Finnish employers with 50 or more staff must provide a confidential internal reporting channel. We set one up, host it in Finland, and keep it running — so you meet the requirement without hiring anyone or running a server.
Your own address · Set up in days · Built on GlobaLeaks, the open-source standard
The Whistleblower Protection Act (1171/2022) came into force on 1 January 2023, implementing EU Directive 2019/1937.
| 250 or more employees | Internal reporting channel required |
|---|---|
| 50–249 employees | Internal reporting channel required (deadline was 17 December 2023) |
| Under 50 employees | Not required — but many adopt one for governance and donor confidence |
Only the people you designate may read reports. Everyone else — including IT — must be shut out.
You must acknowledge receipt to the person who reported, within seven days.
You must give them feedback on what happened within three months.
Finnish law explicitly allows organisations with fewer than 250 employees to share whistleblowing resources, even when they are not part of the same group. That is exactly what this is: your own private, branded channel running on infrastructure we maintain.
A private channel at your own address, carrying your name and logo. Not a shared form with other organisations on it.
Reporters get a 16-digit receipt code instead of an account. No name, no email, no login. They use the code to return, read your reply and answer questions.
Reports and attachments are encrypted before they touch the disk. Even the filenames are encrypted. Only your designated recipients can read them.
Every channel also gets a .onion address, so someone can report without revealing their network or location. Included as standard.
Reports expire and delete themselves on a schedule you choose, so you do not hold personal data longer than you should.
Updates, security patches, certificates, encrypted off-site backups and uptime monitoring. You hear from us only when you need to act.
An employee opens your channel and submits a report, with files if needed. They can stay completely anonymous.
The people you designated get an email immediately. Nobody else can see the report.
You reply through the channel. The reporter returns with their receipt code, reads your response and can answer questions — still anonymously.
Timestamps and an audit log evidence that you acknowledged within seven days and gave feedback within three months.
Your data sits on servers in Helsinki, with a Finnish provider, on 100% hydroelectric power. No transfer outside the EU.
Built on GlobaLeaks, used by newsrooms and anti-corruption bodies across Europe. We run it unmodified, so the code protecting your reporters is public and independently reviewed.
Neither this site nor your reporting channel loads third-party scripts, fonts or analytics. Nothing about a visit leaves our servers.
In normal operation, no — reports are encrypted to your designated recipients. But we will be straight with you: as the platform operator we hold a recovery key, so that your data can be restored if your administrator loses their password. This is written into our data processing agreement rather than left unsaid. Any provider who says recovery is possible and that they can never access anything is not being honest with you.
On servers in Helsinki, Finland, with a Finnish provider. Encrypted backups are held separately. Nothing leaves the EU.
Yes. Reporters are not asked for a name or email and do not create an account. They receive a 16-digit receipt code, which is the only way back into their report. For more caution, every channel has a Tor .onion address that hides their network and location too.
GlobaLeaks — free, open-source whistleblowing software used by newsrooms, anti-corruption bodies and NGOs across Europe. We provide the hosting, setup, maintenance and support.
Yes, and you are welcome to — the software is free. What you would take on is a server, TLS certificates, security updates, encrypted backups, monitoring, and being the person called when it breaks. That is what you are paying us for.
Usually a few days. The technical side takes under an hour; most of the time goes on deciding who receives reports, what you want to ask, and your retention policy.
You can, with one month’s notice. We export your data and help you move it to another provider or your own server. No lock-in — it is open-source software and the data is yours.
It depends on the size of your organisation and how many channels and recipients you need. Tell us roughly how many staff you have and we will send you a fixed monthly price — no per-report or per-user charges, and never any charge to the people who make reports.
Tell us a little about your organisation and we will come back with a price. Happy to talk it through first — no obligation.