Skip to main content
EU Whistleblower Directory
OpenBlow logo

OpenBlow

Italian whistleblowing platform from Laser Romae s.r.l., offered as an AgID-qualified SaaS or on-premise install and built for D.Lgs 24/2023, D.Lgs 231/01, and GDPR.

Rubric score

21 / 50

Evidence tier P

Public pages only. No reporter submission or handler environment was reviewed.

How this score is produced →

Facts

Website
www.openblow.it(opens in new tab)
Headquarters
Rome, Italy
Hosting
Runs on an unnamed Cloud Service Provider qualified under AgID/ACN SaaS requirements and enlisted in Cloud Security Alliance STAR (vendor-stated); on-premise install within the customer's own infrastructure is also offered.
Pricing
Not published. Procurement is contact-sales with custom implementation; a partner/reseller program is offered.
No prices, tiers, or self-serve signup shown on public pages reviewed. The for-business page targets consultants, lawyers, and DPOs reselling to their clients.
Languages on reporting form
Not published
Domain registered
openblow.it
Ownership
Private, Laser Romae s.r.l. (Italy)
Product scope
Standalone whistleblower product

Measured, not published

Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.

DMARC policy
Enforced (reject)
DNSSEC
Signed

Capabilities

  • Anonymous reporting ✓
  • Multi-channel intake ✗
  • Public API —
  • Free trial ✗
  • Two-factor authentication —
  • Audit log —
  • EU Directive 2019/1937 (vendor claim) ✓

✓ published by the vendor · ✗ vendor states it is not offered · — not published either way

Certifications and national law

Certifications

  • AgID/ACN SaaS qualification (vendor-stated)
  • Cloud Security Alliance STAR registry (vendor-stated)

National laws referenced

  • EU Directive 2019/1937
  • Italy (D.Lgs 24/2023)
  • Italy (D.Lgs 231/2001)
OpenBlow homepage screenshot
Typical buyer

Italian public-sector bodies and companies under D.Lgs 231/01 wanting an AgID-qualified whistleblowing channel available as SaaS or on-premise.

Distinctive features

  • AgID/ACN SaaS qualification is stated, aligning it to Italian public-sector cloud procurement
  • Available as SaaS or as an on-premise install inside the customer's own infrastructure
  • Native support for D.Lgs 24/2023, D.Lgs 231/01, and GDPR is stated
  • Implements the operational roles required by the law plus customizable roles and separation of duties
  • Customizable questionnaires, workflow states, and a multilingual web interface accessible on PC, tablet, and smartphone
  • Multi-instance support for corporate groups and holdings; service enlisted in Cloud Security Alliance STAR

Add-ons and conditions

Costs or terms not included in the headline price.

  • No pricing is published; procurement is contact-sales with custom implementation
  • No self-serve free trial was found on public pages reviewed
  • Hosting provider and data-centre country are not named; service is qualified under AgID/ACN and enlisted in CSA STAR
  • ISO 27001 is cited as a security standard supporting VAPT sessions, not as a held product or vendor certificate on public pages reviewed
  • D.Lgs 24/2023 and 231/01 are named without article numbers; DPA/DPIA documentation was not found on public pages reviewed

Notable

  • Operated by Laser Romae s.r.l., an ICT firm based at Viale Cesare Pavese 305, Rome; sales contact and phone are published on the site.
  • Positioned as a whistleblowing platform to report and manage illegal conduct, available as an AgID-qualified SaaS service or as an on-premise install integrated into the customer’s own infrastructure.
  • Compliance page states the platform is in line with D.Lgs 24/2023 (implementing EU Directive 2019/1937), D.Lgs 231/01 organizational models, and GDPR; none of these are cited with article numbers.
  • The product is marketed elsewhere as an open-source whistleblowing platform (its own SEO page title and third-party directories), but the vendor content pages reviewed do not name GlobaLeaks or state a specific licence.
  • Features page describes personalized workflow management with intermediate and final states, validation/transition logic, and phases for acceptance, first assessment, investigation, and corrective actions.
  • Role model implements the operational roles foreseen by the legislation, plus customizable roles and clear separation of duties.
  • Multi-engine architecture with plugins to connect to pre-existing systems (authorization, workflow, message-queue, and object-storage) is described; a public reporting API was not documented on pages reviewed.
  • Homepage lists organizational logos (including RFI) as customers; the platform is used for public and private Italian deployments.
  • Security posture: periodic VAPT sessions supported by security standards (ISO 27001, OWASP, CISA/CISM of ISACA); the service is provided on a Cloud Service Provider enlisted in Cloud Security Alliance STAR (CAIQ documented). No product-held ISO 27001 certificate, hosting provider, or data-centre country was named on public pages reviewed.
  • No public pricing, self-serve trial, or monthly-contract terms were found; the for-business page targets consultants, lawyers, and DPOs reselling to their clients under a partner program.
  • Encrypted transport and storage protecting report contents, documents, and whistleblower identity is stated; DPA/DPIA documentation was not found on public pages reviewed.

Frequently asked questions about OpenBlow

Answers derived from vendor-published materials dated on this page.

Is OpenBlow suitable for SMEs under 250 employees?
OpenBlow does not publish entry-tier pricing, so SME buyers need to request a quote to assess fit. Buying path: Sales contact required. Italian public-sector bodies and companies under D.Lgs 231/01 wanting an AgID-qualified whistleblowing channel available as SaaS or on-premise.
Which national whistleblower laws does OpenBlow explicitly reference?
OpenBlow explicitly cites the following national transpositions of Directive 2019/1937 in its public materials: EU Directive 2019/1937, Italy (D.Lgs 24/2023), Italy (D.Lgs 231/2001). Absence from this list does not mean the platform can't be used in other EU jurisdictions — all 27 member states have transposed the Directive. Verify jurisdictional fit with the vendor directly.
Does OpenBlow process whistleblower report content with AI?
No — OpenBlow does not process report content with AI or machine translation per its vendor materials. Verify the vendor's subprocessor list to confirm no downstream AI processing occurs.

Similar to OpenBlow

Other platforms in the directory with overlapping pricing model, certifications, or procurement path.

Sources and verification

Every fact on this page comes from OpenBlow's own published materials. These are the pages that were read, and the date they were read.

Last verified

4 of the vendor pages cited below has changed since this entry was verified. What this means

Cited pages last re-fetched

Something out of date? Tell us →

Listed here? Show it on your own site →