Reporting, Data Security, and Deadlines
Complete, traceable documentation for accountability requirements and audit readiness – with hosting in ISO 27001-certified data centers in Germany, technically guaranteed anonymity, and automatic deadline monitoring.
REPORTING & EXPORT
Professional Exports for Every Need
Export individual reports as PDF, DOCX, or ZIP with all attachments – professionally formatted with initial report, communication, risk assessment, and checklists. For statistical analysis, filterable XLSX overviews are available.
- Export individual reports as PDF, DOCX, or ZIP
- All attachments included in ZIP export
- Filterable overview tables as XLSX for analysis
- Complete report exportable at any time – for self-directed retention in your own archive
- Ideal for authority requests and internal audits
DEADLINE MONITORING & GDPR
Automatic Deadline Monitoring and GDPR-Compliant Deletion
The system automatically monitors legal deadlines: 7 days for the acknowledgment of receipt and 3 months for feedback. Dashboard notifications warn in advance, and completed reports are automatically marked for deletion after a configurable period.
- 7-day and 3-month deadlines per HinSchG automatically monitored
- Dashboard early warning before approaching deadlines
- Automatic deletion scheduling after configurable period
- Final review possible before permanent deletion
DATA SECURITY
Encryption and Secure Hosting
All data transmissions are SSL/TLS encrypted. Report contents and communication are additionally stored with AES encryption in the database. Cloud and Private Cloud are hosted exclusively in ISO 27001 certified data centers of Hetzner Online GmbH in Germany (Nuremberg, Falkenstein) – running on 100% green electricity, with no transfer of personal data to third countries. Complemented by daily off-site backups.
- Continuous SSL/TLS encryption of all transmissions
- AES encryption of sensitive data in the database
- Hosting in ISO 27001 certified data centers in Germany
- Daily backups with 7-day retention and off-site storage
- Firewall, DDoS protection and network segmentation (Cloud and Private Cloud)
- Continuous monitoring of system availability
- Guaranteed availability of 99.0% per calendar month (Cloud and Private Cloud)
- Regular internal penetration tests, code reviews and security updates
- No transfer of personal data to third countries
- On-premises operation in your own infrastructure available
ACCESS CONTROL & ANONYMITY
Two-Factor Authentication and Technical Anonymity
Two-factor authentication protects the administration area from unauthorized access. At the same time, the system does not log any access data that could reveal the identity of whistleblowers – to protect whistleblowers, preeco | whistleblower deliberately goes as far as not writing system log files. The result is technically guaranteed anonymity.
- Two-factor authentication with common authenticator apps
- Setup of 2FA per user via QR code in the profile settings
- Enforced 2FA per team: administrators can mandate it for all members of a team
- Brute-force protection with staggered lockout periods after repeated failed login attempts
- Default settings at the highest level of security ("Security by Default")
- Single Sign-On (SAML2), optional for Private Cloud and On-Premises
- No storage of IP addresses or tracking mechanisms
- No system log files about whistleblowers
- Technically guaranteed anonymity for whistleblowers
Convinced? Request a Consultation Now
In a personal meeting, we will show you all security and reporting features of preeco | whistleblower.