Security & Privacy
Security you control
ISO 27001 certified and GDPR compliant. Your team sets encryption, hosting region and case access across reporting, investigations and cases.
RUN BY COMPLIANCE TEAMS WORLDWIDE
Secure, anonymous solutions
Anonymity
Reporters can choose to remain completely anonymous.
Data protection
ISO 27001 certified, GDPR compliant and hosted in the region you choose.
Encryption
All communication can be protected with end-to-end encryption (E2EE).
Data protection in detail
Each control below is one your team sets in its own settings: the encryption mode, the hosting region and who sees each case.
Anonymity by design for reporters
Reporters can report without giving their name, and no device ID is linked to a report. Attachment metadata is stripped, reporters' IP addresses aren't logged, and voice messages are altered. A private case key lets them follow up without an account. The reporting form makes no calls to external sites.
You decide who sees each case
FaceUp is GDPR compliant. Your team sets access per member and can change it for a single case, so a person named in a report can be removed from it. Data is stored on Amazon Web Services. Add single sign-on or two-factor authentication to control sign-in.
Choose your encryption mode
Standard encryption is on by default, backups included. Switch on end-to-end encryption and all data is also encrypted with each member's password.
Certifications you can check
FaceUp's information security management system is ISO 27001 certified, and FaceUp is GDPR compliant. Your data is hosted on SOC 2 certified AWS infrastructure.
Tested against cyber threats
FaceUp undergoes regular penetration testing and continuous code security testing to protect against cyber threats.
You choose where data is hosted
Choose where data is stored: AWS regions in the United States, the European Union, the United Arab Emirates or Australia. We recommend one based on your location, and you can pick another.