Anonymous vs. confidential reporting: what actually protects employees
Every workplace reporting tool says some version of "your identity is protected." Almost none of them explain what that actually means technically, and the difference matters more than the marketing copy suggests.
Two different promises, not one
Rectifia gives reporters a real choice at intake, not a single "anonymous-ish" setting: anonymous or confidential. These aren't two flavors of the same protection. They're two different technical guarantees.
Anonymous means no identity is ever stored. Not an email address, not a phone number, not even a hashed version of a name that HR could theoretically reverse later with enough motivation and access. There's simply nothing there to find, because nothing was ever collected. If someone subpoenaed the system, walked in with admin access, or asked HR directly who filed a report - the honest answer would be "we don't know, we never captured it."
Confidential means identity is known, but locked down. The reporter's identity is encrypted and stored behind a split-key vault, and it's visible only to the specific handler assigned to that case. This mode exists because sometimes a reporter genuinely needs follow-up contact - an investigator who needs to schedule an interview, or a reporter who wants to be kept in the loop by name. Confidential trades some of the absolute protection of anonymous mode for that direct line of communication, and the reporter is the one who decides that tradeoff, upfront, before they submit anything.
Both are legitimate. Neither is the "real" anonymity and the other a lesser version. They protect against different things.
The problem anonymous mode alone doesn't solve
Full anonymity is airtight, but it comes with a real cost: if a reporter has no way to prove they're the same person who filed the original report, how do they check on it later, or add evidence they forgot the first time, without creating exactly the kind of identifying trail anonymity was supposed to avoid?
Rectifia's answer is a case ID and passcode, generated at submission, with no login and no email tied to it. The reporter writes it down, keeps it somewhere private, and uses it to come back later - check status, add a document, answer a follow-up question from the handler - without ever creating an account, an email trail, or anything that connects back to who they are. It replaces a login the same way a locker combination replaces a name tag.
Why "we promise not to look" isn't the same as "we can't look"
A lot of reporting tools describe their anonymity as a policy commitment: we collect some identifying data, but we promise not to use it against you, or to only share it under specific conditions. That's a real protection, and it's better than nothing. But it's a different category of protection than a system that architecturally never had the data to begin with.
Anonymous mode in Rectifia isn't a policy promise sitting on top of collected data. There's no identity field to accidentally expose, no database column that could be misconfigured, no access log that could be subpoenaed for something that was never there. The protection isn't a rule someone has to follow correctly every time. It's a property of what the system does and doesn't store in the first place.
What this looks like for the person filing the report
At the point of submission, the reporter sees the tradeoff stated plainly: anonymous means total protection but no direct follow-up channel beyond the case ID and passcode; confidential means the assigned handler can reach out by name, and that identity sits encrypted, accessible only to that one person, for that one case.
Most reporting decisions in a workplace aren't really about the form. They're about whether someone believes what happens after they hit submit. Naming the actual mechanism - what's stored, what isn't, and who can see what - is what makes that belief possible in the first place, instead of asking someone to just take a company's word for it.