Loading
Back to All Sections
4
Confidentiality, Anonymity & Data Security
Policy Section 5.0
Step 1 of 7

Your Safety Comes First

Multiple layers of protection for whistleblowers

5.1 Confidentiality

  • All matters treated with utmost confidentiality
  • Correspondence confidential regardless of anonymity
  • Party identities remain confidential
  • Details never disclosed without consent

5.2 Anonymity

  • Whistleblowers can remain anonymous
  • Contact info is optional
  • Reports should include sufficient detail
  • Include: persons, outline, witnesses, dates
Quick Check
Peter submits a report about procurement fraud but provides his email address. He later worries that his identity might be revealed to the accused person during the investigation.
When would Peter's identity be disclosed?

5.3 Data Security

Military-Grade Encryption

AES-256
Data Encryption
RSA-2048
Key Exchange
End-to-End
Full Protection
  • All data securely stored and transmitted
  • Industry-standard security measures applied
  • Even system administrators cannot read reports
Quick Check
David wants to report research misconduct but is terrified his identity will be exposed. A colleague tells him "the IT team can probably read everything you submit." David isn't sure what to believe.
What encryption standard does the AERC platform use to protect submissions?

Three Layers of Protection

LAYER 1
Confidentiality

All matters and identities kept strictly confidential

LAYER 2
Anonymity

Optional identity disclosure — you choose what to share

LAYER 3
Encryption

Military-grade AES-256 + RSA-2048 end-to-end encryption

Bottom Line: Your submission is encrypted end-to-end. Only authorized recipients with the correct decryption key can access report content. Not even the platform administrators can read it.
Final Check
During an all-staff meeting, someone asks: "If I submit a report, can the IT administrator who manages the platform read what I wrote?" The Designated Officer responds.
Can system administrators access and read whistleblowing reports?

Key Takeaways

  • Confidentiality — all matters and identities are kept strictly confidential; details never disclosed without your consent
  • Anonymity — you can remain completely anonymous; contact information is optional
  • Data Security — AES-256 + RSA-2048 hybrid encryption ensures even system administrators cannot read your reports
Next up: Reporting Channels & Procedures