ανώνυμους καταγγέλλοντες μέσω της ίδιας της πλατφόρμας.

Οδικός χάρτης ασφαλείας

Τρέχουσα ωριμότητα ελέγχων και συνεχής επένδυση. Οι ετικέτες κατάστασης περιγράφουν εργασία ετοιμότητας, όχι ολοκληρωμένες πιστοποιήσεις.

Ολοκληρώθηκε

Ολοκληρώθηκε
  • MFA
  • Κρυπτογράφηση σε ηρεμία και σε μεταφορά
  • Καταγραφή ελέγχου
  • Κέντρο ασφαλείας
  • Πρόσβαση βάσει ρόλου
  • Ασφαλή αντίγραφα

Σε εξέλιξη

Σε εξέλιξη
  • Ετοιμότητα SOC 2 (με υποστήριξη Delve)
  • Ετοιμότητα ISO 27001 (με υποστήριξη Delve)

Προγραμματισμένο

Προγραμματισμένο
  • Cyber Essentials

Διαδρομή συμμόρφωσης

Προγράμματα διασφάλισης σε εξέλιξη ή προγραμματισμένα. Κανένα από τα παρακάτω δεν πρέπει να θεωρείται ολοκληρωμένη πιστοποίηση.

SOC 2

Εργασία ετοιμότητας σε εξέλιξη. Δεν δημοσιεύεται σήμερα αναφορά SOC 2.

Σε εξέλιξη
ISO 27001

Εργασία ετοιμότητας σε εξέλιξη. Δεν ισχυριζόμαστε πιστοποίηση ISO 27001 σήμερα.

Σε εξέλιξη
Cyber Essentials

Καταχωρημένο για μελλοντική εργασία διασφάλισης. Δεν έχει ξεκινήσει ως τρέχων ισχυρισμός.

Προγραμματισμένο

Πόροι Κέντρου εμπιστοσύνης

Αναφορές προμηθειών, ασφαλείας, νομικών και συμμόρφωσης ομαδοποιημένες κατά τη διαδρομή επισκόπησης που συνήθως ακολουθούν οι αγοραστές.

Αρχιτεκτονική

Το Disclosurely λειτουργεί ως διαχειριζόμενη διαδικτυακή εφαρμογή με προαιρετική επεξεργασία AI εκτός της βασικής διαδρομής αναφοράς.

Platform architecture
Disclosurely platform pathPublic summary for security and procurement reviewCORE REPORTING BOUNDARY1ReporterAnonymous or confidential submission2Reporting PortalSecure web access and follow-up3Core PlatformWorkflow, permissions, messaging4Protected Case DataUK/EU-hosted records and evidenceOptional AIUser-invoked onlySUPPORTING CONTROLSAccess controlAudit historyRetention reviewFile handlingSimplified public view. Internal implementation detail is intentionally excluded.

Request flow

  • 1. A reporter or case manager reaches the reporting portal through the managed web application.
  • 2. The application uses managed identity, storage, and core data services for authentication and organisation-scoped operations.
  • 3. Core case data is stored in UK/EU-hosted PostgreSQL tables tied back to the relevant organisation and permission model.
  • 4. Audit records, workflow events, and related security-relevant actions are recorded alongside the case lifecycle.
  • 5. Optional AI processing is invoked only when a user requests supported AI functionality. It is not part of the default reporting path.

Application delivery

Runs the public-facing application through managed delivery infrastructure with HTTPS, request handling, and web-layer protections for the reporting portal.

Core platform services

Supports authentication, organisation-scoped data handling, encrypted storage, and the core data services used by the production platform.

Transactional email

Used for platform notifications and verification-related delivery only. It is not presented as a reporting-data workspace.

Billing systems

Handles billing and subscription events only. It is separate from the reporting and case-handling path.

Operational monitoring

Supports production issue investigation with masking controls so faults can be reviewed without treating operational telemetry as a reporting-data export channel.

Έλεγχος ταυτότητας

Το Disclosurely χρησιμοποιεί μοντέλο ελέγχου ταυτότητας βάσει email σχεδιασμένο να μειώνει την έκθεση διαπιστευτηρίων διατηρώντας την πρόσβαση οριοθετημένη στον σχετικό οργανισμό.

  • Single-use email verification codes are used for account access.
  • One-time verification codes and one-time sign-in codes are issued during authentication flows.
  • Έλεγχος ταυτότητας codes and related sign-in tokens are short-lived and limited to the requested verification or session-establishment step.
  • Secure session management tracks active sessions and related activity after sign-in.
  • Organisation-based permissions determine the data and actions available to each user.
  • Role-based authorisation is enforced through organisation-aware role and permission records.
  • MFA is available in the current production platform.
Compatibility note

Disclosurely uses single-use email verification codes for authentication. Magic-link sign-in is intentionally avoided to maximise compatibility with enterprise email security gateways that inspect links before users interact with them.

Enterprise identity roadmap

MFA is available in production. SSO remains planned for future enterprise tiers and is not represented here as a currently available control.

Κρυπτογράφηση

Το Disclosurely χρησιμοποιεί ελέγχους κρυπτογράφησης μεταφοράς και διακομιστή για να προστατεύει δεδομένα αναφορών και σχετικά τεκμήρια. Η πλατφόρμα δεν πρέπει να περιγράφεται ως κρυπτογραφημένη από άκρο σε άκρο.

  • TLS is used for communication between browsers, the frontend, and platform services.
  • Report content is stored using server-side encryption controls rather than plain-text report bodies in the primary case table.
  • Encrypted report handling is organisation-scoped, with access tied back to organisation permissions and case roles.
  • Uploaded documents are handled through encrypted storage references and linked case metadata.
  • For anonymous submissions, metadata stripping is applied where applicable to reduce identifying information in uploaded files.
  • Authorised users within an organisation can decrypt and view reports according to their permissions and assigned access.
Transparency note

Κρυπτογράφηση in Disclosurely protects data in motion and at rest, but it does not prevent authorised users inside the relevant organisation from decrypting and working on reports when their role allows it.

Απομόνωση πελατών

Οι οργανισμοί πελατών είναι λογικά απομονωμένοι εντός κοινής πλατφόρμας παραγωγής.

  • Organisations are logically isolated inside a multi-tenant architecture.
  • Row Level Security is enabled on core customer data tables, including organisations, reports, profiles, and related operational records.
  • Organisation-scoped queries are used throughout the production data model to keep access bound to the relevant tenant.
  • Πρόσβαση βάσει ρόλου enforcement sits alongside tenant boundaries so users only see the cases and records their role permits.
  • Recent tenant-isolation hardening work has strengthened production organisation boundaries without exposing sensitive implementation detail.
  • Isolation controls continue to be reviewed as part of ongoing security improvement work.

Ανώνυμη αναφορά

Το Disclosurely περιλαμβάνει διαδρομή ανώνυμης αναφοράς σχεδιασμένη ώστε οι καταγγέλλοντες να υποβάλλουν και να συνεχίζουν αναφορές χωρίς δημιουργία λογαριασμού.

  • A dedicated anonymous reporting portal supports account-free submission.
  • Optional file uploads are supported for evidence and supporting material.
  • Metadata stripping is applied where applicable to reduce identifying file metadata on anonymous submissions.
  • Anonymous two-way messaging allows follow-up questions and clarifications without requiring identity disclosure.
  • Reporters use a tracking ID together with a private access secret to return to their report.
  • Organisations cannot identify anonymous reporters through the platform itself.

Έλεγχος και συμμόρφωση

Ο χειρισμός υποθέσεων και η επιχειρησιακή λογοδοσία υποστηρίζονται από δομημένο ιστορικό ελέγχου και παρακολούθηση κύκλου ζωής.

  • Case lifecycle events are recorded from submission through review, investigation, and closure states.
  • Audit history captures user activity, workflow activity, and related operational metadata.
  • Audit records are designed to support change detection and integrity review, including chained record fields in the core audit table.
  • Exportable audit history supports legal, governance, and customer review requirements.
  • Workflow logs, security events, and related audit records help preserve operational traceability around sensitive cases.
  • Internal Disclosurely support activity is kept separate from customer audit records through dedicated internal audit logging.
Separation of records

Customer audit history is distinct from internal founder or support activity. That separation helps preserve a cleaner customer-facing record during investigations and reviews.

Υποδομή

Η υποδομή παραγωγής βασίζεται σε διαχειριζόμενες υπηρεσίες για παράδοση, υπολογισμό, λειτουργία βάσης δεδομένων, αποθήκευση και υποστηρικτικούς ελέγχους.

Managed application delivery

The web application is delivered through managed hosting with HTTPS, request handling, and network-layer protections for the public-facing service.

Core data services

Managed database, authentication, encrypted storage, and organisation-scoped access controls support the production data model.

Web-layer protections

HTTPS is used across the platform, and the web layer applies controls such as CSP, frame restrictions, referrer policy, and MIME-type protections.

Webhook verification

Internal webhook handling verifies provider signatures before events are processed.

Rate limiting and lockouts

Sensitive authentication flows apply throttling and lockout controls to reduce abuse and repeated verification attempts.

Ongoing hardening

Production security improvements are made continuously as the platform evolves and controls are reviewed.

Διαμονή δεδομένων και υποδομή

Πώς σχετίζονται τα δεδομένα πελατών με την πλατφόρμα Disclosurely και τις υπηρεσίες υποστήριξης.

Data path overview
Organisation
Your people, policies, and case handlers
Disclosurely Platform
Reporting portal, case workflows, access controls
UK / EU Hosted Customer Data
Production customer data hosted within the UK/EU
Trusted Υπεργολάβοι
Supporting services such as Vercel, Stripe, ΆνοιγμαAI, and Resend
  • Customer data is hosted within the UK/EU.
  • Disclosurely uses a small number of trusted subprocessors for delivery, billing, email, optional AI, and operations.
  • Appropriate contractual safeguards are in place where applicable.
  • Υπεργολάβοι do not receive unrestricted access to customer data.
  • Category-level service roles are listed in Υπηρεσίες υποστήριξης below for procurement review.

Αντίγραφα ασφαλείας και ανάκτηση

Τα αντίγραφα και η ανάκτηση βασίζονται σε δυνατότητες διαχειριζόμενης υποδομής και όχι σε στοιχεία πλατφόρμας που λειτουργεί ο πελάτης.

  • Managed database backups are used for the production data layer.
  • High availability is supported through managed frontend, database, and storage services.
  • Disaster recovery planning follows the managed-service model used by the platform.
  • Recovery objectives are not stated here unless they are contractually agreed and operationally documented.

AI και επεξεργασία δεδομένων

Η υποστήριξη AI είναι διαθέσιμη για επιλεγμένες ροές υποθέσεων, αλλά είναι προαιρετική και εκτός της προεπιλεγμένης διαδρομής υποβολής.

  • AI features are optional.
  • AI is used only when requested by an authorised user.
  • Reports are not automatically processed by AI as part of the core reporting flow.
  • Supported AI functionality currently covers summarisation, categorisation, and analysis assistance.
  • Customer data remains encrypted at rest in the core platform data layer.
  • AI processing relies on approved third-party providers when enabled.
  • Current service categories are listed in the Υπηρεσίες υποστήριξης section.
  • Customer data is not used to train public AI models.
  • AI processing is limited to the requested functionality and routed through logged, organisation-scoped request handling.
Human review remains required

AI output is designed to assist case handling, not replace human judgement, legal review, or governance decisions.

GDPR και απόρρητο

Το Disclosurely λειτουργεί με γνώμονα το UK GDPR και το EU GDPR, με ελέγχους που στοχεύουν στην ελαχιστοποίηση, υπεύθυνη επεξεργασία και έλεγχο του πελάτη επί των δεδομένων αναφορών.

  • Privacy by design informs product decisions for sensitive reporting workflows.
  • Customer report data is handled with export and deletion request workflows in the production data model.
  • Organisation-level retention controls are available through retention policy records.
  • Privacy handling is described alongside controller and processor roles in the Πολιτική απορρήτου.
  • UK GDPR and EU GDPR considerations are reflected in hosting, retention, deletion, export, and access-control design.
Privacy policy

For controller and processor roles, retention details, international transfer handling, and contact information, review the Πολιτική απορρήτου.

Υπηρεσίες υποστήριξης

Τρέχουσες κατηγορίες υπηρεσιών που χρησιμοποιεί η πλατφόρμα παραγωγής και ο δημόσιος ιστότοπος.

Service AreaPurpose
Core platform servicesAuthentication, organisation-scoped data handling, object storage, and core server-side platform operations.
Application deliveryPublic web application hosting, delivery, and runtime support.
Transactional emailVerification-related and operational email delivery.
Billing systemsSubscription and billing processing.
Optional AI servicesSupported AI-assisted summaries, categorisation, and analysis flows when enabled.
Operational monitoringError monitoring and production issue investigation.
Site analyticsWebsite usage analytics for the public site.

Τεκμηρίωση

Βασικά έγγραφα που χρησιμοποιούνται κατά τις επισκοπήσεις ασφαλείας προμηθευτή. Τα PDF μπορούν να προστεθούν εδώ όταν είναι διαθέσιμα.

Αντιμετώπιση περιστατικών Summary

Summary of incident response practices for supplier due diligence.

Διαθέσιμο κατόπιν αιτήματος.

Επιχειρησιακή συνέχεια Summary

Summary of continuity and recovery practices for procurement review.

Διαθέσιμο κατόπιν αιτήματος.

Σύμβαση επεξεργασίας δεδομένων

DPA materials for legal and procurement review.

Διαθέσιμο κατόπιν αιτήματος.

Πολιτική απορρήτου

Current privacy terms, controller and processor roles, data handling, and contact details.

View
For questionnaires, DPA review, or document packs, email security@disclosurely.com.

Επαγγελματική ασφάλιση

Κάλυψη ασφάλισης που διατηρεί η επιχείρηση. Πληροφορίες συμβολαίου διαθέσιμες κατόπιν αιτήματος.

Professional Indemnity Insurance

Professional indemnity cover is in place. Policy details are available upon request.

Διαθέσιμο upon request. Cover values are not published on this page.

Public Liability Insurance

Public liability cover is in place. Policy details are available upon request.

Διαθέσιμο upon request. Cover values are not published on this page.

Επαφή ασφαλείας

Ερωτήματα προμηθειών και ασφαλείας μπορούν να απευθύνονται στη διεύθυνση παρακάτω.

security@disclosurely.com

Use this contact for supplier questionnaires, security reviews, procurement due diligence, and related trust documentation requests.

Email security

Υπεύθυνη αποκάλυψη

Δεσμευόμαστε να προστατεύουμε το Disclosurely και τους οργανισμούς που βασίζονται σε αυτό. Εκτιμούμε την υπεύθυνη, ιδιωτική αναφορά ζητημάτων ασφαλείας.

How to report a vulnerability

Please email security@disclosurely.com with a clear description of the issue, steps to reproduce where possible, and any relevant impact assessment. You can also reach us via our contact page.

We aim to acknowledge reports within 2 business days and will keep you updated as we investigate and remediate.

Υπεύθυνη αποκάλυψη guidance

  • Give us a reasonable opportunity to investigate and fix the issue before public disclosure.
  • Do not access, modify, or exfiltrate customer data, or attempt to disrupt the availability of Disclosurely services.
  • Avoid privacy violations, destruction of data, and interruption or degradation of service.
  • Act in good faith and only interact with systems you are authorised to test as part of a coordinated report.

We appreciate researchers who help us improve security. Provided you follow this guidance, we will not pursue legal action for good-faith reports.

PGP encryption for vulnerability reports will be supported soon. Until then, email security@disclosurely.com directly.

Ενημερώσεις ασφαλείας

Πρόσφατη εργασία ενίσχυσης που καταγράφεται σε αυτό το Κέντρο εμπιστοσύνης.

  1. Recorded
    2026-07-13Note 01

    Tenant isolation hardening

    Production organisation boundaries were tightened to reinforce organisation-scoped access paths and strengthen isolation controls across sensitive workflows.

    Impact: Reduces the risk of cross-organisation access and improves confidence in tenant boundary enforcement.
  2. Recorded
    2026-07-13Note 02

    Anonymous messaging hardening

    Anonymous follow-up flows were reviewed and tightened so reporters can continue two-way communication without creating an account or exposing their identity.

    Impact: Improves protection around anonymous follow-up without changing the core reporting workflow.
  3. Recorded
    2026-07-13Note 03

    Attachment integrity validation

    Evidence handling was improved around encrypted attachment storage, access tracing, and related upload controls.

    Impact: Strengthens confidence that uploaded evidence remains intact and tied to the correct report context.
  4. Recorded
    2026-07-13Note 04

    Webhook signature verification

    Internal webhook processing was updated to verify provider signatures before events are accepted and processed.

    Impact: Reduces the chance of unauthorised or spoofed webhook traffic being processed by the platform.
  5. Recorded
    2026-07-13Note 05

    Founder Console isolation

    Internal support and founder activity was separated more clearly from customer tenant records and audit history.

    Impact: Improves separation between internal operational activity and customer-visible audit records.
  6. Recorded
    2026-07-13Note 06

    Role-based authorisation improvements

    Role definitions and permission handling were refined to keep access closer to job function and organisation scope.

    Impact: Narrows access to the actions and records needed for each role, supporting least-privilege handling.
  7. Recorded
    2026-07-13Note 07

    Authentication flow improvements

    Email-based sign-in flows, verification handling, and session-related controls were reviewed and improved in production.

    Impact: Improves reliability and control around verification, sign-in, and active session handling.
  8. Recorded
    2026-07-13Note 08

    Security review programme

    Security changes are reviewed continuously, with production improvements informed by internal reviews and customer feedback.

    Impact: Creates a repeatable path for hardening work instead of treating security changes as one-off tasks.

Συχνές ερωτήσεις

Σύντομες απαντήσεις σε συχνές ερωτήσεις επισκόπησης ασφαλείας.

Τελευταία επισκόπησηΑύγουστος 2026
Ασφάλειαscenter | Disclosurely