sales@whistlesentinel.com +91 9867303707
Home / Resources / How we Secure your Data
How we Secure your Data

The highest level of data security and protection for whistleblowing.

Information security is our highest priority. We are committed to securing the data you store with us, eliminating system vulnerability, and ensuring continuity of access. We take multiple measures to keep your information and the whistleblower's identity safe.

ISO/IEC 27001 End-to-end encryption GDPR AWS multi-zone
ISO 27001
ISO 27001 Security Standard

Certified against the international standard for information security.

Digital Business Technology Pvt Ltd, the company behind WhistleSentinel, shows commitment to data protection and minimizes security risks with ISO/IEC 27001 certification, the international standard for an information security management system. This confirms that we handle data security correctly and that it is always a part of development.

How We Protect Your Data

Security built in layers, from the data outward.

Protected at the core

Reports, attachments, and communications are encrypted first, so even the innermost data is unreadable without the keys.

Guarded by access control

Role-based permissions and strong authentication decide who can reach anything at all.

Watched from the perimeter

Continuous testing, auditing, and monitoring keep the outer boundary resilient against emerging threats.

Our Controls

Six areas of protection, working together.

Encryption

  1. Data Encryption: All data, both in transit and at rest, is encrypted. This includes reports, attachments, communication, and any stored data within the system.
  2. End-to-End Encryption: Implemented for communications between whistleblowers and investigators to prevent unauthorized access to content.

Access Control

  1. Role-Based Access: Restricts system access based on users' roles and responsibilities.
  2. Authentication: Strong authentication methods, such as two-factor authentication (2FA), to prevent unauthorized access.

Secured Storage

  1. High Availability: Properly provisioned, redundant servers (e.g., load balancers, web servers, replica databases) in case of failure.
  2. Business Continuity: Daily encrypted backups of data across multiple zones on the AWS platform.
  3. Disaster Recovery: In the event of a region-wide outage, a duplicate environment is brought up in a different AWS region.

Security Testing & Auditing

  1. Regular security assessments, vulnerability scans, and penetration testing to identify and address potential weaknesses.
  2. Independent security audits to ensure the system meets or exceeds industry standards and regulations.

Legal Compliance

  1. Compliance with applicable data protection laws and regulations, such as GDPR in Europe and relevant privacy laws in other regions.

Employee Training

  1. Employees undergo background checks before employment and are trained on security practices during onboarding and annually.
  2. Authentication: Strong authentication methods, such as two-factor authentication (2FA), to prevent unauthorized access.
End-to-End Encryption

The channel opens without ever opening the identity.

Every message between a whistleblower and an investigator travels encrypted end to end, so the content, and the person behind it, stays protected in transit.

Secured Storage

Redundant by design, recoverable by default.

High availability keeps the service running through failures; daily encrypted backups are replicated across multiple AWS zones.

AWS Zone A

Primary

Live, load-balanced servers

AWS Zone B

Replica

Encrypted daily backups

AWS Zone C

Replica

Encrypted daily backups

Disaster recovery: in the event of a region-wide outage, a duplicate environment is brought up in a different AWS region.

Still have questions?

See the security posture that protects your people.

We're happy to walk your security and compliance team through our controls, certifications, and architecture.

ISO 27001 GDPR AWS