Whistleblower channel software: open or owned
Whistleblower channel software: what open source gives you, what a bought copy gives you, and the clocks a channel has to track.
whistleblower solution open source is a search made by somebody who has already rejected two things. They do not want a hosted platform holding reports about their own organisation, and they do not want to write the channel themselves. Open source looks like the answer, and for some organisations it is. The distinction worth drawing before choosing is between open source and owned, because they solve different halves of the problem.
What each arrangement actually gives you
Open source gives you the licence: the right to read, modify and redistribute the code, usually with no fee attached. What it does not give you is anyone whose job it is to have finished the awkward parts. The awkward parts in this category are specific -- genuine anonymity, metadata on attachments, deadline arithmetic across a working calendar, and a handler console that does not leak the reporter through a notification email.
A bought copy gives you the software finished to a stated standard, with the source included so you can still read and change it, and a price that happens once. What it does not give you is the right to redistribute it.
A hosted platform gives you neither the code nor the hosting, and puts reports about your organisation on somebody else's infrastructure. That is the arrangement the search is usually running away from.
The question is therefore not open or closed but *who finishes the difficult parts, and where do the reports sit*.
The parts that are difficult
Anonymity as an application property. A channel that says anonymous and then stamps an IP address into a log has not delivered it. Confida treats anonymity as an application guarantee and says plainly that it is not a network or hosting guarantee -- HTTPS and sane server logging remain yours to arrange. That sentence is the honest version, and a product that omits it is overselling.
Try the Confida demo ↗Live, on sample data, no sign-up.
Attachments. A photograph carries camera metadata; a document carries an author. Confida accepts photographs only, strips their metadata down to pixels, encrypts them at rest, and refuses documents outright because author metadata cannot be reliably removed from them. Attachments never leave the server by email, webhook or calendar feed.
Notifications that carry nothing. Handler email deliberately contains no report content, which is the difference between a notification and a leak.
The clocks. The Directive's shape is an acknowledgement inside seven days and feedback inside three months, tracked per report, counted against your own working calendar rather than a naive month. Arithmetic like that is easy to get slightly wrong and awkward to notice.
Two-way messaging without identity. A handler needs to ask a follow-up question of somebody who never gave a name. That is a design problem, not a form field.
What owning the copy changes
The reports stay in a database on a server you chose, with no vendor in the request path at all. There is no per-report meter and no per-seat charge, so a second handler costs nothing. The source comes with it, so does this really not log the reporter is a question you answer by reading rather than by trusting. And it runs on PHP with PDO and MySQL, MariaDB or SQLite -- ordinary hosting, no container runtime.
The limits, stated plainly
Confida is not legal advice and does not make any organisation anything; it tracks the timers and the workflow and keeps the record. It files nothing with any authority and includes no e-discovery platform. Intake is written only: Article 9(2) of the Directive lets a channel be in writing or orally or both, so a written channel satisfies that wording, but there is no telephone intake here, no screen for typing up a call, and no field recording that a report arrived orally. The physical meeting a reporter may ask for is a process you run. One organisation per installation. Reporter pages are available in German as well as English, and handler-side text is English.
Questions people ask
Is an open-source channel less safe than a bought one? Neither the licence nor the price tells you that. What tells you is how the product handles attachment metadata, logging, notification content and the deadline arithmetic -- so read those four answers in any candidate, whatever its licence.
Can a handler reply to somebody who left no name? Yes. Two-way messaging is tied to the report rather than to a person, so a follow-up question reaches the reporter without an identity ever being attached.
Where are the reports stored? In your own database, on the server you installed it on. Nothing is sent to the people who wrote the software, and attachments never leave the server by any route the product offers.
Where to look next
The product page is Confida, with the full feature record and its limits in the product's own words, and the Compliance Suite holds it alongside the other registers. The alternatives page covers one of the hosted options people arrive from, and the side-by-side sets them against each other. For what the hosted channels charge, read the observatory: each figure is quoted verbatim beside the date it was read and a link to the page it came from. Prices are on the observatory; read them on the date shown there.