Good day #privacy folks. I'm #lookingforhelp.
One of the excellent employee resource groups at my place is trying to setup a secure anonymous reporting option for vulnerable populations among our employees around the world.
While I'm comfortable making general privacy recommendations, I'm not coming up with a good option for anonymous reporting where both I and the person's local government wouldn't be able to tell who it is.
I've considered a web service with logging disabled that can only be reached from TOR exit nodes to avoid people accidently connecting when not using TOR. This is to solve for the "I <company security> don't know who the sender is" requirement.
Doesn't solve for privacy on their end or VPN restrictions in certain countries.
Welcoming any and all thoughts.
Thanks,
-Chris