Confidential Reporting Module

A protected channel for disclosures, walled off from the rest of your organisation.

A dedicated place for oversight teams to receive, triage and investigate sensitive disclosures — with access granted deliberately, and every action independently recorded.


Separation

Its own space — not a folder in your case system

Disclosure records live in their own encrypted store inside your Sanctis instance: a separate schema, separate keys, separate permissions. Someone working on contracts or grants sees nothing here. Access to the module is granted role by role, and Sanctis support staff cannot enter a confidential-reporting tenancy without your approval.

Mockup of a sample confidential reporting case record: reference CR-2026-0042, status Investigating, redacted disclosure text, assigned roles showing separation of duties, and an independent audit trail.
Illustrative — a sample case record. Status, redacted disclosure text, separation of duties and an independent audit trail. Sample data, not a real disclosure.
How it works

How a disclosure reaches you

  1. You get your own instance

    Subscribe, and Sanctis provisions an isolated deployment for your organisation at your-org.sanctis.net, hosted in Australia.

  2. Publish your own reporting address

    Point a web address you control — for example report.your-agency.gov.au — at your instance. The intake form carries your branding and your disclosure categories.

  3. Anyone can raise a disclosure

    A staff member or a member of the public submits through the form. They can choose to stay anonymous — no account and no identifying details are required.

  4. It arrives as a case

    The submission lands directly in your instance as a structured case — reference, category, status — ready for triage. Attachments are virus-scanned and stripped of document metadata on the way in.

  5. Follow up without identifying anyone

    The reporter keeps a case reference and uses it to check progress and exchange messages with your handlers — with their identity never attached.

Mockup of the confidential reporting sign-in screen served from a client's own web address, offering Microsoft sign-in or anonymous access using a case reference.
Illustrative — the sign-in screen a reporter sees, served from the client's own address. Anonymous access needs only a case reference.
Compliance

Built to the standard your auditors will ask about

Confidential reporting is the part of the platform most likely to be independently reviewed. The module is designed around that from the start.

Australian data residency
Every record, backup and process stays in Australian Azure regions. Nothing fails over or replicates offshore. Aligns with the Australian Privacy Principles, including APP 8 (cross-border disclosure).
Security of personal information (APP 11)
Case content is protected with per-case envelope encryption. Keys sit in your instance's own key vault, so a database read alone never yields readable content.
Separation of duties
Intake, triage, investigation and review are distinct roles. The permission model is grant-only, and every grant can be explained — the exact path by which a person has access to a thing.
Independent audit trail
Intake, every access, every status change and every message is written to an append-only log in your instance that your administrators — and your auditors — can read.
Restricted support access
Sanctis operators cannot enter a confidential-reporting tenancy by default. Access is approval-required or switched off entirely; any session is time-boxed and recorded on both sides.
Access & correction (APP 12/13)
The record and field model supports data subject access requests — locating, exporting and correcting the information held about an individual.
Hardened government configuration
An optional preset for agencies: mandatory single sign-on, IP allowlisting, a 15-minute idle timeout, restricted file uploads and customer-managed encryption keys.
Accessibility
The interface is built to WCAG 2.1 AA, the baseline for Australian government procurement.

One image, many isolated instances. Every customer runs the same reviewed build as a separate deployment with its own database, storage and keys. Modules are switched on per customer by signed entitlement — never by shipping different code.

Bringing confidential reporting into Sanctis?

We'll walk you through how the module is isolated, how intake works, and exactly what your auditors will see.

Talk to us