Roadmap

What comes next, and only that. Everything released is in the Changelog, rendered from CHANGELOG.md.

Ordering principle

Breadth before depth. v2.2.0 changes how every deployment receives and connects reports. v2.3.0 adds modules for specific German regulations (LkSG, KWG, CSRD), useful to some operators only. The order is a plan, not a promise: it moves when a reason turns up.

v2.2.0 — Multi-Channel Intake & Integration Hooks

More ways to receive a report, and hooks into compliance tooling (SIEM, GRC, ticketing) that never expose case content.

Additional submission channels

  • Email intake
    • Mail to INTAKE_EMAIL_ADDRESS becomes a pending report, attachments included.
    • A case number and PIN go back only to a sender who gave a return address.
    • One intake address per organisation in multi-tenant deployments.
    • Built on aiosmtplib or IMAP polling.
  • Voice recording
    • Recorded in the browser (Web Audio API, MediaRecorder), stored as an .ogg or .webm attachment.
    • Played back in the case view.
    • Optional pitch shift against speaker identification: VOICE_DISTORTION_ENABLED=true, server-side with ffmpeg.

Integration hooks

  • Admin management API
    • Users, categories, locations and system health; no case content, nothing that identifies a whistleblower.
    • JWT Bearer tokens with scoped API keys: api_keys (key_hash, scopes[], expires_at), managed on the admin settings page.
    • OpenAPI spec at /api/v1/openapi.json; rate-limited per key.
    • Lets GRC and ITSM tools provision OpenWhistle without the admin UI.
  • Aggregate statistics API: read-only, anonymised counts per period, category and status for compliance dashboards.
  • Outbound webhooks
    • Events report.created, report.status_changed, report.reply_added, report.deleted, each switchable.
    • Payload: event type, case number, new status, timestamp. No message, attachment or identifying metadata.
    • Signed with HMAC-SHA256 in X-OpenWhistle-Signature; retried up to 3× with exponential back-off.
    • Delivery log in the admin UI; WebhookEndpoint model (url, secret, enabled_events[], last_delivery_at, last_status_code).
  • Zapier / n8n guide: examples for Zapier, n8n and Make in docs/integrations/. Documentation only, no code change.

Access control

  • IP allowlist for admin routes
    • ADMIN_IP_ALLOWLIST takes CIDR ranges (192.168.1.0/24,10.0.0.0/8); outside them, 403.
    • Unset or empty: no restriction, as today.
    • FastAPI middleware before routing; a new TRUSTED_PROXY_DEPTH setting finds the client address behind load balancers.

Design system

  • DESIGN.md to the depth of easywall's design spec
    • It has held the "Signal" tokens since v1.3.0, but not component states, motion rules or per-pattern accessibility notes.
    • The goal: a design system the next contributor follows instead of reverse-engineering the CSS.

v2.3.0 — Compliance Expansion (LkSG, KWG, CSRD)

Obligations beyond HinSchG, as add-on modules that leave the whistleblower flow unchanged. LkSG (since 2023) needs a supply-chain channel, KWG a banking one; CSRD disclosures refer to internal reporting systems.

Supply chain due diligence (LkSG)

  • LkSG reporting channel
    • A separate form with the §2 LkSG violations as categories: forced labour, child labour, environmental violations, discrimination, excessive working hours and more.
    • Routed to a configurable LkSG case manager role.
    • §12 LkSG deadlines: receipt within 7 days, decision within 3 months, extension to 6 months documented.
    • Switched on by LKSG_ENABLED=true.
  • LkSG transparency report: the annual report of §12 Abs. 4 LkSG (complaints, investigations, measures) as a PDF; LKSG_TRANSPARENCY_YEAR.

Financial sector (KWG / MaRisk)

  • KWG / MaRisk channel
    • Categories for §25a KWG and MaRisk AT 8.5: risk management violations, fraud, AML breaches.
    • Routed to a Compliance/Audit role, with its own admin nav section; KWG_ENABLED=true.

Sustainability reporting (CSRD)

  • CSRD / ESG grievance channel
    • Environmental impact, human rights and social violations, as CSRD requires of large companies from 2025.
    • Categorised by ESRS topic, routed to an ESG officer role; CSRD_ENABLED=true.

Compliance documentation

  • ISO 37002 alignment: docs/iso37002.md maps every ISO 37002:2021 clause to a feature or setting, for auditors. Updated per release.
  • 30 languages
    • From four locales (EN, DE, FR, PT-BR) to every official EU language.
    • New: ES, IT, PL, NL, PT, SV, DA, FI, CS, SK, HU, RO, BG, HR, SL, ET, LV, LT, MT, GA, EL.
    • Formal and informal variants for DE/AT/CH.
    • Machine-translated first, then reviewed by native speakers, in app/locales/{lang}.json with the existing key schema.

Case handling workflow

  • Case redaction
    • Replace any passage of a description or message with [REDACTED] before a case is shared outside.
    • Logged in the audit log; the original is kept in an encrypted redaction log only a superadmin sees.
  • Anonymization / pseudonymization: one click replaces personal identifiers with placeholders (name → [Person A]) in a copy for auditors or regulators. The original stays.
  • Per-case tasks
    • Description, assignee, due date, status (open / in progress / done), visible to the admin team only.
    • Task deadlines are tracked apart from the HinSchG ones.
    • AdminTask model (report_id, assigned_to_id, due_date, completed_at).
  • Case-level access control
    • Restricts a sensitive case to named admins, on top of roles.
    • Others see its case number on the dashboard but cannot open it.
    • CaseRestriction model linking report_id to allowed admin_user_ids.

External collaboration

  • External advisor access
    • Time-limited guest access for law firms, auditors and external ombudspersons, at /advisor/{token} without an admin login.
    • Read cases and add internal notes; never change status or delete. Revocable at once, logged in the audit trail.
    • ExternalAdvisor model (email, access_token as a GUID, expires_at, allowed_report_ids[]).
  • Communication templates
    • Reviewed wording that admins insert into replies and notifications, per organisation.
    • MessageTemplate model (title, body_de, body_en, body_fr).

Reporting & transparency

  • Transparency report
    • An annual PDF + JSON from /admin/stats, for the internal documentation of HinSchG §12 Abs. 3.
    • Totals, by category, status at year-end, average processing time, SLA compliance rate, share closed in time.
  • Handler department on the status page: the team's department label, never a name; SHOW_HANDLER_DEPARTMENT=true, per organisation.

Already released

Every shipped release, newest first, is on the Changelog page.