The whistleblowing channel that holds up as evidence before courts and labor authorities.
When the harassment complaint arrives, your channel has to hold up in court. A form or an email can be altered without a trace. LexCompliance seals every piece of evidence with an RFC 3161 cryptographic timestamp and an immutable chain: you hand over proof, not your word.
Access by request · A ForensicCorp forensic specialist contacts you within 24h

The day this reaches court, will you have proof or just your word?
LexCompliance was built by the forensic examiners of ForensicCorp SpA, who investigate real cases and testify before the Labor Directorate (DT) and the courts. It's not a whistleblowing inbox with a layer of software on top: it's the forensic methodology we use in expert reports, built into the product.
Meet ForensicCorpWhy not keep using what you have?
Every alternative you use today is a source of legal, operational or reputational risk for your company.
vs. Excel or Word
No traceability, no automatic deadlines, no real anonymity. A labor lawsuit for harassment can cost 10x–30x more than LexCompliance per year.
DT fine up to 60 UTM + reputational damageImmutable HMAC-SHA256 audit trail. Decreto 21/2024 deadlines calculated automatically. Encrypted zero-knowledge portal.
vs. Email or WhatsApp
Identifies the whistleblower via IP, phone number or metadata. Violates the right to anonymity under Ley 21.643. Exposes the company to retaliation claims.
Criminal liability for retaliation (art. 485, Labor Code)No IP tracking. No cookies. Automatic EXIF/GPS stripping. Encrypted mailbox with Argon2id PIN. Random tracking code.
vs. Generic solutions (NAVEX, EthicsPoint)
They don't know Decreto 21/2024, the Chilean DT forms or business-day deadlines. The forensic report doesn't meet the 10 mandatory sections. No support for Ley 21.719.
Nullity of the procedure before the DTBuilt specifically for CL/LATAM. Native Decreto 21/2024, business-day deadlines, 10-section report, ROPA/DPIA Ley 21.719.
vs. External consultant
Fees of CLP 300,000–800,000 per case plus business-day response times. No 24/7 availability for new reports. No portal for the whistleblower.
Breach of the 3-business-day DT notification deadlineLexCompliance runs 24/7. Encrypted portal always active. PDF report generated automatically. The consultant as support, not the only channel.
Everything you need for an investigation that holds up.
International tools don't know Ley Karin or Decreto 21/2024. We were born doing forensics in Chile: every feature exists because a real case demanded it.
Evidence that holds up in court
ExclusiveGenerates evidence with a cryptographic timestamp (RFC 3161), prepared to the standard of admissibility as digital proof before a labor court. Generic channels don't offer this.
A record no one can alter
ImmutableAppend-only audit trail with REVOKE UPDATE/DELETE at PostgreSQL level. Each entry chains a SHA-256 hash. Any alteration breaks the entire subsequent chain — detectable in real time.
Detect systematic harassment, no black box
No AI/LLM6 SQL rules detecting systematic harassment and retaliation patterns. No predictive models. Every alert is explainable to a judge — legally defensible because it's not a black box.
Investigations the DT can't challenge
Decree 21/2024The system automatically verifies each investigation meets all 9 principles of art. 2 Decreto 21/2024 before allowing closure. Generic channels don't verify this.
Ready for the new data law (2026)
Act 21.7196 ARCO+ rights (Access, Rectification, Deletion, Opposition, Portability, Restriction) with direct effect on the database, not just as a record. Ready for December 2026.
One system for the whole region
LATAM5 complete legal frameworks in one system: business-day deadlines per country, notification flows and adapted forms. One contract for all LATAM.
3 steps. From report to legal closure.
Every stage automated, documented and 100% compliant with Chilean labor law and anti-corruption law.
Reporter files a complaint
Access by QR, code or direct link. No registration or account. Zero-knowledge anonymity guaranteed by design.
- AES-256-GCM end-to-end encrypted portal
- No IP, no tracking cookies
- Tracking code + Argon2id PIN
- Automatic EXIF/GPS strip from attachments
Team investigates
RBAC + MFA-protected investigators receive the complaint. Automatic working-day deadlines, documented proceedings, digital chain of custody.
- 30 working-day deadlines (Decree 21/2024) automated
- 5 RBAC roles with mandatory TOTP MFA
- Signed proceedings with chain of custody
- Immutable HMAC-SHA256 audit trail
Full legal closure
The system generates the 10-section forensic PDF report and notifies the Labor Directorate. Fully automated and defensible in court.
- 10-section PDF report (Decree 21/2024)
- Labor Directorate notified within 3 working days
- Pronouncement monitored for 30 working days
- Adopted measures + documented closure
Who is LexCompliance for?
Three perspectives. One system that integrates them all.
Reporter
Any employee who needs to report an incident safely, anonymously and without fear of retaliation.
- Anonymity guaranteed by design
- Secret tracking code + PIN
- Anti-retaliation protection
- Portal available 24/7 in 3 languages
Investigator / Case Manager
The team responsible for investigating under Decree 21/2024, Ley Karin and Law 20.393.
- Centralized inbox with working-day deadlines
- Documented proceedings and interviews
- Automatic PDF report generation
- Labor Directorate notifications and tracking
DPO / Compliance / HR
Those who oversee full compliance and personal data protection for the organization.
- Real-time metrics dashboard
- ROPA + DPIA + DPA ready
- Exportable executive reports in PDF
- Labor audits without friction
The whistleblower channel your company needs, today.
30 real complaints. Automatic deadlines. Compliance score. AES-256-GCM encryption on every field.

Mission Control with real-time KPIs: overdue deadlines, compliance score, Ley Karin alerts and SLA per investigation.
Enterprise infrastructure from day one.
The CISO checklist completed. SSO SAML, SCIM 2.0, HRIS connectors, public REST API and multi-tenant with RLS.
SSO OIDC + SAML 2.0
GAMicrosoft Entra, Okta, Google Workspace. SP-initiated and IdP-initiated. The #1 enterprise deal blocker — solved.
SCIM 2.0 Auto-provisioning
GAAutomatic user sync from your IdP. Immediate deprovisioning on directory deactivation. IT procurement requires it — it's already there.
Public REST API + HMAC Webhooks
GAVersioned API v1 + HMAC-SHA256 webhooks. Integrate LexCompliance with your enterprise stack without depending on the UI.
HRIS Connectors + Anti-Retaliation Sentinel
GANative BambooHR. Sentinel detects dismissals of active whistleblowers via HRIS sync — the only feature of its kind in the market.
Multi-tenant with RLS
ArchitectureFull isolation per organization via Row Level Security in PostgreSQL. Org A never sees Org B's data — verifiable with an audit query.
Hierarchical conflict of interest
AutomaticScans 3 management levels in real time. The implicated investigator is automatically blocked and excluded — hierarchical COI, not just flat.
Real zero-knowledge. Forensic-grade.
Every design decision protects the whistleblower and produces legally valid evidence before a court.
Whistleblower zero-knowledge
No IP or User-Agent logging on the public portal. No tracking cookies. The system doesn't know who you are unless you say so.
View security policy →Automatic EXIF/GPS strip
sharp processes every attachment and removes location, device and author metadata before storage. No trace of the device remains on the server.
Argon2id PIN — gold standard
The whistleblower's secure mailbox is protected by a PIN hashed with Argon2id. Resistant to brute-force and rainbow table attacks.
DPA with all sub-processors
Supabase, Vercel, Resend, Upstash — all with signed DPA. ROPA updated automatically. Dynamic DPIA art. 50 Act 21.719.
View security policy →Forensic Bundle with Merkle root
Every exportable bundle includes RFC 3161 TSA timestamp and a Merkle root publicly verifiable at /verify-audit — no need to trust us.
View security policy →Audit trail REVOKE UPDATE+DELETE
PostgreSQL physically prevents modifying or deleting audit records. Chained HMAC-SHA256 — any alteration breaks the entire chain and pinpoints exactly where.
Receiving reports is not the same as being able to prove them.
The gap between a generic channel and a forensic case file that withstands an inspection.
| Capability | Generic channel | LexCompliance |
|---|---|---|
| Native Ley Karin (Decreto 21/2024, business-day deadlines) | ||
| TSA timestamp (RFC 3161) per report | ||
| Public Merkle verification without database access | ||
| Forensic Bundle: evidentiary file with chain of custody | ||
| Act 21.719 (ROPA / DPIA / ARCO+) preconfigured | ||
| Zero-knowledge of the whistleblower | ||
| Backed by forensic examiners (ForensicCorp) |
Built on verifiable standards
Built on real legislation. Not adapted.
ForensicCorp SpA investigates harassment cases before the Labor Directorate. LexCompliance is what we found was missing.
Ley Karin
Flow without admissibility, 9 Decreto 21/2024 principles, business-day deadlines, automatic DT notification.
Criminal Liability PJ
COMPLIANCE flow with admissibility, referral to public prosecutor, MPD and complete forensic audit.
Economic Offences
Good-faith whistleblower protection. Retaliation detected and blocked automatically.
Personal Data
ROPA + DPIA + DPA + ARCO+ already implemented. In force December 2026.
MinTrab
The 9 investigation principles, deadlines and DT forms coded into the FSM.
Multi-jurisdiction
5 LATAM legal frameworks in one system. Spain and Italy on the roadmap.
Don't trust the copy alone? Verify the audit trail integrity yourself.
Verify chain of custody →Frequently asked questions
Yes. Ley Karin (21.643) requires ALL companies with 1 or more workers since August 2024 (art. 3). Ley 20.393/21.595 requires a whistleblower channel for the Crime Prevention Model. Ley 21.719 (December 2026) adds data protection obligations that LexCompliance already meets.
Yes. The LABORAL flow has no admissibility review (as required by Decreto 21/2024 art. 10), calculates all deadlines in Chilean business days, generates the final report with all 10 mandatory sections, notifies the DT within 3 business days, and supports verbal complaints via transcribed record.
Yes. The COMPLIANCE flow has formal admissibility review, prosecution referral when applicable, complete forensic audit trail, and whistleblower protection (Ley 21.595).
Yes, already implemented. LexCompliance includes: multi-step ROPA workflow, dynamic DPIA per art. 50, DPA with certified sub-processors, ARCO+ module for data subject requests, and a 72h breach notification template.
Yes: (1) No IP or User-Agent logged on the public portal, (2) no tracking cookies, (3) automatic EXIF/GPS metadata strip on attachments, (4) random-gap tracking codes (not sequential), (5) PIN-encrypted mailbox using Argon2id, separate from identity.
The audit trail is an append-only PostgreSQL table with REVOKE UPDATE and REVOKE DELETE. Each entry chains a HMAC-SHA256 hash with the previous entry — any modification breaks the entire subsequent chain, detectable instantly. Minimum 5-year retention.
PostgreSQL on Supabase (AWS infrastructure). Frontend on Vercel (edge, no PII). Whistleblower PII encrypted field-by-field with AES-256-GCM. TLS 1.3 in transit. Encrypted backups with separate key. DPA signed with all sub-processors available for audit.
LexCompliance generates the forensic PDF report with all 10 sections required by Decreto 21/2024 in one click. The HMAC-SHA256 audit trail provides complete digital chain of custody for every action — defensible before the DT and in labor court.
LexCompliance automatically detects this situation and mandatorily refers to the DT, per Decreto 21/2024. The system blocks the implicated legal representative's access to the case and records the event in the audit trail.
Yes. The system implements Ley 21.595 protections: encrypted whistleblower identity, communication exclusively via anonymous mailbox, conflict-of-interest detection and alerts, and recording of any unauthorized access to the case file.
Access is by request. After completing the registration form, a ForensicCorp SpA specialist contacts you within 24 business hours to configure your account with the exact features your company needs. No credit card — monthly or annual billing in CLP + VAT once activated.
ForensicCorp SpA (forensic.cl) is a Chilean company specializing in digital forensics and legal compliance. The team has direct experience with DT procedures, labor investigations, and compliance audits. LexCompliance is built on 2271+ automated tests and security architecture audited against ISO 27001 and CIS Controls v8.
The law is already in force. Is your company ready?
Ley Karin since August 2024. Ley 21.719 in December 2026. Don't wait for a complaint or fine. LexCompliance sets up in under 2 hours.
Request accessAccess by request · A ForensicCorp specialist contacts you within 24 business hours