sygnadesk

Mid-sized manufacturer

Whistleblowing system for a manufacturer: corruption in procurement

The situation

A purchasing officer notices one supplier keeps winning tenders despite worse bids. She has the documents, but the person involved sits two desks away. Going to her manager is not an option.

How it works

She files the report anonymously with the files attached. The system strips the metadata that could identify her, and she continues the conversation with the case handler through a case number and PIN. The board gets the signal before the matter reaches a prosecutor or the press.

Retail chain

Reporting channel for a retail chain: bullying in one of the branches

The situation

In one store the manager has been humiliating staff for months. Everyone knows, nobody reports it, because the only route runs through that same manager. Head office finds out from the resignations.

How it works

Each branch has its own report form, and access to a case is granted only to someone outside the local hierarchy, such as HR at head office. A report never passes through the hands of the person it concerns.

Hospital

Whistleblowing system for a hospital: a warning about patient safety

The situation

A nurse sees a ward procedure being bypassed and none of the doctors reacting. Raising it directly would mean a conflict with the consultant who sets her rota.

How it works

The report goes to the people named in the procedure, bypassing the ward. The system tracks the statutory seven-day acknowledgement, so the case cannot sit in a drawer. The response comes before an event that cannot be undone.

University

Anonymous reporting at a university: irregularities in a grant

The situation

A doctoral student notices grant costs being booked against equipment nobody on the team has seen. The project lead is also the supervisor of his thesis. The field is small and everyone knows who works with whom.

How it works

Anonymity here is not a convenience but the precondition for reporting at all. Revealing an identity requires the consent of two authorised people, so nobody can look it up alone, even out of curiosity. The reporter follows the case without an account or a login.

IT company as an MSP partner

Whistleblowing for an MSP partner: channels for many clients from one panel

The situation

An IT provider serves dozens of companies, most of which have just crossed the 50-employee threshold. Each needs a channel, none wants to set one up itself, and the provider does not want responsibility for the content of other people's reports.

How it works

The partner creates client accounts in one panel, under its own brand and domain, with a discount that grows with the number of clients. It sees metadata only: case counts and deadlines. It will never see report content or reporter identities, which it can put in writing for its clients.

Public authority

Reporting channel for a public authority: a statutory duty, not a formality

The situation

A local government body must run an internal channel by law. The previous email inbox met the requirement on paper, but during an inspection nobody could show when a report had arrived or who had read it.

How it works

Every report carries a timestamp and every access to it leaves an entry in a log that cannot be altered. The system counts the seven-day and three-month deadlines itself and escalates as they approach. An inspection is shown a register, not an assurance.

Family business at the 50-employee threshold

Whistleblowing system for a small company: a first channel with no IT department

The situation

The company has crossed the headcount threshold and the owner learned of the obligation from the accountant. There is no IT department and no compliance function, and rolling out a system sounds like a quarter of work and an invoice from a law firm.

How it works

A wizard walks through the setup: logo, responsible people, the form, and procedural documents ready to adapt. The channel is live under the company's own domain the same day. The owner does not need to understand the act in detail, because the system handles the deadlines and the register.

Financial institution

Whistleblowing in a financial institution: data the vendor cannot see

The situation

A bank's compliance team judges vendors by one test: what happens if the vendor is breached, or receives a demand from a foreign authority. Whistleblower reports are the most sensitive data in the organisation.

How it works

Content and identity are encrypted with a key held on the client side, so the operator cannot read them even with full database access. Emergency access requires two parties at once: the operator and the client. Data never leaves the European Union, and every operation leaves a trace in the log.

Foundation or watchdog organisation

Reporting channel for a watchdog organisation: protecting the source's identity

The situation

The organisation takes signals from people outside its own structure: former employees of companies, residents, officials. For them, exposure means losing a job or worse. An email inbox records the sender's address, and that is already too much.

How it works

The reporting page stores no IP address, loads nothing from third parties and uses no tracking tools. The reporter returns to the case with a number and a PIN, with no account and no email. Attachments lose their metadata before anyone opens them.

Newsroom and investigative journalism

A secure channel for journalistic sources: a conversation without revealing identity

The situation

Someone with documents from inside an institution approaches a newsroom. They want to hand them over but will not identify themselves, because doing so could cost them their job, or worse. Email and messaging apps leave traces that can be recovered on demand.

How it works

The source hands over files and talks to the journalist through a case number and PIN, with no account, no address and no IP record. Content and identity are encrypted with a key held by the newsroom, so the operator has no key and nothing to hand over on demand. Source protection stops depending on a vendor's goodwill.

Transport and logistics company

Whistleblowing in a transport company: staff in the field

The situation

Drivers and warehouse staff have no company laptop and no email address, and the only computer at the depot is in the dispatcher's office. A channel that works only on the intranet does not exist for them.

How it works

A report can be made by SMS, by phone, or from a personal mobile through the page at the company's address. Case status is checked the same way, from a phone, with a code and a PIN. The channel is genuinely available to everyone, not just to the office.

Questions about whistleblowing systems

Who must have a whistleblowing system?

The Polish Act on the protection of whistleblowers of 14 June 2024 requires an internal reporting channel in entities with at least 50 employees. In some sectors, including finance, the threshold is lower and the duty does not depend on headcount. It applies to companies as well as public bodies and local government.

What are the penalties for not having a reporting channel?

The act provides for criminal liability for the absence of an internal reporting procedure and for retaliation against a whistleblower. The scale and procedure are set out in the act itself. Beyond the sanction, something else matters more: without a channel, an organisation learns of wrongdoing from the press or a regulator rather than from its own employee.

How does a whistleblowing system differ from an email inbox?

An inbox records the sender's address and tracks no deadlines. The system stores no IP address, runs the conversation through a case number and PIN, counts the statutory acknowledgement and feedback deadlines, and logs every access to a report in a record that cannot be altered. An inspection is shown a register, not an assurance.

Can the vendor read a report?

With near end-to-end encryption enabled, report content and the reporter's identity are encrypted with a key held on the client side. The operator cannot read them even with full database access. Emergency access requires two parties at once, the operator and the client, so neither can do it alone.

Can one system serve many branches or group companies?

Yes. Each branch can have its own report form, and permissions are granted per form and per case, so a report from a branch reaches the designated people and bypasses the local hierarchy. Law firms and IT providers serving many entities use the partner model: separate client accounts in a single panel.

We do not publish client names. As a rule.

The discretion we promise whistleblowers extends to the organisations that trust us. The examples above illustrate typical use and do not describe specific deployments. If an organisation chooses to talk about its channel publicly, it will do so with its own consent and under its own name.

Recognise your situation?

Let us talk about how a reporting channel would work in your organisation. No commitment, in the language of your sector.