Ashio whistleblowing software

Security

Ashio is built with privacy and security at its core — GDPR-compliant, encrypted at rest, and hosted in ISO 27001-certified Swiss data centers.

GDPR compliantAES-256-GCM encryption🇨🇭 Swiss hostingEU Directive 2019/1937 compliant

GDPR compliance

Data protection by design and by default. All data is processed under strict EU data protection laws.

Encryption at rest

All stored data is encrypted at rest with AES-256-GCM, and all traffic is encrypted in transit with TLS. A database breach yields only useless ciphertext.

Swiss hosting

Everything runs in ISO 27001-certified, carbon-neutral data centers in Switzerland. Your data never leaves Europe.

Zero-access architecture

Reports are encrypted with a zero-access architecture — Ashio itself cannot read them.

No tracking on report pages

Reporting pages set no cookies, run no analytics, and use no fingerprinting. Submitters stay completely anonymous.

Audit-ready logging

Every action and status change is recorded in an immutable, timestamped activity log — ready for audits and compliance reviews.