A compliant whistleblower channel, without law-firm prices
With 50+ employees, an internal whistleblower channel is required by EU law. Law firms charge thousands a year for a form and an inbox. Verkta does the same (compliant, secure and in 25 languages) at a fraction of the price.
No credit card required. Set up in 5 minutes.
Whistleblower channel (50+ employees)
An anonymous portal in your name
Employees report via a secure page in 25 EU languages, fully anonymous, with encrypted attachments.
Deadlines handle themselves
Acknowledgement within 7 days and feedback within 3 months are legal requirements. Verkta counts down and documents that they were met.
Only designated officers see cases
Access is limited to your whistleblower officers, and every case action is logged in a tamper-evident audit trail.
Policy and awareness included
A ready-made whistleblower policy generated with your name and legal references, plus texts for your intranet.
โAn anonymous portal in your name
Employees report via a secure page in 25 EU languages, fully anonymous, with encrypted attachments.
โOnly designated officers see cases
Access is limited to your whistleblower officers, and every case action is logged in a tamper-evident audit trail.
Every feature, in detail
Full transparency about what the channel does and how it protects the reporter. Every line here corresponds to something the system actually does, not something we plan to do.
For the reporter
- 100% anonymous reporting
Name and contact details are optional. The portal requires no login, no email and no app.
- Case number + personal access key
The reporter receives a case number and a random access key and can follow the case and reply, without ever revealing who they are.
- Secure two-way dialogue
Officers can ask clarifying questions and the reporter can answer, still anonymously.
- Encrypted file attachments
Images and documents can be attached and are stored in private EU object storage with no public URLs.
- 25 EU languages
The reporter picks their own language on the portal, independent of the company's language.
- No IP logging
Neither IP address nor browser data is stored on the report. The spam guard's ephemeral counter uses hashed IPs only.
- No traces in the browser
The portal is served with no-store cache headers, no-referrer, and is excluded from search engines, safe even from a shared computer.
- Receipt with deadlines
The reporter immediately sees when the acknowledgement (7 days) and feedback (3 months) are due.
For whistleblowing officers
- Strict access separation
Only designated officers can see cases. Administrators, colleagues and external advisors never can, regardless of their permissions elsewhere in the system.
- Automatic deadline monitoring
The 7-day acknowledgement and 3-month feedback deadlines are monitored automatically with reminders before they are breached.
- Case management with statuses
Received, in progress, closed, with a full history of every step.
- Complete audit log
All case handling is logged with timestamp and responsible person, the documentation that proves the scheme is run correctly.
- Notifications without case content
Officers are notified of new reports by email, but the email never contains the case content.
- Anonymised annual report
Print-ready annual report with case statistics and no personally identifiable information, ready for the board or an inspection.
- Optional portal access code
The portal can be locked with a shared access code, e.g. if the link should only circulate internally.
- Your name on the portal
The portal runs on your own address (verkta.com/w/your-name) with your company name, and the address can be changed at any time.
Legal & compliance
- Built for EU Directive 2019/1937
The deadlines, anonymity and access control follow the Whistleblowing Directive's requirements, and the national laws implementing it.
- Law overview for all 28 countries
The law pages cover the national whistleblowing act, thresholds and external authorities across the EU + Norway.
- Whistleblowing policy included
A ready-made policy template for the staff handbook, ready for your adjustments.
- GDPR as data processor
A data processing agreement under art. 28 is part of the terms. All data is hosted in the EU (Frankfurt), and you can export everything yourself.
- Inspection-ready documentation
Audit log, annual report and deadline history together form the evidence that the scheme is followed in practice.
Security & operations
- Encryption throughout
All traffic is TLS-encrypted, and data at rest is encrypted in EU data centres in Frankfurt.
- Hashed keys and tokens
Access keys are stored only as SHA-256 hashes, unreadable even with database access.
- Private file storage
Attachments live in private object storage with no public URLs. Access requires an authorised lookup.
- Spam protection without surveillance
Rate limiting and honeypots protect the form, with hashed IPs and no permanent logging.
- Organisational separation
Every query in the system is bound to your organisation, data cannot cross between customers.
- Certified infrastructure
Verkta runs on ISO 27001 and SOC 2 certified infrastructure (Vercel, Neon). Verkta itself is not yet certified, we say so honestly until that changes.
Compliant today, literally
Create the account, activate the portal, share the link. The channel is in place and the deadlines take care of themselves.