Skip to content

The law requires a channel. Trust requires more.

WayIntegrity is the internal reporting channel and case-management system the law requires — anonymity by design, access restricted to those who genuinely need it, and an audit trail that lets you demonstrate every step from first contact to closure.

  • Municipalities
  • Public entities
  • Companies with 50+ employees
  • Port and utility operators
  • Multi-entity groups

Where a whistleblowing channel usually fails.

It almost never fails for want of a written policy. It fails at intake, at trust, and at proof.

inbox auditable channel

with a case number, deadlines and a record

Reports arriving through the wrong door

The real route is a director’s personal inbox, an envelope at reception, or a conversation in a corridor. No acknowledgement, no clock running, and nothing that survives the departure of whoever received it.

With WayIntegrity

One encrypted point of entry, with a case number, an acknowledgement and system-tracked deadlines — including reports received by other means, which get logged into the same case file.

promise technical guarantee

anonymity enforced by the architecture

Anonymity promised, not guaranteed

Forms behind corporate SSO, invitations by internal email, IP logs on the server. Anyone who knows the infrastructure does not believe the promise — so they report externally, or not at all.

With WayIntegrity

Submission requires no account and no authentication, and the system never stores what would allow re-identification. Follow-up runs on a code issued at submission time, held only by the reporter.

reconstruct export

a case timeline ready to hand over

Scattered proof when the audit arrives

Who read the case, when, on what grounds and what they decided is spread across mailboxes and shared drives. The timeline gets reconstructed after the fact — which is precisely why it can be disputed.

With WayIntegrity

Every read, classification, decision and status change is recorded with author and timestamp in chained records where any retroactive edit is detectable. The case timeline exports exactly as it stands.

Trust

Nobody reports through a channel they do not trust — and trust is built, not declared.

Four building blocks over one case record.

The modules share the same case model, the same roles and the same audit trail, so scope can grow without migrating anything.

Report intake

The point of entry, designed for people who are afraid to use it — anonymous or identified, at the reporter’s choice.

  • Web form with no account and no authentication, in several languages
  • Secure code-based inbox for follow-up questions
  • Logging of verbal, in-person and otherwise received reports

Case handling and deadlines

The investigation itself, with access limited to those who must see it and the statutory clocks visible while they run.

  • Statutory acknowledgement and response deadlines tracked by the system
  • Triage, classification by breach type and routing
  • Per-case access, restricted to strict need-to-know

Compliance registers

The registers an audit asks for right after the channel: conflicts of interest, gifts, policy attestations, risks and mitigations.

  • Conflict-of-interest and gifts-and-hospitality registers
  • Policy and code-of-conduct attestations with proof of reading
  • Risk-prevention plan with owners assigned to each measure

Audit trail and reporting

Everything that happens on the platform is evidence, and evidence has to leave the platform in a usable form.

  • Chained, tamper-evident record of every action
  • Case-timeline export for auditors or authorities
  • Aggregate reporting for management and the board

From legal framing to operation in five steps.

The hard part is not installing the channel: it is deciding who receives, who investigates and who decides — and being able to defend that decision.

  1. Legal framing and scope

    We identify the entities involved, the obligations that apply to each, and what each one has to be able to demonstrate.

  2. Roles and conflict rules

    We define who receives, who investigates and who decides, with deputies and recusal rules for cases involving the hierarchy itself.

  3. Channel and policy configuration

    We switch on the channel, the forms, the deadlines and the compliance registers, aligned with the internal policies already approved.

  4. Communication and training

    Internal awareness material and training for the receiving team, including an end-to-end dry run on a fictional case.

  5. Operation and annual review

    Deadline monitoring, statistics for management reporting, and an annual review of the channel with the compliance team.

Built from the legal obligation, not from good intentions.

For many organizations an internal reporting channel is not optional. The product starts from that requirement — and from what has to be proven afterwards.

Lei 93/2021
Portuguese whistleblower-protection regime
Directive (EU) 2019/1937
Protection of people reporting breaches of EU law
RGPC · DL 109-E/2021
Prevention plan · code of conduct · channel
GDPR
Minimization · retention · data-subject rights
ISO 37002
Aligned with whistleblowing management guidance
ISO 37301
Aligned with compliance management requirements

No published references. Verifiable commitments instead.

A whistleblowing channel is not sold on client testimonials — confidentiality is the product. What can be shown is how it is built and what we hold ourselves to.

Anonymity by design

Anonymity does not rest on a promise in an internal policy: it rests on what the system never stores in the first place.

  • Submission with no account, no authentication and no email invitation
  • The application records no IP, session or device fingerprint
  • Follow-up through an access code held only by the reporter

Tamper-evident audit trail

Every read, decision and status change is recorded in chained form — administrative actions included.

  • Append-only records, cryptographically chained
  • Any retroactive change is detectable when the trail is verified
  • Administration and support access logged like any other action

Data residency and retention

Data stays on your own infrastructure and nowhere else — no cloud edition of ours, no third-country transfers — and stays no longer than it needs to.

  • On-premise installation only, with no third-country transfers
  • Retention periods per case type, with effective deletion
  • Encryption in transit and at rest, with documented key management

Role separation and incident response

Whoever receives does not decide alone, the vendor is not a party to the case, and an incident has a procedure before it happens.

  • Segregation between intake, investigation and decision, with recusals
  • No Waymotion access to case content by default
  • Periodic penetration testing and a documented incident-response procedure

One entity or a whole group, under your governance.

The architecture is multi-entity: each entity with its own channel, deadlines and owners, and no cases shared between them.

On-premise, in your custody

The channel and the cases stay inside your infrastructure where governance or the sector demands it — and verifying the audit trail remains yours to do.

Multi-entity on one installation

Each entity in the group with its own channel, deadlines and owners, and no shared cases — all inside the perimeter you already control.

Commercial model

Foundation setup, plus an annual subscription.

Foundation setup

Legal framing, role and recusal model, configuration of the channel, deadlines and compliance registers, internal communication material and training for the receiving team.

Annual operations subscription

Support, tracking of regulatory change, evolution of the registers and reporting, and an annual review of the channel with the compliance team.

What people ask us before committing.

Is the anonymity real, or just a checkbox on the form?

It is technically enforced: submission requires no account or authentication, and the system stores no IP, session identifier or device fingerprint. What no platform can guarantee is the content — a highly specific account can identify its author, and the form says so before submission. If a reporter chooses to identify themselves, that identity is restricted to the people handling the case.

Where is the data hosted?

On your own infrastructure, and only there: WayIntegrity is installed on-premise exclusively. There is no cloud edition managed by us, there are no third-country transfers, and case content never leaves your perimeter.

Does it work for a group with several entities?

Yes. Each entity has its own channel, deadlines and owners, and cases are not visible across entities; consolidation exists only as aggregate statistics for the group. The law does allow entities to share resources under certain conditions — we validate that case by case rather than assuming it.

Can Waymotion see the reports?

No. Because the installation is on-premise, case content sits on your infrastructure and we have no access to it. A support intervention requires you to grant access explicitly and for a limited time, and it is written to the same audit trail as every other action.

How long until the channel is live?

The technical configuration is quick; what sets the calendar is your internal decision on roles, recusals and policies. With those decided, a live channel with active deadlines is a realistic goal within a few weeks. The compliance registers and management reporting usually follow in a second phase.

Are you certified against ISO 37002 and ISO 37301?

No, and it matters to be clear about that: the product is built in line with those standards’ process requirements, but we do not sell certifications. Certification, where it makes sense, belongs to the organization operating the channel — not to the software vendor. We support that preparation with system documentation and the evidence the platform produces.

WayIntegrity — Recovery and Resilience Plan (PRR)

An operation supported by the PRR, Portugal’s Recovery and Resilience Plan, funded by the European Union through NextGenerationEU.

Project designation
New digital product – “WayIntegrity”
Beneficiary
Waymotion, Lda.
Investment
TD-C16-i02 — Transição Digital das Empresas Digital Transition of Enterprises.
Measure
Vales Startups – Novos Produtos Verdes e Digitais Startup Vouchers – New Green and Digital Products.
Objective
Desenvolvimento de uma nova solução digital Cloud/SaaS destinada à digitalização e gestão de processos de integridade e conformidade. Development of a new Cloud/SaaS digital solution for digitalising and managing integrity and compliance processes.
Result
Desenvolvimento e disponibilização do novo produto digital WayIntegrity. Development and release of the new WayIntegrity digital product.
PRR incentive
€30.000 Thirty thousand euro.
Official funding bar: PRR — Plano de Recuperação e Resiliência, República Portuguesa, and Financiado pela União Europeia — NextGenerationEU (Funded by the European Union).

More about the Recovery and Resilience Plan at Recuperar Portugal.