Confidentiality

Private by design, accountable when support is needed.

Confidentiality here is structural, not a policy promise. What each person can see is decided by the architecture, and every exception is recorded.

The four guarantees

How privacy is enforced.

Grouped reporting

Employer and manager reporting is aggregated by department. Individual answers are never shown.

Small groups hidden

Any group with fewer than five responses is suppressed, so no one can be inferred from a small denominator.

No answers leave

Answers and personal details are not sent to partner systems. Only the routing signal crosses the boundary.

Audited reveal

Authorised Confidential Care users can access one person’s information at a time. They must give a reason, set an end date, and the access is permanently recorded.

Identity reveal

One person at a time, for a stated reason.

Confidential Care shows participant references, not names. When support genuinely requires knowing who someone is, an authorised user reveals a single participant and gives a reason.

The reveal expires on its own, only one can be active at a time, and the full history is available for review, including who revealed whom, when, and why.

Why it works this way

Making the exception visible and finite is what keeps the default private.

Read the architecture, then try it.

Open the demo to see exactly what each role can and cannot see.

Request a demo