Immutable activity log
Every action — report creation, status change, comment added, file uploaded — is timestamped in a tamper-proof log. Auditors see who did what when, with no way to alter the records after the fact.

Ashio is built with privacy and security at its core — end-to-end encrypted in the browser, hosted in ISO 27001-certified Swiss data centers, and GDPR-compliant by design.
Data protection by design and by default. All data is processed under strict EU data protection laws.
Reports and messages are encrypted in the reporter's browser with a per-report AES-256-GCM key that's wrapped for each recipient using P-256 ECDH. The server only stores ciphertext — it cannot decrypt your reports.
Everything runs in ISO 27001-certified, carbon-neutral data centers in Switzerland. Your data never leaves Europe.
Built on a true zero-access architecture — even Ashio cannot read report bodies or messages. Keys live in the reporter's URL and on each handler's device, protected by an Argon2id-derived password key.
Reporting pages set no cookies, run no analytics, and use no fingerprinting.
Every action and status change is recorded in an immutable, timestamped activity log — ready for audits and compliance reviews.
For auditors
Ashio gives you complete, tamper-proof documentation from day one — ready for ISO 37002 audits, GDPR reviews, regulatory inspections and internal compliance reviews. Every action is automatically timestamped — no manual work, no spreadsheets, no missing evidence.
Every action — report creation, status change, comment added, file uploaded — is timestamped in a tamper-proof log. Auditors see who did what when, with no way to alter the records after the fact.
From report intake to closure, Ashio documents every step with the responsible person, timestamp and reasoning. During an audit you can reconstruct the entire incident lifecycle in seconds.
The EU Directive and national whistleblower laws require acknowledgment within 7 days and feedback within 3 months. Ashio documents both deadlines automatically — if your auditor asks whether the deadlines were met, the evidence is already there.
All reports, activities and audit trails can be exported as PDF and CSV — ideal for external auditors, regulators or internal compliance teams. No vendor lock-in, no proprietary formats.