Skip to main content
EU Whistleblower Directory
Ashio logo

Ashio

Estonian-registered whistleblowing SaaS with 18 site locales, a law page per market, client-side encryption, and one €23–30/month plan that includes every feature.

AI processes report content — EU AI Act consideration

This vendor applies AI or machine learning to whistleblower reports (for example summarisation, severity or category classification, drafting replies, or machine translation). Automated processing of disclosures can bring the deployment within scope of the EU AI Act and routes sensitive personal data through a third-party inference provider. Confirm the model provider, its data-retention terms, and whether report content can be excluded before relying on it. Vendor detail: Voice intake is transcribed on the reporter's device and the audio is deleted once the transcript exists, so no recording is retained.

Facts

Website
ashio.eu(opens in new tab)
Headquarters
Tallinn, Estonia
Hosting
ISO 27001-certified data centres in Switzerland. The security page says "your data never leaves Europe" — Switzerland is a third country under GDPR, covered by an adequacy decision, not an EU or EEA location.
Pricing
€30/month billed monthly, or €23/month billed yearly (€276/year). One plan, all features, unlimited team members, no per-report fee.
A 14-day free trial with no credit card is advertised, and the vendor states setup needs no demo call. Because there is a single plan, nothing is tier-gated — including voice reporting, which the announcement bar states is "live on all plans".
Languages on reporting form
18
Customers
50+ SMEs (vendor claim)
Product scope
Standalone whistleblower product
Encryption posture
End-to-end

Measured, not published

Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.

DMARC policy
Enforced (quarantine)
DNSSEC
Unsigned
Legal entity
COWBOYS AND WITCHES OÜ Estonian Commercial Register 16770622 · imprint

Capabilities

  • Anonymous reporting
  • Multi-channel intake
  • Public API
  • Free trial
  • Two-factor authentication
  • Audit log
  • EU Directive 2019/1937 (vendor claim)

✓ published by the vendor · ✗ vendor states it is not offered · — not published either way

Certifications and national law

Certifications

None published

National laws referenced

  • EU Directive 2019/1937
  • ISO 37002:2021
  • Germany (HinSchG)
  • France (Loi Sapin II, Loi Waserman)
  • Spain (Ley 2/2023)
  • Italy (D.Lgs. 24/2023)
  • Netherlands (Wet Klokkenluiders)
  • Poland (Ustawa o Ochronie Sygnalistów)
  • Romania (Legea 361/2022)
  • Portugal (Lei 93/2021)
  • Denmark (Lov om beskyttelse af whistleblowere)
  • Czechia (Zákon o ochraně oznamovatelů)
  • Lithuania (Pranešėjų apsaugos įstatymas)
  • Finland (Ilmoittajansuojelulaki)
  • Estonia (Süüteost teavitaja kaitse seadus)
  • Latvia (Trauksmes celšanas likums)
  • Hungary (Panasz- és közérdekű bejelentés törvénye)
  • Sweden (listed as "Visselblåsardirektivet", the Swedish name for the Directive, not for Lag 2021:890)
  • Switzerland (Bundesgesetz über den Datenschutz)
Typical buyer

SMEs across several EU markets that want one price, every feature included, a law page in each local language, and client-side encryption — and whose data-protection review can accept Swiss rather than EU hosting.

Distinctive features

  • One plan at €23–30/month with every feature included, unlimited team members and no per-report charge — the tier-gating that complicates most comparisons is simply absent
  • Eighteen site locales, each with a dedicated page for that market's transposition law, named by statute rather than by "EU Directive compliant"
  • The encryption design is described concretely enough to assess: a per-report AES-256-GCM key wrapped to each recipient with P-256 ECDH, ECDSA P-256 message signatures, handler keys derived with Argon2id, and ciphertext-only storage

Add-ons and conditions

Costs or terms not included in the headline price.

  • Hosting is in Switzerland, not the EU or EEA, while the security page describes it as data never leaving Europe — accurate geographically, but a third-country transfer in GDPR terms
  • The ISO 27001 certification named belongs to the data centres, not to Ashio; no certificate held by the vendor is published
  • API access is not offered
  • SSO is not mentioned on any public page reviewed
  • The operating company, COWBOYS AND WITCHES OÜ, does not carry the product name, and the imprint records "VAT ID: not available"

Notable

  • Operated by COWBOYS AND WITCHES OÜ of Tallinn (register number 16770622), with a named managing director on the imprint and no VAT ID recorded.
  • The pricing model is the simplest in this directory: a single plan, monthly or yearly, every feature included, unlimited invited team members with admin and investigator roles. Voice reporting shipped to all plans rather than to a premium tier.
  • Voice intake is designed to avoid creating a recording at all. Audio is transcribed in the reporter’s browser and deleted as soon as the transcript exists, so the organisation never holds an audio file or biometric data to retain, produce or purge.
  • The security model is client-side. A fresh AES-256-GCM key is generated per report and wrapped for each recipient using P-256 ECDH; the server stores ciphertext with no key material, and handler keys are protected by an Argon2id-derived password key. The vendor states it cannot read report bodies or messages.
  • Reporting pages are stated to set no cookies, run no analytics and apply no fingerprinting, and a PGP key is published for a dedicated critical-contact address.
  • The 7-day acknowledgment and 3-month feedback deadlines are both described as tracked automatically, with the evidence exportable as PDF and CSV for an auditor.
  • Hosting is the one place where the framing is looser than the rest of the page. “Hosted in ISO 27001-certified data centres in Switzerland” and “your data never leaves Europe” are both true statements, but a buyer reading them as EU residency would be reading them wrongly, and the certification named is the data centre operator’s rather than Ashio’s.

Status: not yet scored

Ashio was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in a country ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool.

Frequently asked questions about Ashio

Answers derived from vendor-published materials dated on this page.

Is Ashio suitable for SMEs under 250 employees?
Yes — Ashio's entry-tier pricing is published under €50/month, inside the range most 50–249-employee organisations budget for a reporting channel. €30/month billed monthly, or €23/month billed yearly (€276/year). One plan, all features, unlimited team members, no per-report fee. SMEs across several EU markets that want one price, every feature included, a law page in each local language, and client-side encryption — and whose data-protection review can accept Swiss rather than EU hosting.
Which national whistleblower laws does Ashio explicitly reference?
Ashio explicitly cites the following national transpositions of Directive 2019/1937 in its public materials: EU Directive 2019/1937, ISO 37002:2021, Germany (HinSchG), France (Loi Sapin II, Loi Waserman), Spain (Ley 2/2023), Italy (D.Lgs. 24/2023), Netherlands (Wet Klokkenluiders), Poland (Ustawa o Ochronie Sygnalistów), Romania (Legea 361/2022), Portugal (Lei 93/2021), Denmark (Lov om beskyttelse af whistleblowere), Czechia (Zákon o ochraně oznamovatelů), Lithuania (Pranešėjų apsaugos įstatymas), Finland (Ilmoittajansuojelulaki), Estonia (Süüteost teavitaja kaitse seadus), Latvia (Trauksmes celšanas likums), Hungary (Panasz- és közérdekű bejelentés törvénye), Sweden (listed as "Visselblåsardirektivet", the Swedish name for the Directive, not for Lag 2021:890), Switzerland (Bundesgesetz über den Datenschutz). Absence from this list does not mean the platform can't be used in other EU jurisdictions — all 27 member states have transposed the Directive. Verify jurisdictional fit with the vendor directly.
Does Ashio process whistleblower report content with AI?
Yes — Ashio processes report content with AI (typically for translation, summarisation, or classification). If your compliance posture requires keeping disclosures out of third-party LLMs or machine-translation services, confirm data-processing terms and vendor subprocessors before procurement. Voice intake is transcribed on the reporter's device and the audio is deleted once the transcript exists, so no recording is retained.

Similar to Ashio

Other platforms in the directory with overlapping pricing model, certifications, or procurement path.

Sources and verification

Every fact on this page comes from Ashio's own published materials. These are the pages that were read, and the date they were read.

Last verified

Something out of date? Tell us →

Listed here? Show it on your own site →