Skip to main content
Required by EU law for organizations with 50+ employees

Trust #

Everything a procurement reviewer, DPO, or legal team needs to evaluate EthicsPortal.

Last updated: 2026-09-13.


Contracting party #

Registry evidence and the proposed contracting documents can be requested during procurement. Executed documents depend on the agreement reached with the customer.


Data residency and processor relationship #

In the standard subscription model, the customer is the controller and EthicsPortal acts as processor for customer report data.

Core whistleblower report data, including the application, database, and file storage, is hosted in Nuremberg, Germany on Hetzner . Transactional email runs through Mailjet (France). Vendors used for account, billing, and public-website processing are disclosed in the Privacy Notice but are outside the customer-instructed processing chain covered by the DPA. The whistleblowing channel and handler portal do not load Cloudflare.


Continuity and personnel #

Customer data export and continuity. While the Service is reachable, organization administrators can export individual cases without operator intervention. A machine-readable bulk export is available on request during an orderly contract exit. The Data Processing Agreement and business continuity plan state the applicable rights, operational dependencies, activation triggers, RPO 24 hours / RTO 4 hours, and current operator-incapacity limitations.

Backups. Daily PostgreSQL dumps to Hetzner Object Storage (EU, maximum 28-day retention) plus Hetzner server-level snapshots (7-day retention). Last restore drill: 2026-09-01.

Personnel controls. Access to customer data is limited to specifically authorized personnel and named sub-processors on a need-to-know basis. Privileged-access controls and the current personnel-access scope are documented and available during procurement review.


Certification status #

EthicsPortal does not currently claim accredited ISO 27001 certification on this site. An independent external penetration test is not currently on record. When either changes, the certification name (or test scope, date, and remediation summary) will be published here.

In place of accredited certification, EthicsPortal publishes a structured self-assessment against the same control sets that an external audit would evaluate:

These materials provide evidence for procurement review. They are self-assessments, not certification, assurance, or an independent audit opinion.


Operational lifecycle #

QuestionAnswer
Live availabilityPublished at secure.ethicsportal.eu/up for the covered surfaces. See Service level agreement for measurement methodology and exclusions.
Session and access lifecycleSessions expire automatically after 14 days of inactivity and are swept nightly. Users can review and revoke their own sessions at any time. Each session records last_seen_at so stale devices are identifiable. Member deactivation cuts access at the request boundary, unassigns open reports, and removes participantships while preserving audit history. See Security .
Backups and restoreDaily PostgreSQL dumps to Hetzner Object Storage (EU, maximum 28-day retention) plus Hetzner server-level snapshots (7-day retention). RPO 24 hours, RTO 4 hours. Last restore drill: 2026-09-01. See Security .
Dependency and patch managementContinuous SCA in CI (Brakeman, bundler-audit, importmap audit) plus weekly Dependabot updates. No end-of-life components deployed. See Security .
Export and deletionPDF case export is available in-app for every case (description, messages, audit trail, attachments). Machine-readable bulk export of the full organization data set is available on request during contract exit. Contractual commitments are in the Data Processing Agreement .
Recovery objectivesSee Service level agreement .

Contracting positions #

A single source of truth for the contractual questions enterprise procurement teams most often ask. Each row links to the document that controls.

ItemEthicsPortal position
Aggregate liability cap12 months of fees paid in the 12 months preceding the event giving rise to the claim (Terms §11 ). Claims under the Data Processing Agreement, Service Level Agreement and any signed order fall within the same aggregate cap, subject to mandatory law and any express signed exception.
Intellectual-property claimsThe standard Terms do not provide a duty to defend or indemnify the customer. Any such obligation requires a separate signed order (Terms §12 ).
Breach notification windowWithout undue delay after becoming aware, as required of a processor by Art. 33(2) GDPR (DPA §6.6 ). Available material information is supplied with the initial notice and supplemented as it becomes available.
Audit rightsThe ordinary DPA provides the information and audit cooperation required by Art. 28(3)(h) GDPR, subject to reasonable scope, confidentiality, security, scheduling, and cost safeguards (DPA §6.9 ). Any DORA-specific authority access, inspection, audit, or cooperation terms require a separate bilateral signed DORA order that defines their scope and logistics. A customer’s unilateral classification does not amend the contract.
Service creditsStandard plans do not include monetary service credits. Remedies for material or repeated availability failures are governed by the aggregate liability cap (SLA ).
Customer-managed encryption keys (BYOK / external KMS)Not supported. Processor-managed keys maintain the current reporter–handler encryption design. Deletion follows the production and backup lifecycle stated in DPA §6.8 and §6.11 ; no instantaneous deletion from every backup copy is promised.
Source code escrowNot offered. Continuity is handled through the operator-incapacity provisions of the business continuity plan and the Controller’s data-export and deletion rights under DPA §6.8 .
Sub-processor change noticeAt least 30 days before adding or replacing a sub-processor; the Controller may object and terminate if no resolution is reached (DPA §6.4 ).
Data export and deletion on exitSelf-service PDF case export in-product, plus machine-readable bulk export on request during exit. After the Service ends, data is returned or deleted at the Controller’s choice; backups expire under the stated lifecycle, currently no later than 28 days after production deletion (DPA §6.8 ).
Cyber liability insuranceUnder review. Coverage amount and carrier will be published here when in place.
Independent external penetration testNone currently on record. Scope, date, and remediation summary will be published here when one is performed. First-party testing is summarized under self-conducted security testing and is not a substitute.
Governing law and venueLaws of Poland; courts of Warsaw (Terms §13 ). The Service is offered only for organizational business or professional use.

These positions are reflected in the published Terms of Service , Data Processing Agreement , and Service level agreement . Material deviations are not granted on standard plans.


Public documents #

Everything a procurement reviewer needs is published openly. Grouped by what the document does.

Contractual #

What governs the relationship between EthicsPortal and the customer.

DocumentPurpose
Terms of serviceSubscription terms, cancellation, refunds, liability cap, IP-claim position
Data Processing AgreementProcessor terms under GDPR Art. 28
Service level agreementAvailability target and measurement
DORA contracting templateNon-binding starting point for a customer-specific bilateral DORA order; publication does not create obligations
Privacy policyHow personal data is handled

Operational #

How the Service runs day-to-day and who else is involved.

DocumentPurpose
SecurityTechnical and organizational measures
SubprocessorsNamed subprocessors and their scope
Incident registerMaterial incidents affecting personal data
AccessibilityEAA / EN 301 549 conformance status

Directive reference #

How EthicsPortal maps to, and reads, EU Directive 2019/1937.

DocumentPurpose
Directive 2019/1937 coverage mapFeature-to-Directive 2019/1937 article map
Directive 2019/1937 interpretationsInterpretive positions on ambiguous Directive provisions
Whistleblower laws by countryNational transpositions, enforcement authorities
Penalties by countryFines and criminal liability per Member State

Self-assessment #

Named policy documents and the control mappings an external audit would evaluate.

DocumentPurpose
Information security policyStatement of intent, scope, roles, control commitments
Business continuity planActivation triggers, recovery objectives, operator-incapacity disclosure
Risk registerTop risks, treatment, residual position
Internal audit recordAudit programme, findings, and the impartiality limitation of a self-performed audit
Management review recordInputs considered, conclusions, and decisions taken on the management system
Anti-corruption and business ethics policyProhibited conduct, gifts and hospitality thresholds, conflicts of interest, referral-fee disclosure
ISO/IEC 27001:2022 self-assessmentClause 4–10 requirements and all 93 Annex A controls, as a Statement of Applicability
Self-conducted security testingScope, dates, findings, and remediation for first-party testing
CAIQ-aligned questionnairePre-filled vendor security assessment (CSA CAIQ v4 domain structure)
DPIA template for whistleblowingPre-filled GDPR Art. 35 assessment for the Controller to adapt and sign
DORA ICT third-party mapArticle 28–30 map and register-of-information data for financial entities

Available during procurement review #

The following materials are shared in controlled disclosure rather than published openly:

To request these, email support@ethicsportal.eu . For security-review questions, email security@ethicsportal.eu .

Last updated: