Trust & Security

Confidentiality you can inspect, not just believe.

Privacy-first by architecture: the protections reporters depend on are structural decisions in the platform, documented and reviewable, not promises in a policy.

01 · Built in, not promised

Four decisions made in the architecture, where a policy cannot reach.

01

Anonymous by default

No employee identifier, no IP address, no device fingerprint. Identity is never inferred. ARIA identifies itself as automated and never asks who the reporter is unless they choose to say.

02

Follow-up without exposure

Each submission returns a reference number and an access code. The reporter can check status, add information, or answer a follow-up question through a two-way channel, without identifying themselves.

03

Conflict-free routing

Anyone named in a report is excluded from its review path automatically, including from notifications. The exclusion is applied by the platform and recorded in the audit log.

04

Access is narrow and logged

Reviewers see only what their role, category, and location permit. Restricted categories narrow the audience further. Opening a case is itself an auditable event.

02 · Security practices

How the data is handled.

Encryption

Data encrypted in transit and at rest, in the region you select.

Data residency

Hosted in the United States by default, with a Canadian residency option. Data stays in the region you choose.

Subprocessors

The subprocessor list is available on request and kept current: documentation transparency by default.

Role-scoped access

Access by role, category, and location, with restricted categories for sensitive matters. Every access logged.

Retention controls

Case data is retained 6 years on Basic and Voice with automatic scheduled export, and to your record policy on Enterprise. Retention is configured by your admins to your policy, applied consistently and recorded.

Exit without lock-in

Full case history, attachments, and audit logs export in standard structured and document formats.

03 · Straight answers

Anonymity, stated honestly, including its limits.

A reporting program earns trust by being exact about what anonymity protects, where it stops, and how the platform behaves at those edges.

Never collectedWhat the platform never gathers

Employee identifiers, IP addresses, device fingerprints, and network metadata are not captured for anonymous reports. The system is built so those signals are never gathered in the first place, which means there is nothing to disclose later, under subpoena or otherwise.

Reporter decidesWhat stays in the reporter's hands

Whether to share a name, how much detail to give, and whether to answer follow-up questions. Those choices sit with the reporter at intake and for the life of the case, and no reviewer setting can override them.

The honest limit

Anonymity protects identifiers, not content. A report describing a specific incident in a specific place can narrow who could have written it, and no platform can prevent that. Reporters see this stated plainly at intake, so the choice they make is an informed one.

04 · Governance & compliance

Clear boundaries. No ambiguity. Every framework, mapped.

See the industry configurations →
OIG Compliance ProgramSeven elements
ARIA providesA confidential, anonymous reporting channel that satisfies the open-lines-of-communication element, with documented intake, routing, and response.
You retainThe remaining six elements: written standards, compliance leadership, training, auditing, discipline, and corrective action.
Sarbanes-Oxley (SOX)Whistleblower mechanism
ARIA providesA secure, anonymous whistleblower mechanism with two-way follow-up and a complete audit trail for accounting and audit concerns.
You retainAudit committee oversight of the channel and the disposition of each report.
State Reporting LawsStatutory timelines
ARIA providesConfigurable categories, severity levels, and routing that support your statutory timelines and reporting workflows.
You retainThe legal determination of what must be reported externally, and when.
Security ControlsMapped in your agreement
ARIA providesEncryption in transit and at rest, role-scoped access, multi-factor authentication, logged administrative actions, and documented incident response.
You retainReviewer access management and credential hygiene within your own environment.
The safeguards matrix in your service agreement maps each control to its ISO 27001 and NIST CSF reference. Records are complete from the moment of intake, with no reconstruction required at audit.