Everything compliance requires. In one tool.
From an anonymous report, through statutory deadline tracking, to a full audit trail and export for inspections. Built around whistleblower privacy and the obligations of organisations.
Confidentiality and identity protection
- How end-to-end mode is described in the data processing agreement
-
Identity reveal only with a second person's approval
Revealing a reporter's identity is a request that a second authorised person must approve. No one lifts anonymity single-handedly.
-
Four-eyes principle
Weakening the protection (turning the rule off) requires a second person's confirmation. Critical decisions are never made by one person.
-
Encryption close to E2E
Content and identity encrypted with a client-side key. Operator and partner cannot read the report. Emergency access (break-glass) needs two parties: operator and client.
-
Reporter anonymity
Report without an account or login, a case number and PIN, encrypted chat. No IP stored, no tracking, no external resources.
-
Immutable audit log
Every access to a report and every action recorded in a log that cannot be altered. Hard evidence for inspections.
-
Metadata stripped from attachments
Files automatically lose metadata (EXIF, author) that could expose the reporter.
Case handling and workflow
-
Case lifecycle
Statuses, priorities, categories, labels, notes and history. All visible to the handling team only.
-
Auto-assignment
New reports reach the right people by rules, without manual routing.
-
Statutory deadlines, automatically
Acknowledgement within 7 days and feedback within 3 months tracked by the system. Escalations and no closing without a reply.
-
Notification engine
Email and SMS from the client domain, real-time in-panel notifications, per-role rules, deadline alerts.
-
Reply templates
Predefined messages and automatic acknowledgements speed up handling and keep it consistent.
-
Case PDF and reports
Export a report to PDF (with anonymisation, password-protected) plus statistical reports by status, category and timeliness.
Compliance, permissions and data
-
Authorisations repository
Issue data processing authorisations with confirmation of receipt by the employee. GDPR accountability.
-
Granular permissions (RBAC)
Roles and permissions per form and per case. Access for authorised people only.
-
Retention with controlled deletion
3-year retention; deletion is manual and confirmed (deleting a report is irreversible), with a log entry.
-
Versioned consents and terms
Informed statements and acceptances are versioned and recorded in an immutable log.
-
Data export and migration
Full tenant export (JSON/CSV + attachments) for migration or audit, with identity masking and password protection.
-
EU data only
Hosting, encryption and backups in the European Union. No transfer outside the European Economic Area.
Onboarding, channels and integrations
-
Onboarding wizard
Logo, colours, domain, people and form in a few steps. No technical knowledge and no IT department.
-
No-code form builder
Custom fields, sections and form variants, with duplication. A form tailored to your organisation.
-
White-label and your own domain
The channel under your brand and address. It looks like part of your company, not a foreign tool.
-
Channels: online, email, SMS
The reporter picks the form that is safe for them. A shared intake address without exposing content.
-
WCAG 2.1 AA accessibility
Contrast, keyboard navigation, ARIA, text size control. The channel is accessible to everyone.
-
Google and Microsoft 365 sign-in
Convenient SSO for the handling team, alongside mandatory 2FA, brute-force protection and a password policy.
-
Integrations: webhooks and API
Notifications to Slack, Teams, Power BI and your own systems. Metadata only, never report content, with HMAC signing.
This is what working in sygnadesk looks like
A few snippets from the case-handling panel: a clear dashboard, a case list with metadata (no report content) and a no-code form builder.
For the whole compliance team
One tool that answers the needs of different roles across the organisation.
-
Data Protection Officer (DPO)
GDPR compliance: data minimisation, a data processing agreement (DPA), 3-year retention, EU data. Accountability in an immutable log.
-
Compliance director and manager
The whole legal obligation in one place. The 7-day and 3-month deadlines tracked automatically, full register and audit.
-
Board and CEO
Reduced legal and reputational risk without involving IT. Launch in minutes, predictable cost, calm during inspections.
-
HR director
A safe channel for employee, harassment and ethics cases. Anonymity, reply templates, per-case permissions.
-
Legal counsel and legal team
Compliance with the act and the directive, ready procedures, control over identity disclosure (four-eyes principle).
-
Internal audit and risk
An immutable log, statistics and export for proceedings. Hard proof the system works.
For every regulated industry
- Healthcare and hospitals
- Industry and manufacturing
- Public sector and local government
- Finance, banking and insurance
- Education and universities
- Retail and store chains
- Transport and logistics
- Energy and utilities
- IT and professional services
Compliance and privacy at the core
We protect reporters' data at every stage: from the form, through transmission, to storage and deletion.
-
Legal basis
The Act of 14 June 2024 and EU Directive 2019/1937. Categories cover breaches of law and ethical standards.
-
Reporter privacy
No IP or location stored, no external resources, strict CSP, self-hosted fonts. Anonymity and confidentiality of identity.
-
Data protection
Data in the EU only, encryption in transit and at rest, 3-year retention with automatic deletion, a DPA.
Ready to see it in action?
A 14-day trial with full access. No technical knowledge needed.