A protected channel for disclosures, walled off from the rest of your organisation.
A dedicated place for oversight teams to receive, triage and investigate sensitive disclosures — with access granted deliberately, and every action independently recorded.
Its own space — not a folder in your case system
Disclosure records live in their own encrypted store inside your Sanctis instance: a separate schema, separate keys, separate permissions. Someone working on contracts or grants sees nothing here. Access to the module is granted role by role, and Sanctis support staff cannot enter a confidential-reporting tenancy without your approval.
How a disclosure reaches you
-
You get your own instance
Subscribe, and Sanctis provisions an isolated deployment for your organisation at
your-org.sanctis.net, hosted in Australia. -
Publish your own reporting address
Point a web address you control — for example
report.your-agency.gov.au— at your instance. The intake form carries your branding and your disclosure categories. -
Anyone can raise a disclosure
A staff member or a member of the public submits through the form. They can choose to stay anonymous — no account and no identifying details are required.
-
It arrives as a case
The submission lands directly in your instance as a structured case — reference, category, status — ready for triage. Attachments are virus-scanned and stripped of document metadata on the way in.
-
Follow up without identifying anyone
The reporter keeps a case reference and uses it to check progress and exchange messages with your handlers — with their identity never attached.
Built to the standard your auditors will ask about
Confidential reporting is the part of the platform most likely to be independently reviewed. The module is designed around that from the start.
- Australian data residency
- Every record, backup and process stays in Australian Azure regions. Nothing fails over or replicates offshore. Aligns with the Australian Privacy Principles, including APP 8 (cross-border disclosure).
- Security of personal information (APP 11)
- Case content is protected with per-case envelope encryption. Keys sit in your instance's own key vault, so a database read alone never yields readable content.
- Separation of duties
- Intake, triage, investigation and review are distinct roles. The permission model is grant-only, and every grant can be explained — the exact path by which a person has access to a thing.
- Independent audit trail
- Intake, every access, every status change and every message is written to an append-only log in your instance that your administrators — and your auditors — can read.
- Restricted support access
- Sanctis operators cannot enter a confidential-reporting tenancy by default. Access is approval-required or switched off entirely; any session is time-boxed and recorded on both sides.
- Access & correction (APP 12/13)
- The record and field model supports data subject access requests — locating, exporting and correcting the information held about an individual.
- Hardened government configuration
- An optional preset for agencies: mandatory single sign-on, IP allowlisting, a 15-minute idle timeout, restricted file uploads and customer-managed encryption keys.
- Accessibility
- The interface is built to WCAG 2.1 AA, the baseline for Australian government procurement.
One image, many isolated instances. Every customer runs the same reviewed build as a separate deployment with its own database, storage and keys. Modules are switched on per customer by signed entitlement — never by shipping different code.
Bringing confidential reporting into Sanctis?
We'll walk you through how the module is isolated, how intake works, and exactly what your auditors will see.