GlobaLeaks, an open source whistleblowing platform for confidential reporting, with encrypted intake and two way anonymous follow up.
GlobaLeaks is a free and open source whistleblowing platform used by news organisations, NGOs, corporates and public bodies to receive confidential reports. Reporters submit through a web questionnaire without creating an account and are given a 16 digit access code they can use to return to their case, read replies from your team and add further information, which makes genuine two way follow up possible even when the reporter stays anonymous. Reports are encrypted and delivered to named recipients, so only the people you designate can read them. Role separation between administrator, recipient, custodian and analyst, configurable questionnaires and reporting channels, file attachments, per report retention and a full audit log make it a common choice for organisations running an EU Whistleblowing Directive compliance programme or any confidential disclosure channel.
The cloudimg image is secure by default and ships with no account of any kind: GlobaLeaks creates the administrator only inside its first run setup wizard, so you choose the username and password yourself and there is no vendor default to rotate. Every instance generates its own platform database, receipt salt, node identity and TLS certificate on first boot, so no two deployments share cryptographic material. HTTPS works from the very first visit using that per instance certificate, and the admin panel switches to a trusted certificate through ACME whenever you are ready. The optional Tor onion service is deliberately switched off so the appliance is HTTPS only out of the box, and a shipped self check command proves that posture on demand. Installed from the official upstream package repository so you keep receiving upstream security updates, fully patched, with a paired deploy guide and 24/7 cloudimg support.
Real screenshots taken while testing this image against its deployment guide.