Prototypes Prototype docsP11 · Docs and assistant
Whistleblower channel (P7)
DocsPage 8 of 30

Whistleblower channel (P7)

An anonymous report, a case handler's inbox, and a conversation that the reporter reopens with a receipt code.

The receipt code

The reporter's page makes a receipt code of 80 random bits, written as 16 letters and digits in four groups. PBKDF2 with 200,000 rounds turns the code into two values: the case number and the case key. The server never sees the code, so it cannot find a case from a person or a person from a case.

The report

The report is encrypted with the case key. The case key is also wrapped for the organization's public key, so the case handler can open the case with the organization's private key, which is kept in the handler's browser.

The conversation

The case handler answers in the same case, encrypted with the case key, and can set the status to Received, In review or Closed. The reporter types the code on the page Your report, reads the answer and writes back. A wrong code opens nothing.

What is stored

The case number, the wrapped key, the status, the times and ciphertext. No name, email, address or receipt code.

Previous: Client portal (P6). Next: Offline inspections (P8).

How Prototype docs is built

The pages are written in Markdown and built into these pages and an index of 154 sections. The assistant answers from the index, and every answer names the sections it was taken from.