Frequently Asked Questions (FAQs)

Below are Safecall’s frequently asked questions about our whistleblowing software, hotline, training, investigations, security and processes.


Calls


Service

  • How do whistleblowing solutions ensure accessibility for all employees?

    True accessibility means removing every possible barrier that might prevent someone from speaking up about wrongdoing. This goes far beyond language translation to encompass physical disabilities, cultural barriers, technological limitations, and different communication preferences.

    Our multilingual service supporting 68+ languages is just the foundation. We also provide multiple reporting channels – phone, web-based, and written options – because people have different comfort levels with technology and communication methods.

    For employees with hearing impairments, we can provide text-based communication options and ensure our digital platforms are compatible with screen readers and other assistive technologies. Visual impairments are accommodated through high-contrast interfaces and audio options.

    We consider cultural accessibility too – some cultures may view direct confrontation or criticism differently, so our training and communication materials are adapted to work effectively across diverse cultural contexts.

    For shift workers or those in remote locations, our 24/7 availability ensures that reporting doesn’t depend on traditional office hours. This is particularly important for manufacturing, healthcare, and other industries with round-the-clock operations.

    We can also provide specialised support for employees with learning difficulties or literacy challenges, ensuring that everyone has a voice in maintaining workplace standards regardless of their communication abilities.

  • How do whistleblowing solutions support corporate governance?

    Effective whistleblowing is a cornerstone of good corporate governance, providing boards and executives with early warning systems for risks that could threaten the organisation’s reputation, financial performance, or legal compliance.

    Our comprehensive reporting and analytics give leadership teams visibility into the ethical climate of their organisation. This isn’t just about counting reports – it’s about understanding what the patterns tell you about your culture, risks, and management effectiveness.

    We provide boards with the insights they need to demonstrate to stakeholders – investors, regulators, customers – that they’re actively managing governance risks. Our independent status adds credibility to these assurances.

    Our case management platform supports board-level reporting with dashboards and metrics that help non-executive directors understand key governance trends without getting lost in operational details.

    We can also support governance committees by providing expertise on best practices, regulatory developments, and benchmarking against industry standards. The goal is to move beyond compliance to creating genuine transparency and accountability throughout the organisation.

  • How do whistleblowing systems help meet anti-corruption requirements?

    Anti-corruption compliance requires more than policies and training – it needs effective detection and response mechanisms. Whistleblowing systems are often the first line of defence against corruption, providing early warning before problems become crises.

    Our service helps organisations meet their obligations under various anti-corruption frameworks by providing secure channels for reporting suspicious activity, potential conflicts of interest, and other ethical concerns.

    We can customise reporting categories to align with specific anti-corruption risks in your industry and geography. This might include facilitation payments, kickbacks, nepotism, or other forms of corrupt practice.

    Our experienced call handlers understand how to handle corruption-related reports sensitively while gathering the information needed for effective investigation. They can identify when immediate action might be needed to prevent ongoing harm or preserve evidence.

    We also provide guidance on when corruption reports should be escalated to law enforcement or regulatory authorities, helping organisations balance their duty to investigate with their obligations to cooperate with authorities.

  • How do you assess the reliability of a whistleblowing service?

    When choosing a whistleblowing service provider, you’re essentially choosing a partner who will handle your most sensitive organisational risks. The stakes are too high for anything less than complete reliability.

    Look for proven track record and experience. We’ve been providing whistleblowing services since 1999 and have successfully managed tens of thousands of cases. This experience translates into knowledge of what works and what doesn’t.

    Professional qualifications matter. Our call handlers are all former UK police officers with over 25 years of investigative experience, licensed under the Private Security Industry Act. This isn’t just impressive credentials – it’s practical assurance that your cases will be handled professionally.

    Technical reliability is crucial. Our secure platform built on Microsoft Dynamics 365 ensures your data is protected and accessible when you need it. We’re GDPR compliant and meet the highest data protection standards.

    Look for transparency in reporting and analytics. A reliable service provider should give you clear insights into trends, resolution times, and case outcomes, not just basic statistics. Consider the provider’s financial stability and ownership structure. Being wholly owned by The Law Debenture Corporation PLC, a FTSE 250 company established in 1889, gives our clients confidence in our long-term stability.

  • How is whistleblower data stored and protected?

    Data security isn’t just important in whistleblowing – it’s absolutely critical. Breaches don’t just compromise information; they can destroy trust and put people at risk.

    We take pride in the security of all data received from confidential reporters as well as information supplied by client organisations. Our secure portal is built on Microsoft Dynamics 365, providing enterprise-grade security with robust access controls and encryption.

    We’re fully GDPR compliant, meeting the highest European standards for data protection. This compliance extends to all aspects of data handling, from collection through storage to eventual secure deletion.

    Our data retention policies ensure that information is kept only as long as necessary for legitimate business purposes, with secure deletion procedures when data is no longer needed.

    Access to whistleblowing data is strictly controlled, with audit trails showing exactly who has accessed what information and when. Only authorised personnel can view case details, and access is granted on a need-to-know basis.

    Our backup and disaster recovery procedures ensure that critical case information is protected against system failures while maintaining the same security standards for backed-up data.

  • Is the service expensive?

    The provision of the service is based upon the number of employees. A number of clients have immediately recouped the initial cost with the information provided by employees regarding fraud and other potentially expensive concerns. The system has hidden cost advantages such as the lessening of bullying and discrimination and can lead to significant savings in legal fees and damages awards. Even when an industrial tribunal case has been lost, the final settlement would be significantly reduced.

  • We already have an Employee Assistance Programme, what further advantages do you offer?

    We believe a difference exists between an assistance programme, which is in essence an advice line, and an external reporting line. A number of Employee Assistance Programmes provide advice on a wide range of subjects but due to confidentiality restraints, do not always pass information to employers.

  • We know our employees very well, why would we need your service?

    Experience has shown that it is normally long serving and trusted employees who present the biggest risk to organisations when it comes to fraud or financial misconduct in the workplace. These employees are fully aware of the organisation’s systems and processes;  research has shown that they are rarely questioned by management. 

    A leading international insurer established that over 80% of frauds or instances of financial misconduct were being committed by employees within their own organisation. 

    Further research identified that almost 48% of all instances of fraud and financial misconduct were detected by whistleblowing systems. Whistleblowing systems are by far the best method of detection, with internal and external audits resulting in detections of 19% and 10% respectively.

  • What about my suppliers and customers?

    Our philosophy is that if someone is calling us with information that could affect your business we will take the report. Many of our customers have extended the service to include suppliers, contractors, supply chain and in some cases customers.

  • What are the latest regulatory updates for whistleblowing compliance?

    The regulatory landscape for whistleblowing continues to evolve rapidly, with new requirements and updates emerging regularly across different jurisdictions. Key recent developments include:

    The EU Whistleblowing Directive implementation is now complete across member states, but individual countries are still refining their specific requirements. We monitor these changes closely to ensure our services remain compliant across all EU jurisdictions.

    In the UK, the Economic Crime and Corporate Transparency Act 2023 and the Workers Protection Act 2023 have created new obligations for organisations, particularly around harassment prevention and corporate accountability.

    Emerging markets are increasingly adopting comprehensive whistleblowing legislation, creating new compliance requirements for multinational organisations operating in these regions.

    We regularly update our compliance guidance and training materials to reflect these changes, ensuring our clients stay ahead of regulatory developments rather than scrambling to catch up after implementation deadlines.

    Stay tuned to our latest news section and training programmes for the most current regulatory updates affecting your industry and geography.

  • What impact does effective whistleblowing have on ethics and compliance?

    Effective whistleblowing transforms organisational culture by shifting from reactive damage control to proactive risk management. Through our work with over 1,000 organisations worldwide, we’ve seen firsthand how proper systems create lasting positive change.

    When employees see that concerns are taken seriously and lead to meaningful action, it sends a powerful message about organisational values. This creates a virtuous cycle where more people feel comfortable speaking up, leading to earlier detection and resolution of problems.

    Our analytics show that organisations with mature whistleblowing programmes experience faster resolution of ethical issues, reduced repeat incidents, and improved employee satisfaction scores related to organisational integrity.

    From a compliance perspective, effective whistleblowing provides documented evidence of an organisation’s commitment to ethical behaviour. This can be crucial in regulatory investigations or when demonstrating due diligence to stakeholders.

    The data generated through whistleblowing programmes also helps organisations identify training needs, policy gaps, and systemic issues that might not be visible through other means.

    The ultimate impact is cultural: organisations with effective whistleblowing systems develop stronger ethical climates where doing the right thing becomes the natural choice, not the difficult one.


Security


Reporting an Incident


Online


Training


Safecall Portal


Investigations


Technical

  • What are your exact SLA terms and penalty structures? 

    We offer comprehensive SLAs, typically covering: 

    • System availability (usually 99.9%) 
    • Response times based on priority levels 
    • Data security guarantees 

    Penalty structures and remedies are tailored to your organisation’s needs and the criticality of the service. Our contracts team can share detailed SLA frameworks and discuss appropriate penalty or credit structures during commercial negotiations. 

  • What are your specific database technologies and data retention policies? 

    We use enterprise-grade database technologies with built-in redundancy and encryption at rest. Our data retention policies are configurable to meet your regulatory and organisational requirements — typically ranging from 3 to 7 years, with secure deletion options. We can provide full documentation on data lifecycle management and work with your data governance team to ensure compliance. 

  • What backup and disaster recovery measures do you have?   

    We have robust availability controls to prevent data loss or destruction. These include: 

    • A comprehensive backup strategy (online/offline; on-site/off-site) 
    • Uninterruptible power supply (UPS) 
    • Virus protection and firewalls 
    • Documented reporting procedures 

    Our backup and disaster recovery plans are part of our ISO 27001 ISMS, independently verified by BSI UK. 

  • What case management features does your software include? 

    Our platform includes a wide range of case management tools, such as: 

    • Customised intake via web and hotline 
    • Custom field creation 
    • Case triage, routing, and delegation 
    • Risk assessment and outcomes tracking 
    • Remedial action and root cause analysis 
    • Classification, assignment, and task setting 
    • Metadata tagging and labelling 
    • Investigation checklists and templates 
    • Real-time anonymous chat 
    • Detailed analytics and dashboards for tracking and reporting 
  • What corporate backing supports your technical infrastructure? 

    Safecall is wholly owned by The Law Debenture Corporation p.l.c., established in 1889. Law Debenture has supported blue chip and government organisations globally for over 120 years, with trusted data handling and IT systems. All Safecall systems are hosted within the Microsoft Azure high-availability cloud, based in the UK, offering industry-leading availability and security. 

  • What customisation options are available?   

    We offer a range of customisation options to suit your organisation’s needs. Costs vary depending on factors such as complexity, number of users, and level of customisation. Out-of-the-box options include: 

    • Intake forms 
    • Landing pages 
    • Hotlines (e.g. dedicated numbers, language options, messaging) 
    • Processing routes and workflows 
    • Notifications 
    • Investigation workflows 
  • What data entry controls do you have?   

    We use verification systems to track who enters, changes, or deletes personal data within our processing systems. This includes logging and document management to maintain accountability and data integrity. 

  • What encryption standards do you use for data protection?   

    We use AES256 encryption to protect data at rest, alongside Transport Layer Security (TLSv2) for all connections and public endpoints. These are recognised industry standards designed to keep your data secure. 

  • What implementation timeline can we expect?   

    Setting up the whistleblowing hotline is straightforward — we’ve launched confidential telephone lines for clients in as little as 24 hours. The key differentiating timescale factors are due diligence, authorisation, process completion and size and complexity of the organisation’s needs. An SME might take just 24 hours, but a global solution across ten countries, with 30+ languages and management software implementation will naturally take longer.

  • What security certifications and compliance standards do you maintain?   

    Safecall is certified to ISO27001 by BSI UK. Our infrastructure also meets compliance standards including HIPAA, FedRAMP, SOC1, SOC2, UK G-Cloud, ISO 9001, ISO 37001, and ISO 27001. 

  • What specific hardware specifications and network architecture support your platform? 

    For security reasons, we don’t publicly share detailed infrastructure specifications. However, our UK-based data centres use enterprise-grade hardware, with redundant systems, multiple network paths, and high availability guarantees. We also implement load balancing, failover mechanisms, and capacity planning to ensure performance and resilience. If needed, our technical team can provide more detailed information during a confidential technical briefing. 

  • What specific incident response procedures do you have in place? 

    We follow comprehensive incident response procedures aligned with ISO 27001, including clearly defined escalation paths, communication protocols, and recovery processes. Our response team includes both internal security specialists and external forensic partners when needed. We can share our incident response framework and discuss notification timelines and procedures during a security briefing. 

  • What sub-processors do you work with for technical services?   

    We work with trusted sub-processors for technical services, including: 

    • Microsoft Ireland Operations Ltd 
    • Mimecast Services Ltd 
    • CrowdStrike UK Ltd 
    • Systran S.A. 

    Each provider is carefully selected to support our infrastructure and maintain high security standards. 

  • What technical expertise do your staff possess? 

    Safecall call handlers have a minimum of 25 years’ investigative experience. They are licensed under the Private Security Industry Act 2001 and trained in investigations, interviews, and evidence handling. 

  • What user experience design principles do you follow? 

    We follow modern UX design principles to ensure our software is intuitive and easy to navigate. All online intake forms are WCAG 2.2 compliant, with a range of accessibility options to support diverse user needs. 

  • Where are your data centres located?   

    All our data centres are based in the UK, ensuring full compliance with GDPR. We apply strict data protection measures covering retention, security, and redaction.