Skip to content
Product ยท Security

Built for the most sensitive data you hold

A whistleblowing report can name colleagues, allege crimes and end careers, in both directions. Security here isn’t a feature list; it’s the product.

Where your data lives

Every company’s channel runs in its own isolated environment: no shared database, no cross-tenant queries, no way for one customer’s incident to touch another’s data. Hosting is within the EU, and data handling is GDPR-first: report data is processed for case handling and nothing else.

Who can read a report

Only the case handlers you name. They activate their own account through an activation email; there are no shared logins and no side doors. Belfort staff do not read your reports unless you engage Belfort as your external report recipient, in which case that role is explicit and contractual.

Confidentiality & anonymity

Reporter identity is protected end to end. If your channel accepts anonymous reports, anonymity is structural: the two-way dialogue works through the reporter’s secure link, and case handlers never see identifying data the reporter didn’t type in themselves.

Retention

Because a channel cannot be deleted from the platform once created, retention and access terms are agreed explicitly in your contract at signup, before anything is provisioned rather than after.

Security questions from your DPO?

Send them over. You get written answers you can file with your DPIA.