Loading…
Since EU Directive 2019/1937 and France’s Sapin 2 law, every employer above 50 staff must operate an internal reporting channel, guarantee anonymity, acknowledge within 7 days, and give feedback to the whistleblower within 3 months. Illizeo Whistleblowing covers the whole chain — anonymous filing, cryptographic tracking, investigation workflow, retaliation protection, signed audit trail.
Sapin 2 · EU Directive 2019/1937 · GDPR · nFADP · 9 report categories · 190-bit tracking secret · Recused referents · Implicated excluded · Multi-channel · Bilingual EN/FR · Encrypted attachments
Without a dedicated tool, reports come through in person, personal emails or shared inboxes. The implicated person can read the complaint about themselves. The legal feedback deadline slips. Faced with an inspection or lawsuit, the company cannot produce anything.
A personal email reveals the identity to the first recipient. The reporter can’t follow their case without exposing themselves. Fear of retaliation blocks real information flow.
EU Directive 2019/1937 mandates a 7-day acknowledgment and 3-month feedback. Without a tracking tool, these deadlines slip unnoticed. Potential sanction for the supervisor.
The implicated person reads the accusation against them. The referent with a conflict of interest stays on the case. No partitioning, no recusal, no audit trail — the law is not respected.
Public anonymous reporting portal, 190-bit cryptographic tracking secret, investigation workflow with referent recusal and implicated party exclusion, signed audit trail, automated legal deadlines. Everything the law requires, coded into the module.
The 9 categories cover the Sapin 2 scope (crimes, offences, threat or serious harm to the general interest) and EU Directive 2019/1937 (European law).
Moral, sexual, or any degrading behaviour experienced at work.
Based on origin, gender, orientation, age, disability, religion, opinion.
Misappropriation, accounting falsification, forgery, embezzlement.
Bribery, influence peddling, illegal taking of interests — Sapin 2 core.
Workplace safety, hazardous product, health risk, environment.
GDPR, personal data leak, undisclosed cyberattack.
Illegal taking of interests, undisclosed family ties, dual mandates.
Any breach of law not covered by the other categories.
Free-text field with open comment for uncategorisable cases.
Every status change is cryptographically signed (SHA-256 chained), named, timestamped. No action can be erased or altered after the fact.
4 configurable priorities: low · medium · high · critical. Auto-escalation if EU 2019/1937 deadlines are missed (7 days acknowledgment, 90 days feedback).
A clear legal framework — Sapin 2 and EU Directive 2019/1937 — translated into code, workflow and automated deadlines.
Cryptographic anonymity: a 32-character secret (~190 bits) issued once. No cookie, no session, no IP log on the public portal.
The implicated party never accesses their own case — checked at model level on every request. A referent with a conflict of interest can be recused, with controlled reassignment.
Automatic acknowledgment within 7 days. Feedback to the reporter guaranteed by workflow within 3 months. Chained signed audit trail for any inspection.
A real-life scenario: anonymous filing via the public portal, cryptographic secret issued, referent assigned, implicated party excluded, two-way exchanges, closing within legal deadlines.
Sophie has suffered moral harassment from her manager for 4 months. She does not want to be identified. Illizeo’s public portal issues her a secret. The HR referent opens the investigation. The implicated manager is excluded from the case. Sophie exchanges via secure messaging. Decision made on D+38, feedback on D+42.
Protection lives in the module’s code, not in the docs. Every guarantee is verifiable, testable, auditable.
A 32-character base62 secret (~190 bits of entropy) is issued to the reporter at the end of filing. It is stored only as a hash (SHA-256). The reporter can follow their case without ever providing identity — even under judicial order, no one can trace them back from the hash.
The person accused is registered in the implicated_employee_ids field. On every access attempt to the case, the module verifies: if the user is in this list, access is refused, with no notification, no visible trace on the frontend. Neither reading, writing, nor statistics.
An HR referent cannot handle a case where they have a personal interest (family, hierarchical, close friendship). They can be recused — registered in recused_employee_ids — and the case is reassigned to another referent in the channel, with no loss of traceability.
Every action (filing, opening, status change, message, exclusion, recusal, closing) is cryptographically signed (SHA-256 chained). Any retrospective modification breaks the whole chain. Signed PDF/JSON export available for inspection or litigation.
Each legal requirement is translated into a business rule coded into the module, with automatic deadlines and non-compliance alerts.
Law no. 2016-1691 of 9 December 2016. Mandatory reporting channel for companies with 50+ staff, protection of the whistleblower, scope: crimes, offences, harm to the general interest.
European Directive of 23 Oct. 2019, transposed in France by the Waserman law of 21 March 2022. Acknowledgment within 7 days, feedback within 3 months, ban on retaliation.
GDPR Article 30 (record of processing), Article 32 (security). Swiss nFADP since 2023. Automatic anonymisation after legal retention. Right to erasure honoured at the end of retention.
AI helps qualify, prioritise, summarise. No decision is automated — every conclusion remains human.
Every new filing is summarised in 3 lines: likely category, urgency, key factual elements.
Content analysis to propose a priority (low, medium, high, critical). The referent validates.
Across the 9 legal categories, AI suggests the best fit. Ambiguous cases flagged.
Suggested replies to the reporter based on stage: acknowledgment, questions, decision, closing.
7 days for acknowledgment, 90 days for feedback: automatic reminders 3 days before deadline.
Cross-check with HR records: performance drop, role change, post-report sanction.
Aggregated statistics (count by category, average delays) — never nominative, never re-identifiable.
Pre-filled compliance report for the French Defender of Rights or national supervisory authority.
A compliant channel avoids sanctions (up to €30,000 for the executive, €150,000 for the legal entity in France) and reassures employees.
Included in Enterprise plans. Add-on billed at entity level (not per employee) for other plans.
Bilingual public portal + anonymous tracking + full investigation workflow + signed audit trail + pre-filled compliance reports.
Sapin 2 and EU Directive 2019/1937 translated into code, workflow and automated deadlines. Activate the Whistleblowing module today.
Contact Illizeo