The best self-hosted whistleblowing tools in 2026 — open source and owned
An honest field guide to EU-Directive reporting channels: GlobaLeaks and SecureDrop reviewed on their real strengths, the quote-gated SaaS field, and where a simple owned channel fits.
The EU Whistleblowing Directive (2019/1937) obliges organisations with 50 or more employees to run a secure internal reporting channel that protects the reporter and lets them follow up. This is the one category where self-hosting is not just a cost argument — the entire point of the channel is that the most sensitive reports your organisation will ever receive stay out of third-party hands. Here is the honest field, free options first.
The open-source options (genuinely strong here)
- GlobaLeaks — the reference open-source whistleblowing platform, mature and actively maintained, used by anti-corruption authorities, companies, and NGOs worldwide. Questionnaire-based intake, reporter follow-up, case management, and serious attention to anonymity. The trade-off: it is its own Python application stack to deploy and operate, and its breadth (multi-tenant, custom questionnaires, contexts) is more machinery than a 60-person company needs for the Directive's core duty.
- SecureDrop — the gold standard for journalist–source communication, built by the Freedom of the Press Foundation and run over Tor. Listed here for honesty: if you are a newsroom protecting sources, this is the tool. For a company's internal Directive channel it is the wrong shape — the operational bar (dedicated hardware, air-gaps, Tor-only access) is far beyond what employee reporting needs.
If GlobaLeaks fits your ops capacity, it is an excellent free answer. That sentence appears in this guide because it is true, and guides that hide it are ads.
The hosted field
The SaaS vendors here — FaceUp, NavEx, and most enterprise GRC suites — are quote-gated: "Book a Demo" instead of a price. Whistlelink is among the few publishing numbers, and it is a recurring annual fee. Whatever the quote turns out to be, the structural trade remains: a legally-required channel, rented forever, with the reports themselves sitting in a vendor's cloud.
The buy-once option
Confida is our entry: a self-hosted, genuinely anonymous reporting channel bought once. A reporter files a case with no name, email, phone, or IP collected; follow-up runs on a case code plus a passphrase stored only as a one-way hash; a handler answers through a two-way thread while the reporter stays anonymous. It is deliberately narrower than GlobaLeaks — one channel, done carefully, on the same plain PHP + MySQL stack as the rest of this store, installable in minutes on ordinary hosting.
The honest limits: Confida is the reporting channel and the case thread. It is not a GRC suite — no policy management, no DPIA workflows, no training records. If you need those, the enterprise platforms bundle them, and charge accordingly.
The honest chooser
- You have real ops capacity and want free: GlobaLeaks — the strongest FOSS answer in this guide.
- You are a newsroom protecting sources: SecureDrop, nothing else.
- You want the Directive's core duty met on your own server, minimal machinery, one payment: Confida.
- You want the full GRC bundle and accept the quote: the enterprise suites exist for you.
What the duty looks like in practice
Whatever tool you run, the Directive's headline mechanics are worth knowing before you choose (and your national transposition law is the binding text — member states differ in details, so check yours). The channel must acknowledge a report within seven days and give the reporter substantive feedback within three months — which is why a tool with a real two-way, still-anonymous follow-up thread is not a nice-to-have but the core requirement: an anonymous mailbox with no way to answer fails the feedback duty by construction. The handler role matters too: reports must reach a designated impartial person, and the fewer people who can technically open the case data, the easier that assurance is to give. This is where the self-hosted argument stops being philosophical — "the reports live in one database on one server we control, and here is the list of people with access" is an answer an auditor accepts and a works council believes.
Two operational habits round it out: put the reporting link somewhere staff can reach without logging into anything monitored (the point of anonymity dies if reaching the form is itself logged), and test your own channel quarterly by filing a dummy report — the worst possible discovery is that follow-up was broken the month a real report arrived.
Whichever you choose, choose self-hosted if you possibly can. In every other category on this site that is a preference; here it is close to the point of the law: the channel is only as trustworthy as the answer to "who else can read these reports?" — and "nobody, it runs on our own server" is the strongest answer there is.
Every vendor figure in this category also lives in the Price Observatory — verified, dated, and source-linked, free to cite — and the calculator turns those figures into your own three-year number in ten seconds.