You can get a whistleblowing system (Hinweisgebersystem) with EU hosting in two ways. One is self-hosted software on a server in the EU, the other a service with a data centre in the EU. OpenWhistle is self-hosted software. All reports sit on the operator's server, and if that server is in the EU, the data stays in the EU.

Transparency note

This article is written by the developers of OpenWhistle. Information on other offerings comes from their own websites, retrieved on 27 September 2026. Not legal advice.

Who offers whistleblowing systems with EU hosting?

Offering Model Where the data lives
OpenWhistleSoftware, GPL-3.0on your server; you choose the location
GlobaLeaksSoftware, AGPL-3.0on your server; you choose the location
Hinweisgeberportal OpenSourcemanaged GlobaLeaksdata centres in Germany
WhistlePortSaaSGermany, ISO/IEC 27001

Sources, prices and further offerings are listed in Whistleblowing software providers compared. With a service, the provider is your processor. Self-hosted, that is at most your hosting provider.

What OpenWhistle encrypts

Data Protection
Report text and messagesa data key of its own per report (Fernet: AES-128-CBC with HMAC-SHA256)
Attachments: content and file namethe same key as the report, in S3 storage too
Name and contact in confidential reportsencrypted; visible only after a logged reason
TOTP secrets of the accountsencrypted
Master keyderived from ENCRYPTION_KEY, otherwise SECRET_KEY (HKDF-SHA256); never in the database
Draft while reportingin Redis, 2 hours at most; the key lives only in the reporting person's cookie
TransportTLS 1.2 and 1.3 via nginx, from the first start

Whoever steals only the database gets ciphertext. The details are in the documentation on key rotation.

What OpenWhistle never stores

  • IP addresses. nginx removes the IP headers and writes no access log. The app discards the address, and the database has no IP column.
  • Times of the reporting person. The report, messages and attachments carry only the date.
  • Data for third parties. Every outbound request is optional and listed in the documentation. The update check and the installation count stay off until you switch them on.

Is a whistleblowing system GDPR-compliant?

Compliance belongs to the operation, not the software. OpenWhistle supports GDPR-compliant operation; the operator bears the responsibility.

GDPR OpenWhistle Your part
Data minimisation, Art. 5anonymous mode, no IP, date onlythe form's categories and texts
Storage limitation, Art. 5automatic deletion, by default 1095 days after closureset the period
Erasure, Art. 17deletion only after confirmation by a second admin accountreview requests
Security, Art. 32encryption, TOTP for every account, roles, audit logserver, updates, backups
Processing on behalf, Art. 28no service run by the project; without opt-in, no connection to the projectcontract with your hosting provider
Records, Art. 30; impact assessment, Art. 35not part of the softwarecreate where required

Reports in several languages

The interface is available in German, English, French and Portuguese (Brazil). It follows the browser's language until the person chooses one. They can write the report text in any language.

Open source: verifiable instead of promised

OpenWhistle is licensed under the GPL-3.0, and the entire source code is on GitHub. You can verify every statement in this article there. OpenWhistle has not had an external audit yet.

Try OpenWhistle without installing it

The live demo shows the reporting wizard and the admin area with sample data. It is reset every 6 hours.

Open the live demo →

More resources: OpenWhistle whistleblowing software · HinSchG compliance guide · Step-by-step installation guide