Skip to content
Home / Company / Security – Trust center

Protecting reporters, cases and companies

Secured, isolated, encrypted, audited

An icon of Lock with wi-fi conection lines in blue and green colors

Extract from Information security policy

Ethicontrol:

dot  
provides support and continuous improvement of ISMS
dot  
employees undergo regular information security training
dot  
undergoes regular audits
dot  
implemented a number of controls required by standards: database encryption, SSL encryption, proactive vulnerability scanning, ISM

Ethicontrol:

dot  
collects limited data and never sells data
dot  
familiarizes clients with the data we collect
dot  
keeps a transparent list of subcontractors
dot  
supports the right to be forgotten and deleted

Extract from Personal data protection policy

Check our certificates and confidential security documents at the vendor portal

icon ISO in blue color

ISO 27001 Information
security certified

icon ISO in blue color

ISO 27701 Privacy
management certified

GDPR compliance in a snapshot

Manager showing project presentation to his colleagues
Organisational level
  • Company registered in EU
  • Assigned Data Protection Officer
  • Created and maintain Privacy management system certified under ISO 27701 
  • Information security measures.
  • GDPR Handbook
  • Number of additional disclosures made on https://ethicontrol.gdprpage.com/
  • Support of DPA, data requests, data breach
    notifications, data deletion requests.
Technician checking routers in server room
Technical level
  • Storage within EU only
  • No logging of personal data of visitors and whistleblowers
  • No use of scripts or any other digital footprint tracking tools
  • Encryption of data in transit and stored data
  • No metadata analysis or research with our customer data
  • Data protection disclaimers and other information during the reporting process
  • Special security functions in relation to
    access and processing of data
  • Single view of a person and collected
    data (Dossier) - ability to delete / sanitise
Side view portrait of businesswoman using computer at office desk
Functional level
  • Reminders and notifications when certain data protection criteria occur
  • Support of sanitisation (anonymisation) of case details (e.g. personal data) and optionally also file attachments
  • Zero trust policy within apps
  • Authorisation management and role concept for fine-tuning access to sensitive case contents

Common Security Related Questions