
GlobaLeaks
Secure whistleblowing and anonymous reporting platform
GlobaLeaks is free and open-source whistleblowing software for creating secure reporting portals where people can submit information while protecting their identity. It is designed as a flexible framework and is widely used by media organizations, NGOs, and institutions to receive and manage sensitive reports.
Key Features
- Anonymous reporting workflow designed to protect the whistleblower’s privacy by default
- Customizable multi-tenant style configuration to adapt forms, questionnaires, and processes to different initiatives
- Case management interface for recipients to review submissions and communicate securely
- Internationalization with extensive localization (translated into many languages)
- Security-focused design for hardening deployments and reducing metadata leakage
- Compliance-oriented deployments suitable for common whistleblowing program requirements
Use Cases
- Internal or external whistleblowing channels for public agencies and companies
- Secure tip lines for investigative journalism and independent media
- Reporting platforms for civil society, anti-corruption, and human-rights initiatives
Limitations and Considerations
- Operating a safe whistleblowing channel requires careful deployment hardening and ongoing maintenance to avoid misconfiguration risks
- Legal and compliance obligations vary by jurisdiction and may require additional organizational processes beyond the software
GlobaLeaks provides a strong foundation for running privacy-preserving reporting programs with configurable workflows and a security-first approach. It is best suited for organizations that need an auditable, structured way to receive and handle sensitive disclosures.
Categories:
Tags:
Tech Stack:
Similar Services
Web-Check
All-in-one OSINT tool for analyzing any website.
Comprehensive on-demand OSINT to analyze a website's security, architecture, and tech stack.

SafeLine
Self-hosted WAF and reverse proxy for securing web apps
SafeLine is a self-hosted Web Application Firewall (WAF) and reverse proxy that defends web apps from SQL injection, XSS, bot abuse, and DDoS using ML-powered threat dete...

Fail2Ban
Log-monitoring daemon that bans abusive IPs via firewall rules
Fail2Ban monitors service logs for repeated failures and automatically bans abusive IP addresses by updating firewall rules for a configurable time.
CrowdSec
Crowdsourced IDS/IPS and WAF with shared malicious IP intelligence
CrowdSec is an open-source security engine that detects attacks from logs and blocks malicious IPs using bouncers and community-curated threat intelligence.

Graylog
Centralized log management and analysis platform
Graylog is an open source platform for collecting, indexing, searching, and alerting on logs and machine data from many sources in one place.

OneUptime
Open-source monitoring, incident management, and observability platform
Self-hostable observability platform for uptime monitoring, alerting, incident management, on-call, status pages, logs, and APM in one integrated suite.
Angular
Docker
TypeScript
Python
Bootstrap