sygnadesk
Security

Your data in safe hands, in the European Union only

A whistleblowing channel has to be tight. The system is built and tested by software engineers, and every update goes through rigorous testing and red and blue team checks. Hosting in certified EU data centres, 24/7 physical security, encryption and backups. No data leaves the European Union.

Engineering and operations

Security watched by people, not just by configuration

sygnadesk is backed by software engineers and a DevOps team. The code, the infrastructure and every change are tested and monitored, before and after they reach you.

  • Rigorous testing of every update

    Before a change ships to production it passes automated tests, end-to-end tests and code review. Nothing goes live unverified.

  • Red team and blue team checks

    We regularly attack our own system (red team) and verify the defences (blue team) to catch gaps before anyone outside does.

  • DevOps and server security

    DevOps engineers harden the servers and keep them available, patched, redundant and recoverable.

  • WAF and anti-DDoS protection

    A web application firewall (WAF) and DDoS protection filter malicious traffic before it reaches the system.

  • 24-hour monitoring

    Round-the-clock monitoring of availability and security events. We respond immediately, at any hour.

  • Confidentiality built into the architecture

    Report content and identity are encrypted client-side. Even the team running the system cannot read a report.

Roles under the GDPR

Who is the data controller

The first question any data protection officer asks. The answer is split, and it does not change with the plan you buy.

Report content and reporter identity
Your organisation remains the controller. sygnadesk acts as processor under a data processing agreement and has no sight of report content.
Account, contact details, billing
The operator is the controller, to the extent needed to run the service. The privacy policy sets out the detail and the legal bases.
Screenshot of the audit log: a table of events with date, category, description and the person who triggered it.
Every access to a report leaves a trace that cannot be deleted. This is the screen an inspection asks for.

Data centres in the European Union

Two EU locations provide performance and continuity. Reporter data is never transferred outside the European Economic Area.

Frankfurt DE · EU Warsaw PL · EU
  • Warsaw (PL)
  • Frankfurt (DE)
  • EU data only
  • Warsaw and Frankfurt

    Two data centres in the European Union. Business continuity and low latency for users in the region.

  • 24/7 physical security

    Round-the-clock surveillance, access control and facility monitoring. Only authorised people reach the servers.

  • ISO/IEC 27001 certified

    The system operator runs an information security management system compliant with ISO/IEC 27001.

  • Encryption throughout

    Encryption in transit (TLS 1.3) and at rest. Report content and reporter identity are additionally encrypted in the application layer.

  • EU data only

    Hosting, backups and processing in the European Union. No transfer outside the European Economic Area.

  • Backups and monitoring

    Regular encrypted backups, availability monitoring and a web application firewall (WAF) against attacks.

Content delivery

Close to the user, data only in the EU

The reporting page and the handling panel reach the user through a global edge network. The nearest node handles the connection, but no report content ever stays there — every request comes back to a data centre in the European Union for the data itself.

  1. The reporter, wherever they are

    An employee opens the reporting page from any country and connects to the nearest node of the network. Fonts, styles and icons already sit on that node, so they do not have to cross half of Europe.

  2. Edge node: protection, not storage

    This is where TLS 1.3 terminates and where the web application firewall and DDoS filtering work. The node stores no report content — it inspects the request and passes it on.

  3. Data centre in the EU

    Only here does the data live: Warsaw and Frankfurt, encryption at rest, backups. Nothing leaves the European Economic Area.

Only static assets are cached at the edge: fonts, icons and stylesheets. Report content and personal data — never.

Certified data centre in the European Union
Physical infrastructure

Security you do not see day to day

sygnadesk servers run in certified data centres in Warsaw and Frankfurt: round-the-clock surveillance and access control, power and cooling redundancy, fire protection and monitoring. Data never leaves the European Union.

  • 24/7 physical security
  • ISO/IEC 27001 certified
  • EU data only

System operator

The owner and operator of the sygnadesk platform is:

Jeton Cloud spółka z ograniczoną odpowiedzialnością spółka komandytowa

Certificate number: 4801270

VAT ID
5213901362
KRS
0000850403
REGON
386529721
Address
Domaniewska 37, 02-672 Warsaw, Poland

Questions about security or compliance?

We are happy to answer questions from IT, security or compliance teams, and can share documentation on request.