Confidentiality you can inspect, not just believe.
Privacy-first by architecture: the protections reporters depend on are structural decisions in the platform, documented and reviewable, not promises in a policy.
Four decisions made in the architecture, where a policy cannot reach.
Anonymous by default
No employee identifier, no IP address, no device fingerprint. Identity is never inferred. ARIA identifies itself as automated and never asks who the reporter is unless they choose to say.
Follow-up without exposure
Each submission returns a reference number and an access code. The reporter can check status, add information, or answer a follow-up question through a two-way channel, without identifying themselves.
Conflict-free routing
Anyone named in a report is excluded from its review path automatically, including from notifications. The exclusion is applied by the platform and recorded in the audit log.
Access is narrow and logged
Reviewers see only what their role, category, and location permit. Restricted categories narrow the audience further. Opening a case is itself an auditable event.
How the data is handled.
Encryption
Data encrypted in transit and at rest, in the region you select.
Data residency
Hosted in the United States by default, with a Canadian residency option. Data stays in the region you choose.
Subprocessors
The subprocessor list is available on request and kept current: documentation transparency by default.
Role-scoped access
Access by role, category, and location, with restricted categories for sensitive matters. Every access logged.
Retention controls
Case data is retained 6 years on Basic and Voice with automatic scheduled export, and to your record policy on Enterprise. Retention is configured by your admins to your policy, applied consistently and recorded.
Exit without lock-in
Full case history, attachments, and audit logs export in standard structured and document formats.
Anonymity, stated honestly, including its limits.
A reporting program earns trust by being exact about what anonymity protects, where it stops, and how the platform behaves at those edges.
Employee identifiers, IP addresses, device fingerprints, and network metadata are not captured for anonymous reports. The system is built so those signals are never gathered in the first place, which means there is nothing to disclose later, under subpoena or otherwise.
Whether to share a name, how much detail to give, and whether to answer follow-up questions. Those choices sit with the reporter at intake and for the life of the case, and no reviewer setting can override them.
Anonymity protects identifiers, not content. A report describing a specific incident in a specific place can narrow who could have written it, and no platform can prevent that. Reporters see this stated plainly at intake, so the choice they make is an informed one.