Republic of Trust
EU Whistleblower Protection Directive 2019/1937

The reporting channel your employees can actually trust.

An EU-hosted, GDPR-first whistleblowing platform. Anonymous by architecture — not by policy — and compliant out of the box. Deploy in days, not months.

Here to make a report? Use the private link your employer gave you.

If you employ 50+ people in the EU, a compliant reporting channel is the law.

The EU Whistleblower Protection Directive (2019/1937) requires a secure internal reporting channel, acknowledgement within 7 days, feedback within 3 months, strict confidentiality, and an auditable record. Legacy vendors are expensive, slow to deploy, and often US-hosted. We built the alternative.

Built for trust, from the ground up.

Anonymous by architecture

No name, no email, no account. Reporters get a case reference and password — no identity, IP, or device data is ever tied to a report. Uploaded files are stripped of hidden metadata before storage.

EU-hosted, GDPR-first

Data stays in the EU. Case content is encrypted at the field level with keys we control, and strict tenant isolation is enforced in the database itself — not just the app.

Compliance built in

The 7-day acknowledgement and 3-month feedback deadlines are tracked per case and per jurisdiction, with alerts before they're breached. Every action is written to an immutable audit log.

Deploy in days

A four-step setup gives your organization a live, branded reporting link. Invite your case handlers, set retention, launch. No lengthy integration project.

How it works

01

A reporter speaks up — anonymously

They open your reporting link, describe the concern, and receive a case reference and password. No identity is ever collected.

02

Your team handles the case

Case handlers triage, message the reporter two-way, and resolve — all inside a secure, role-based dashboard with mandatory 2FA.

03

Compliance takes care of itself

Deadlines are tracked and alerted automatically, retention runs on schedule, and the full audit trail is export-ready for regulators.

Trust is the product.

Confidentiality enforced architecturally — two independent isolation layers, field-level encryption, append-only audit.
EU data residency; we publish our subprocessor chain and are moving it fully EU-owned.
Accessible (WCAG 2.1 AA) and multilingual reporter intake — because the people who need it most must be able to use it.
Standalone product under Samarkand Industries OÜ. No shared database or branding with any other product.

See it for yourself.

Book a 20-minute demo. We'll walk through the reporter flow, the handler dashboard, and the compliance model.

Republic of Trust — EU-native whistleblowing & compliance