Security & data protection
This page describes how the platform handles supplier data and worker reports today, in plain terms, including what we deliberately do not claim. It is maintained by Axiom Signal and is not a third-party audit.
The reporting page asks for no name, phone number, email address or precise location, and requires no account. Libera stores the selected concerns, optional free text, language and time of submission.
Company users see grouped indicator counts and priorities at supplier or site level. Individual worker narratives are not returned in the management console, reducing retaliation risk.
Every supplier record and every linked report belongs to one workspace. Database-level row policies restrict reading and writing to members of that workspace; a user of one company cannot query another company's data.
The site and the database API are served over HTTPS/TLS. Data at rest is held by our hosting provider under their own encryption and backup arrangements.
Sign-in uses email and password or Google sign-in. Sessions are handled by the managed authentication service; passwords are never stored by us in readable form.
A workspace owner can delete supplier records from the console at any time. Written requests to delete a full workspace and its linked records are actioned by us.
Critical review questions
Libera does not ask for identity, contact details, an account or precise location. We call the channel confidential rather than promise perfect anonymity, because internet infrastructure can create limited technical security logs outside the report itself.
The customer workspace receives aggregated counts and indicator clusters, not the worker's free-text narrative. Access for authorised safeguarding or investigation roles requires a separate operating agreement and is not part of the current management console.
The application uses managed Supabase and Cloudflare infrastructure. Region, retention and sub-processor commitments are confirmed in the data processing agreement for each pilot; we do not make an unverified blanket claim that every service and log stays in the EU.
No. Libera does not currently hold either certification. We can provide the current security controls and sub-processor information for pilot due diligence without presenting provider certifications as our own.
Supplier records can be removed by a workspace owner. Full workspace and linked-data deletion is handled on written request and documented during the pilot.
Libera is not an emergency service or a continuously monitored hotline. Every worker flow directs immediate danger to local emergency services and appropriate independent help.
Sub-processors
Supabase
Database, authentication and API hosting for supplier records, workspace accounts and worker reports.
Cloudflare
Application hosting and content delivery for the website and server functions.
We tell customers in advance when a new sub-processor is added to this list.
What we do not claim
If a worker is in immediate danger, local emergency services come first — in the Netherlands 112, elsewhere the national emergency number.
Send the request through the access form and we answer with the current documentation.
Request access