Illizeo — Header EN (preview mega-menus)

Loading…

Whistleblowing — Illizeo Module · EU Directive 2019/1937 · Sapin 2 compliant reporting channel
WHISTLEBLOWING — REPORTING CHANNEL · EU DIRECTIVE 2019/1937 · SAPIN 2

A safe channel to report. A legal framework to follow through.

Since EU Directive 2019/1937 and France’s Sapin 2 law, every employer above 50 staff must operate an internal reporting channel, guarantee anonymity, acknowledge within 7 days, and give feedback to the whistleblower within 3 months. Illizeo Whistleblowing covers the whole chain — anonymous filing, cryptographic tracking, investigation workflow, retaliation protection, signed audit trail.

Cryptographic anonymity Acknowledgment in 7 days (auto) Feedback in 3 months Signed audit trail

Sapin 2 · EU Directive 2019/1937 · GDPR · nFADP · 9 report categories · 190-bit tracking secret · Recused referents · Implicated excluded · Multi-channel · Bilingual EN/FR · Encrypted attachments

Case lifecycleWB-2026-047
New3
Open12
Pending7
Resolved4
Closed31
Anonymous reportD+3
Harassment — Marketing Dept.
ReporterAnonymous
AcknowledgmentSent D+2
Feedback deadlineD+90 (EU)
Alert: implicated party
Marc D. excluded from case
→ Zero access. Zero notification. Zero trace.
Signed audit trail
147 actions · SHA-256 chained · eIDAS-compatible

A report ends up in a mailbox. The reporter never hears back. The company has no proof.

Without a dedicated tool, reports come through in person, personal emails or shared inboxes. The implicated person can read the complaint about themselves. The legal feedback deadline slips. Faced with an inspection or lawsuit, the company cannot produce anything.

No anonymity

A personal email reveals the identity to the first recipient. The reporter can’t follow their case without exposing themselves. Fear of retaliation blocks real information flow.

No deadline met

EU Directive 2019/1937 mandates a 7-day acknowledgment and 3-month feedback. Without a tracking tool, these deadlines slip unnoticed. Potential sanction for the supervisor.

No protection

The implicated person reads the accusation against them. The referent with a conflict of interest stays on the case. No partitioning, no recusal, no audit trail — the law is not respected.

THE ILLIZEO SOLUTION

A module engineered for Sapin 2 and EU Directive 2019/1937 compliance.

Public anonymous reporting portal, 190-bit cryptographic tracking secret, investigation workflow with referent recusal and implicated party exclusion, signed audit trail, automated legal deadlines. Everything the law requires, coded into the module.

  • Public anonymous reporting portal (no cookie, no session)
  • 32-character tracking secret (~190 bits) issued once, hashed with SHA-256
  • 9 categories covering harassment, discrimination, fraud, corruption, safety, GDPR…
  • Multi-channel: one channel per entity, department or risk, with dedicated referents
  • Full lifecycle: new → open → pending → resolved → closed → archived
  • Automatic exclusion of implicated parties (never any access to their own case)
  • Recusal of referents with conflict of interest, with controlled reassignment
  • Secure two-way messaging with the reporter throughout the case
  • SHA-256 chained audit trail on every action (filing, opening, mutation, closing)
7d
automatic acknowledgment (EU 2019/1937)

90d
feedback to reporter guaranteed by workflow

0
access by the implicated party to their own case
9 REPORT CATEGORIES

Every alert the law asks you to process.

The 9 categories cover the Sapin 2 scope (crimes, offences, threat or serious harm to the general interest) and EU Directive 2019/1937 (European law).

Harassment

Moral, sexual, or any degrading behaviour experienced at work.

Discrimination

Based on origin, gender, orientation, age, disability, religion, opinion.

Fraud

Misappropriation, accounting falsification, forgery, embezzlement.

Corruption

Bribery, influence peddling, illegal taking of interests — Sapin 2 core.

Safety

Workplace safety, hazardous product, health risk, environment.

Data breach

GDPR, personal data leak, undisclosed cyberattack.

Conflict of interest

Illegal taking of interests, undisclosed family ties, dual mandates.

Illegal activity

Any breach of law not covered by the other categories.

Other

Free-text field with open comment for uncategorisable cases.

CASE LIFECYCLE

6 statuses. A chained audit trail at every transition.

Every status change is cryptographically signed (SHA-256 chained), named, timestamped. No action can be erased or altered after the fact.

1
New
Anonymous filing
Auto ack in 7d
2
Open
Referent assigned
Investigation starts
3
Pending
Investigation
Reporter messaging
4
Resolved
Decision made
Measures notified
5
Closed
Reporter feedback
≤ 90 days (EU)
6
Archived
Anonymisation
Legal retention

4 configurable priorities: low · medium · high · critical. Auto-escalation if EU 2019/1937 deadlines are missed (7 days acknowledgment, 90 days feedback).

TRACK. INVESTIGATE. CLOSE.

3 pillars to meet the legal framework.

A clear legal framework — Sapin 2 and EU Directive 2019/1937 — translated into code, workflow and automated deadlines.

1. Protect the reporter

Cryptographic anonymity: a 32-character secret (~190 bits) issued once. No cookie, no session, no IP log on the public portal.

  • Non-guessable tracking secret
  • SHA-256 without salt (find without storing)
  • Optional contact email
  • Retaliation banned (EU dir. art. 8)

2. Partition the investigation

The implicated party never accesses their own case — checked at model level on every request. A referent with a conflict of interest can be recused, with controlled reassignment.

  • implicated_employee_ids → 0 access
  • recused_employee_ids → off the case
  • Multi-referent per channel
  • Audit on every access attempt

3. Prove the deadlines

Automatic acknowledgment within 7 days. Feedback to the reporter guaranteed by workflow within 3 months. Chained signed audit trail for any inspection.

  • ACK_DAYS = 7 (EU 2019/1937 art. 9)
  • DEADLINE_DAYS = 90 (EU 2019/1937 art. 9)
  • Automatic referent reminders
  • Export eIDAS-signed audit trail
DEMO: ANONYMOUS HARASSMENT REPORT

Sophie reports, in 6 steps, without ever revealing herself.

A real-life scenario: anonymous filing via the public portal, cryptographic secret issued, referent assigned, implicated party excluded, two-way exchanges, closing within legal deadlines.

FULL CYCLE · 42 DAYS · COMPLIANT WITH EU 2019/1937

Moral harassment · Marketing Dept.

Sophie has suffered moral harassment from her manager for 4 months. She does not want to be identified. Illizeo’s public portal issues her a secret. The HR referent opens the investigation. The implicated manager is excluded from the case. Sophie exchanges via secure messaging. Decision made on D+38, feedback on D+42.

Legal constraint: ack D+7 (EU dir. art. 9) · feedback D+90 (EU dir. art. 9) · anonymity preserved (art. 16)

WALK-THROUGH · 6 STEPS

1
D+0 · Anonymous filing
Public portal, 32-char secret issued
New
2
D+2 · Auto acknowledgment
Confirmation email (under 7d EU)
Open
3
D+3 · Implicated excluded
Manager identified, 0 case access
Partitioned
4
D+12 · Active investigation
3 exchanges with Sophie via messaging
Pending
5
D+38 · Decision
Precautionary + disciplinary measures
Resolved
6
D+42 · Closed
Feedback to Sophie (under 90d EU) + signed audit
Closed
REPORTER PROTECTION — 4 CODED GUARANTEES

Anonymity, partitioning, traceability, retention.

Protection lives in the module’s code, not in the docs. Every guarantee is verifiable, testable, auditable.

Cryptographic anonymity

A 32-character base62 secret (~190 bits of entropy) is issued to the reporter at the end of filing. It is stored only as a hash (SHA-256). The reporter can follow their case without ever providing identity — even under judicial order, no one can trace them back from the hash.

Implicated party exclusion

The person accused is registered in the implicated_employee_ids field. On every access attempt to the case, the module verifies: if the user is in this list, access is refused, with no notification, no visible trace on the frontend. Neither reading, writing, nor statistics.

Referent recusal

An HR referent cannot handle a case where they have a personal interest (family, hierarchical, close friendship). They can be recused — registered in recused_employee_ids — and the case is reassigned to another referent in the channel, with no loss of traceability.

Tamper-evident chained audit trail

Every action (filing, opening, status change, message, exclusion, recusal, closing) is cryptographically signed (SHA-256 chained). Any retrospective modification breaks the whole chain. Signed PDF/JSON export available for inspection or litigation.

LEGAL COMPLIANCE

3 legal frameworks covered natively.

Each legal requirement is translated into a business rule coded into the module, with automatic deadlines and non-compliance alerts.

FRANCE · SINCE 2016

Sapin 2 Law

Law no. 2016-1691 of 9 December 2016. Mandatory reporting channel for companies with 50+ staff, protection of the whistleblower, scope: crimes, offences, harm to the general interest.

EU · SINCE 2019

Directive 2019/1937

European Directive of 23 Oct. 2019, transposed in France by the Waserman law of 21 March 2022. Acknowledgment within 7 days, feedback within 3 months, ban on retaliation.

GDPR + nFADP

Data protection

GDPR Article 30 (record of processing), Article 32 (security). Swiss nFADP since 2023. Automatic anonymisation after legal retention. Right to erasure honoured at the end of retention.

ARTIFICIAL INTELLIGENCE

Powered by Claude: 8 AI features to assist the referent.

AI helps qualify, prioritise, summarise. No decision is automated — every conclusion remains human.

Case summary

Every new filing is summarised in 3 lines: likely category, urgency, key factual elements.

Suggested priority

Content analysis to propose a priority (low, medium, high, critical). The referent validates.

Categorisation

Across the 9 legal categories, AI suggests the best fit. Ambiguous cases flagged.

Reply templates

Suggested replies to the reporter based on stage: acknowledgment, questions, decision, closing.

Deadline alerts

7 days for acknowledgment, 90 days for feedback: automatic reminders 3 days before deadline.

Retaliation detection

Cross-check with HR records: performance drop, role change, post-report sanction.

Compliant analytics

Aggregated statistics (count by category, average delays) — never nominative, never re-identifiable.

Annual report

Pre-filled compliance report for the French Defender of Rights or national supervisory authority.

ROI & COMPLIANCE

100% of legal deadlines met. Zero blind spot.

A compliant channel avoids sanctions (up to €30,000 for the executive, €150,000 for the legal entity in France) and reassures employees.

100%
Legal deadlines met
auto ack 7d + feedback 90d
190bits
Secret entropy
non-guessable, non-enumerable
9
Categories covered
Sapin 2 & EU 2019/1937
0
Implicated access
exclusion coded at model level

Add-on module on top of your Illizeo subscription.

Included in Enterprise plans. Add-on billed at entity level (not per employee) for other plans.

WHISTLEBLOWING ADD-ON · PRICING TO BE CONFIRMED

Compliant reporting channel

Bilingual public portal + anonymous tracking + full investigation workflow + signed audit trail + pre-filled compliance reports.

Bilingual public portal, your brand
190-bit cryptographic secret
Multi-channel, multi-referent
9 Sapin 2 & EU categories
Coded implicated party exclusion
Referent recusal
Secure two-way messaging
6-status cycle + 4 priorities
Auto ack within 7 days (EU)
90-day feedback workflow (EU)
SHA-256 chained audit trail
eIDAS export for litigation
AI qualification + templates
Annual compliance report
Legal-retention anonymisation
Native bilingual EN/FR
Request a quote →

Frequently asked questions

Are we required to have a reporting channel?+
In France, yes above 50 employees (Sapin 2 law, art. 8). At EU level, Directive 2019/1937 sets the same threshold for all private and public organisations. Failing to set up this channel exposes the executive to administrative sanctions and criminal liability.
How do you guarantee anonymity when investigators can demand identity?+
Illizeo does not store the reporter’s identity. The tracking secret is hashed with SHA-256 without salt. If the reporter provided an email, it is used only for acknowledgment and feedback, and never directly linked with case content on the admin side. In case of judicial request, only the filed content can be handed over — the identity remains unknown until the reporter reveals themselves.
How is the implicated party kept out?+
When opening the case, the referent enters the persons targeted in the “implicated” field. On every access attempt (read, write, statistics), the module checks the user’s identity: if they are in the list, access is refused. No notification is sent to the implicated party. The rule is coded in the business model — impossible to circumvent via another interface.
What happens if the 90-day feedback deadline is exceeded?+
The workflow sends reminders on D-14, D-7, D-3 before the deadline. If feedback is not sent by D+90, a critical alert is issued to the executive team. The case remains open with an “EU overdue” flag for audit. Referent (and DPO) liability may be engaged in case of litigation.
Is the public portal really on your domain?+
Yes — by default on your Illizeo subdomain (e.g. reports.yourcompany.illizeo.app). You can set up a custom domain (reports.yourcompany.com) to reassure users of the channel’s legitimacy. Mandatory HTTPS, HSTS, strict security headers.
Can we have multiple channels?+
Yes, as many as needed: a general channel, an ethics channel per subsidiary, a dedicated harassment channel, a financial-fraud channel. Each channel has its own referents (manager_ids). Reporters see a dropdown on the public portal to choose the appropriate route.
How long do you keep case records?+
France’s CNIL recommends 2 months for an unfounded report, 6 months after closing for a founded report with no follow-up, up to the end of proceedings plus 5 years for a judicialised case. Illizeo applies these durations automatically: past the deadline, full anonymisation (personal data erased, row kept for statistics).
Is the module available in French?+
Yes. Bilingual public portal (EN/FR), bilingual admin interface, translated categories, bilingual automatic emails matching the reporter’s language.

A compliant channel, a safe framework, an unassailable audit.

Sapin 2 and EU Directive 2019/1937 translated into code, workflow and automated deadlines. Activate the Whistleblowing module today.

Contact Illizeo
Hosted in Europe
Sapin 2 · EU 2019/1937 · GDPR
eIDAS-compatible signed audit trail