Evidence

Reporters can attach files to their submission. Those files stay in your organisation’s secure intake system — Secure Report builds a chain-of-custody register over them instead of copying them out. When you register a case’s evidence:
  • Each attachment is fingerprinted with a SHA-256 hash, computed directly from the stored file.
  • The register records the file’s identifier, its hash, when it was registered and by whom.
  • The reporter’s original filename is deliberately not recorded — filenames can themselves identify someone. Files appear as Attachment 1, 2, … in the register; you see live filenames when viewing the report itself.
The hash is your integrity proof: if the file is ever questioned, recomputing its SHA-256 and comparing it to the register shows whether it changed since registration.

Messaging the reporter

Two-way messaging with the whistleblower runs through the intake system’s secure channel, referenced by the case — the reporter stays anonymous, and the conversation is read live rather than stored in Secure Report.
  • The reporter checks for replies using the receipt code they got when submitting.
  • Your messages appear to them on the intake site; their replies appear on the case.
  • The case records that a message was sent (for the timeline and audit), never the message text.
Write to the reporter as if the message could be read aloud in a hearing: professional, neutral, and free of anything that could pressure them or hint at their identity being known.