Case Study - Elker
Elker is an encrypted reporting and feedback tool which helps employees get support without risk and aids leaders in strategic data-driven decisions.
- Client
- Elker
- Year
- Service
- Database architecture, System design, UX Design, Branding, Web development, Machine Learning, Artificial Intelligence

Overview: Technology for Psychological Safety
Elker is reimagining how organisations respond to feedback, whistleblowing, and incident reporting. The platform enables safe, anonymous communication between employees and leadership — with the right balance of empathy, structure, and compliance.
Codacora partnered with Elker to build a complete, privacy-first reporting ecosystem. From infrastructure and app development to behavioural design and AI, we helped transform a bold idea into a platform that’s now used by government agencies, councils, and national organisations across Australia.
The result is a highly secure, scalable, and user-friendly solution that gives voice to those who need it most — and helps organisations respond with confidence and care.
Human-Centred UX for Difficult Moments
We approached Elker’s design not just as a technical challenge, but a human one. Reporting a workplace issue can be emotionally charged — especially when anonymity is involved — so every design decision needed to support safety, clarity, and calm.
We collaborated closely with stakeholders to map out the emotional and functional journeys for reporters, reviewers, and administrators. The interface avoids heavy-handed prompts or complex forms, instead guiding users gently with plain language, autosave, and flexible reporting pathways.
Accessibility was also core to our process. The platform meets WCAG compliance standards, supports assistive technologies, and works effectively across low-bandwidth environments — including on mobile devices in remote areas.
Business-Focused AI, Built for Privacy and Precision
At the core of Elker’s mission is trust — and our AI implementation was built to reflect that. Every AI feature was developed with privacy preservation as a first principle, ensuring that automation never compromises user safety or data confidentiality.
Rather than building for engagement, we focused on delivering operational value to those managing workplace feedback: streamlining analysis, reducing manual load, and surfacing critical issues — all without exposing sensitive information.
Key AI Features
- Privacy-Preserving Categorisation
- AI models automatically tag and route reports based on severity, topic, and risk indicators — without ever storing or reusing the underlying message content. All processing is done securely, within Elker’s encrypted infrastructure.
- Redaction and Smart Anonymity Safeguards
- Our models help preserve user anonymity by identifying and flagging potentially identifying information in real time. Where needed, automatic redaction tools remove names, roles, and locations — giving users peace of mind while maintaining the integrity of the report.
- Context-Aware Summarisation
- For case managers, long and complex reports are summarised using on-platform AI into concise briefs — never stored, reused, or shared outside the secure environment. This reduces cognitive load and helps decision-makers focus on action.
- Emerging Risk Detection
- By analysing report metadata and themes (not identities or content), the system can surface patterns such as recurring issues in a team or geography — without violating reporter privacy. This allows leaders to respond proactively while respecting anonymity.
These AI-powered tools aren’t just smart — they’re accountable, transparent, and aligned with Elker’s ethical standards. Every function operates within a clear privacy and data handling framework designed to meet ISO 27001 and GDPR-aligned obligations.
Security Architecture: Encryption, Controls & Certification
Security was never an afterthought. From the first discovery session, we embedded secure-by-design principles into every part of Elker’s infrastructure and codebase. The goal: a platform that clients could trust with their most sensitive data.
Highlights:
- End-to-End Encryption: All message data — including metadata — is encrypted in transit and at rest, using industry-standard protocols and rotating keys.
- Role-Based Access Controls: Access to sensitive functions is restricted through granular roles, with audit trails tracking every action taken on a case.
- Data Sovereignty: All data is stored onshore in Australian data centres, meeting legal requirements for government and public sector clients.
- ISO 27001-Aligned: The system is governed by documented security policies and change management processes aligned with ISO 27001 and ISM frameworks.
- Privacy Impact Assessment (PIA): Every feature passed through a privacy review process, ensuring compliance with Australia’s Privacy Act and global best practices.
By focusing on user protection and rigorous security posture, we made sure Elker could scale into high-trust sectors — without compromise.
Scalable Infrastructure & Deployment Pipelines
To support future growth and institutional clients, we built Elker’s backend to be both robust and flexible. The platform is cloud-native, modular, and designed for zero-downtime deploys.
What We Delivered:
- Containerised Architecture: All components run in Docker containers, orchestrated via ECS and managed through Infrastructure as Code for repeatable, auditable deployments.
- Multi-Zone Redundancy: Production workloads are distributed across multiple availability zones for resilience.
- CI/CD Pipeline: Automated testing, build, and deployment workflows reduce human error and enable rapid iteration with rollback safety.
- Monitoring & Alerts: Integrated observability with custom dashboards, error reporting, and performance tracking.
- Feature Flagging & Environment Isolation: Enables parallel testing and controlled releases without risk to production users.
Whether it’s a small policy change or a major new feature, Elker’s team can deploy it confidently — knowing the platform will remain stable, secure, and responsive.
Unified Mobile & Web Development
We designed and developed Elker as a cross-platform experience from day one. While many tools focus on desktop use, Elker needed to be just as effective on a mobile phone in a remote community as in an office setting.
- Single Codebase with Platform-Specific Optimisation: Shared business logic between mobile and web apps reduces duplication, while native interfaces ensure smooth usability.
- Offline and Low-Connectivity Support: Mobile reporting features include local data caching and delayed sync for rural or field-based users.
- Accessibility Features: Designed to support keyboard navigation, screen readers, and WCAG 2.1 AA compliance on all devices.
- Frontend Stack: Vue.js for the web, combined with a Rails backend and API-first architecture, enables rapid delivery and strong maintainability.
The result is a consistent, reliable user experience — no matter where or how someone uses the platform.
Outcome: A Platform Trusted by Institutions and Individuals Alike
Codacora helped Elker turn a bold vision into a secure, intelligent, and deeply human product. Every element — from encryption to interface copy — was crafted to build trust and reduce the barriers to speaking up.
Today, Elker supports government, education, not-for-profits, and private organisations in building safer, more responsive workplaces. And with a secure, scalable foundation in place, the platform is now poised for expansion across sectors and international markets.