Ashio whistleblowing software

Security

Ashio is built with privacy and security at its core — end-to-end encrypted in the browser, hosted in ISO 27001-certified Swiss data centers, and GDPR-compliant by design.

GDPR compliance

Data protection by design and by default. All data is processed under strict EU data protection laws.

End-to-end encryption

Reports and messages are encrypted in the reporter's browser with a per-report AES-256-GCM key that's wrapped for each recipient using P-256 ECDH. The server only stores ciphertext — it cannot decrypt your reports.

Swiss hosting

Everything runs in ISO 27001-certified, carbon-neutral data centers in Switzerland. Your data never leaves Europe.

Zero-access architecture

Built on a true zero-access architecture — even Ashio cannot read report bodies or messages. Keys live in the reporter's URL and on each handler's device, protected by an Argon2id-derived password key.

No tracking on report pages

Reporting pages set no cookies, run no analytics, and use no fingerprinting.

Audit-ready logging

Every action and status change is recorded in an immutable, timestamped activity log — ready for audits and compliance reviews.

For auditors

Audit-ready documentation for compliance audits.

Ashio gives you complete, tamper-proof documentation from day one — ready for ISO 37002 audits, GDPR reviews, regulatory inspections and internal compliance reviews. Every action is automatically timestamped — no manual work, no spreadsheets, no missing evidence.

Immutable activity log

Every action — report creation, status change, comment added, file uploaded — is timestamped in a tamper-proof log. Auditors see who did what when, with no way to alter the records after the fact.

Complete case lifecycle

From report intake to closure, Ashio documents every step with the responsible person, timestamp and reasoning. During an audit you can reconstruct the entire incident lifecycle in seconds.

Automatic 7-day and 3-month tracking

The EU Directive and national whistleblower laws require acknowledgment within 7 days and feedback within 3 months. Ashio documents both deadlines automatically — if your auditor asks whether the deadlines were met, the evidence is already there.

Standard format exports

All reports, activities and audit trails can be exported as PDF and CSV — ideal for external auditors, regulators or internal compliance teams. No vendor lock-in, no proprietary formats.