Security and privacy

Privacy is the foundation, not a feature.

SpeakHarbour handles sensitive information. These are the protections currently built into the platform and the remaining controls planned before wider production use.

Encryption

Data is encrypted in transit and at rest by the hosting and database infrastructure.

Anonymous report data minimisation

SpeakHarbour's application database does not add IP addresses or device identifiers to anonymous case records.

No advertising trackers

The employee reporting page does not use advertising trackers or third-party advertising analytics.

Role-based access

Database rules isolate organisations. Investigators see assigned cases, and conflicted users can be excluded.

Secure sign-in

Organisation users authenticate using managed password or supported single sign-on flows.

Protected audit records

Important case changes are recorded and cannot be edited by organisation users.

Public endpoint abuse protection

Report submission and reporter portal actions are protected by server-side limits. Only keyed one-way request fingerprints are retained for short-lived rate-limit windows.

Logo metadata removal

Organisation logos are re-encoded in the browser before upload and restricted to validated image formats and sizes.

Private evidence handling

Evidence is held in private storage. Images are decoded and re-encoded on the server to remove source metadata; files are checked for type, signature, size and integrity before release.

Enforced two-step verification

Organisation data is protected by database rules requiring a verified second factor. Privileged sessions sign out after 30 minutes of inactivity.

Content-free email notifications

Case and reporter notification emails contain no report narrative, reporter identity, evidence, access keys or sensitive investigation details. Anonymous reporters are never emailed.

Retention and privacy controls

Owners can configure closed-case retention, apply legal holds, export organisation data and use staged anonymisation and deletion controls.

Remaining launch configuration and planned controls

  • A production malware-scanning provider must be configured before PDF evidence uploads are enabled; PDFs fail closed until then
  • Policy library uploads, scheduled deadline and digest emails, and automated escalation rules
  • Optional domain-bound bot challenge after the final production domain is selected

SpeakHarbour does not currently hold ISO 27001, SOC 2 or Cyber Essentials certification. Using SpeakHarbour does not determine whether someone is legally protected as a whistleblower; organisations should take their own legal advice.