Your data in safe hands, in the European Union only
A whistleblowing channel has to be tight. The system is built and tested by software engineers, and every update goes through rigorous testing and red and blue team checks. Hosting in certified EU data centres, 24/7 physical security, encryption and backups. No data leaves the European Union.
Security watched by people, not just by configuration
sygnadesk is backed by software engineers and a DevOps team. The code, the infrastructure and every change are tested and monitored, before and after they reach you.
-
Rigorous testing of every update
Before a change ships to production it passes automated tests, end-to-end tests and code review. Nothing goes live unverified.
-
Red team and blue team checks
We regularly attack our own system (red team) and verify the defences (blue team) to catch gaps before anyone outside does.
-
DevOps and server security
DevOps engineers harden the servers and keep them available, patched, redundant and recoverable.
-
WAF and anti-DDoS protection
A web application firewall (WAF) and DDoS protection filter malicious traffic before it reaches the system.
-
24-hour monitoring
Round-the-clock monitoring of availability and security events. We respond immediately, at any hour.
-
Confidentiality built into the architecture
Report content and identity are encrypted client-side. Even the team running the system cannot read a report.
Who is the data controller
The first question any data protection officer asks. The answer is split, and it does not change with the plan you buy.
- Report content and reporter identity
- Your organisation remains the controller. sygnadesk acts as processor under a data processing agreement and has no sight of report content.
- Account, contact details, billing
- The operator is the controller, to the extent needed to run the service. The privacy policy sets out the detail and the legal bases.
Data processing agreement, full text List of sub-processors, who we share processing with
Data centres in the European Union
Two EU locations provide performance and continuity. Reporter data is never transferred outside the European Economic Area.
- Warsaw (PL)
- Frankfurt (DE)
- EU data only
-
Warsaw and Frankfurt
Two data centres in the European Union. Business continuity and low latency for users in the region.
-
24/7 physical security
Round-the-clock surveillance, access control and facility monitoring. Only authorised people reach the servers.
-
ISO/IEC 27001 certified
The system operator runs an information security management system compliant with ISO/IEC 27001.
-
Encryption throughout
Encryption in transit (TLS 1.3) and at rest. Report content and reporter identity are additionally encrypted in the application layer.
-
EU data only
Hosting, backups and processing in the European Union. No transfer outside the European Economic Area.
-
Backups and monitoring
Regular encrypted backups, availability monitoring and a web application firewall (WAF) against attacks.
Close to the user, data only in the EU
The reporting page and the handling panel reach the user through a global edge network. The nearest node handles the connection, but no report content ever stays there — every request comes back to a data centre in the European Union for the data itself.
-
The reporter, wherever they are
An employee opens the reporting page from any country and connects to the nearest node of the network. Fonts, styles and icons already sit on that node, so they do not have to cross half of Europe.
-
Edge node: protection, not storage
This is where TLS 1.3 terminates and where the web application firewall and DDoS filtering work. The node stores no report content — it inspects the request and passes it on.
-
Data centre in the EU
Only here does the data live: Warsaw and Frankfurt, encryption at rest, backups. Nothing leaves the European Economic Area.
Only static assets are cached at the edge: fonts, icons and stylesheets. Report content and personal data — never.

Security you do not see day to day
sygnadesk servers run in certified data centres in Warsaw and Frankfurt: round-the-clock surveillance and access control, power and cooling redundancy, fire protection and monitoring. Data never leaves the European Union.
- 24/7 physical security
- ISO/IEC 27001 certified
- EU data only
System operator
The owner and operator of the sygnadesk platform is:
Jeton Cloud spółka z ograniczoną odpowiedzialnością spółka komandytowa
Certificate number: 4801270
- VAT ID
- 5213901362
- KRS
- 0000850403
- REGON
- 386529721
- Address
- Domaniewska 37, 02-672 Warsaw, Poland
- Phone
- +48 22 378 48 62
- Contact
- hello@sygnadesk.com
Questions about security or compliance?
We are happy to answer questions from IT, security or compliance teams, and can share documentation on request.