Whistleblower and disclosure management

Help people speak up. Be ready to respond.

Give people an anonymous reporting channel and a way to follow up. Give your receiving team a restricted workspace to investigate, record protection measures and carry the response through.

Illustrative workflow

A report can be anonymous.
The response still needs a record.

For the person reporting

Submit anonymously. Save the token.

Check status and add information without an account.

For the receiving team

Investigate. Record measures. Remediate.

Keep the case, protection notes and outcome together.

Simplified workflow. Report access follows the provider’s recipient configuration and fallback rules.

From disclosure to follow-through

A clear route for the concern. A record of the response.

The reporting channel is only the beginning. Help the receiving team keep investigation, protection measures and remediation connected without placing protected details in a general work queue.

01

Give people a way to speak up

Use a provider-linked disclosure form with an anonymous submission option and no account requirement. For an anonymous report, the submission receipt gives the discloser a reference token to save securely.

The token supports later follow-up without asking for an email address.

02

Keep the investigation on the record

Review the report in the restricted case workspace. Record an internal or external investigator, review the case status and maintain protection notes alongside the investigation.

Review recipient configuration and the fallback routing before sharing your reporting link.

03

Follow through on the response

Record remediation and the outcome. Where wider operational action is needed, create a neutral improvement task with the private link retained on the case.

Keep protected report details out of shared improvement tasks.

Before you share the reporting link

Set up the people behind the process.

Confirm the provider’s reporting link, designated recipients and arrangements for changes in responsibility. Walk through default routing so your team understands what happens when no active recipient is configured.

Pair the software setup with your policy, training and handling procedures. Software supports the record of your response; the people receiving the disclosure remain responsible for how it is handled.

Walk through a disclosure from both sides.

Use a fictional concern to see the reporting experience and the receiving team’s workflow.

Submit and return
See the anonymous option, submission receipt and reference-token follow-up.
Check access
Review active recipients, provider scope and what default routing permits.
Carry the response through
Record the investigator, protection notes and remediation; inspect a neutral improvement handoff.

Agree receiving responsibilities, policy and access configuration for your provider.

Disclosure handling, explained.

Can someone submit and follow up anonymously?

Yes. The provider-linked public form supports anonymous submission without an account. The receipt provides a reference token, shown once, which the discloser should save securely. The follow-up page uses that token to check status and add information without asking for a name or email address. The content of a report or message may itself identify someone, so care is still needed when describing events.

Who can access reports inside Statura?

Configured active recipients can access reports within their provider scope. When no active recipient is configured, tenant or system administrators can access reports accepted through default routing, only while no active recipient exists. This does not grant access to earlier reports submitted through configured recipients. Review recipients and fallback handling during setup and whenever responsibilities change.

Does selecting a recipient in the software establish legal eligibility?

No. Software access settings and the legal definition of an eligible recipient serve different purposes. Your provider needs to establish appropriate receiving arrangements and handling procedures under the applicable law.

How are protection measures recorded?

The case workspace supports protection status and notes alongside investigation and remediation records. Your team is responsible for taking and reviewing the actual measures. Recorded status is not a guarantee that retaliation or other detriment has been prevented.

Can remediation become an improvement task?

Yes. The case workspace supports a neutral improvement task for wider follow-up, with a private link retained on the disclosure case. The task is created without protected report details; keep later additions appropriate for the wider audience.

Legal protections depend on a qualifying disclosure and the applicable law. Read the Commission’s provider guidance.