The reporting channel your law already requires. Built and run by us.
Every EU member state now obliges employers with 50 or more workers to operate an internal channel for reports of wrongdoing. We set one up for your organisation, in your languages, and we operate it under a data processing agreement. Your designated person decides what happens.
A supplier was told to keep quiet about a failed pressure test on line two. The shift report was changed the next morning.
Illustration of the case view. The category and severity are a suggestion. A person on your side always decides, and no automated decision is taken about anyone.
A duty since 2023, in every member state, with real consequences.
Directive (EU) 2019/1937 required all 27 member states to oblige private employers with 50 or more workers to run internal reporting channels. Larger employers were caught first, smaller ones from December 2023. Each country wrote its own law, with its own authority, its own penalties and its own rules on anonymous reports.
A shared mailbox is not a channel
Email is not confidential in the sense the directive uses, it cannot take an anonymous report while keeping a dialogue open, and it leaves no record that the deadlines were met.
The clock starts on receipt
Acknowledge within seven days, appoint an impartial person to follow up, give feedback within three months. Those three deadlines are where most in-house arrangements come apart.
Retaliation is the expensive part
Penalties for missing the channel differ by country. The larger exposure is a penalisation claim from someone who reported and had nowhere safe to do it.
Three steps, and the third one is yours.
Someone reports
A page in your own design, reachable from a poster, an intranet link or a supplier contract. In writing, named or anonymous, in whatever language the person writes in. Where your law or your works council wants a spoken route as well, we add a voicemail intake.
The system prepares the case
The report is encrypted before it leaves the browser. A suggested category and severity, the deadlines, and a secure two way channel back to the reporter are ready before your team opens it.
Your person decides
Only the impartial person you designate can read the report and decide what happens. No one at Lacop Systems reads reports. Every step is logged for the audit you may one day have to show.
Four systems. One team that builds and runs them.
We are software engineers, not a reseller and not a law firm. Everything below is written by us and operated by us, which is why we can change it to fit the way your organisation actually works.
Speak-Up channel →
The internal reporting channel required by Directive (EU) 2019/1937 and your national law. Anonymous or named, end to end encrypted, deadline tracking, secure dialogue, exportable case file. Reachable by staff and, where your law asks for it, by agents and suppliers.
Phishing simulation and awareness →
Realistic phishing campaigns against your own staff, run lawfully: aggregated results, no naming of individuals, works council material prepared. Short training that follows the campaign, in the languages your people actually speak.
Accessibility work →
The European Accessibility Act has applied since 28 June 2025 to consumer facing services including e-commerce. We audit against EN 301 549 and WCAG, fix what fails in your code, and write the information your customers are entitled to.
Custom engineering →
The internal tools that compliance work leaves behind: registers, approvals, supplier portals, integrations with the systems you already run. Built to the same standard as the channel, hosted in the EU, handed over with the source.
Custody is the whole product.
A reporting channel is only used if the person using it believes it is safe. These are design decisions, not settings, and they do not change per customer.
Encrypted before it leaves the browser
Report text and attachments are encrypted client side with AES-256-GCM, with a separate key per case. The stored record is ciphertext.
Nothing that identifies an anonymous reporter
No IP address stored, no tracking cookies, no browser fingerprinting, no analytics on the reporting page. The reporter keeps a token and can come back to the conversation.
Your designated person holds the keys
Only the impartial person you appoint can open a case. No one at Lacop Systems reads reports, and our access to your instance is limited to operating it.
Hosted in Germany
Data stays on servers inside the European Union. No transfer to a third country as part of normal operation, stated in the processing agreement.
A processing agreement before anything goes live
Article 28 GDPR agreement, our sub-processors listed, retention set to what your national law requires, deletion on schedule.
An audit trail you can hand over
Every action stamped and exportable as a case file, so you can show a regulator or a court that the seven day and three month deadlines were met.
A small Austrian engineering firm, on purpose.
Lacop Studio OG is registered in Wels, Austria under FN 659759i. Lacop Systems is the part of it that builds compliance systems. It is run by its two partners, Constantin Claus Pavel and Lazar Peric, so you deal with the people who wrote the software, and the answer to "can it do this" is usually yes, because we can change it.
- We write the code ourselves. No white labelled platform behind the logo.
- We operate what we build, so support is not a ticket queue in another time zone.
- We do not read your reports and we do not sell data. There is nothing to sell.
- We say what we do not know. Legal questions go to your counsel, not to a sales deck.
See it running on your own case, not on a slide.
Thirty minutes, two engineers, your questions on data protection answered on the call. No obligation and no sales script.