sygnadesk
Features

Everything compliance requires. In one tool.

From an anonymous report, through statutory deadline tracking, to a full audit trail and export for inspections. Built around whistleblower privacy and the obligations of organisations.

Confidentiality and identity protection

  • Identity reveal only with a second person's approval

    Revealing a reporter's identity is a request that a second authorised person must approve. No one lifts anonymity single-handedly.

  • Four-eyes principle

    Weakening the protection (turning the rule off) requires a second person's confirmation. Critical decisions are never made by one person.

  • Encryption close to E2E

    Content and identity encrypted with a client-side key. Operator and partner cannot read the report. Emergency access (break-glass) needs two parties: operator and client.

  • Reporter anonymity

    Report without an account or login, a case number and PIN, encrypted chat. No IP stored, no tracking, no external resources.

  • Immutable audit log

    Every access to a report and every action recorded in a log that cannot be altered. Hard evidence for inspections.

  • Metadata stripped from attachments

    Files automatically lose metadata (EXIF, author) that could expose the reporter.

Case handling and workflow

  • Case lifecycle

    Statuses, priorities, categories, labels, notes and history. All visible to the handling team only.

  • Auto-assignment

    New reports reach the right people by rules, without manual routing.

  • Statutory deadlines, automatically

    Acknowledgement within 7 days and feedback within 3 months tracked by the system. Escalations and no closing without a reply.

  • Notification engine

    Email and SMS from the client domain, real-time in-panel notifications, per-role rules, deadline alerts.

  • Reply templates

    Predefined messages and automatic acknowledgements speed up handling and keep it consistent.

  • Case PDF and reports

    Export a report to PDF (with anonymisation, password-protected) plus statistical reports by status, category and timeliness.

Compliance, permissions and data

  • Authorisations repository

    Issue data processing authorisations with confirmation of receipt by the employee. GDPR accountability.

  • Granular permissions (RBAC)

    Roles and permissions per form and per case. Access for authorised people only.

  • Retention with controlled deletion

    3-year retention; deletion is manual and confirmed (deleting a report is irreversible), with a log entry.

  • Versioned consents and terms

    Informed statements and acceptances are versioned and recorded in an immutable log.

  • Data export and migration

    Full tenant export (JSON/CSV + attachments) for migration or audit, with identity masking and password protection.

  • EU data only

    Hosting, encryption and backups in the European Union. No transfer outside the European Economic Area.

Onboarding, channels and integrations

  • Onboarding wizard

    Logo, colours, domain, people and form in a few steps. No technical knowledge and no IT department.

  • No-code form builder

    Custom fields, sections and form variants, with duplication. A form tailored to your organisation.

  • White-label and your own domain

    The channel under your brand and address. It looks like part of your company, not a foreign tool.

  • Channels: online, email, SMS

    The reporter picks the form that is safe for them. A shared intake address without exposing content.

  • WCAG 2.1 AA accessibility

    Contrast, keyboard navigation, ARIA, text size control. The channel is accessible to everyone.

  • Google and Microsoft 365 sign-in

    Convenient SSO for the handling team, alongside mandatory 2FA, brute-force protection and a password policy.

  • Integrations: webhooks and API

    Notifications to Slack, Teams, Power BI and your own systems. Metadata only, never report content, with HMAC signing.

See the product

This is what working in sygnadesk looks like

A few snippets from the case-handling panel: a clear dashboard, a case list with metadata (no report content) and a no-code form builder.

Report list with metadata: status, priority, category and deadline. Only authorised staff see the content.
Report list with metadata: status, priority, category and deadline. Only authorised staff see the content.
No-code report form builder: arrange fields, sections and translations yourself.
No-code report form builder: arrange fields, sections and translations yourself.

For the whole compliance team

One tool that answers the needs of different roles across the organisation.

  • Data Protection Officer (DPO)

    GDPR compliance: data minimisation, a data processing agreement (DPA), 3-year retention, EU data. Accountability in an immutable log.

  • Compliance director and manager

    The whole legal obligation in one place. The 7-day and 3-month deadlines tracked automatically, full register and audit.

  • Board and CEO

    Reduced legal and reputational risk without involving IT. Launch in minutes, predictable cost, calm during inspections.

  • HR director

    A safe channel for employee, harassment and ethics cases. Anonymity, reply templates, per-case permissions.

  • Legal counsel and legal team

    Compliance with the act and the directive, ready procedures, control over identity disclosure (four-eyes principle).

  • Internal audit and risk

    An immutable log, statistics and export for proceedings. Hard proof the system works.

For every regulated industry

  • Healthcare and hospitals
  • Industry and manufacturing
  • Public sector and local government
  • Finance, banking and insurance
  • Education and universities
  • Retail and store chains
  • Transport and logistics
  • Energy and utilities
  • IT and professional services

Compliance and privacy at the core

We protect reporters' data at every stage: from the form, through transmission, to storage and deletion.

  • Legal basis

    The Act of 14 June 2024 and EU Directive 2019/1937. Categories cover breaches of law and ethical standards.

  • Reporter privacy

    No IP or location stored, no external resources, strict CSP, self-hosted fonts. Anonymity and confidentiality of identity.

  • Data protection

    Data in the EU only, encryption in transit and at rest, 3-year retention with automatic deletion, a DPA.

Security

Ready to see it in action?

A 14-day trial with full access. No technical knowledge needed.