One platform · Seven compliance products · Hosted in the EU

Every EU compliance clock. One platform.

Whistleblowing reports, GDPR rights requests, NIS2 incidents, pay-transparency requests, policy attestations, conflict-of-interest declarations, vulnerability disclosures — each arrives with a statutory deadline attached. Klaruna receives them, counts the clocks down, and keeps the proof a regulator or auditor actually asks for.

3 months free · No credit card · Just your work email · One invoice, add modules anytime · From €39/month

  • Data stored in the EU (Frankfurt)
  • Envelope encryption per case
  • Externally pen-tested
  • Zero tracking on employee-facing pages
  • No AI touches your records
Seven products, one engine

Turn each obligation on as it reaches you.

Every product covers one statutory duty. The six compliance modules share your tenant, your team, your audit log, and one invoice at account.klaruna.eu — buy one, a suite, or everything. The seventh, Klaruna Disclose, serves a different buyer and has its own front door.

Speak-Up

LIVE
EU 2019/1937 · Whistleblower Directive

The confidential internal reporting channel every 50+ employee company must operate.

  • Anonymous two-way dialogue via case key
  • 7-day acknowledgment & 3-month feedback clocks
  • Lawyer-reviewed templates, register exports
from 49/mo

DSAR

LIVE
GDPR Arts. 12–22

Data-subject requests — access, erasure, portability — out of the shared inbox and onto the clock.

  • Structured intake with identity verification
  • 1-month deadline clock (+2 for complex cases)
  • Register export for the supervisory authority
add-on 29/mo

NIS2 Incidents

EARLY ACCESS
NIS2 · EU 2022/2555

The 24h / 72h / 1-month notification cascade for essential and important entities, plus the register.

  • Fast intake with the 24h early-warning clock
  • 72h notification & 1-month final-report workflow
  • Immutable incident register, CSIRT-ready exports
add-on 39/mo

Paygap

EARLY ACCESS
EU 2023/970 · Pay Transparency

Worker pay-information requests today; gender pay-gap reports before the first June 2027 deadline.

  • Pay-info request portal with the 2-month clock
  • Statutory gap reports by category & quartile
  • Joint pay-assessment workflow for ≥5% gaps
add-on 59/mo

Policy Attestation

EARLY ACCESS
Every regulation's last sentence

Distribute policies and prove who read them — the evidence works councils, auditors, and courts ask for.

  • No-account attestation via signed links
  • Automatic chasing until everyone has signed
  • "Who read version Y on date Z" in one export
add-on 25/mo

COI & Gifts

EARLY ACCESS
ISO 37001 / 37301 · anti-corruption

Conflict-of-interest declarations and a gifts & hospitality register — the un-Googleable questionnaire answer.

  • Declaration campaigns with tokenised forms
  • Gifts register with approval thresholds
  • Coverage reports for ISO & customer audits
add-on 25/mo

Klaruna Disclose

EARLY ACCESS · OWN SIGNUP
CRA · EU 2024/2847 · Art. 14

For manufacturers of software and connected devices — a different buyer than the six modules above, with its own front door and invoice. Reporting duties begin 11 September 2026.

  • Public CVD channel, policy & security.txt
  • Vulnerability register with triage & dedup
  • Art. 14 clocks: 24 h → 72 h → 14 days
59/mo · self-serve at cra.klaruna.eu · details below
Why one platform

Seven duties. One operating pattern.

Every duty on this page reduces to the same mechanics: something arrives, a statutory clock starts, you must respond in a prescribed way and keep proof you did. That's one engine — intake, deadline, evidence — not seven separate tools.

EU 2019/1937

Whistleblowing

Confidential channel, anonymous dialogue, register of every report.

⏱ acknowledge 7 days · feedback 3 months
GDPR 12–22

Data-subject rights

Verify identity without over-collecting, respond, prove handling.

⏱ reply 1 month (+2 complex)
NIS2

Incident notification

Strict cascade to your CSIRT, plus an ongoing incident register.

⏱ 24 h → 72 h → 1 month
EU 2023/970

Pay transparency

Answer worker pay-data requests; publish gap reports by category.

⏱ answer 2 months · first reports June 2027
Audit practice

Policy attestation

"…and inform your employees" — with proof of who read what, when.

⏱ evidence on demand
ISO 37001

Ethics registers

COI declarations and gift approvals, recorded so an auditor can read them.

⏱ annual campaigns · threshold approvals
CRA Art. 14

Vulnerability disclosure & reporting

Run a coordinated disclosure channel; report actively exploited vulnerabilities to ENISA and your national CSIRT. The one duty here owned by engineering, not HR or the DPO — which is why it's a separate product.

⏱ early warning 24 h → notification 72 h → final report 14 days · from 11 Sept 2026
The shared machinery: a deadline engine that escalates before you're late, no-account portals for employees (case keys and signed links — nothing to install, nobody to provision), a hash-chained audit log, PDF case files and CSV registers, and retention applied automatically. Built once, compliant seven times.
How it works

Three roles. Zero training required.

Your employees

No accounts, no app, no IT ticket

  • Report, request, declare, or attest from a link or QR poster
  • Anonymous where the law allows it — return with a private case key
  • Plain-language rights & process info, multi-language
  • Files cleaned of metadata before anyone sees them
case key: KX7-Q2M-99F-TRD
Your compliance owners

One login, every clock

  • One team & billing hub at account.klaruna.eu
  • Deadline countdowns across all modules, escalation before you're late
  • One-click templated responses, lawyer-reviewed
  • Each module keeps its own handlers — HR never sees whistleblower cases
Your auditor / regulator

Proof, not promises

  • Every read and write lands in an immutable audit log
  • Complete case files as PDF in one click
  • Registers as CSV — reports, requests, incidents, gifts
  • Retention and deletion applied automatically per national law
Security & anonymity

We built it so even we can't read it.

Whistleblower reports, pay data, incident details, health-related DSARs — this platform holds the most sensitive records a company generates. Trust doesn't depend on our word; it's in the architecture, and it's documented publicly.

[✓] Envelope encryption

Record content is encrypted per case, wrapped per tenant. Database backups — and Klaruna staff — cannot casually read your records.

[✓] Anonymity by construction

No accounts for reporters. IP addresses stripped at the proxy on employee-facing routes. No analytics scripts, no cookies, no fingerprinting on any portal.

[✓] Metadata scrubbing

Uploaded files are cleaned of EXIF and Office metadata server-side before a handler ever sees them.

[✓] EU-region hosting

Application, database, storage, backups, and email run in EU data centres (Frankfurt). Your records are stored and processed within the European Union.

[✓] Audited access

Every access to a case — including viewing a reporter's identity — is itself logged in a hash-chained, append-only audit trail.

[✓] Independently tested

External penetration test before launch and annually, with the attestation letter available to customers. No AI or LLM ever processes your records.

For HR consultancies, payroll bureaus, DPOs & law firms

Your brand. Your clients. Our plumbing.

Your clients ask you about all of these laws anyway. Answer with one platform that carries your logo and your domain — and turn your clients' compliance questions into one recurring revenue line. (The partner program covers the six modules; Klaruna Disclose is self-serve only.)

  • White-label portal: your logo, colors, and domain on every client channel
  • Manage all client tenants from one dashboard, with cross-client deadline health
  • Payroll bureaus: you already hold the data their pay-gap report needs
  • External DPOs: run DSARs and incident registers for your whole book
  • One blended wholesale rate per client — no per-module negotiation
  • One consolidated invoice — you bill your clients your way
Book a partner call

Partner economics · per client · full stack

You charge your client (typical)€120–180 /mo
You pay Klaruna (blended wholesale)75 /mo
Speak-Up only wholesale25 /mo
Minimum clients3
Your margin, recurring38–58%

A bureau with 20 clients on the full stack adds roughly €11,000–25,000/year of recurring revenue — with no software to build or host.

Bundles & pricing

Priced by the budget that pays for it.

Each suite maps to one budget-holder — compliance, HR, or the DPO. Start with just your work email at account.klaruna.eu — no credit card for 3 months. Annual billing gets 2 months free.

Speak-Up
The statutory channel — for the compliance officer
49 /mo
490 /yr billed annually
  • Compliant reporting channel, multi-language
  • Anonymous two-way dialogue
  • 7-day / 3-month deadline engine
  • Audit log, PDF & CSV exports
  • Up to 100 employees — €89/mo up to 500
Start 3 months free
Privacy & Incidents
For the DPO — requests and breaches, one register
59 /mo
590 /yr billed annually
  • DSAR — GDPR rights requests
  • NIS2 — incident register & clocks
  • Save €9/mo vs à la carte
  • Works with or without Speak-Up
Start 3 months free
Klaruna Complete
All six modules, one invoice
149 /mo
1490 /yr billed annually
  • Speak-Up channel included
  • Both suites — all six modules
  • Save €77/mo vs à la carte
  • Priority support
Start 3 months free

Already on Klaruna? Add modules one at a time.

Every module attaches to your existing subscription independently — no plan migration, no lost access, same invoice.

DSAR — GDPR rights requests29 /mo · €290/yr
NIS2 — incident register & notifications39 /mo · €390/yr
Paygap — pay transparency toolkit59 /mo · €590/yr
Policy Attestation — distribute & prove25 /mo · €250/yr
COI & Gifts — ethics registers25 /mo · €250/yr

Klaruna Disclose is deliberately not in any bundle — it's bought by your engineering team, on its own signup and invoice, priced on its own below. Shipping software with 50+ employees? You likely need Speak-Up and Disclose — talk to us.

Prices exclude VAT. Public sector: Speak-Up from €39/mo with the procurement paperwork pack — ask us. Larger groups (multiple entities): talk to us. Advisors: wholesale from €25/client/mo — partner program.

For manufacturers of products with digital elements

Klaruna Disclose. Your CRA disclosure channel.

The EU Cyber Resilience Act gives every manufacturer of software or connected devices two duties: run a coordinated vulnerability disclosure channel, and report actively exploited vulnerabilities to ENISA and your national CSIRT under Art. 14 — reporting obligations begin 11 September 2026. A different buyer than the rest of this page, on purpose: this one is for your security and engineering team.

[✓] CVD channel & policy

A public "report a vulnerability" page researchers trust — anonymous-capable intake with case-key dialogue, a generated CVD policy, and security.txt placement on your domain.

[✓] Vulnerability register

A first-class record of each vulnerability's lifecycle — reported by a researcher or found internally — with triage, dedup, and the audit trail that proves how you handled it.

[✓] Art. 14 reporting clocks

One asserted "we became aware" timestamp starts all three statutory clocks, with generated notification drafts for the Single Reporting Platform and a permanent record of what was submitted, when.

59 /mo · self-serve · 3 months free Start at cra.klaruna.eu

Same engine, same EU hosting, same anonymity architecture as the rest of Klaruna — researchers frequently want anonymity too. Separate signup: Disclose is its own product, not a module of the compliance suites.

Running a municipality?

You're covered by the whistleblower law — and many municipalities are NIS2 entities too — with less budget and more procurement rules. Our Public plan ships with the paperwork already done: data-processing agreement, EU-hosting attestation, retention policy, and a memo justifying an under-threshold purchase.

Get the public-sector pack
Questions we get on every call

FAQ

Do we have to buy the whole platform?
No. Every module works alone, and each suite works with or without the others. Start with the one duty that's on fire, add the rest as they reach you — modules attach to your tenant as independent subscriptions on one invoice, and you never lose access to what you already have. The suites just price a sensible set for one budget-holder below the sum of its parts. Klaruna Disclose sits outside the bundles on purpose: it's bought by engineering, not HR or the DPO, with its own signup and invoice — so your security team never has to route through HR procurement.
Which modules are live today?
Speak-Up and DSAR are in production. NIS2, Paygap, Policy Attestation, and COI are in early access: sign up at account.klaruna.eu and you can activate them from your account as they roll out. Suite pricing applies once a suite's modules are generally available — early-access activation costs nothing while a module is in preview. Klaruna Disclose (CRA) is being built against the 11 September 2026 reporting deadline; its own signup opens at cra.klaruna.eu.
Isn't a shared inbox enough to comply?
In practice, no — for any of these duties. The laws require restricted, verifiable access; tracked statutory deadlines; anonymous dialogue where applicable; and a complete register. A mailbox can't restrict access verifiably, can't prove a deadline was met, and can't run an anonymous two-way conversation. Regulators, works councils, and courts look for exactly these gaps.
How can whistleblower dialogue be truly anonymous?
Reporters never create an account. On submission they receive a random high-entropy case key; returning with the key opens the conversation. We strip IP addresses on reporter routes at the proxy, run no analytics or cookies on the portal, and scrub file metadata server-side. There is no identity to leak because none is collected. The key is stored only as a hash — not even Klaruna can recover it.
Where is our data stored, and who can read it?
Everything — application, database, file storage, backups, email delivery — runs in EU data centers. Record content is envelope-encrypted per case and per tenant; Klaruna staff cannot casually read it, and every access by your own handlers is audit-logged. Our security page documents the full architecture, and our annual external penetration-test attestation is available on request.
How does billing work across modules?
One tenant, one invoice, at account.klaruna.eu. Adding a module starts an independent subscription — no plan migration, and removing one never touches the others. Annual billing is ten months' price for twelve everywhere. Partners get a single blended wholesale rate per client across their whole book instead of per-module line items.
How long does setup really take?
Under 30 minutes per module, self-serve: upload your logo, choose languages and categories, name your handlers, set retention — you get the portal links, QR posters, and staff-notice templates. No IT project, nothing to install. Policy Attestation is the natural second step: once a channel is live, notify your staff about it — with proof.
Are the legal templates actually valid for our country?
Every country pack — policies, staff notices, acknowledgment and response letters, DPA — is reviewed by a local employment-law firm before release and re-reviewed annually. Templates are general model documents; for unusual situations, your own counsel has the final word.

Be compliant before lunch. Seven times over.

3 months free — no credit card, just your work email. Cancel anytime. Or ask us for a 30-minute demo — we'll walk one real case through every clock, from intake to closed file.