Ashio
Estonian-registered whistleblowing SaaS with 18 site locales, a law page per market, client-side encryption, and one €23–30/month plan that includes every feature.
This vendor applies AI or machine learning to whistleblower reports (for example summarisation, severity or category classification, drafting replies, or machine translation). Automated processing of disclosures can bring the deployment within scope of the EU AI Act and routes sensitive personal data through a third-party inference provider. Confirm the model provider, its data-retention terms, and whether report content can be excluded before relying on it. Vendor detail: Voice intake is transcribed on the reporter's device and the audio is deleted once the transcript exists, so no recording is retained.
Facts
- Website
- ashio.eu(opens in new tab)
- Headquarters
- Tallinn, Estonia
- Hosting
- ISO 27001-certified data centres in Switzerland. The security page says "your data never leaves Europe" — Switzerland is a third country under GDPR, covered by an adequacy decision, not an EU or EEA location.
- Pricing
- €30/month billed monthly, or €23/month billed yearly (€276/year). One plan, all features, unlimited team members, no per-report fee.A 14-day free trial with no credit card is advertised, and the vendor states setup needs no demo call. Because there is a single plan, nothing is tier-gated — including voice reporting, which the announcement bar states is "live on all plans".
- Languages on reporting form
- 18
- Customers
- 50+ SMEs (vendor claim)
- Product scope
- Standalone whistleblower product
- Encryption posture
- End-to-end
Measured, not published
Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.
- DMARC policy
- Enforced (quarantine)
- DNSSEC
- Unsigned
- Legal entity
- COWBOYS AND WITCHES OÜ Estonian Commercial Register 16770622 · imprint
Capabilities
- Anonymous reporting ✓
- Multi-channel intake ✓
- Public API ✗
- Free trial ✓
- Two-factor authentication —
- Audit log ✓
- EU Directive 2019/1937 (vendor claim) ✓
✓ published by the vendor · ✗ vendor states it is not offered · — not published either way
Certifications and national law
Certifications
None published
National laws referenced
- EU Directive 2019/1937
- ISO 37002:2021
- Germany (HinSchG)
- France (Loi Sapin II, Loi Waserman)
- Spain (Ley 2/2023)
- Italy (D.Lgs. 24/2023)
- Netherlands (Wet Klokkenluiders)
- Poland (Ustawa o Ochronie Sygnalistów)
- Romania (Legea 361/2022)
- Portugal (Lei 93/2021)
- Denmark (Lov om beskyttelse af whistleblowere)
- Czechia (Zákon o ochraně oznamovatelů)
- Lithuania (Pranešėjų apsaugos įstatymas)
- Finland (Ilmoittajansuojelulaki)
- Estonia (Süüteost teavitaja kaitse seadus)
- Latvia (Trauksmes celšanas likums)
- Hungary (Panasz- és közérdekű bejelentés törvénye)
- Sweden (listed as "Visselblåsardirektivet", the Swedish name for the Directive, not for Lag 2021:890)
- Switzerland (Bundesgesetz über den Datenschutz)
SMEs across several EU markets that want one price, every feature included, a law page in each local language, and client-side encryption — and whose data-protection review can accept Swiss rather than EU hosting.
Distinctive features
- One plan at €23–30/month with every feature included, unlimited team members and no per-report charge — the tier-gating that complicates most comparisons is simply absent
- Eighteen site locales, each with a dedicated page for that market's transposition law, named by statute rather than by "EU Directive compliant"
- The encryption design is described concretely enough to assess: a per-report AES-256-GCM key wrapped to each recipient with P-256 ECDH, ECDSA P-256 message signatures, handler keys derived with Argon2id, and ciphertext-only storage
Add-ons and conditions
Costs or terms not included in the headline price.
- Hosting is in Switzerland, not the EU or EEA, while the security page describes it as data never leaving Europe — accurate geographically, but a third-country transfer in GDPR terms
- The ISO 27001 certification named belongs to the data centres, not to Ashio; no certificate held by the vendor is published
- API access is not offered
- SSO is not mentioned on any public page reviewed
- The operating company, COWBOYS AND WITCHES OÜ, does not carry the product name, and the imprint records "VAT ID: not available"
Notable
- Operated by COWBOYS AND WITCHES OÜ of Tallinn (register number
16770622), with a named managing director on the imprint and no VAT ID recorded. - The pricing model is the simplest in this directory: a single plan, monthly or yearly, every feature included, unlimited invited team members with admin and investigator roles. Voice reporting shipped to all plans rather than to a premium tier.
- Voice intake is designed to avoid creating a recording at all. Audio is transcribed in the reporter’s browser and deleted as soon as the transcript exists, so the organisation never holds an audio file or biometric data to retain, produce or purge.
- The security model is client-side. A fresh AES-256-GCM key is generated per report and wrapped for each recipient using P-256 ECDH; the server stores ciphertext with no key material, and handler keys are protected by an Argon2id-derived password key. The vendor states it cannot read report bodies or messages.
- Reporting pages are stated to set no cookies, run no analytics and apply no fingerprinting, and a PGP key is published for a dedicated critical-contact address.
- The 7-day acknowledgment and 3-month feedback deadlines are both described as tracked automatically, with the evidence exportable as PDF and CSV for an auditor.
- Hosting is the one place where the framing is looser than the rest of the page. “Hosted in ISO 27001-certified data centres in Switzerland” and “your data never leaves Europe” are both true statements, but a buyer reading them as EU residency would be reading them wrongly, and the certification named is the data centre operator’s rather than Ashio’s.
Status: not yet scored
Ashio was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in a country ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool.
Frequently asked questions about Ashio
Answers derived from vendor-published materials dated on this page.
Is Ashio suitable for SMEs under 250 employees?
Which national whistleblower laws does Ashio explicitly reference?
Does Ashio process whistleblower report content with AI?
Similar to Ashio
Other platforms in the directory with overlapping pricing model, certifications, or procurement path.
Reler Pre-configured Italian whistleblowing platform sold through a storefront at €79/month with a 60-day free trial and the two documents D.Lgs. 24/2023 requires included.
Tu Canal de Denuncias
Spanish whistleblowing channel for Ley 2/2023. Public annual pricing from €150/year.EthicLink Romanian self-serve whistleblowing SaaS from SELFSOFT TECH SRL. €30/month or €300/year, EU-hosted, 7-day free trial. No EU Directive or Law 361/2022 citation on the public pages reviewed.
hintcatcher
German whistleblowing platform from product kitchen GmbH. Flat pricing from €39/month, independent of headcount.
Sources and verification
Every fact on this page comes from Ashio's own published materials. These are the pages that were read, and the date they were read.
- Last verified
- ashio.eu/ (opens in new tab)
- ashio.eu/security (opens in new tab)
- ashio.eu/impressum (opens in new tab)
- ashio.eu/fr/loi-sapin-2 (opens in new tab)