Required by Finnish law since 2023

A whistleblowing channel
your people can trust.

Finnish employers with 50 or more staff must provide a confidential internal reporting channel. We set one up, host it in Finland, and keep it running — so you meet the requirement without hiring anyone or running a server.

Request a quote See a live channel

Your own address · Set up in days · Built on GlobaLeaks, the open-source standard

What the law actually requires

The Whistleblower Protection Act (1171/2022) came into force on 1 January 2023, implementing EU Directive 2019/1937.

250 or more employeesInternal reporting channel required
50–249 employeesInternal reporting channel required (deadline was 17 December 2023)
Under 50 employeesNot required — but many adopt one for governance and donor confidence

Confidentiality

Only the people you designate may read reports. Everyone else — including IT — must be shut out.

Seven days

You must acknowledge receipt to the person who reported, within seven days.

Three months

You must give them feedback on what happened within three months.

Smaller organisations may share a channel

Finnish law explicitly allows organisations with fewer than 250 employees to share whistleblowing resources, even when they are not part of the same group. That is exactly what this is: your own private, branded channel running on infrastructure we maintain.

What you get

Your own reporting site

A private channel at your own address, carrying your name and logo. Not a shared form with other organisations on it.

Anonymity that holds up

Reporters get a 16-digit receipt code instead of an account. No name, no email, no login. They use the code to return, read your reply and answer questions.

Encrypted before it is stored

Reports and attachments are encrypted before they touch the disk. Even the filenames are encrypted. Only your designated recipients can read them.

A Tor address as well

Every channel also gets a .onion address, so someone can report without revealing their network or location. Included as standard.

Automatic retention

Reports expire and delete themselves on a schedule you choose, so you do not hold personal data longer than you should.

We keep it running

Updates, security patches, certificates, encrypted off-site backups and uptime monitoring. You hear from us only when you need to act.

How it works

Someone reports

An employee opens your channel and submits a report, with files if needed. They can stay completely anonymous.

You are notified

The people you designated get an email immediately. Nobody else can see the report.

You have a conversation

You reply through the channel. The reporter returns with their receipt code, reads your response and can answer questions — still anonymously.

You stay compliant

Timestamps and an audit log evidence that you acknowledged within seven days and gave feedback within three months.

Why this one

Hosted in Finland

Your data sits on servers in Helsinki, with a Finnish provider, on 100% hydroelectric power. No transfer outside the EU.

Open-source, unmodified

Built on GlobaLeaks, used by newsrooms and anti-corruption bodies across Europe. We run it unmodified, so the code protecting your reporters is public and independently reviewed.

No trackers anywhere

Neither this site nor your reporting channel loads third-party scripts, fonts or analytics. Nothing about a visit leaves our servers.

Questions

Can you read our reports?

In normal operation, no — reports are encrypted to your designated recipients. But we will be straight with you: as the platform operator we hold a recovery key, so that your data can be restored if your administrator loses their password. This is written into our data processing agreement rather than left unsaid. Any provider who says recovery is possible and that they can never access anything is not being honest with you.

Where is the data stored?

On servers in Helsinki, Finland, with a Finnish provider. Encrypted backups are held separately. Nothing leaves the EU.

Is it really anonymous?

Yes. Reporters are not asked for a name or email and do not create an account. They receive a 16-digit receipt code, which is the only way back into their report. For more caution, every channel has a Tor .onion address that hides their network and location too.

What software is this?

GlobaLeaks — free, open-source whistleblowing software used by newsrooms, anti-corruption bodies and NGOs across Europe. We provide the hosting, setup, maintenance and support.

Could we run it ourselves?

Yes, and you are welcome to — the software is free. What you would take on is a server, TLS certificates, security updates, encrypted backups, monitoring, and being the person called when it breaks. That is what you are paying us for.

How long does setup take?

Usually a few days. The technical side takes under an hour; most of the time goes on deciding who receives reports, what you want to ask, and your retention policy.

What if we want to leave?

You can, with one month’s notice. We export your data and help you move it to another provider or your own server. No lock-in — it is open-source software and the data is yours.

What does it cost?

It depends on the size of your organisation and how many channels and recipients you need. Tell us roughly how many staff you have and we will send you a fixed monthly price — no per-report or per-user charges, and never any charge to the people who make reports.

Get in touch

Tell us a little about your organisation and we will come back with a price. Happy to talk it through first — no obligation.

We use your details only to reply to this enquiry. We do not share them and we do not send marketing.