Go to navigation Go to content Go to footer

Our security standards: Protection is our top priority.

Learn how we protect your sensitive information and the high standards to which our security practices adhere.

Physical security

Even though our main priority is digital security, we don't neglect the physical protection of your data:

  • Access Control: Our facilities have controlled access. Only authorized personnel have access to sensitive areas to ensure optimal security.
  • 24/7 Surveillance: Our premises are constantly monitored to ensure that no irregularities or security breaches occur.
  • Specialized Storage: Your data is stored in specially designed and protected areas that meet the highest security standards.

Regardless of how secure our digital protocols are, we understand the value of physical security measures and consistently implement them.

Application security

In today's digital world, application security is essential. At WhistleTube, we understand this and are committed to developing secure and reliable software solutions.

Our approach:

  • Teamwork: Application security is not a solo task for us; it's a shared responsibility. Our entire development team is involved in the process and continually undergoes training.
  • Quality Assurance: Every piece of code we write undergoes thorough reviews. We rely on both automated and manual testing to identify potential vulnerabilities early.
  • Vigilant Examination: Through a combination of internal reviews and external penetration testing, we ensure that our applications meet current security standards.
  • Continuous Improvement: The cybersecurity landscape is constantly evolving. Therefore, we regularly review and update our practices to stay up to date with the latest developments.

At WhistleTube, we believe that security is not just a technical feature but also a core value. That's why we consistently work to provide you and your customers with a secure and trustworthy user experience.

Network security

At WhistleTube, the security of your data, especially when transmitted over the internet, is of the utmost importance. We employ advanced technologies and practices to ensure that your data is always protected from prying eyes:

  • Transport Security: To ensure the integrity and confidentiality of your data during its transmission, we rely on the most cutting-edge transport encryption protocols. This technology ensures that your data is protected from unauthorized access and tampering during its journey through the network.
  • End-to-End Encryption: Our offering of end-to-end encryption means that your data is already encrypted on your device and is only decrypted at the intended recipient. This preserves confidentiality even in a compromised network.
  • Continuous Monitoring: Through ongoing network monitoring, we detect potential anomalies or unwanted activities in real-time. This enables us to proactively respond and neutralize threats before they can cause harm.
  • Updates and Training: In addition to technical security measures, regular software updates and employee training ensure that we stay up-to-date with network security best practices.

With these measures, we at WhistleTube ensure that your data transmission is as secure as possible, allowing you to use our services with confidence.

Data privacy

At WhistleTube, we prioritize the security of your data. All data transmissions between you and WhistleTube are protected by state-of-the-art SSL encryption to ensure that your data cannot be intercepted or manipulated during transport.

The end-to-end encryption we employ already ensures that we, as a platform, have no access to the content of your data. In addition to this security measure, we implement an additional layer of encryption before data is sent to our database. This underscores our commitment to ensuring the integrity and protection of your data at all times. All this data is exclusively stored on servers in Germany that adhere to the highest security standards.

In terms of data privacy, WhistleTube is committed to strict compliance with German data protection regulations.

Compliance

In a world where responsibility and integrity set the tone, compliance is a cornerstone for businesses and organizations. It represents a conscious commitment to meet ethical standards, legal regulations, and industry guidelines. Compliance goes beyond mere adherence; it embodies the dedication to act transparently, minimize risks, and strengthen the trust of customers, partners, and society as a whole. In today's complex business landscape, compliance is more than a rule; it is a promise that lays the foundation for sustainable success.

Data secutiry

At WhistleTube, your data is always protected, both during transmission and storage. Our platform utilizes state-of-the-art end-to-end encryption to ensure that your communication remains private. During transmission, we employ advanced encryption methods, and the data stored on our servers remains in an encrypted state.

Hosting

They are exclusively hosted in the Planetary data center in Germany. We rigorously adhere to all local data protection regulations.

Access security

We respect and uphold your data sovereignty. All data is solely owned by our customers. We use it exclusively to provide our services to you and to perform necessary maintenance. Through stringent access controls, we ensure that unauthorized individuals have no access to your data. Even our technical staff cannot access it. It's worth highlighting that anonymously submitted reports from whistleblowers are transmitted using end-to-end encryption, ensuring that even we as a platform have no insight into these reports.

Authentication at Whistletube relies on a three-tier security measure: password login, two-factor authentication (2FA), and a secret key. When a person creates a new organization (tenant), sole access to that organization and its reports belongs exclusively to that person. Only when the original creator invites other individuals to the organization do they gain access as well. This guarantees the highest level of discretion and tailored access control for our users

Security management

Whistletube is not responsible for security management. The primary responsibility for security within your organization lies with you. Anyone invited into your organization gains access to the reports, and this access remains in place until the individual is actively removed from the organization. Therefore, it's crucial to carefully consider whom you grant access to and regularly review membership to minimize risks from internal employees.

Whistletube recommends and supports multi-factor authentication, including the use of passwords, two-factor authentication (2FA), and a secret key. While we provide the tools and guidelines for such comprehensive security practices, the consistent implementation and monitoring are in the hands of your organization.

Availability

At Whistletube, we make every effort to ensure that our platform is always available and operational. Our architecture utilizes redundant systems to guarantee maximum uptime. Thanks to continuous monitoring, regular integrity checks, and comprehensive data backups, we minimize the risk of outages and, thus, ensure a reliable and stable service.

Password security

At Whistletube, we place a high emphasis on strong passwords. We employ a password strength verification method developed by Dropbox to ensure that no insecure or commonly used passwords are accepted. As you enter your password, you'll receive continuous feedback on its complexity and security, ensuring optimal protection.

Partnership

In the dynamic world of business solutions, the choice of a trusted partner is essential. Our company boasts an outstanding track record, marked by consistently delivering excellent and robust solutions tailored to the individual needs and expectations of our clients. We are committed not only to meeting current requirements but also to placing great importance on innovation and continuous improvement to ensure that our solutions can tackle future challenges.

Although Whistletube was founded in 2023, it is a sister company of TPWD, which has been in existence for over 20 years, providing software solutions to clients across various sectors. For more information about TPWD, please visit: tpwd.de