Every EU compliance clock. One platform.
Whistleblowing reports, GDPR rights requests, NIS2 incidents, pay-transparency requests, policy attestations, conflict-of-interest declarations, vulnerability disclosures — each arrives with a statutory deadline attached. Klaruna receives them, counts the clocks down, and keeps the proof a regulator or auditor actually asks for.
3 months free · No credit card · Just your work email · One invoice, add modules anytime · From €39/month
- Data stored in the EU (Frankfurt)
- Envelope encryption per case
- Externally pen-tested
- Zero tracking on employee-facing pages
- No AI touches your records
Turn each obligation on as it reaches you.
Every product covers one statutory duty. The six compliance modules share your tenant, your team, your audit log, and one invoice at account.klaruna.eu — buy one, a suite, or everything. The seventh, Klaruna Disclose, serves a different buyer and has its own front door.
Speak-Up
LIVEThe confidential internal reporting channel every 50+ employee company must operate.
- Anonymous two-way dialogue via case key
- 7-day acknowledgment & 3-month feedback clocks
- Lawyer-reviewed templates, register exports
DSAR
LIVEData-subject requests — access, erasure, portability — out of the shared inbox and onto the clock.
- Structured intake with identity verification
- 1-month deadline clock (+2 for complex cases)
- Register export for the supervisory authority
NIS2 Incidents
EARLY ACCESSThe 24h / 72h / 1-month notification cascade for essential and important entities, plus the register.
- Fast intake with the 24h early-warning clock
- 72h notification & 1-month final-report workflow
- Immutable incident register, CSIRT-ready exports
Paygap
EARLY ACCESSWorker pay-information requests today; gender pay-gap reports before the first June 2027 deadline.
- Pay-info request portal with the 2-month clock
- Statutory gap reports by category & quartile
- Joint pay-assessment workflow for ≥5% gaps
Policy Attestation
EARLY ACCESSDistribute policies and prove who read them — the evidence works councils, auditors, and courts ask for.
- No-account attestation via signed links
- Automatic chasing until everyone has signed
- "Who read version Y on date Z" in one export
COI & Gifts
EARLY ACCESSConflict-of-interest declarations and a gifts & hospitality register — the un-Googleable questionnaire answer.
- Declaration campaigns with tokenised forms
- Gifts register with approval thresholds
- Coverage reports for ISO & customer audits
Klaruna Disclose
EARLY ACCESS · OWN SIGNUPFor manufacturers of software and connected devices — a different buyer than the six modules above, with its own front door and invoice. Reporting duties begin 11 September 2026.
- Public CVD channel, policy & security.txt
- Vulnerability register with triage & dedup
- Art. 14 clocks: 24 h → 72 h → 14 days
Seven duties. One operating pattern.
Every duty on this page reduces to the same mechanics: something arrives, a statutory clock starts, you must respond in a prescribed way and keep proof you did. That's one engine — intake, deadline, evidence — not seven separate tools.
Whistleblowing
Confidential channel, anonymous dialogue, register of every report.
Data-subject rights
Verify identity without over-collecting, respond, prove handling.
Incident notification
Strict cascade to your CSIRT, plus an ongoing incident register.
Pay transparency
Answer worker pay-data requests; publish gap reports by category.
Policy attestation
"…and inform your employees" — with proof of who read what, when.
Ethics registers
COI declarations and gift approvals, recorded so an auditor can read them.
Vulnerability disclosure & reporting
Run a coordinated disclosure channel; report actively exploited vulnerabilities to ENISA and your national CSIRT. The one duty here owned by engineering, not HR or the DPO — which is why it's a separate product.
Three roles. Zero training required.
No accounts, no app, no IT ticket
- Report, request, declare, or attest from a link or QR poster
- Anonymous where the law allows it — return with a private case key
- Plain-language rights & process info, multi-language
- Files cleaned of metadata before anyone sees them
One login, every clock
- One team & billing hub at account.klaruna.eu
- Deadline countdowns across all modules, escalation before you're late
- One-click templated responses, lawyer-reviewed
- Each module keeps its own handlers — HR never sees whistleblower cases
Proof, not promises
- Every read and write lands in an immutable audit log
- Complete case files as PDF in one click
- Registers as CSV — reports, requests, incidents, gifts
- Retention and deletion applied automatically per national law
We built it so even we can't read it.
Whistleblower reports, pay data, incident details, health-related DSARs — this platform holds the most sensitive records a company generates. Trust doesn't depend on our word; it's in the architecture, and it's documented publicly.
[✓] Envelope encryption
Record content is encrypted per case, wrapped per tenant. Database backups — and Klaruna staff — cannot casually read your records.
[✓] Anonymity by construction
No accounts for reporters. IP addresses stripped at the proxy on employee-facing routes. No analytics scripts, no cookies, no fingerprinting on any portal.
[✓] Metadata scrubbing
Uploaded files are cleaned of EXIF and Office metadata server-side before a handler ever sees them.
[✓] EU-region hosting
Application, database, storage, backups, and email run in EU data centres (Frankfurt). Your records are stored and processed within the European Union.
[✓] Audited access
Every access to a case — including viewing a reporter's identity — is itself logged in a hash-chained, append-only audit trail.
[✓] Independently tested
External penetration test before launch and annually, with the attestation letter available to customers. No AI or LLM ever processes your records.
Your brand. Your clients. Our plumbing.
Your clients ask you about all of these laws anyway. Answer with one platform that carries your logo and your domain — and turn your clients' compliance questions into one recurring revenue line. (The partner program covers the six modules; Klaruna Disclose is self-serve only.)
- White-label portal: your logo, colors, and domain on every client channel
- Manage all client tenants from one dashboard, with cross-client deadline health
- Payroll bureaus: you already hold the data their pay-gap report needs
- External DPOs: run DSARs and incident registers for your whole book
- One blended wholesale rate per client — no per-module negotiation
- One consolidated invoice — you bill your clients your way
Partner economics · per client · full stack
A bureau with 20 clients on the full stack adds roughly €11,000–25,000/year of recurring revenue — with no software to build or host.
Priced by the budget that pays for it.
Each suite maps to one budget-holder — compliance, HR, or the DPO. Start with just your work email at account.klaruna.eu — no credit card for 3 months. Annual billing gets 2 months free.
- Compliant reporting channel, multi-language
- Anonymous two-way dialogue
- 7-day / 3-month deadline engine
- Audit log, PDF & CSV exports
- Up to 100 employees — €89/mo up to 500
- Paygap — pay transparency toolkit
- Policy Attestation — proof of reading
- COI & Gifts — ethics registers
- Save €10/mo vs à la carte
- Works with or without Speak-Up
- DSAR — GDPR rights requests
- NIS2 — incident register & clocks
- Save €9/mo vs à la carte
- Works with or without Speak-Up
- Speak-Up channel included
- Both suites — all six modules
- Save €77/mo vs à la carte
- Priority support
Already on Klaruna? Add modules one at a time.
Every module attaches to your existing subscription independently — no plan migration, no lost access, same invoice.
Klaruna Disclose is deliberately not in any bundle — it's bought by your engineering team, on its own signup and invoice, priced on its own below. Shipping software with 50+ employees? You likely need Speak-Up and Disclose — talk to us.
Prices exclude VAT. Public sector: Speak-Up from €39/mo with the procurement paperwork pack — ask us. Larger groups (multiple entities): talk to us. Advisors: wholesale from €25/client/mo — partner program.
Klaruna Disclose. Your CRA disclosure channel.
The EU Cyber Resilience Act gives every manufacturer of software or connected devices two duties: run a coordinated vulnerability disclosure channel, and report actively exploited vulnerabilities to ENISA and your national CSIRT under Art. 14 — reporting obligations begin 11 September 2026. A different buyer than the rest of this page, on purpose: this one is for your security and engineering team.
[✓] CVD channel & policy
A public "report a vulnerability" page researchers trust — anonymous-capable intake with case-key dialogue, a generated CVD policy, and security.txt placement on your domain.
[✓] Vulnerability register
A first-class record of each vulnerability's lifecycle — reported by a researcher or found internally — with triage, dedup, and the audit trail that proves how you handled it.
[✓] Art. 14 reporting clocks
One asserted "we became aware" timestamp starts all three statutory clocks, with generated notification drafts for the Single Reporting Platform and a permanent record of what was submitted, when.
Same engine, same EU hosting, same anonymity architecture as the rest of Klaruna — researchers frequently want anonymity too. Separate signup: Disclose is its own product, not a module of the compliance suites.
Running a municipality?
You're covered by the whistleblower law — and many municipalities are NIS2 entities too — with less budget and more procurement rules. Our Public plan ships with the paperwork already done: data-processing agreement, EU-hosting attestation, retention policy, and a memo justifying an under-threshold purchase.
FAQ
Do we have to buy the whole platform?
Which modules are live today?
Isn't a shared inbox enough to comply?
How can whistleblower dialogue be truly anonymous?
Where is our data stored, and who can read it?
How does billing work across modules?
How long does setup really take?
Are the legal templates actually valid for our country?
Be compliant before lunch. Seven times over.
3 months free — no credit card, just your work email. Cancel anytime. Or ask us for a 30-minute demo — we'll walk one real case through every clock, from intake to closed file.