Encrypted Whistleblower and Ethics Reporting Forms

Client-side encryption can keep response contents unreadable from stored server-side data alone. It does not make a reporting channel anonymous or replace an organization's response and protection procedures.

Confidentiality and anonymity are different

Encryption limits who can read response contents. Anonymity concerns whether a report can be linked to the person who submitted it. A report may identify its author through names, job details, events, or writing; web and proxy access logs may also retain network or request metadata depending on deployment.

Cyphorm should be described as an encrypted form service, not as an anonymous reporting system. Review the entire hosting and response workflow before offering it for whistleblower reports, and do not promise anonymity unless the system has been assessed to support it.

What client-side encryption changes

Cyphorm encrypts response contents in the respondent's browser using the form owner's public key. In the intended application flow, the service does not receive the private key needed to decrypt the stored response. The service still handles form schema, field labels, account and operational metadata, and ciphertext. Users must also trust the browser code and deployment.

The interactive homepage demo illustrates local encryption with sample values; it does not demonstrate anonymity or network-log behavior.

Plan the reporting channel

  • Name a limited set of people authorized to decrypt reports and respond.
  • Keep private-key backups protected and ensure there is a continuity plan for the responsible team.
  • Ask only what is needed and avoid form wording that invites unnecessary identifying details.
  • Explain who receives reports, how quickly they are reviewed, and how follow-up works.
  • Review web-server and proxy logging, retention, incident response, and the reporter's device and network context.

If a reporter faces immediate danger, a web form may not be an appropriate emergency channel.

Encrypted reporting FAQ

Can Cyphorm read an encrypted report?

Cyphorm does not receive the form owner's private key through the intended application flow, so stored response data alone cannot be decrypted by the service. Users still trust the browser code and deployment.

Are Cyphorm reporting forms anonymous?

Cyphorm provides encrypted forms, not a guarantee of anonymous reporting. Reports may include identifying details, and web or proxy access logs may retain network or request metadata depending on deployment. Review the complete reporting system before promising anonymity.

What should an organization plan before opening an encrypted reporting channel?

Name authorized response owners, protect private-key backups, limit questions and metadata, define response and retention procedures, and explain confidentiality and anonymity limits to reporters.