Evidence
Reporters can attach files to their submission. Those files stay in your organisation’s secure intake system — Secure Report builds a chain-of-custody register over them instead of copying them out.
When you register a case’s evidence:
- Each attachment is fingerprinted with a SHA-256 hash, computed directly from the stored file.
- The register records the file’s identifier, its hash, when it was registered and by whom.
- The reporter’s original filename is deliberately not recorded — filenames can themselves identify someone. Files appear as Attachment 1, 2, … in the register; you see live filenames when viewing the report itself.
The hash is your integrity proof: if the file is ever questioned, recomputing its SHA-256 and comparing it to the register shows whether it changed since registration.
Messaging the reporter
Two-way messaging with the whistleblower runs through the intake system’s secure channel, referenced by the case — the reporter stays anonymous, and the conversation is read live rather than stored in Secure Report.
- The reporter checks for replies using the receipt code they got when submitting.
- Your messages appear to them on the intake site; their replies appear on the case.
- The case records that a message was sent (for the timeline and audit), never the message text.
Write to the reporter as if the message could be read aloud in a hearing: professional, neutral, and free of anything that could pressure them or hint at their identity being known.