I

Your anonymity · What we hold

We do not retain what would let us identify a reporter.

Not “we cannot identify you”, and not “we will not look”. Every claim on this page is a claim about what we keep, because what we keep is a fact about our schema that can be checked, and what we could compute is a prediction about every future court order and every future owner of this company.

What is never kept

You can report with no account and no email address at all. No verification data of any kind is retained. No IP address is kept anywhere in our stack — though our upstream CDN and cloud provider hold flow records we neither control nor can audit, which we say here rather than claim otherwise.

Employment attestation

Attestation is verified and destroyed. The service that sees your work address issues a blind signature and never sees your report; the service that receives your report never sees the address.

II

The split

Two services that cannot be joined.

A Verifier sees an employment address and issues an unlinkable token. A Collector receives the token, the signature and the structured claim. Neither holds both halves, and there is no join key between them — by design, not by policy.

  • Per-epoch keys held non-exportably in an HSM, destroyed at the end of the epoch.
  • Nothing publishes below a minimum cell size, so no published figure can be narrowed to one person.
  • Complementary suppression: if one cell in a row is suppressed, a second is too, so the suppressed value cannot be recovered by subtraction.
  • A signed, dated warrant canary published at a fixed cadence.

III

The residual exceptions, and what we cannot promise

Where the promise is narrower than it sounds, we say so here.

Between a report arriving and the epoch key being destroyed there is a window in which a live key exists. A compelled production served inside that window against that specific key is the one case the architecture does not fully close. We publish the window length and we publish every demand we receive.

  • The verification email arrives in a mailbox the employer administers. That log is the employer’s record, not ours, and no architecture of ours reaches it.
  • We cannot promise that nobody can infer who you are from what we publish. In a team of three, inference beats architecture — and it is least true early, when a corpus is thin and cells sit at the floor rather than comfortably above it.
  • We cannot promise that free text cannot be attributed to you by writing style. Against an employer holding years of your messages, authorship attribution is close to solved.
  • We cannot promise that re-identification can be undone. Retraction removes the page, never the knowledge — not from a reader, a screenshot or a search index.

Every one of these sits with the promise it qualifies rather than in a footnote, because a privacy claim with an unstated exception is a privacy claim that will be broken in public. The three we cannot make are the ones every competitor implies it has solved.