Reporters can now speak their report. Voice reporting is live on all plans.Learn more
Ashio whistleblowing software

EU Directive 2019/1937

How Ashio keeps you compliant.

A short, plain-language summary of the frameworks Ashio meets and how each maps to a feature in the product.

Frameworks

Six frameworks, one product.

Ashio is designed around the EU Whistleblower Directive and the local whistleblower law in your jurisdiction.

EU Directive 2019/1937

Written intake (the form), voice-to-text (oral reports), 7-day acknowledgment deadline, internal and external channels.

GDPR (EU 2016/679)

Lawful basis, data minimisation, retention limits, breach notification, data-subject access requests.

ISO 27001 hosting

Switzerland-hosted infrastructure, per-report event log, server-side AES-256-GCM encryption for sensitive fields, ISO 27001-aligned operations.

End-to-end encryption

Reporters encrypt reports in the browser with a key only they hold. Your company decrypts. We cannot read the contents.

Local whistleblower laws covered

Ashio supports the local whistleblowing statute in Germany, France, Spain, the Netherlands, Sweden, Finland, Italy, Poland, Czech Republic, Hungary, Romania, Portugal, Estonia, Latvia, and Lithuania.

Oral reports (Article 10(2)(b))

Voice-to-text intake runs entirely in the reporter's browser. Audio is transcribed locally and deleted; the server only sees the text.

Audit posture

Tamper-evident, exportable, replay-able.

Every case, every status change, every acknowledgement, every message is appended to a per-report event log.

Per-report event log

Created, viewed, assigned, status changed, acknowledged, closed — one row each, immutable, time-stamped, with the acting user.

Append-only, time-stamped

Every event is recorded with a time stamp and the acting user. Once written, events are immutable — the full case history is visible from the case detail page.

Two compliance timers per case

7 days to acknowledge, 3 months to give feedback. Admins see both in the case list from day one.

What is an audit trail and how does Ashio create one?

An audit trail is the chronological record of events on a case: created, assigned, status changed, response, closed. Ashio logs each event with a timestamp and the acting user, append-only and exportable for your auditor.

Need a specific framework letter?

Procurement, security review, or your DPA team often wants our architecture overview, our sub-processor list, or our penetration-test report. We send these within one business day.

Stay compliant by default.

Start a 14-day free trial. Compliance, audit log, end-to-end encryption, and the public intake channel are all included.