Security
What we actually do to protect what you send us, stated without certification badges we have not earned. And the things only you can do, which matter more than any of it.
Last updated 26 July 2026
What you should do first
The strongest protection on this page is yours, not ours.
- Use a personal device on a personal network. Not a work laptop, not a work phone, not company wifi. Employers can lawfully monitor equipment and networks they own, and browsing history on a work machine is how most people are identified.
- Use a personal email address. Never a work address, and never one your employer administers.
- On the report page itself, use the Quick exit button in the top right, or press Escape twice. Both leave immediately for weather.gov, a deliberately unremarkable destination, and replace the report page in your history rather than adding to it. Note that earlier pages in the same session are still reachable with the back button.
- Consider a private browsing window, and clear your history afterwards.
- Do not discuss your report on work chat, work email, or a work-issued phone.
What we do
- All traffic is served over HTTPS/TLS. Data is encrypted in transit and encrypted at rest by our hosting and database providers.
- We load no third-party code on /report. No analytics, no tag manager, no advertising pixels, no externally hosted fonts. Our typefaces are served from our own origin specifically so that loading the page does not tell a font CDN that you were here, and a Content-Security-Policy on that path blocks off-origin scripts. The honest caveat: the site is served through Cloudflare, whose edge can inject its own telemetry independently of our code. We are disabling that for this path and will say so here once it is verified.
- We do not store your IP address or browser fingerprint with a report. An IP is held briefly in memory to stop automated abuse, and is never written to the database alongside what you told us.
- Nothing is written to your device. No cookies, no local storage, no draft saving. Close the tab before the last step and the draft is gone from everywhere, including from us.
- Notification emails to our team contain only a reference code, never the contents of a report, so disclosures do not end up sitting in a mailbox.
- Access to submitted reports is limited to the two founders. There is no shared team inbox and no partner access.
- Submissions are rate-limited to resist automated abuse.
Why is confidentiality here a legal obligation rather than a preference?
Because for a qui tam matter it is ordered by a court. Under 31 U.S.C. § 3730(b)(2), a qui tam complaint is filed in camera and “shall remain under seal for at least 60 days,” and it is not served on the defendant until the court so orders. Courts routinely extend that period, so the confidentiality obligation attaching to the record set is measured in months or years rather than weeks.
That is the standard the handling described above is meant to meet. It is also why the honest answer to “are you certified” is the one in the next section rather than a badge.
What we do not claim
We would rather be trusted for what is true than impressive about what is not. As of the date above:
- WOLF AI is not SOC 2 certified. No audit has been completed.
- We do not hold a HIPAA attestation, and this site is not a HIPAA-covered service.
- No independent penetration test has been performed on this site.
- We are an early-stage company. Our infrastructure is small, and its main protection is that very few people have access to it.
- We cannot make you anonymous. We can decline to collect what would identify you, and we do, but our host processes network requests to serve any page at all. That is why this site says confidential and never says anonymous.
When any of that changes, this page changes with it, and not before.
Reporting a vulnerability
If you find a security problem with this site, please tell us at contact@getwolf.ai before disclosing it publicly. We will acknowledge within three business days and will not pursue legal action against anyone acting in good faith to make this safer for the people who use it.
Questions about any of this go to contact@getwolf.ai. If your question is about a report you submitted, include your reference code and nothing else. Do not repeat the details in email.