# EU Whistleblower Directory — Full Content > Independent directory of whistleblower reporting tools for EU Directive 2019/1937 compliance. Compare features, pricing, and compliance coverage. This directory lists whistleblower reporting platforms marketed for compliance with EU Directive 2019/1937. Every fact is sourced from the vendor's own published materials and dated at last verification. --- ## Rankings # Whistleblowing software in Austria — scored ranking Of the 3 platforms scored against HSchG, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/austria/ - Law applied: HinweisgeberInnenschutzgesetz (HSchG), in force 25 February 2023 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Austria modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Austria bonus 5, tier P+R+H) 2. Hintbox — 37/56 (base 32, Austria bonus 5, tier P) 3. Fraud Line — 19/56 (base 16, Austria bonus 3, tier P) The finding in Austria is what is absent. No Austrian vendor appears in this ranking at all. The three scored platforms are a German product, a Greek one, and the publisher’s own — and none of them hosts data in Austria. That is unusual for a market with a 50-employee threshold and an obligation in force since February 2023. Germany, next door and on the same language, supports thirty-two scored platforms. Austrian buyers are effectively choosing from the German market, which works linguistically and does not answer the residency question if an Austrian authority ever asks it. Two of the three name Austria or the HSchG in their stated coverage, and neither is Austrian: one is a German platform that lists Austria alongside Germany, the other is ours. The third describes national coverage generically and does not name the act. This is a thin edition and it is published as one. More platforms will appear as scoring completes, and an Austrian vendor that publishes its hosting country would enter near the top of the modifier on day one. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Austria modifier, which rewards an explicit HSchG reference, a named hosting country or EU provider, and a genuine German-language surface. --- # Whistleblowing software in Belgium — scored ranking Of the 3 platforms scored against Law of 28 November 2022, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/belgium/ - Law applied: Wet/Loi van 28 november 2022 - Edition: Edition I, 2026, tested June 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Belgium modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Belgium bonus 5, tier P+R+H) 2. Whistleblower Software (Formalize) — 36/56 (base 32, Belgium bonus 4, tier P) 3. FaceUp — 30/56 (base 26, Belgium bonus 4, tier P) Belgium is an unusual market: there is no Belgium-origin whistleblowing-software vendor. Belgian employers buy from pan-EU platforms — frequently introduced through a Belgian law firm — rather than from a domestic product. So this ranking is not “local vendors vs. imports”; it is a comparison of the directive-grade tools that actually serve the Belgian market, scored on the same rubric as every other country. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Belgium modifier, which rewards explicit reference to the Law of 28 November 2022, a named Belgium-acceptable hosting posture, and a Dutch- or French-language reporter / handler surface (Belgium’s two main working languages). That combination rewards tools that go beyond generic Directive 2019/1937 marketing to a real Belgian-law posture and Belgium’s bilingual reality. This ranking is software-only. Belgian law firms and consultancies that resell or wrap a third-party platform are not listed in their own right; the underlying platform is what is scored. The Federal Ombudsman’s Integrity Centre is the external reporting coordinator and the FSMA covers the financial sector — those are reporting destinations, not products, and are out of scope here. --- # Whistleblowing software in Bulgaria — scored ranking Of the 5 platforms scored against Act on Protection of Persons Reporting or Publicly Disclosing Information on Breaches, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/bulgaria/ - Law applied: Act on Protection of Persons Reporting or Publicly Disclosing Information on Breaches - Edition: Edition I, 2026, tested April 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Bulgaria modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Bulgaria bonus 5, tier P+R+H) 2. WeMoral — 32/56 (base 29, Bulgaria bonus 3, tier P) 3. Phoenix — 25/56 (base 23, Bulgaria bonus 2, tier P+H) 4. Confidential Reporting System — 24/56 (base 20, Bulgaria bonus 4, tier P) 5. Fraud Line — 19/56 (base 16, Bulgaria bonus 3, tier P) Bulgaria is thinner than Romania, but it is not empty. The visible field today is one real Bulgaria-native software product, several imported tools with live Bulgarian-language commercial surfaces, and a larger ring of advisory-led offers whose underlying product is not independently reviewable. This edition therefore uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Bulgaria modifier, which rewards explicit Bulgarian-law posture, a named Bulgaria-acceptable hosting disclosure, and a real Bulgarian-language reporter / handler surface. That combination penalises the three most common Bulgaria-market failure modes: service-heavy compliance wrappers with no independently reviewable software; imported tools with Bulgarian localisation but no local-law posture; and local offers with credible law framing but weak commercial or security disclosure. This ranking is software-only and includes both Bulgaria-native vendors and foreign tools with concrete Bulgarian-language or Bulgaria-market go-to-market signal. Law-firm, hotline, or investigations-led services are excluded unless the underlying whistleblowing product is independently reviewable. --- # Whistleblowing software in Czechia — scored ranking Of the 5 platforms scored against Act No. 171/2023 Coll., EthicsPortal ranks first with 50 of 56 points. - URL: https://whistleblowertools.eu/countries/czech-republic/ - Law applied: Act No. 171/2023 Coll. on the Protection of Whistleblowers (zákon o ochraně oznamovatelů) - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Czechia modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 50/56 (base 47, Czechia bonus 3, tier P+R+H) 2. Firmsys — 33/56 (base 28, Czechia bonus 5, tier P) 3. OhlasTo — 31/56 (base 25, Czechia bonus 6, tier P) 4. FaceUp — 29/56 (base 26, Czechia bonus 3, tier P) 5. Whispero — 28/56 (base 23, Czechia bonus 5, tier P) Czechia is a small field that is nonetheless well served locally: three of the five scored platforms are Czech vendors, four ship a Czech reporter surface, and the Ministry of Justice runs a public whistleblower portal that makes the legal baseline freely available. A vendor restating the law adds little here; what it discloses about itself is the differentiator. Only one platform names domestic Czech servers. The rest assert EU residency without naming a country, which is the common pattern across smaller EU markets — the vendor is local, the infrastructure is not described. The largest vendor by international reach in this field, FaceUp, is Czech-founded but names the German HinSchG rather than Act No. 171/2023 in its stated national-law coverage. It scores zero on the law criterion in its own home market. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Czechia modifier, which rewards an explicit reference to Act No. 171/2023 Coll., a named hosting country or EU provider, and a genuine Czech-language surface. --- # Whistleblowing software in Denmark — scored ranking Of the 3 platforms scored against Act 1436/2021, EthicsPortal ranks first with 50 of 56 points. - URL: https://whistleblowertools.eu/countries/denmark/ - Law applied: Act No. 1436 of 29 June 2021 on the Protection of Whistleblowers, in force 17 December 2021 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Denmark modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 50/56 (base 47, Denmark bonus 3, tier P+R+H) 2. Whistlelink — 43/56 (base 39, Denmark bonus 4, tier P+H) 3. WhistleSystem — 25/56 (base 20, Denmark bonus 5, tier P) Denmark transposed early, in December 2021, and has one of the longest-running obligations in the EU — but only three scored platforms in this directory cover it, and each falls down on a different criterion. The one Danish vendor in the field is the only platform here shipping a Danish reporter surface, and it is also the only one that does not name the Danish act in its stated coverage. The Nordic platform names Denmark but ships no Danish locale. The publisher’s own product names the act and ships neither a Danish locale nor Danish hosting. No platform in this ranking scores full marks on the Denmark modifier, and none hosts data in Denmark. A Danish buyer should read this edition as a thin one rather than a verdict on the market. Danish organisations often buy from the wider Nordic field, and Swedish vendors that have not yet been scored against the Danish act would change this table. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Denmark modifier, which rewards an explicit reference to Act No. 1436/2021, a named hosting country or EU provider, and a genuine Danish-language surface. --- # Whistleblowing software in France — scored ranking Of the 12 platforms scored against Loi Waserman, EthicsPortal ranks first with 54 of 58 points. - URL: https://whistleblowertools.eu/countries/france/ - Law applied: Loi n° 2022-401 du 21 mars 2022 (Loi Waserman) + Loi Sapin II for 500+ organisations - Edition: Edition I, 2026, tested April 2026 - Rubric: 50-point base fixed before scoring, plus a 8-point France modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 54/58 (base 47, France bonus 7, tier P+R+H) 2. Whistleblower Software (Formalize) — 39/58 (base 32, France bonus 7, tier P) 3. Whispli — 38/58 (base 31, France bonus 7, tier P) 4. IntegrityLog — 36/58 (base 33, France bonus 3, tier P) 5. BeSignal — 34/58 (base 26, France bonus 8, tier P) 6. EQS Integrity Line — 34/58 (base 27, France bonus 7, tier P) 7. WeMoral — 34/58 (base 29, France bonus 5, tier P) 8. NAVEX — 30/58 (base 27, France bonus 3, tier P) 9. Alertcys — 27/58 (base 19, France bonus 8, tier P) 10. FaceUp — 27/58 (base 26, France bonus 1, tier P) 11. Witik — 27/58 (base 20, France bonus 7, tier P) 12. IntegrityCounts — 25/58 (base 24, France bonus 1, tier P) France is one of the few EU markets where the local bonus genuinely matters. A generic “EU Directive compliant” claim is not enough here: buyers ask whether the vendor understands Loi Waserman, whether Sapin II is still in scope for larger organisations, and whether the product feels credible in a French procurement context. This edition therefore mixes two layers: the 50-point base rubric, which is country-agnostic and measures product quality, security posture, pricing transparency, and workflow depth; the 8-point France modifier, which rewards explicit Waserman / Sapin II framing, French-language UI, and France-specific residency where it is publicly offered. The result is a ranking that penalises two common failure modes in the French market: old domestic products with strong local positioning but weak product depth, and strong global products with almost no France-law posture. --- # Whistleblowing software in Germany — scored ranking Of the 32 platforms scored against HinSchG, EthicsPortal ranks first with 53 of 56 points. - URL: https://whistleblowertools.eu/countries/germany/ - Law applied: Hinweisgeberschutzgesetz (HinSchG), in force 2 July 2023 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Germany modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 53/56 (base 47, Germany bonus 6, tier P+R+H) 2. Confidly — 48/56 (base 42, Germany bonus 6, tier P) 3. Whistlelink — 44/56 (base 39, Germany bonus 5, tier P+H) 4. OpenSource Hinweisgeberportal — 39/56 (base 33, Germany bonus 6, tier P) 5. Hintbox — 38/56 (base 32, Germany bonus 6, tier P) 6. IntegrityLog — 38/56 (base 33, Germany bonus 5, tier P) 7. Whistleblower Software (Formalize) — 38/56 (base 32, Germany bonus 6, tier P) 8. whistle.law — 36/56 (base 31, Germany bonus 5, tier P) 9. whistly — 35/56 (base 29, Germany bonus 6, tier P) 10. hinweis.de — 34/56 (base 28, Germany bonus 6, tier P) 11. Legality Whistleblowing (DigitalPA) — 34/56 (base 29, Germany bonus 5, tier P) 12. tell it — 34/56 (base 28, Germany bonus 6, tier P) 13. Whispli — 34/56 (base 31, Germany bonus 3, tier P) 14. WhistlePort — 33/56 (base 27, Germany bonus 6, tier P) 15. EQS Integrity Line — 32/56 (base 27, Germany bonus 5, tier P) 16. whizzla — 32/56 (base 28, Germany bonus 4, tier P) 17. hintcatcher — 31/56 (base 25, Germany bonus 6, tier P) 18. Zateo — 31/56 (base 25, Germany bonus 6, tier P) 19. Cortina Compliance Hub — 30/56 (base 24, Germany bonus 6, tier P) 20. FaceUp — 30/56 (base 26, Germany bonus 4, tier P) 21. LegalTegrity — 30/56 (base 24, Germany bonus 6, tier P) 22. NAVEX — 30/56 (base 27, Germany bonus 3, tier P) 23. whistlebox — 30/56 (base 24, Germany bonus 6, tier P) 24. Hintbird — 28/56 (base 24, Germany bonus 4, tier P) 25. SpeakUp — 28/56 (base 26, Germany bonus 2, tier P) 26. CLUE#ZO — 27/56 (base 22, Germany bonus 5, tier P) 27. preeco — 26/56 (base 20, Germany bonus 6, tier P) 28. otris — 24/56 (base 20, Germany bonus 4, tier P) 29. WhistleFox — 22/56 (base 18, Germany bonus 4, tier P) 30. PRIMA Compliance — 21/56 (base 15, Germany bonus 6, tier P) 31. Fraud Line — 19/56 (base 16, Germany bonus 3, tier P) 32. osapiens — 19/56 (base 15, Germany bonus 4, tier P) Germany is the most crowded whistleblowing software market in the EU — 32 scored platforms here against 12 in Italy and 7 in the Netherlands — and the crowding is what makes the ranking useful. When three dozen vendors all claim HinSchG compliance, the separation comes from what each one actually discloses. Two details of the German regime drive the scoring. The act requires written and oral intake with an in-person meeting on request, so a web form alone is not a complete channel. And the 50–249 band may operate a joint internal reporting office, which makes multi-entity and shared-office handling a real product requirement rather than an enterprise nicety. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Germany modifier, which rewards an explicit HinSchG reference, a named hosting country or EU provider, and a genuine German-language surface. The modifier exposes a pattern worth naming: several German-domiciled vendors anchor their compliance copy on the Supply Chain Act (LkSG) or the Geldwäschegesetz rather than the HinSchG. That is a different obligation with a different scope, and it scores zero on the law criterion — not because the product is weak, but because the buyer researching a HinSchG channel is not being answered. --- # Whistleblowing software in Greece — scored ranking Of the 9 platforms scored against Law 4990/2022, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/greece/ - Law applied: Law 4990/2022 (Greek transposition of EU Directive 2019/1937) - Edition: Edition I, 2026, tested April 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Greece modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Greece bonus 5, tier P+R+H) 2. Whistleblower Software (Formalize) — 37/56 (base 32, Greece bonus 5, tier P) 3. Whispli — 32/56 (base 31, Greece bonus 1, tier P) 4. Digitech (TalkNow) — 28/56 (base 23, Greece bonus 5, tier P) 5. EQS Integrity Line — 28/56 (base 27, Greece bonus 1, tier P) 6. NAVEX — 28/56 (base 27, Greece bonus 1, tier P) 7. FaceUp — 27/56 (base 26, Greece bonus 1, tier P) 8. myETHOS — 24/56 (base 19, Greece bonus 5, tier P) 9. Fraud Line — 20/56 (base 16, Greece bonus 4, tier P) --- # Whistleblowing software in Italy — scored ranking Of the 12 platforms scored against D.Lgs. 24/2023, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/italy/ - Law applied: Legislative Decree No. 24 of 10 March 2023 (D.Lgs. 24/2023) - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Italy modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Italy bonus 5, tier P+R+H) 2. Confidly — 47/56 (base 42, Italy bonus 5, tier P) 3. Legality Whistleblowing (DigitalPA) — 33/56 (base 29, Italy bonus 4, tier P) 4. Secure Blowing — 32/56 (base 28, Italy bonus 4, tier P) 5. ISWEB — 29/56 (base 24, Italy bonus 5, tier P) 6. Whistleflow — 29/56 (base 24, Italy bonus 5, tier P) 7. Segnala Sicuro — 27/56 (base 22, Italy bonus 5, tier P) 8. Whistleblowing24 — 27/56 (base 23, Italy bonus 4, tier P) 9. OpenBlow — 26/56 (base 21, Italy bonus 5, tier P) 10. Whisper — 26/56 (base 22, Italy bonus 4, tier P) 11. MyGovernance — 24/56 (base 19, Italy bonus 5, tier P) 12. Comunica Whistleblowing — 21/56 (base 17, Italy bonus 4, tier P) Italy has a wider addressable base than its headline threshold suggests. Alongside the standard 50-worker rule, any entity that has adopted a Model 231 organisational and management model needs an internal reporting channel regardless of headcount — so the Italian market reaches well below the size band that defines most of Europe. That shapes the vendor field. Italian platforms compete on precise legal positioning — D.Lgs. 24/2023, Model 231 and the ANAC guidelines named together — rather than on a generic “EU Directive compliant” claim, and the ranking reflects that: every one of the 12 scored platforms earns full marks on the law criterion. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Italy modifier, which rewards an explicit D.Lgs. 24/2023 reference, a named hosting country or EU provider, and a genuine Italian-language surface. Because the law criterion barely separates this field, hosting disclosure does the work instead. Italian vendors are strong on legal framing and weak on infrastructure transparency: of the 12 platforms scored, only two name a specific hosting provider and country — neither of them Italian — and four disclose nothing at all about where data sits. In a documentation-heavy regime where ANAC is the central reference point, that is the gap a procurement reviewer will hit first. --- # Whistleblowing software in Poland — scored ranking Of the 12 platforms scored against Ustawa o ochronie sygnalistów, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/poland/ - Law applied: Act of 14 June 2024 on the Protection of Whistleblowers, in force 25 September 2024 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Poland modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Poland bonus 5, tier P+R+H) 2. Sygnali — 40/56 (base 34, Poland bonus 6, tier P) 3. Ethicontrol — 38/56 (base 35, Poland bonus 3, tier P) 4. Sygnanet — 36/56 (base 31, Poland bonus 5, tier P) 5. SygnaApp — 35/56 (base 29, Poland bonus 6, tier P) 6. Sygnalista — 34/56 (base 29, Poland bonus 5, tier P) 7. WeMoral — 34/56 (base 29, Poland bonus 5, tier P) 8. AMODIT — 33/56 (base 28, Poland bonus 5, tier P) 9. e-nform — 33/56 (base 30, Poland bonus 3, tier P) 10. WhistBoard — 26/56 (base 21, Poland bonus 5, tier P) 11. Sygnalista 365 — 16/56 (base 12, Poland bonus 4, tier P) 12. Whiblo — 15/56 (base 11, Poland bonus 4, tier P) Poland is the most locally served market in this directory: ten of the twelve scored platforms are Polish vendors, every one of them ships a Polish reporter surface, and ten name the Act of 14 June 2024 explicitly. Poland transposed late, in September 2024, and the domestic market filled the gap quickly. That density changes what a ranking can tell you. Where German or Italian buyers can separate vendors on whether the law is named at all, here almost everyone clears that bar, and Polish-language UI separates nobody — all twelve score full marks. Hosting disclosure is the only criterion that still sorts this field. Two vendors name Poland-resident hosting, eight assert EU hosting without naming a country or provider, and two disclose nothing at all. In a market this crowded and this uniform on the obvious criteria, where the data physically sits is the question a procurement reviewer is left with. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Poland modifier, which rewards an explicit reference to the Act, a named hosting country or EU provider, and a genuine Polish-language surface. --- # Whistleblowing software in Portugal — scored ranking Of the 8 platforms scored against Lei 93/2021, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/portugal/ - Law applied: Lei n.º 93/2021, de 20 de dezembro - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Portugal modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Portugal bonus 5, tier P+R+H) 2. WhistleOn — 29/56 (base 24, Portugal bonus 5, tier P) 3. Double Voice — 28/56 (base 24, Portugal bonus 4, tier P) 4. +Transparente — 27/56 (base 23, Portugal bonus 4, tier P) 5. iBlow — 27/56 (base 23, Portugal bonus 4, tier P) 6. Portal das Denúncias — 27/56 (base 23, Portugal bonus 4, tier P) 7. GOWhistleblow — 24/56 (base 20, Portugal bonus 4, tier P) 8. Fraud Line — 19/56 (base 16, Portugal bonus 3, tier P) Portugal has the weakest infrastructure transparency of any market in this directory. Five of the eight scored platforms disclose nothing at all about where report data is hosted, and not one names Portugal-resident hosting. The single vendor that names a location puts European data in Belgium. On every other axis the field looks healthy. Seven of eight name Lei 93/2021, all eight ship a Portuguese reporter surface, and six are Portuguese vendors. The legal framing is there; the answer to “where does the data sit” mostly is not. That gap matters more in Portugal than the rankings alone suggest. Lei 93/2021 obliges employers with 50 or more workers to operate an internal channel, and a buyer who cannot establish the hosting jurisdiction cannot complete a GDPR transfer assessment for it. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Portugal modifier, which rewards an explicit Lei 93/2021 reference, a named hosting country or EU provider, and a genuine Portuguese-language surface. One note on language tagging: several Portuguese vendors serve their site as Brazilian Portuguese rather than European Portuguese. That is recorded in the evidence but does not change the score, since the reporter can read it either way. --- # Whistleblowing software in Romania — scored ranking Of the 7 platforms scored against Law 361/2022, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/romania/ - Law applied: Law 361/2022 - Edition: Edition I, 2026, tested April 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Romania modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Romania bonus 5, tier P+R+H) 2. Whistlelink — 44/56 (base 39, Romania bonus 5, tier P+H) 3. WeMoral — 33/56 (base 29, Romania bonus 4, tier P) 4. Whistleblow.ro / avertizori.eu — 27/56 (base 23, Romania bonus 4, tier P) 5. Phoenix — 25/56 (base 23, Romania bonus 2, tier P+H) 6. WIBSO — 24/56 (base 21, Romania bonus 3, tier P) 7. Whistle UP — 23/56 (base 19, Romania bonus 4, tier P) Romania is not just a local-vendor market. Local-law posture still matters, but several imported tools now maintain Romanian-language commercial surfaces, public pricing, partner motions, or local case studies. The result is a market with thin domestic software depth, but more real cross-border competition than a first pass suggests. This edition therefore uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Romania modifier, which rewards explicit Law 361/2022 framing, a named Romania-acceptable hosting posture, and a real Romanian-language reporter / handler surface. That combination penalises the three most common Romania-market failure modes: local vendors with strong legal copy but weak product disclosure; foreign tools with Romanian-language marketing but no Romania-law posture; and service-led compliance offers whose underlying product is not independently reviewable. This ranking is software-only and includes both Romania-native vendors and foreign tools with concrete Romania-market go-to-market signal. Advisory or investigations-led service firms are excluded unless the underlying whistleblowing product is identifiable and independently reviewable. --- # Whistleblowing software in Spain — scored ranking Of the 4 platforms scored against Ley 2/2023, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/spain/ - Law applied: Ley 2/2023, de 20 de febrero - Edition: Edition I, 2026, tested June 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Spain modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Spain bonus 5, tier P+R+H) 2. ithikios — 34/56 (base 29, Spain bonus 5, tier P) 3. Tu Canal de Denuncias — 25/56 (base 21, Spain bonus 4, tier P) 4. LegalSending — 22/56 (base 18, Spain bonus 4, tier P) Spain has the harshest non-compliance regime in the EU: failing to maintain a Sistema interno de información is a muy grave infraction under Ley 2/2023, carrying fines up to €1,000,000 for legal entities, and the national authority (AIPI) only began operating in September 2025 — so this is a market where the obligation is both severe on paper and starting to be enforced in practice. That raises the bar for software. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Spain modifier, which rewards explicit Ley 2/2023 framing, a named Spain-acceptable hosting posture, and a real Spanish-language reporter / handler surface. That combination penalises the three most common Spain-market failure modes: local vendors with strong legal copy but weak product disclosure; foreign tools with Spanish-language marketing but no Spain-law posture; and service-led compliance offers whose underlying product is not independently reviewable. This ranking is software-only and includes both Spain-native vendors and foreign tools with concrete Spain-market go-to-market signal. Advisory or investigations-led service firms are excluded unless the underlying whistleblowing product is identifiable and independently reviewable. The Catalan authority (Oficina Antifrau de Catalunya) holds parallel competence for Catalonia-scoped matters; that is a jurisdictional nuance, not a product criterion. --- # Whistleblowing software in Sweden — scored ranking Of the 14 platforms scored against Lag (2021:890), EthicsPortal ranks first with 50 of 56 points. - URL: https://whistleblowertools.eu/countries/sweden/ - Law applied: Lag (2021:890) om skydd för personer som rapporterar om missförhållanden, in force 17 December 2021 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Sweden modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 50/56 (base 47, Sweden bonus 3, tier P+R+H) 2. Whistlelink — 45/56 (base 39, Sweden bonus 6, tier P+H) 3. IntegrityLog — 38/56 (base 33, Sweden bonus 5, tier P) 4. NorthWhistle — 36/56 (base 32, Sweden bonus 4, tier P) 5. Visslan — 36/56 (base 30, Sweden bonus 6, tier P) 6. WhistleSecure — 32/56 (base 27, Sweden bonus 5, tier P) 7. Heimdal — 31/56 (base 26, Sweden bonus 5, tier P) 8. Visselblåsaren — 30/56 (base 24, Sweden bonus 6, tier P) 9. 2Whistle — 29/56 (base 24, Sweden bonus 5, tier P) 10. Interaktiv Säkerhet — 29/56 (base 23, Sweden bonus 6, tier P) 11. Lumgo — 26/56 (base 21, Sweden bonus 5, tier P) 12. Qnister Whistle — 26/56 (base 21, Sweden bonus 5, tier P) 13. Lantero — 22/56 (base 16, Sweden bonus 6, tier P) 14. Tissla — 19/56 (base 15, Sweden bonus 4, tier P) Sweden is the second-largest field in this directory after Germany, at fourteen scored platforms, and it is the strongest anywhere on data residency: five vendors name Swedish hosting outright, several of them naming the data centre and city. Sweden transposed early, in December 2021, and the domestic market has had the longest run of any EU market to mature. It is also the one ranking where the publisher’s own product is beaten on a criterion by most of the field. EthicsPortal has no Swedish reporter or handler locale and scores zero on Swedish-language UI, against twelve of fourteen platforms scoring full marks. It leads on base product score; it does not lead here, and the matrix shows exactly where. The criterion that still separates the Swedish field is the law. Eleven of fourteen name Lag (2021:890); three describe national coverage generically, including two Swedish vendors who might be expected to name their own statute. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Sweden modifier, which rewards an explicit Lag (2021:890) reference, a named hosting country or EU provider, and a genuine Swedish-language surface. --- # Whistleblowing software in the Netherlands — scored ranking Of the 7 platforms scored against Wbk, EthicsPortal ranks first with 52 of 56 points. - URL: https://whistleblowertools.eu/countries/netherlands/ - Law applied: Wet bescherming klokkenluiders (Wbk), in force 18 February 2023 - Edition: Edition I, 2026, tested September 2026 - Rubric: 50-point base fixed before scoring, plus a 6-point Netherlands modifier - Access tiers: P = public pages only, P+R = plus a test report, P+R+H = plus the handler dashboard Ranked result: 1. EthicsPortal — 52/56 (base 47, Netherlands bonus 5, tier P+R+H) 2. Confidly — 47/56 (base 42, Netherlands bonus 5, tier P) 3. IntegrityLog — 36/56 (base 33, Netherlands bonus 3, tier P) 4. UpTalkly — 30/56 (base 25, Netherlands bonus 5, tier P) 5. SpeakUp — 28/56 (base 26, Netherlands bonus 2, tier P) 6. HiTrust — 25/56 (base 21, Netherlands bonus 4, tier P) 7. Confide — 17/56 (base 17, Netherlands bonus 0, tier P) The Netherlands is the thinnest major market in this directory — 7 scored platforms, against 32 for Germany — and that scarcity is the finding. Dutch buyers at the 50-worker threshold are choosing from a short list, and several entrants on it serve the country without addressing Dutch law at all. The Dutch regime also changes what counts as a differentiator. Because the government runs a dedicated employer-facing site for the Wet bescherming klokkenluiders and the Dutch Whistleblowers Authority is institutionally prominent, the basic legal explanation is freely available from official sources. A vendor restating it adds nothing. What is scarce, and what the modifier rewards, is a vendor that names the Wbk specifically rather than the Directive generically, and that ships a Dutch reporter and handler surface rather than an English one with a Dutch marketing page. This edition uses two layers: the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity; the 6-point Netherlands modifier, which rewards an explicit Wbk reference, a named hosting country or EU provider, and a genuine Dutch-language surface. Hosting disclosure is the weakest column in this market. Of the seven platforms scored, three disclose no hosting location at all — including two headquartered in the Netherlands. --- ## Compare ## Tools # +Transparente - Website: https://maistransparente.com - Headquarters: Portugal - Pricing: Professional EUR 49/month (up to 250 employees, 5 managers); Corporate EUR 99/month (up to 1,000 employees, unlimited managers); Enterprise EUR 199/month (1,000+ employees, unlimited managers). Prices shown as starting-from (desde) figures. - Note: Monthly prices are stated as starting-from (desde) figures, with no hidden fees or implementation costs claimed. Add-ons (custom setup, UI/UX and form customization, custom workflows, automations, system integration, SSO, whistleblowing training, compliance consulting, external triage and investigation services, phone channel) are quote-based. Acquisition is demo-first via a request form. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Portugal (Lei 93/2021) - Last verified: 2026-07-19 - Sources: - https://maistransparente.com/ - https://maistransparente.com/politica-privacidade/ - https://maistransparente.com/termos-condicoes/ - https://www.closer.pt/ Notable Operated by Closer Consultoria, Lda, a Portuguese data-science company; the terms of service list the entity as legal person number 507 246 152, registered at the Seixal commercial registry. The product is marketed as +transparente and is also presented on the site as Evalyze Guard, Closer’s branding. Positioned as a Portuguese platform for setting up a whistleblowing channel in about two hours, in conformity with Lei 93/2021, which transposes Directive (EU) 2019/1937. Reporter flow is described as: access via the organization’s official website, submit a confidential report, receive a generated QR code to follow the case, optionally request contact, and track case status anonymously. Handler side routes reports to the people or entities responsible for investigation, with alerts distributed and managed automatically and remote, anonymous follow-up. Three published plans: Professional (up to 250 employees, EUR 49/month, 5 managers), Corporate (up to 1,000 employees, EUR 99/month, unlimited managers), and Enterprise (1,000+ employees, EUR 199/month, unlimited managers, custom branding). All prices are shown as starting-from (desde) figures. Paid add-ons include custom setup, UI/UX and form customization, bespoke workflows and automations, integration with other systems, SSO, whistleblowing training, compliance consulting, external triage and investigation services, and a phone channel. The site states no hidden fees or implementation costs and offers a demo request rather than a self-serve trial. The homepage quotes OBEGEF (a Portuguese fraud-study observatory) as considering the solution suitable for the whistleblowing-channel requirements of Lei 93/2021. The privacy policy claims data encryption and GDPR compliance and acknowledges use of subprocessors; hosting location, EU data-residency country, a subprocessor list, and any ISO 27001 certification were not found on public pages reviewed. Public reporting indicates the platform operates whistleblowing channels for Portuguese public bodies, including the Lisbon municipality (Câmara Municipal de Lisboa). --- # 2Whistle - Website: https://2secure.se/personalsakerhet/visselblasarsystem/ - Headquarters: Stockholm, Sweden - Hosting: Encrypted communication and storage (vendor-stated); data-residency country not disclosed on public pages reviewed - Pricing: 0-50 employees SEK 1,700/month; 50-250 employees SEK 2,500/month; 250-500 employees SEK 3,750/month; 500+ employees custom quote. - Note: Three employee-band tiers are shown on the product page; the top band (500+ employees) is quote-only. Prices are stated per month; contract length and any setup fee were not disclosed on public pages reviewed. - Languages on reporting form: 20 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Lag 2021:890) - Last verified: 2026-07-19 - Sources: - https://2secure.se/ - https://2secure.se/personalsakerhet/visselblasarsystem/ - https://wb.2secure.se/ - https://2secure.se/whistleblowing-information/ - https://2secure.se/visselblasning-information/ - https://2secure.se/om-oss/ Notable 2Whistle is the whistleblowing product of 2Secure AB, a Swedish risk and security consultancy founded in 2006, headquartered in Stockholm with further offices including Gothenburg, Lund, Copenhagen, and London. Vendor materials state 2Secure has offered the 2Whistle service since 2015; the reporter-facing portal is at wb.2secure.se. It is positioned as a managed service: 2Secure’s own experienced, independent investigators receive and triage each report and maintain dialogue with the whistleblower, and customers receive advisory support on each case. Reporting channels are web form, phone (0771-77 99 77), and postal mail, described as available 24/7; the product page does not mention in-person meetings. Reporters can choose to remain anonymous, no contact details are stored, and follow-up requires a case number and password issued at submission. The reporting tool is stated to be available in roughly 20 languages, including Swedish, English, German, Danish, French, Italian, Polish, Spanish, and Finnish among others. The product page states acknowledgment within 7 days and feedback within 3 months in line with the Swedish whistleblower law (Lag 2021:890), which applies to organizations with 50+ employees, and describes the service as compatible with GDPR and the whistleblower law. Pricing is published for three employee bands (SEK 1,700 / 2,500 / 3,750 per month) with the 500+ band as a custom quote. Security posture disclosed on public pages is limited to “encrypted communication and storage”; the data-residency country, a sub-processor list, and any ISO 27001 certification of the vendor or product were not found on public pages reviewed. Legal entity is 2Secure AB (Swedish org.nr 556695-7543); a separate 2Secure Sverige AB (org.nr 556763-8308) also exists in company registries. --- # Alertcys - Website: https://www.alertcys.io - Headquarters: France - Hosting: Marketing site on OVH (Roubaix, France); app.alertcys.io on SAS OC3 Network (Paris, France), both named in the mentions legales - Pricing: Published annual pricing: Essentiel €300/year (<50 FTE), Standard €1,500/year (50+ FTE, 3 referents), Pro €4,600/year (unlimited referents). - Note: Annual pricing is public; mediation / outsourced handling is sold separately. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: France (Loi Waserman / Sapin II); EU Directive 2019/1937 - Last verified: 2026-09-20 - Sources: - https://www.alertcys.io/offres-dispositif-dalerte-professionnelle-loi-sapin-2/ - https://www.alertcys.io/legalite/ - https://www.alertcys.io/protection-des-lanceurs-dalerte-loi-waserman-2074/ - https://www.alertcys.io/loi-sapin-2-et-lanceurs-dalerte-guide-complet-2331/ Notable France-native positioning centred on whistleblowing, psychosocial-risk handling, and optional external mediation. Public tier matrix is explicit: Essentiel, Standard, and Pro are all priced publicly. Standard plan is explicitly calibrated around 50+ employee organisations with 3 referent seats included. Vendor-stated customer count: 250+ clients on the offer page. Product positioning leans heavily on French legal compliance rather than pan-EU breadth. The site publisher named in the mentions legales is Concord SAS, registered at the Paris address of the Chambre Nationale des Commissaires de Justice, the statutory national body for French judicial officers, and of its publishing arm Editions Juridiques et Techniques. Handling is a managed service: Alertcys states that its own team performs the first analysis, works with the reporter to put the report in form, and sets aside reports it judges calumnious or unfounded; admissible reports pass to the employer’s designated referent, and a commissaire de justice then mediates between the parties. Reports can be submitted via the public web flow or by post; optional human mediation / outsourced handling is available for organisations that do not want an internal first-line process. Vendor-page evidence - 2026-09-20 Current vendor pages show 300EUR HT / an, 1 500EUR HT / an, 4 600EUR HT / an, Plateforme de gestion des alertes, Situe en France, postal/web intake, and France-law content for Sapin II, Loi Waserman, and Directive 2019/1937. The reporting surface at app.alertcys.io/file/create/ answers 200. Its HTML loads Bootstrap 3.3.7 and Font Awesome 4.7, both end-of-life front-end builds, alongside a Bootstrap 5.3 stylesheet. The same host returns Server: Microsoft-IIS/8.0. Recorded, not classified: an IIS banner is not evidence of patch level, because distributions backport security fixes without moving the advertised version. It did not contribute to the d20 score. alertcys.io publishes no SPF record. A DMARC record exists but is set to p=none, which monitors without enforcing, and its rua value contains a stray space after mailto:. The mentions legales names OVH as host of the marketing site and SAS OC3 Network (Paris) as host of app.alertcys.io. This is more hosting disclosure than the May 2026 pass credited. No public ISO 27001 certificate, sub-processor list, DPA pack, or API documentation was found in the public pages reviewed. Scoring review - 2026-09-20 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no self-serve trial or public handler environment). Base score: 19 / 50. France country bonus: 8 / 8. Category Score Max A. Legal compliance 5 16 B. Reporter experience 6 10 C. Handler experience 3 10 D. Security 2 8 E. Commercial 3 6 Changed since 2026-05-24: criterion d20 moves from 2 to 0. The May pass recorded no visible end-of-life components but did not open the reporting surface; this pass did, and found end-of-life front-end builds on the page that serves the report form. Security falls from 4 to 2 and the base score from 21 to 19. Criterion d21 keeps its score of 2, but its evidence is corrected in the vendor’s favour: hosting providers are disclosed in the mentions legales, which the May pass recorded as not found. Evidence supporting the score: annual pricing, employee-band segmentation, referent limits, Sapin II and Loi Waserman content, France-location positioning, named French hosting providers, and mediator-supervised handling claims are public. Unverified from public pages: reporter return-access method, structured intake, audit immutability, sub-processors, and security certifications. Alertcys is more documented on France-law service posture than on public technical disclosure. Buyer fit: French SMEs and mid-market organisations that want a domestic vendor and may value a commissaire de justice as mediator. Buyers who need a second language, a documented security posture, or a channel that delivers reports to their own referent without third-party pre-screening will need vendor confirmation on each point. --- # AMODIT - Website: https://amodit.com/whistleblower-protection/ - Headquarters: Warsaw, Poland - Hosting: Microsoft Azure infrastructure (vendor-stated); Standard version can be deployed in the cloud or on customer servers; specific Azure region not disclosed on public pages reviewed - Pricing: Lite: 1,500 PLN per year (no customization). Standard: 6,000 PLN per year plus a one-time 500 PLN activation fee. Add-ons: additional reporting language 5,000 PLN each; data encryption 20% of licence value; phone/email intake 100 PLN per month readiness plus 250 PLN per report; legal document templates 1,500 PLN; legal consultation 4,500 PLN. Net prices. - Note: Prices are quoted net and the public offer page carries a validity date of 31.12.2024, so figures may be out of date. Licences are annual; no self-serve online checkout or free trial was found on public pages reviewed. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001 (Astrafox, vendor-stated; certificate no. 488468) - National laws referenced: EU Directive 2019/1937; Poland (Ustawa o ochronie sygnalistow) - Last verified: 2026-07-19 - Sources: - https://amodit.com/whistleblower-protection/ - https://amodit.pl/ochrona-sygnalistow/ - https://amodit.pl/bezpieczenstwo-amodit/ - https://astrafox.com/ - https://astrafox.pl/wp-content/uploads/2023/09/CERTYFIKAT-NR-488468-ISO-27001_2013-1.pdf - https://sygnalista.amodit.com/ Notable The whistleblowing capability is a module on AMODIT, Astrafox’s broader workflow and document-management platform, and can be run inside an existing AMODIT deployment or as a standalone reporting channel. Vendor legal entity is Astrafox Sp. z o.o., ul. Poloneza 93, 02-826 Warsaw, Poland (office@amodit.com, +48 22 355 21 64). The product markets three reporting channels: an online reporting form with a unique organizational link, a phone hotline (paid add-on), and email. Reporters choose among three modes: fully anonymous, confidential (identity withheld from the employer), and open. Anonymous reporters receive a link to follow their report and can exchange messages without revealing their identity. Case handling includes automatic assignment to personnel, forwarding between users and teams, status tracking, priority and deadline assignment, attachments, and a full action history per report. Compliance is framed against EU Directive 2019/1937 and the Polish whistleblower law (“ustawa o ochronie sygnalistow”), named descriptively without article numbers or the statute date. Two pricing tiers are published in PLN: Lite at 1,500 PLN per year with no customization, and Standard at 6,000 PLN per year plus a one-time 500 PLN activation fee, with paid add-ons for extra languages, data encryption, phone/email intake, and legal templates. The public offer page carries a validity date of 31.12.2024, so the listed figures may be out of date. Standard-tier customers can deploy in the cloud or on their own servers. The platform runs on Microsoft Azure, but a specific EU region was not disclosed on public pages reviewed. Astrafox states an independent ISO/IEC 27001 certificate (no. 488468) and lists Azure’s own ISO 27001, ISO 27018, and SOC 1/2/3 certifications for the hosting layer. The two should not be conflated: the vendor certificate is the one relevant to d19. Security page states TLS (SHA-256 with RSA) in transit and optional multi-factor authentication via third-party providers. No free trial, no self-serve online checkout, no published sub-processor list, and no API documentation for the whistleblower module were found on public pages reviewed. --- # Ashio - Website: https://ashio.eu - Headquarters: Tallinn, Estonia - Hosting: ISO 27001-certified data centres in Switzerland. The security page says "your data never leaves Europe" — Switzerland is a third country under GDPR, covered by an adequacy decision, not an EU or EEA location. - Pricing: €30/month billed monthly, or €23/month billed yearly (€276/year). One plan, all features, unlimited team members, no per-report fee. - Note: A 14-day free trial with no credit card is advertised, and the vendor states setup needs no demo call. Because there is a single plan, nothing is tier-gated — including voice reporting, which the announcement bar states is "live on all plans". - Languages on reporting form: 18 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; ISO 37002:2021; Germany (HinSchG); France (Loi Sapin II, Loi Waserman); Spain (Ley 2/2023); Italy (D.Lgs. 24/2023); Netherlands (Wet Klokkenluiders); Poland (Ustawa o Ochronie Sygnalistów); Romania (Legea 361/2022); Portugal (Lei 93/2021); Denmark (Lov om beskyttelse af whistleblowere); Czechia (Zákon o ochraně oznamovatelů); Lithuania (Pranešėjų apsaugos įstatymas); Finland (Ilmoittajansuojelulaki); Estonia (Süüteost teavitaja kaitse seadus); Latvia (Trauksmes celšanas likums); Hungary (Panasz- és közérdekű bejelentés törvénye); Sweden (listed as "Visselblåsardirektivet", the Swedish name for the Directive, not for Lag 2021:890); Switzerland (Bundesgesetz über den Datenschutz) - Last verified: 2026-09-21 - Sources: - https://ashio.eu/ - https://ashio.eu/security - https://ashio.eu/impressum - https://ashio.eu/fr/loi-sapin-2 Notable Operated by COWBOYS AND WITCHES OÜ of Tallinn (register number 16770622), with a named managing director on the imprint and no VAT ID recorded. The pricing model is the simplest in this directory: a single plan, monthly or yearly, every feature included, unlimited invited team members with admin and investigator roles. Voice reporting shipped to all plans rather than to a premium tier. Voice intake is designed to avoid creating a recording at all. Audio is transcribed in the reporter’s browser and deleted as soon as the transcript exists, so the organisation never holds an audio file or biometric data to retain, produce or purge. The security model is client-side. A fresh AES-256-GCM key is generated per report and wrapped for each recipient using P-256 ECDH; the server stores ciphertext with no key material, and handler keys are protected by an Argon2id-derived password key. The vendor states it cannot read report bodies or messages. Reporting pages are stated to set no cookies, run no analytics and apply no fingerprinting, and a PGP key is published for a dedicated critical-contact address. The 7-day acknowledgment and 3-month feedback deadlines are both described as tracked automatically, with the evidence exportable as PDF and CSV for an auditor. Hosting is the one place where the framing is looser than the rest of the page. “Hosted in ISO 27001-certified data centres in Switzerland” and “your data never leaves Europe” are both true statements, but a buyer reading them as EU residency would be reading them wrongly, and the certification named is the data centre operator’s rather than Ashio’s. Status: not yet scored Ashio was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in a country ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Avertizori Integritate - Website: https://www.avertizoriintegritate.ro - Headquarters: Zalau, Romania - Hosting: Stored encrypted on the hosting provider's servers with a DPA executed; provider and country not named on public pages reviewed - Pricing: Not published. The site describes a subscription requiring account creation but shows no RON or EUR amounts, tiers, or trial terms. - Note: A refunds and returns policy page exists, implying paid subscriptions, but no prices are shown on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Romania (Law 361/2022) - Last verified: 2026-07-19 - Sources: - https://www.avertizoriintegritate.ro/ - https://www.avertizoriintegritate.ro/servicii/ - https://www.avertizoriintegritate.ro/formular-raportare/ - https://www.avertizoriintegritate.ro/instructiuni-de-utilizare/ - https://www.avertizoriintegritate.ro/protectia-datelor/ - https://www.avertizoriintegritate.ro/acordul-de-procesare-a-datelor-dpa/ - https://www.avertizoriintegritate.ro/politica-de-confidentialitate/ Notable Operated by SC LOCASIWEB SRL, a Romanian company registered as J31/407/2022, CUI 46186972, based in Zalau, Salaj County. Positioned as a whistleblowing channel aligned to Romanian Law 361/2022 (the national transposition of EU Directive 2019/1937) and to GDPR. The public site names both internal and external reporting channels and lists the Directive coverage areas (public procurement, financial services, product safety, transport, environment, health, consumer protection, data privacy). Anonymous reporting is explicitly supported, and the usage instructions state that anonymous two-way communication through the platform is possible for clarifications. The online reporting form is publicly reachable as a multi-step flow (security, subject, report, submit) with anonymity guidance, a data-protection consent checkbox, and a CAPTCHA. The privacy policy states personal data is stored encrypted on the hosting provider’s servers over SSL/TLS, with a DPA executed with that provider; the provider and hosting country are not named. A dedicated DPA page and a GDPR privacy policy referencing Articles 6, 9, 21, and 25 are published, along with rights of access, rectification, deletion, portability, and complaint to ANSPDCP. Retention is described as purpose-based (“until the purpose for which the data was collected is no longer valid”); no automatic-deletion schedule was documented. The service is described as a subscription requiring account creation, and a refunds and returns policy page exists, but no pricing, tiers, or trial terms are shown on public pages reviewed. No ISO 27001 or other security certification was found on public pages reviewed; the site and reporter interface are Romanian only. --- # BeSignal - Website: https://besignal.com/fr/ - Headquarters: France - Pricing: Not published publicly. - Note: Sales-led procurement; no public self-serve pricing or trial. - Languages on reporting form: 7 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (badge displayed; certificate/scope not found), HDS (badge displayed / HDS security-reference claim; certificate/scope not found) - National laws referenced: France (Sapin II / Loi Waserman); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.vaco.io/ - https://besignal.com/fr/ - https://besignal.com/fr/solution/dispositif-dalertes-professionnelles - https://besignal.com/fr/bs/mentions-legales - https://besignal.com/fr/bs/besignal-politique-de-confidentialite Notable Signalement.Net is now presented by Vaco as BeSignal. Legal pages identify the site publisher as Valeur & Conformité SAS. Current vendor materials describe written and voice reports, anonymous reporting, automatic translation/document analysis options, manager profiles, and France-hosted data. BeSignal publicly claims 1,500+ user organisations; treated here as vendor-stated, not independently verified. Privacy materials disclose optional automatic translation and document analysis, but do not explain whether those functions use AI models. Commercial transparency remains limited: no public price list, no public self-serve trial, and no public API documentation were found. Security disclosure is more detailed than the old entry reflected, but still incomplete: OVH/CleverCloud are named and ISO 27001/HDS badges are displayed, while certificate scope, pricing, and a public DPA pack were not found. Vendor-page evidence - 2026-05-24 besignal.com/fr/ says Signalement.Net becomes BeSignal and references Directive 2019/1937, Sapin II, and Loi Waserman. Product copy claims voice and written declarations, several-language reporting, automatic translation/document-analysis options, France-localized hosting, manager profiles, and ISO/HDS badges. The privacy policy names OVH for the alert-management platform and CleverCloud for infrastructure; it also discloses optional automatic translation, automatic document analysis, and telephone-communication handling. Pricing, API access, certification scope, legal-deadline timer automation, and public sub-processor objection mechanics were not disclosed on the public pages reviewed. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no trial or public handler environment). Base score: 26 / 50. France country bonus: 8 / 8. Category Score Max A. Legal compliance 9 16 B. Reporter experience 7 10 C. Handler experience 5 10 D. Security 5 8 E. Commercial 0 6 Evidence supporting the score: current vendor pages publicly describe France hosting, anonymous voice/written intake, several-language reporting, optional automatic translation/document analysis, and France-law positioning. Unverified from public pages: pricing, self-serve trial, API access, reporter return-access mechanism, ISO/HDS certificate scope, deadline timer automation, and a public DPA/sub-processor objection pack. Buyer fit: French organisations that want a domestic Vaco-operated alert platform and multilingual reporting. Buyers requiring public pricing or a procurement-ready trust centre will need vendor confirmation. --- # Canal Ético App - Website: https://canaleticoapp.com - Headquarters: Spain - Pricing: €96/month (€116.16/month incl. 21% IVA). Annual plan available (saves €153/year). Enterprise plan quote-based. - Note: Unlimited reports, written and voice channels. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Spain (Ley 2/2023) - Last verified: 2026-05-24 - Sources: - https://canaleticoapp.com/ - https://canaleticoapp.com/centro-de-ayuda/ Notable Flat pricing of €96/month regardless of organisation size; annual billing available with €153 savings. Unlimited reports, written and voice reporting modes, tracking code for reporters. Bidirectional anonymous channel between reporter and case handler. No IP addresses, location data, or device identifiers stored; content encrypted; HTTPS in transit. Positioned specifically for Spanish Ley 2/2023 obligations (mandatory for organisations with 50+ employees from 1 December 2023). Also referenced for companies with UNE 19601, UNE-ISO 37001, ISO 37002, or AML compliance contexts; the page presents these as reasons an anonymous reporting mailbox may be needed, not as certifications held by the product. Enterprise plan adds custom field personalisation, multiple portals for corporate groups, custom payment terms, multilingual service, and dedicated compliance expert support. Operated by Smart Dev Technology; Spanish-language support via phone, email, and WhatsApp chat. Implementation process typically completed in 1-2 business days (vendor-stated). Fines referenced on vendor page: up to €300,000 for individuals and €1,000,000 for legal entities for non-compliance with Ley 2/2023. Public API, ISO 27001 certification, hosting-country disclosure, DPA, retention configuration, and subprocessor list were not disclosed on public pages reviewed. --- # CLUE#ZO - Website: https://www.c-a-s.de/digitales-hinweisgebersystem-cluezo/ - Headquarters: Hamburg, Germany - Hosting: European data centres (vendor states ISO 27001 certified data centres); built on SAP Business Technology Platform - Pricing: Basic EUR 99/month (12 reports/year, 3 users); Standard EUR 299/month (50 reports/year, 6 users); Enterprise EUR 1,499/month (unlimited reports, 15 users). Prices are ex-VAT. - Note: Report volume and user seats are capped per tier. Overage per additional report is EUR 28 (Basic) and EUR 19 (Standard); overage is included on Enterprise. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (Hinweisgeberschutzgesetz, HinSchG) - Last verified: 2026-07-19 - Sources: - https://www.c-a-s.de/digitales-hinweisgebersystem-cluezo/ - https://www.c-a-s.de/hinweisgebersystem-fuer-whistleblower/ - https://www.sap.com/germany/products/artificial-intelligence/partners/cas-concepts-and-solutions-ag-cluezo-saas-whistleblower-service.html - https://store.sap.com/dcp/en/product/display-2001016795_live_v1/clue-zo-saas-whistleblower-service/ - https://www.c-a-s.de/impressum-rechtliche-informationen-cas-ag/ Notable Offered by CAS Concepts and Solutions AG (CAS AG), Hamburg, Germany (Commercial Register HRB 69127). CLUE#ZO is a digital whistleblowing system positioned for private and public sector organizations to comply with the EU Whistleblowing Directive (2019/1937) and the German Hinweisgeberschutzgesetz (HinSchG, in force since 2023). Delivered as SaaS on SAP Business Technology Platform, integrated with SAP S/4HANA, and listed in the SAP Store as a whistleblower service. A chatbot assistant guides whistleblowers through structured report intake, described as dialogue-guided receipt of reports. Anonymous reporting is supported, with a mailbox function for ongoing two-way communication with anonymous reporters about case progress. A separate web application is provided for employees to review and handle submissions. Multilingual support is provided through GDPR-compliant real-time translation; a specific language count was not stated on public pages reviewed. The vendor states data is hosted GDPR-compliant exclusively in certified European data centres, with encryption of stored and transmitted data; ISO 27001 is stated for the data centres, not as a vendor or product certification. Pricing is published in three monthly tiers: Basic EUR 99 (12 reports/year, 3 users), Standard EUR 299 (50 reports/year, 6 users), and Enterprise EUR 1,499 (unlimited reports, 15 users), all ex-VAT, with per-report overage fees on the lower tiers. No free trial or API documentation was found on public pages reviewed. --- # Clym - Website: https://www.clym.io - Headquarters: United States (exact legal seat not disclosed on public pages reviewed) - Hosting: Not specified on public pages; Enterprise tier offers choice of data server location - Pricing: Start $49/month (no whistleblowing); Grow $149/month (includes whistleblowing); Enterprise starts at $449/month with custom annual plan, data server choice, API integration, dedicated account manager, email/phone support, and SLA. - Note: Start and Grow show free-trial CTAs with no credit card required. Installation assistance is $349; additional AI assistant credits are $5 per 100. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: yes - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: SOC 2 Type 2 (pricing page logo), Google CMP (pricing page logo) - National laws referenced: EU Whistleblower Directive (general) - Last verified: 2026-05-24 - Sources: - https://www.clym.io/ - https://www.clym.io/solutions/whistleblowing - https://www.clym.io/pricing - https://www.clym.io/about-us Notable Clym is primarily an all-in-one web compliance platform for consent, DSAR, privacy policies, accessibility, video privacy, HIPAA authorization, age gating, content takedown, and whistleblowing. Whistleblowing is included in Grow at $149/month and Enterprise from $449/month; it is not included in Start at $49/month. Public whistleblowing copy supports anonymous/confidential structured reporting, protected communication, documentation, investigation tracking, customizable categories, automated response email templates, granular access control, and business-continuity reporting. Enterprise adds custom data server location, shared or dedicated instance, API integration, dedicated account manager, and business support with email, phone, and SLA. Pricing page displays SOC 2 Type 2 and Google CMP logos under certifications and memberships; public pages reviewed did not disclose certificate reports, dates, scope, ISO 27001, reporting-language coverage, public DPA, subprocessor list, or a specific EU hosting location. --- # Complylaw Canal Ético - Website: https://www.aranzadilaley.es/productos/complylaw-canal-etico - Headquarters: Spain - Pricing: Not published — quote-based. - Note: No self-serve pricing, trial, or checkout flow on the public page. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: Esquema Nacional de Seguridad (ENS) — Medium category, valid to 2026-08-14 - National laws referenced: Spain (Ley 2/2023); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.aranzadilaley.es/productos/complylaw-canal-etico - https://www.aranzadilaley.es/documentos/certificado-%20conformidad-ENS.pdf - https://www.aranzadilaley.es/certificaciones - https://www.aranzadilaley.es/declaracion-uso-ia Notable Aranzadi LA LEY is part of Karnov Group. Complylaw Canal Ético is positioned inside a broader legal-tech/product line rather than as a standalone whistleblowing-only vendor. The vendor PDF certificate names Aranzadi LA LEY SAU, states ENS category Media, and lists Comply Law Canal Ético design, development, maintenance, customer service, sales, and professional services as covered services. The product is framed as meeting Ley 2/2023, the EU Directive 2019/1937, GDPR, LOPD-GDD, and ISO 37002:2021 good practices. The ISO reference is alignment/good practice, not a product ISO 37002 certification. The FAQ section lists end-to-end encryption, restricted access, anonymous reporting with bidirectional communication, identity protection through blocking/pseudo-anonymisation, roles, traceability, alerts, reports, and statistics. Spanish-only public product surface documented on the product page; no multi-language reporter UI referenced. Procurement is sales-led. Public pages reviewed did not disclose pricing, a free trial, hosting/data residency, a public API, DPA, or subprocessor list. Aranzadi LA LEY’s general AI declaration says its solutions may include AI tools, but Complylaw Canal Ético product-specific AI use was not disclosed on public pages reviewed. --- # Comunica Whistleblowing - Website: https://www.ufwhistleblowing.it - Headquarters: Milan, Italy - Pricing: Not published. Purchasing is handled through the vendor's consulting area; a demo is offered via a 'Prova la demo' link. - Note: No self-serve pricing or trial found on public pages reviewed. Interested buyers are directed to contact the consulting area by phone or email. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs 24/2023) - Last verified: 2026-07-19 - Sources: - https://www.ufwhistleblowing.it/ - https://www.ufwhistleblowing.it/software/ - https://www.ufwhistleblowing.it/chi-siamo/ - https://www.ufwhistleblowing.it/software-whistleblowing/ - https://www.ufwhistleblowing.it/cos-e-whistleblowing/ - https://www.ufwhistleblowing.it/contatti/ Notable Operated by Unione Fiduciaria S.p.A., a Milan-based financial trust and services company (VAT 01513210151, founded 1958) owned by a consortium of Italian banks. Comunica Whistleblowing was launched in 2015, when Italy’s first private-sector whistleblowing regulation came into force, and is presented as one of the earliest national IT platforms for internal violation reporting. Public pages state the software is used by more than 200,000 users and is widely adopted in the banking and insurance sectors, with named references including major Italian banks, insurers, and listed companies. The vendor states compliance with D.Lgs 24/2023 (Italy’s transposition of EU Directive 2019/1937) and with ANAC requirements, for both private companies and public administration. Reporting channels described include a web/app platform, a mobile app with a guided flow, and a voicemail and phone channel connected to an international network, where calls are recorded and translated by specialized operators. Anonymous reporting is emphasized, and access is described as secure and encrypted using AES with dynamic encryption keys. Handler-side features described include a status-tracking dashboard for authorized personnel, detailed report forms, document attachments, and a reporting section with quantitative and qualitative analysis. No ISO 27001 or other product certification was found on public pages reviewed; hosting location, EU data residency, and cloud provider were not disclosed. Pricing is not published; buyers are directed to the consulting area by phone (02 72422 210) or email (whistleblowing@unionefiduciaria.it), with a “Prova la demo” demo request link. Reporter language count, API access, statutory deadline tracking, configurable retention, and DPIA support were not documented on public pages reviewed. --- # Confide - Website: https://www.confideplatform.com - Headquarters: Singapore - Hosting: Not documented publicly - Pricing: Not published. Procurement is book-a-call / sales-led on public pages reviewed. - Note: No pricing tiers, self-serve signup, or trial terms were found on public pages reviewed. The site uses 'Book a Call' and 'Learn More' calls to action. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: yes - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, SOC 2 (AICPA) - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-07-19 - Sources: - https://www.confideplatform.com/ - https://www.confideplatform.com/products/confide-whistleblowing-software - https://www.confideplatform.com/our-story Notable Operated by Confide Global Pte. Ltd., headquartered in Singapore; the site positions Confide as an end-to-end whistleblowing and full case-management platform within a broader GRC suite. Founded by Pav Gill, the former Wirecard in-house lawyer whose disclosure helped expose the Wirecard fraud; the vendor’s story page centres the platform on that experience. Product modules span whistleblowing, grievances, conflict of interest, health and safety, vendor risk management, fraud detection, and AI governance, sold as a unified platform. The whistleblowing product supports report intake via forms, voice, meetings, and API, described as fully customisable, plus fully branded reporting channels. Anonymous reporting is listed as a supported feature; two-way anonymous follow-up communication was not separately documented on public pages reviewed. Case management runs from intake to resolution with entity and case-data tracking, ready-made and customisable dashboards, and report export. Public pages display ISO 27001, AICPA SOC 2, and GDPR badges, and reference bank-level security; the ISO 27001 mark is presented as the vendor’s own certification. Data residency, hosting region, and supported reporter languages were not disclosed on public pages reviewed. No pricing, self-serve signup, or free trial was found; the site uses book-a-call calls to action, indicating sales-led procurement. Press coverage and the vendor’s story page state Confide plans to establish its European operational base in The Hague, Netherlands, with support from InnovationQuarter; the platform is positioned to comply with EU whistleblowing regulation. --- # Confidential Reporting System - Website: https://crsys.org/ - Headquarters: Sofia, Bulgaria - Hosting: Hosting country not disclosed. Public footer says the platform is hosted according to PCI DSS, ISO 27001:2013, and ISO 9001:2015 standards. - Pricing: Public monthly pricing: BGN 295/month for 50-149 employees, BGN 395/month for 150-249, BGN 595/month for 250-499, BGN 995/month for 500+; under 50 employees by quote. - Note: Prices are quoted per month but billed annually, ex VAT, with a 12-month minimum term. Initial integration, technical and administrative resources, and onboarding training are included. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Bulgaria (Law on the Protection of Persons Reporting or Publicly Disclosing Information on Breaches, in force 4 May 2023); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://crsys.org/en/ - https://crsys.org/en/%D1%81%D0%B8%D1%81%D1%82%D0%B5%D0%BC%D0%B0%D1%82%D0%B0/ - https://crsys.org/en/%D1%81%D0%B8%D0%B3%D0%BD%D0%B0%D0%BB%D0%B8%D1%82%D0%B5/ - https://crsys.org/en/%D0%B7%D0%B0-%D0%BD%D0%B0%D1%81/ - https://crsys.org/%D1%83%D1%81%D0%BB%D1%83%D0%B3%D0%B8-%D0%B8-%D1%86%D0%B5%D0%BD%D0%B8 - https://app.crsys.org/ - https://app.crsys.org/register - https://app.crsys.org/login - https://app.crsys.org/static/js/main.068bde41.js - https://app.crsys.org/static/js/main.068bde41.js.map Notable The commercial site exposes public pricing, LOGIN and REGISTRATION links to app.crsys.org, and a distinct product identity rather than only advisory copy. Public positioning is tightly local. The site repeatedly cites the Bulgarian whistleblowing act, frames the product as an internal channel for Bulgarian private and public organisations, and explicitly targets municipalities, private employers with 50+ staff, and certain regulated employers regardless of headcount. The product story is institutional for a local entrant. The public site says the system was created by Transparency International Bulgaria and Happi Company Ltd / HAPPY COMPANY Ltd, while the domain and site policy are owned by "CONFIDENTIAL REPORTING SYSTEM" Ltd. in Sofia. The pricing page publishes BGN 295, 395, 595, and 995 monthly bands by headcount, with onboarding support included. Billing is annual and the CTA still routes to /contact, so pricing is public but procurement is not self-serve. The public legal explainer spells out written and oral reports, phone and in-person channels, 7-day acknowledgement, 3-month feedback, and routing to the CPDP where relevant. The public app bundle exposes Bulgarian and English locale support and operational product strings such as public reporting pages, internal correspondence, forwarding to external institutions, hidden staff-only notes, deanonymisation requests, registration success, activation emails, and login history. Anonymity needs buyer confirmation: anonymous written reports are listed, but the same explainer says proceedings cannot be initiated from them. BlockChain is listed in package/pricing copy. The public copy does not describe the chain, ledger, or verification surface, so it should be treated as an unexplained product claim rather than an audited control. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages, app shell, and current public bundle inspection only; no reporter submission or handler account reviewed). Base score: 20 / 50 in the Bulgaria context. Bulgaria country bonus: 4 / 6. Category Score Max A. Legal compliance 5 16 B. Reporter experience (BG) 6 10 C. Handler experience 5 10 D. Security 2 8 E. Commercial 2 6 Evidence supporting the score: public local-law framing, public price bands, and a live software surface beyond a contact form. The app bundle also shows handler-side mechanics such as status buckets, hidden notes, and correspondence modes. Unverified from public pages: hosting country, self-serve onboarding, vendor-held ISO certification, sub-processor posture, and how anonymous written reports are handled in practice given the vendor legal explainer. --- # Confidly - Website: https://confidly.eu - Headquarters: Tallinn, Estonia - Hosting: Hetzner Online GmbH, Falkenstein, Germany (vendor-stated) - Pricing: Starter EUR 39/month billed annually (EUR 468/year, up to 100 employees); Pro EUR 124/month billed annually (EUR 1,488/year, 100-500 employees); Enterprise EUR 332/month billed annually (EUR 3,984/year, up to 2,000 employees / 5 channels). Monthly billing also offered; annual billing stated to save roughly 17%. - Note: Priced by total employee headcount, not per user. All plans include a 14-day free trial (full Pro features, no credit card). Prices are EUR plus VAT, reverse-charged for EU B2B. 10,000+ employees, on-prem, or custom integrations are quote-only via sales. - Languages on reporting form: 25 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: yes - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG); France (Loi Sapin II); Italy (D.lgs 24/2023); Spain (Ley 2/2023); Netherlands (Wbk) - Last verified: 2026-07-21 - Sources: - https://confidly.eu/ - https://confidly.eu/features - https://confidly.eu/pricing - https://confidly.eu/trust - https://confidly.eu/eu-directive - https://confidly.eu/legal/imprint - https://confidly.eu/legal/dpa - https://confidly.eu/legal/privacy Notable Operated by Confidly OU, a private limited company registered in the Estonian Business Register with a registered office in Tallinn, Estonia; the site footer states the product is built in Helsinki and hosted in the EU. Positioned as a focused, self-serve reporting channel for EU companies of roughly 50 to 500 employees, deliberately narrower than a full GRC or compliance suite. Reporter intake is anonymous by design: no account, no IP, no email, and no device fingerprint; the reporter receives a case code plus a 6-digit secret (stated to be stored only in hashed form) for two-way anonymous follow-up. Multiple intake channels are documented: web form, audio and video attachments, and mobile-first WhatsApp and SMS intake, plus printable QR-code posters in six EU languages. AI features (Pro and Enterprise) summarise reports, classify severity, suggest categories, translate 25+ languages, and draft acknowledgement replies; all AI output is stated to be advisory and human-confirmed. Inference runs on AWS Bedrock eu-central-1 (Frankfurt) with stated zero data retention. Compliance features include automatic reporter status updates at 7 days and 3 months (mapped to Directive Article 9), an append-only hash-chained audit log exportable as CSV or JSON, and an auto-generated country-tailored annual compliance report. The trust page states EU data residency with production data in Hetzner Falkenstein, Germany, TLS 1.3 and AES-256 encryption, a public sub-processor list with a 30-day objection window, and an annual third-party penetration test (summary under NDA). Handler authentication is delegated to Clerk (clerk.com), a US-based identity platform: report data is EU-hosted, but sign-in and session identity run through a US sub-processor, a cross-border transfer consideration under GDPR Chapter V. ISO 27001 and SOC 2 Type II are listed as in progress with target dates; ISO 27701 and TISAX are planned or on request. No certification was verified as complete on the public pages reviewed. Public legal artifacts include an Article 28 DPA with SCCs, a privacy policy, a pre-filled Article 35 DPIA template, and a RoPA entry; some pen-test, TIA, and BCP documents are stated to be available only under NDA. Pricing is published for all three standard tiers, banded by total employee headcount rather than per user, with a 14-day free trial (no credit card) and both monthly and annual billing. Deployments above 2,000 employees, on-prem, or custom integrations are handled via sales. The public imprint lists Confidly OU in Tallinn but shows the registry number and VAT identification number as placeholders as of the reviewed date; the stated supervisory authority is the Estonian Data Protection Inspectorate (AKI). --- # Cortina Compliance Hub - Website: https://cortina-consult.com/software/ - Headquarters: Münster, Germany - Hosting: German data centres / German data holding (vendor claim); specific data-centre location and provider not disclosed on public pages reviewed - Pricing: Compliance Hub from €45/month for one core module, including the Hinweisgeberschutz/whistleblowing module. Separate managed services, including external whistleblower officer, are advertised from €125/month. - Note: Published starting prices are public; detailed module configuration is calculator / offer-led. No free trial found. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: yes - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (vendor-stated for Compliance Hub; certificate/scope not found) - National laws referenced: Germany (HinSchG); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://cortina-consult.com/software/ - https://cortina-consult.com/software/preise/ - https://cortina-consult.com/unternehmen/ Notable Cortina Consult GmbH is headquartered in Münster and markets 400+ managed customers, TÜV-certified advisers, and 10+ years of experience. Hybrid offering — consulting practice plus a software product line. The software line is “Compliance Hub”: core modules include DSMS for data protection, ISMS for information security, and Hinweisgeberschutz for whistleblowing. Whistleblower module described as HinSchG-compliant with anonymous reporting and structured case management; audit trail and deadline tracking included. The company also markets a standalone whistleblower portal brand called Parlabox (launched 2023); documented pricing paths lead to Compliance Hub. REST API with named integrations to Personio, Microsoft Azure, and SAP SuccessFactors is public on the software page. Security posture is vendor-stated rather than trust-centre documented: German data centres, end-to-end encryption, 99.9% availability, and ISO 27001 certification are claimed, but no certificate/scope or hosting-provider page was found. Related managed services (separately priced): External Data Protection Officer, External Information Security Officer, External Whistleblower Officer — each from €125/month. Reporting-form languages, customer names, exact data-centre location/provider, public sub-processor list, and product-level ISO certificate scope were not disclosed on public pages reviewed. Best fit when the buyer wants both software and a managed officer service from one vendor, or is already deploying DSMS/ISMS. --- # Digitech (TalkNow) - Website: https://digitechsa.gr/en/service/whistleblowing/ - Headquarters: Greece - Pricing: Not published (quote-based). - Note: No public pricing on pages reviewed. - Languages on reporting form: 90 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (TalkNow platform), ISO 27701 (TalkNow platform) - National laws referenced: Greece (Law 4990/2022) - Last verified: 2026-06-10 - Sources: - https://digitechsa.gr/en/service/whistleblowing/ Notable Greek implementer (Digitech, Chalandri-Athens) deploying the TalkNow whistleblowing platform for Law 4990/2022. Underlying platform is vendor-stated as certified to ISO 27001:2013 and ISO 27701:2019; hosting on secure servers within the EU. Anonymous or named reporting with a unique 16-digit follow-up code and a reporter↔Responsible-Officer chat; report auto-deletion within the regulatory timeframe; 90+ languages. Delivered as platform plus consulting (legal advice, officer training, policy drafting, ongoing support). Certifications are vendor-stated for the TalkNow platform; pricing, specific hosting country, subprocessor list, and DPA were not disclosed on the page reviewed. --- # Disclosurely - Website: https://disclosurely.com - Headquarters: London, United Kingdom - Hosting: Stated as UK/EU for production customer data, without naming a country or region. Named sub-processors are Vercel, Stripe, OpenAI and Resend. - Pricing: Pro £39.99/month, Organisation £149/month, Enterprise on quote. Annual billing gives two months free. Pro is described as introductory pricing held for the life of an active subscription. - Note: A 7-day free trial is offered and billing can be switched between monthly and annual. Pro is marketed as an introductory rate that will rise for new customers, with the current price locked while the subscription stays active. API access, webhooks and custom integrations are all listed as coming soon on the Enterprise tier. - Languages on reporting form: undisclosed - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-09-21 - Sources: - https://disclosurely.com/ - https://disclosurely.com/pricing - https://disclosurely.com/security - https://disclosurely.com/privacy Notable Operated by Umbrella Rank Ltd, registered in England and Wales with a registered office at London EC1V 2NX. The operating company name does not carry the product name. The security centre is the most candid document of its kind in this directory. It separates what is live from what is planned, states that encryption protects data in motion and at rest but does not stop authorised handlers reading reports, and tells buyers not to call the platform end-to-end encrypted. Reporters return to a case with a tracking ID plus a private access secret, submit without an account, and have file metadata stripped where applicable. The vendor states organisations cannot identify anonymous reporters through the platform. Audit records are described as including chained fields in the core audit table to support integrity review, and internal vendor support activity is logged separately from the customer’s own audit history. Tenant isolation is described as logical, with row-level security on core customer tables and organisation-scoped access paths, in a shared multi-tenant platform. Authentication deliberately avoids magic links, on the stated grounds that enterprise email security gateways follow links before the user does. Access uses single-use email codes with MFA available. Legal positioning is thinner than the security posture. Pages reference the EU Whistleblowing Directive, UK requirements and GDPR in general terms; no transposition statute is named with article numbers on the pages reviewed. Status: not yet scored Disclosurely was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in a country ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Double Voice - Website: https://doublevoice.io - Headquarters: Caldas da Rainha, Portugal - Pricing: Starter EUR 500/year (up to 100 employees); Growth EUR 650/year (up to 250); Business EUR 900/year (up to 500); Enterprise EUR 1,200/year (up to 1,000); Corporate EUR 1,900/year (1,000+). Prices exclude 23% VAT. - Note: All tiers are billed annually (marketed as roughly 17% cheaper than a monthly equivalent). No self-serve checkout or free trial is offered; acquisition runs through a scheduled demo and a contract, after which the platform is configured in a few days. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Portugal (Lei 93/2021) - Last verified: 2026-07-19 - Sources: - https://doublevoice.io/ - https://double-shore.com Notable Double Voice is a standalone, vendor-hosted cloud whistleblowing channel operated by Momentapproach Unipessoal, Lda., trading as Double Shore (a registered trademark), based in Caldas da Rainha, Portugal. Positioning is squarely Portuguese: the site is in pt-PT and centers on Lei 93/2021, the Portuguese transposition of EU Directive 2019/1937, which obliges private employers with 50+ workers and public bodies serving 10,000+ inhabitants to run a reporting channel. Reporting is via an online form supporting file uploads (PDF, Word, images) across 15+ violation categories, with submissions described as truly anonymous and an anonymous two-way dialogue for follow-up. Handler side includes a case-management dashboard with tracking from submission to resolution, statistics and charts, automatic email notifications at each phase, and color-coded legal-deadline alerts. Security claims cover SSL certificates, servers with encrypted data (“Always Encrypted”), and access restricted to authorized administrators; no hosting provider or data-center country is named on public pages reviewed. No ISO 27001 or other certification was found on public pages reviewed. Pricing is fully published across five annual tiers keyed to employee count: EUR 500, 650, 900, 1,200, and 1,900 per year, all excluding 23% Portuguese VAT. Billing is annual only (marketed as roughly 17% below a monthly equivalent); there is no monthly contract and no self-serve free trial. Acquisition is demo-first: a 30-minute personalized demo and a contract, after which the platform is configured with the customer’s branding in a few days. The privacy policy and terms render client-side, so a subprocessor list and detailed retention terms were not verifiable on the public pages reviewed. --- # e-CAS - Website: https://e-cas.es - Headquarters: Spain - Hosting: Spanish servers (vendor-stated); ISO 27001 homologation stated for the server hosting only - Pricing: Three whistleblowing-channel tiers (Estandar, Premium, Profesional) differing by user count and language options; external investigation or instruction of a report from EUR 150 per report. Tier prices are shown in images on the pricing page rather than as readable text, and prices exclude VAT and are billed per full year. - Note: The public pricing section names three tiers and states prices are shown at the foot of the page, but the tier figures render as images rather than text on the public page reviewed. External case investigation is quoted from EUR 150 per report. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Spain (Ley 2/2023) - Last verified: 2026-07-19 - Sources: - https://e-cas.es - https://canal.e-cas.es Notable e-CAS (Compliance Assisting Solution) is a Spanish cloud compliance platform; its public pages state it was created by eCompliance Consultores & Abogados and Borak IT Solutions. The whistleblowing channel (canal de denuncias) is presented as a module of the wider e-CAS penal-risk and compliance platform aligned to UNE 19601 and ISO 19600. The channel page cites Spain’s Ley 2/2023 by name and publication date (21 February 2023) and references ISO 37002:2021 as the standard for the internal reporting channel; no article numbers are cited. The vendor states the channel is activated within about 36 hours, later qualified as a variable timeframe that “can be” 36 hours. Anonymous reporting is supported in written and verbal form, including voice distortion, with photo and document upload and report-type discrimination (irregularities, violations, criminal acts). A 7-day acknowledgement of receipt, case tracking with restricted access, two-way confidential communication, and encrypted communications certified by Rubricae are described. Security claims include dual-factor authentication, end-to-end encryption, activity logging, and WCAG 2.1 AA accessibility. Servers are stated to be located in Spain; the referenced ISO 27001 homologation is explicitly for the server hosting only, not a vendor or product certification. Three channel tiers are named (Estandar, Premium, Profesional), differing by user count and language options; the public page states prices appear at the foot of the page but the figures render as images rather than text. Prices are stated to exclude VAT and to be billed per full year; external investigation or instruction of a report is quoted separately from EUR 150 per report. Reporter languages are stated as Spanish and English, with additional languages available on request; no self-serve trial or public API documentation was found on the pages reviewed. --- # e-nform - Website: https://enform.pl - Headquarters: Warsaw, Poland - Hosting: Microsoft Azure managed by the vendor (Western Europe, vendor-stated), or on-premises deployment on the Platinum tier - Pricing: Silver EUR 397/month or EUR 4,329/year (up to 3 operators); Gold EUR 879/month or EUR 9,588/year (up to 10 operators); Platinum from EUR 14,500/year (unlimited operators, individual pricing). - Note: All plans are stated to include licensing, hosting, installation, configuration, and technical support. Platinum is quote-based (from EUR 14,500/year) and adds on-premises deployment and custom forms. Silver and Gold list both monthly and annual prices. - Languages on reporting form: 11 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-07-19 - Sources: - https://enform.pl/ - https://enform.pl/o-e-nform/ - https://enform.pl/system-dla-sygnalistow/ - https://enform.pl/produkty/aplikacja-dla-sygnalistow/ - https://enform.pl/faq/ - https://enform.pl/zasady-bezpieczenstwa-sygnalisty/ Notable Operated by E-nform Sp. z o.o., ul. Laurowa 39, 03-197 Warsaw, Poland. Marketed as compliant with EU Directive 2019/1937 and GDPR/RODO; the Polish transposition law (ustawa o ochronie sygnalistow, 14 June 2024) is not named on the pages reviewed. Offered in three variants: Silver (up to 3 operators), Gold (up to 10 operators), and Platinum (unlimited operators, individual pricing). Silver and Gold list both monthly and annual prices; Platinum starts from EUR 14,500/year and is quote-based. Hosting is Microsoft Azure managed by the vendor (servers stated to be in Western Europe), with on-premises deployment available on the Platinum tier. Anonymity measures stated publicly: no IP-address collection, automatic metadata stripping from attachments, and antivirus scanning of uploads. Reporters return to their case using a unique identifier and PIN, communicating with coordinators through a per-case chat. Handler side includes a report registry with sorting, filtering, full-text search, case linking, assignment to coordinators and experts, system notifications, and a handling-history audit trail. The FAQ states the system is available in 11 languages by default, with additional language versions on higher tiers. Public pages reference annual external security testing; no ISO 27001 certification was found on the pages reviewed. The vendor also markets separate e-nvote (voting) and communication applications alongside the whistleblowing product, and offers consulting, implementation, training, and audit services. No self-serve free trial, API documentation, or sub-processor list was found on public pages reviewed. --- # e-Zaupnik - Website: https://e-zaupnik.si - Headquarters: Ljubljana, Slovenia - Pricing: Basic EUR 49/month (single trustee); Multi-user EUR 79/month; Premium with legal assistance from EUR 99/month. Prices stated excluding VAT. - Note: Prices are quoted per month excluding VAT. The Premium tier bundles legal assistance and is priced from EUR 99, with the legal assistance page being contact-only. No free trial or annual billing terms were found on public pages reviewed. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001 (vendor-stated) - National laws referenced: EU Directive 2019/1937; Slovenia (ZZPri, Zakon o zaščiti prijaviteljev) - Last verified: 2026-07-19 - Sources: - https://e-zaupnik.si/ - https://e-zaupnik.si/zaupnik/ - https://e-zaupnik.si/prijavitelj/ - https://e-zaupnik.si/pravna-asistenca/ Notable Operated by Virtual IT, informacijske tehnologije d.o.o. of Ljubljana, part of the Infocenter Group. Positioned specifically for Slovenia’s whistleblower protection law ZZPri (Zakon o zaščiti prijaviteljev) and the EU Whistleblowing Directive 2019/1937. Reporters can submit anonymously using a self-selected unique code, or register with personal contact details, and communicate securely with the appointed trustee (zaupnik). The application records and manages reports and supports reporting toward organization leadership and the KPK (Commission for the Prevention of Corruption). A multi-user tier supports multiple trustees within one organization. Markets an AI chatbot that explains the ZZPri law to reporters and trustees and helps users navigate the application. Public pricing shows Basic at EUR 49/month, Multi-user at EUR 79/month, and a Premium tier with legal assistance from EUR 99/month, all excluding VAT. The separate legal assistance offering covers policy preparation, staff training, program evaluation, and, by agreement, external review of internal reports. Homepage states ISO 27001 as a security claim and GDPR and ZVOP-2 compliance; no certificate number is published and it is not clear whether ISO 27001 covers the vendor or a hosting provider. Hosting location and EU data residency country were not disclosed, and the interface and documentation are Slovenian only, on public pages reviewed. No free trial, annual billing, API access, or sub-processor list was found on public pages reviewed. --- # EasyWhistle - Website: https://www.easywhistle.com - Headquarters: Finland - Hosting: Google Cloud Platform data centres within the EU (vendor-stated) - Pricing: Starter EUR 69/month or EUR 468/year (0-49 employees); Medium EUR 119/month or EUR 948/year (50-249); Large EUR 149/month or EUR 1,308/year (250-1,000); Enterprise EUR 299/month or EUR 2,388/year (1,000+). - Note: Annual prices equal EUR 39 / EUR 79 / EUR 109 / EUR 199 per month. 14-day free trial with no charge during trial. SSO included; customisable forms cost EUR 10/month or EUR 60/year. Pricing renders inside the embedded self-signup app. - Languages on reporting form: 30 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.easywhistle.com/en/ - https://www.easywhistle.com/en/pricing/ - https://www.easywhistle.com/en/software/features/ - https://www.easywhistle.com/en/security/ - https://www.easywhistle.com/en/company/ - https://www.easywhistle.com/en/privacy/ - https://self-signup-prod.web.app/ - https://items-nv4sofdg6q-uc.a.run.app Notable Operated by Easywhistle Oy, Finnish VAT FI31327372. Marketed as compliant with the EU Whistleblowing Directive and GDPR; specific Finnish transposition law not explicitly named. Self-signup app exposes four tiers with both monthly and annual billing: Starter, Medium, Large, and Enterprise. Annual equivalents range from EUR 39 to EUR 199 per month; month-to-month prices range from EUR 69 to EUR 299 per month. Customisable forms cost EUR 10/month or EUR 60/year; SSO is listed as included in the self-signup data reviewed. Public features page states support for more than 30 languages, anonymous two-way communication, deadline reminders, and Microsoft/Google integrations. Security page states Google Cloud Platform hosting in EU data centres and encryption at rest and in transit. Security page references a 2023 technical security audit by 2NS; no ISO 27001 certification was found on public pages reviewed. Pricing page itself does not show the tier table without loading the embedded self-signup app; the direct price JSON endpoint used by that app was reviewed. No public API documentation or subprocessor list was found on public pages reviewed. --- # Elker - Website: https://elker.com - Headquarters: Australia - Hosting: Described as regional data hosting to meet local data privacy requirements. No region, country or provider is named on public pages reviewed. - Pricing: Quote-only. The vendor states pricing is tailored to organisation size, required features and compliance needs. - Note: Every commercial route is a demo booking or a quote request; no plan names, bands or amounts are published. There is no self-serve trial. - Languages on reporting form: undisclosed - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): no - Certifications: ISO/IEC 27001, SOC 2 - National laws referenced: Australia (Corporations Act, Public Interest Disclosure Act); Australia (Work Health and Safety Act, Sex Discrimination Act, Modern Slavery Act, Aged Care Act) - Last verified: 2026-09-21 - Sources: - https://elker.com/ - https://elker.com/about - https://elker.com/security Notable Elker is a genuine whistleblowing and case-management platform, but it is an Australian one. The compliance pages map to the Corporations Act, the Public Interest Disclosure Act, the Work Health and Safety Act, the Sex Discrimination Act, the Modern Slavery Act and the Aged Care Act. EU Directive 2019/1937 does not appear. The country selector in the footer offers Australia / Global and New Zealand. There is no EU locale, no EU transposition page and no European office named. Security disclosure is stronger than most of this field: ISO 27001 certification, SOC 2 attestation, a published Vanta trust portal, annual independent penetration testing, staff background checks, and AES-256 encryption in transit and at rest. The product spans more than reporting — surveys, analytics, psychosocial hazard management, investigation workflows and an anonymous suggestion box sit in the same platform, with named use-case tracks for universities, schools, government and aged care. Founders and board are named on the about page, with backgrounds in dispute resolution and mediation rather than compliance software, and a roster of external investigators and mediators is listed as consultants. Status: not yet scored Elker was added from the September 2026 AI-citation coverage audit, where assistants answering European whistleblowing questions cited it repeatedly. It is listed here so that citation can be checked against what the vendor actually sells: an Australian and New Zealand product with no European market surface. The entry carries no 25-criterion rubric score and does not appear in a country ranking, because the rubric scores products against EU Directive 2019/1937 and its transpositions, which this vendor does not claim to cover. --- # EQS Integrity Line - Website: https://www.integrityline.com - Headquarters: Munich, Germany - Pricing: English global package page does not publish prices. UK package page publishes Essential from £85/month and Professional from £170/month; Enterprise on request. - Note: Essential offers Start free trial. Professional and Enterprise are demo-led. Telephone reporting is available on Professional and Enterprise. - Languages on reporting form: 80 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISAE 3000 Type I and II, WACA Bronze - National laws referenced: EU Directive 2019/1937; Germany (HinSchG); United Kingdom (PIDA); France (Sapin II / Loi Waserman) - Last verified: 2026-09-18 - Sources: - https://www.eqs.com/ - https://www.integrityline.com/product/ - https://www.integrityline.com/en-gb/product/packages/ - https://www.integrityline.com/security/ - https://www.eqs-news.com/news/corporate/eqs-group-nimmt-exklusive-verhandlungen-zur-uebernahme-von-data-legal-drive-auf/77442d26-a35b-4296-92dd-6b826d28be98_en - https://www.eqs.com/fr/solutions-by-objective/conformite-abac/ - https://www.integrityline.com/fr/ - https://www.eqs.com/fr/ressources-compliance/loi-sapin-2/ - https://www.thomabravo.com/press-releases/thoma-bravo-announces-closing-of-eqs-acquisition - https://datalegaldrive.com/mentions-legales/ Notable EQS publishes three packages: Essential, Professional, and Enterprise. EQS’ main site states 14,000+ customers around the globe; this appears to be an EQS Group platform-scale claim, not an Integrity Line-only count. The global English package page does not show prices; the UK localized page publishes Essential from £85/month and Professional from £170/month, with Enterprise on request. Essential has a public free-trial CTA. Professional and Enterprise use Book a demo. Package features include anonymous dialogue, over 80 reporting languages, case management, automated or configurable translation, deadline monitoring, case documentation, 2FA, and European ISO 27001-certified hosting. The security page states EQS Group and data centres are ISO 27001 certified, the hotline has ISAE 3000 Type I and II audits, no IP/location/device details are stored, and EQS says it cannot access customer or whistleblower data. Public pages reviewed did not disclose API access, customer-held PGP/RSA key custody, a public DPA, or a public subprocessor list. Data Legal Drive - 2026-09-25 EQS bought the French compliance-software vendor Data Legal Drive (RGPD plus DLD Sapin II, the French anti-corruption and internal-alert product) in 2024 for €35m against roughly €5m ARR. The brand is now being absorbed: datalegaldrive.com returns 301 to www.eqs.com/fr, and the Sapin II product page redirects to the EQS anti-corruption solution page, which markets a “dispositif d’alerte professionnelle” and names Integrity Line as the product behind it. Only legacy blog and legal pages still resolve on the old domain. No separate directory entry is warranted, on the same reasoning that keeps EthicsPoint and WhistleB inside the NAVEX entry: a retired brand pointing at this product is this product. The old brand names redirect here instead. The French-market consequence for a buyer is simply that EQS entered France by acquisition rather than by localisation, so a French organisation evaluating “Data Legal Drive” today is evaluating EQS. Their French-law coverage survived the move. integrityline.com/fr/ names Loi Sapin 2, Loi Waserman and Directive 2019/1937 in its own heading, and eqs.com/fr carries a Sapin 2 resource hub, so France and the French laws are recorded here alongside Germany and the UK. An earlier draft of this section claimed the Sapin II mapping had not reappeared under the EQS brand; that was inferred from one solution page that happens not to name it, and it is wrong. --- # EthicLink - Website: https://ethiclink.eu - Headquarters: Voluntari, Romania - Hosting: Privacy policy states all data is stored on secured servers in the EU ('servere securizate aflate în Uniunea Europeană'); specific country and hosting provider are not named. Stripe (payments) and Google Ireland (Analytics) are named as processors. - Pricing: Standard €30/month or €300/year (both incl. 19% Romanian VAT): up to 5 users, 20 extra fields, 5 pages. Custom tier (unlimited users/fields/pages, priority support, custom domain) is quote-based. - Note: Both monthly and annual billing offered on the Standard tier. Subscription fees are explicitly non-refundable. A 7-day free trial is advertised (no credit card), but on 2026-07-18 both self-serve signup paths (email and Google) returned 'For security reasons the registration process is suspended.' - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Last verified: 2026-07-18 - Sources: - https://ethiclink.eu/ - https://ethiclink.eu/privacy.html - https://ethiclink.eu/therms.html - https://portal.ethiclink.eu/users/create Notable Operated by SELFSOFT TECH SRL (CUI RO23359004) out of Voluntari, Romania; the interface runs in English and Romanian. One of the few small Romanian channels with a real monthly billing option: €30/month or €300/year, both VAT-inclusive, on a self-serve Standard tier capped at 5 users, 20 extra fields, and 5 pages. A quote-based Custom tier lifts those limits. A 7-day free trial with no credit card is advertised, but on 2026-07-18 both signup paths (portal.ethiclink.eu/users/create and /users/google) returned “For security reasons the registration process is suspended. Please try again later.” Combined with a stale “© 2025 Selfsoft Tech” footer and no dated activity, this suggests the project may be dormant rather than actively operated. The privacy policy discloses EU hosting, TLS/SSL encryption in transit plus at-rest encryption, a stated retention approach, and named processors (Stripe for payments, Google Ireland for Analytics); a DPA is referenced but not published for download. Positioning is generic “ethics / misconduct reporting” rather than transposition-law compliance: neither EU Directive 2019/1937 nor Romania Law 361/2022 is named anywhere on the public pages reviewed, and the hosting country, ISO 27001, and handler-workflow depth are not disclosed. Status: not rated EthicLink is kept in the directory because it was reviewed, but it is not scored. A tool that cannot be accessed cannot be rated on the 25-criterion rubric without inventing evidence, so it does not appear in the Romania ranking. On 2026-07-18, every self-serve signup path returned “For security reasons the registration process is suspended. Please try again later.” (portal.ethiclink.eu/users/create and /users/google; see the screenshot above). The marketing site, legal pages, and Stripe billing links are still live, but the footer copyright still reads “© 2025 Selfsoft Tech” with no dated activity, so the product appears dormant rather than actively operated. What the public pages do document is captured above under Notable, strengths, and the pricing caveats. If registration reopens and the product becomes testable, this profile will be scored under the same rubric as every other tool and moved into the ranking. --- # Ethicontrol - Website: https://ethicontrol.com - Headquarters: Estonia (Ethicontrol OÜ); offices listed in Tallinn, Berlin, Warsaw, and Kyiv - Hosting: European data center in Frankfurt; vendor also lists data centers in the US, Ukraine, UAE, Brazil, India, and more depending on client needs. - Pricing: Starter €89/mo · Standard €174/mo · Advanced €369/mo · Pro €919/mo. Annual billing saves 8%. Standard plans cap at <2,000 employees; >2,000 routes to sales. On-premise license: €13,900 one-time (15-year, 36 months updates). - Note: Homepage still says tariff plans get test access to all features for the first 6 months; the pricing page does not repeat that trial language. Up to 90% discount available for non-profits and education via cover-letter application. Final pricing 'determined based on individual discussions' per vendor disclaimer. - Languages on reporting form: 60 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISO 27701 - National laws referenced: EU Directive 2019/1937; France (Sapin II); United Kingdom (PIDA); Various international frameworks (ISO 37002, ISO 37001, US DoJ guidelines) - Last verified: 2026-05-24 - Sources: - https://ethicontrol.com - https://ethicontrol.com/en/pricing - https://ethicontrol.com/en/eu-whistleblowing-directive-platform - https://ethicontrol.com/en/trust-center - https://ethicontrol.com/en/about-us - https://ethicontrol.com/en/blog/ukrenergo072019 Notable Estonia-headquartered, Ukrainian-founded. Ethicontrol identifies Ethicontrol OÜ as HQ and lists offices in Tallinn, Berlin, Warsaw, and Kyiv; the footer also names Ethicontrol LLC. Contracting entity and sub-processor details should be checked in the DPA. Audit log and MFA start at Advanced (€369/mo). The Starter and Standard tiers include the basic reporting/case-management cycle, but audit log, MFA, machine translation, and custom roles are listed from Advanced. Unlimited users on every tier. The pricing page states “Unlimited users, admins, employees, messages, cases, and reports” across Starter through Pro, so cost does not rise with the number of case handlers. Language coverage, not seats, is what the tiers gate. Headcount ceiling: 2,000 employees on self-serve tiers. Larger organisations enter a sales-led process. Ukrenergo is a public case-study reference — Ethicontrol’s own 2019 case-study post says Ukraine’s state-owned transmission-system operator introduced an ethics hotline using Ethicontrol. UNIC member. Ethicontrol participates in the Ukrainian Network of Integrity and Compliance (unic.org.ua), the main Ukrainian compliance community — useful context for buyers evaluating local presence. On-premise license: €13,900 one-time (15-year license, 36 months updates / support). Self-disclosed caveat: “Limitations on reporters’ confidentiality and anonymity protection” — a notable admission for a compliance vendor and worth scrutinising in the contract. Non-profit / education programme: up to 90% discount by cover-letter application from an org/edu email. Toll-free helpline is an add-on (from €99/mo, 180 countries) — not bundled at any standard tier. Messaging-app intake from Standard tier. Web, email and phone are in all tiers; WhatsApp, Telegram, Viber and Facebook chatbots start at Standard. Language coverage is tier-gated, and the vendor’s own pages disagree on the total. The homepage says 60+ languages and the About page says 70+. Included languages are 4 on Starter and Standard, 10 on Advanced, and unlimited only on Pro. Vendor pages conflict on scale. The homepage states 254k+ client employees across 17 jurisdictions, while the About page states 354k client employees and 37 jurisdictions. Treat exact scale as vendor-claimed and inconsistent across public pages reviewed. ISO 27701 privacy certification (in addition to ISO 27001) across all tiers is uncommon at this price band. Trial language is inconsistent. The pricing page does not foreground a current free trial, while the homepage still says all tariff plans get test access to all features for the first 6 months. Re-verify with the vendor before relying on the exact trial terms. --- # Ethicorp - Website: https://www.ethicorp.com - Headquarters: Paris, France - Hosting: SaaS hosted in France with in-country data replication by a French operator (vendor-stated); optional on-premise hosting - Pricing: Not published. Quote-based. EthiAlert is offered as Pro (internal referents receive alerts) and Premium (ethics lawyers receive and process alerts). - Note: Pricing is not disclosed on public pages reviewed. Procurement is contact-led; the Premium tier is a managed service where ethics lawyers act as the confidential intermediary and handle alerts under attorney-client privilege. - Languages on reporting form: 28 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 37002 (Bureau Veritas audit), ISO 37008 (Bureau Veritas audit) - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II); France (Loi Waserman) - Last verified: 2026-09-18 - Sources: - https://www.ethicorp.com/ - https://www.ethicorp.com/presentation/main/index.php Notable Ethicorp is a French legaltech founded in 2016 by William Feugere, a Paris Bar lawyer specialising in ethics and compliance; the whistleblowing product is marketed alongside a related lawyer practice. The whistleblowing channel is EthiAlert, one of three products in the Ethicorp suite alongside EthiCase (internal investigation management) and EthiMap (compliance risk mapping). EthiAlert is offered in two tiers: Pro, where the organisation’s internal referents receive and supervise alerts, and Premium, where ethics lawyers receive and process alerts, screen conflicts of interest, and provide attorney-client privilege protection. The Premium tier is a managed service; the lawyers acting as the confidential intermediary are positioned as the distinctive feature, making legal professional privilege an ally of whistleblower confidentiality. Positioning references Loi Sapin II and French Anti-Corruption Agency recommendations; Loi Waserman transposes EU Directive 2019/1937 into French law. Article-level mapping was not found on public pages reviewed. The platform states anonymous reporting support (aligned to ISO 37002), customisable reporting home pages with logo, welcome message, ethics documents and FAQs, and integrated messaging designed to avoid standard email exchanges. Reporter submission (“Deposer une alerte”) is web-based and the interface offers 28+ languages including French, English, German, Spanish, Portuguese, Chinese, and Japanese. The vendor states it is a 100% French company with SaaS hosted in France, in-country data replication by a French operator, and an optional on-premise hosting arrangement. Certifications listed are ISO 37002 (whistleblowing management systems) and ISO 37008 (internal investigations), audited by Bureau Veritas. No ISO 27001 certification was found on public pages reviewed. Named public client logos include RATP, CNR, Eau de Paris, AG2R, Manutan, 360Learning, and roughly 40 others; no detailed case studies were published. No pricing, self-serve trial, API documentation, or sub-processor list was found on public pages reviewed; procurement is contact-led. --- # EthicsPortal - Website: https://ethicsportal.eu - Headquarters: Poland - Hosting: Hetzner, Nuremberg, Germany - Pricing: €60/month, or €41.67/month billed annually (€500/year) - Note: Single plan. Unlimited users, reports, file uploads. - Languages on reporting form: 14 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (Hetzner hosting) - National laws referenced: Germany (HinSchG); France (Loi Waserman); Italy (D.Lgs. 24/2023); Spain (Ley 2/2023); Poland (Act of 14 June 2024); Bulgaria (Whistleblowing Act, in force 4 May 2023); Greece (Law 4990/2022); Romania (Legea nr. 361/2022); All 27 EU member states — a dedicated /whistleblower-laws// page exists per state, citing the official law text - Last verified: 2026-09-20 - Sources: - https://ethicsportal.eu/ - https://ethicsportal.eu/pricing/ - https://ethicsportal.eu/compliance/ - https://ethicsportal.eu/product/ - https://ethicsportal.eu/dpa/ - https://ethicsportal.eu/dpia/ - https://ethicsportal.eu/subprocessors/ - https://ethicsportal.eu/trust/ - https://ethicsportal.eu/security/ - https://ethicsportal.eu/iso-37002/ - https://ethicsportal.eu/iso-27001/ - https://ethicsportal.eu/caiq/ - https://ethicsportal.eu/dora/ - https://ethicsportal.eu/dora-addendum/ - https://ethicsportal.eu/industries/financial-services/ - https://ethicsportal.eu/incidents/ - https://ethicsportal.eu/accessibility/ - https://ethicsportal.eu/whistleblower-laws/ Notable Single flat plan; pricing does not vary by employee count, report volume, or user count. Reporter and handler UI are available in English, Bulgarian, German, Greek, Spanish, French, Croatian, Italian, Dutch, Polish, Portuguese, Romanian, Slovenian, and Luxembourgish (14 locales total; 13 EU official languages plus Luxembourgish). Vendor publishes an article-by-article mapping of features to EU Directive 2019/1937, plus a dedicated public page at /whistleblower-laws// for each of the 27 EU member-state transpositions, citing official law text and external authorities. File uploads are stripped of EXIF, GPS, and author metadata before storage. No reporter IP addresses are stored; rate limiting uses one-way hashes. Personal data is encrypted in transit (TLS); sensitive fields — report descriptions, reporter contact details, and message bodies — are encrypted at rest. Append-only audit trail logs every action with timestamp, actor, and action type; the complete audit log of submissions, status changes, messages, assignments, and report views is visible to handlers on each report. Two-factor authentication available for handler and admin accounts, with an onboarding step prompting setup. Reporter access uses two factors: a case reference (format WB-XXXX-XXXX) plus a 6-digit passcode chosen by the reporter at submission. The passcode is stored only as a hashed digest and cannot be recovered. The follow-up inbox and message-posting are gated on the passcode check; no account creation required. Reporters can also download a PDF copy of their own report from the follow-up portal (audit-logged). Configurable data retention: 12, 24, 36, 48, or 60 months, with automatic deletion of expired closed reports. 7-day acknowledgement and 3-month feedback deadlines tracked automatically with overdue notifications and a lifecycle stepper UI. Closure reason captured as a structured outcome (action taken, no action needed, outside reporting scope, referred to external authority, withdrawn) aligned with Directive Art 9(1)(c) feedback obligations. Oral reporting (Directive Art 9(2)(b)) is supported directly in the portal: reporters can record a voice message at submission. Anonymization is always-on and irreversible — the audio is pitch-shifted, only the altered clip is attached, and the original is purged, so the reporter’s true voice never persists past processing. The pipeline fails closed: until conversion succeeds the recording is hidden from handlers, and on permanent failure the raw audio is purged rather than retained. Handlers can set a case priority (low, normal, high, urgent) during assessment; the priority shows as a badge on the report list, every change is audit-logged, and the compliance report includes a breakdown of reports by priority. Admins can export an organisation-level compliance report PDF directly from the dashboard. Handlers can manually log reports received by phone, email, or in person. Report categories are mapped to the Directive’s Art 2(1) Union-law domains: each category carries a directive (with article reference) or national tag, the article surfaces as a badge on the handler-facing report detail, and reporters continue to choose from plain-language groups. Structured intake questionnaire: five optional, Directive-aligned questions — relationship to the organization (Art 4 personal scope), how the reporter knows, when/how often it happened, whether it was reported before, and whether the reporter fears or faces retaliation (Art 19) — presented as a skippable guided step on the reporter form so anonymity is never compromised by a required answer. Answers are encrypted at rest, shown to handlers and in the PDF export, and a retaliation concern is surfaced as a prominent urgency badge. The same questions are available when a handler logs an offline (phone/in-person) report. Three membership role tiers: member (handler), admin, and viewer — a read-only seat for auditors and external legal counsel that can see every report and the full audit trail but cannot act on a case or manage the organisation. Organization-level GDPR Art 20 data export: an admin can request a ZIP of the full tenant dataset (reports, messages, attachments, with encrypted fields decrypted for portability); the request and the download are both audit-logged, access is admin-only, and the ZIP auto-purges after 7 days. Deleting an organisation that holds reports is a retention-aware soft-delete, not an instant wipe: the org disappears for users immediately while its reports ride out their per-portal retention windows and are auto-purged afterward, preserving the Directive’s retention obligation. Orgs with no reports still hard-delete immediately. SCIM 2.0 user provisioning: an organization can connect its identity provider (e.g. Okta, Microsoft Entra ID) to provision case handlers and automatically deprovision them when they are removed from the directory. Admins generate, rotate, and enable or disable a per-organization token and choose the default role for provisioned users. SAML 2.0 single sign-on: an organization can connect its identity provider (e.g. Okta, Microsoft Entra ID) so its team signs in through it. SSO is configured per organization and can cover one or more email domains; enforcement (requiring SSO for those domains) and just-in-time provisioning of accounts on first sign-in are both optional. Magic-link sign-in remains available when SSO is not enforced. SSO authenticates logins while SCIM provisions accounts — the two together are the standard enterprise-identity pairing. No public reporting API or third-party integrations published; the SAML SSO and SCIM endpoints are scoped to authentication and identity provisioning respectively. Hosted in Hetzner’s Nuremberg data-centre park, which holds ISO/IEC 27001:2022 certification (audited by SOCOTEC) covering infrastructure, operation, and customer support. EthicsPortal itself is not separately ISO 27001 certified. Publishes an ISO 37002:2021 guidance-alignment map (/iso-37002/) mapping the standard’s operating clauses to shipped features, plus an ISO 27001 Annex A self-assessment. ISO 37002 is a guidelines standard, so this is alignment, not certification. Published DPA grants the Controller an explicit right to object to subprocessor changes (§6.4, 30-day notice + termination remedy) and commits to 72-hour breach notification (§6.6). Publishes a DORA page (/dora/) for financial entities: the service is classified as type S19 (Cloud services: SaaS) in the ICT-services taxonomy used by the register of information, with the provider-side register fields supplied under Article 28(3) DORA and Implementing Regulation (EU) 2024/2956, and the ICT service supply chain named rather than summarised. Article 30(2) baseline provisions and Article 30(3) extended provisions (for ICT services supporting a critical or important function) are each listed requirement-by-requirement with status and location, and a signable contractual addendum is published at /dora-addendum/ covering subcontracting, audit and authority cooperation, incident assistance, exit and transition. Concentration risk is stated plainly on the same page rather than omitted: report data sits with a single IaaS subcontractor in one region, so it can enter the customer’s Article 29 assessment. Zero-AI commitment codified in DPA §6.10 and on the public subprocessor list: no LLM or AI inference provider is in the data chain. Accessibility statement at /accessibility/ declares WCAG 2.2 Level AA and EN 301 549 V3.2.3 conformance posture, with non-conformances enumerated and a detailed conformance table at /en-301-549-conformance/. Users can review and revoke their own active sessions; each session records when it was last seen so stale devices are identifiable. Scoring review - 2026-06-21 Reviewed across the public site plus the reporter and handler environments, under the 25-criterion rubric (v2_25_criteria). Base score: 47 / 50 in the France, Bulgaria, Greece, and Romania contexts. Country bonuses: France 5 / 8, Bulgaria 6 / 6, Greece 4 / 6, Romania 6 / 6, Spain 5 / 6, Belgium 5 / 6. Category Score Max A. Legal compliance 16 16 B. Reporter experience (BG/FR/GR/RO) 10 10 C. Handler experience 10 10 D. Security 6 8 E. Commercial 5 6 What caps the base score: D19 — ISO 27001 of EthicsPortal itself: only Hetzner infrastructure is certified. A7 — hash-chained audit log: append-only at the database level, but not hash-chained. E24 — free trial: pay-first with 30-day money-back; no upfront self-serve trial. Buyer fit: Bulgaria 53 / 56, France 52 / 58, Greece 51 / 56, Romania 53 / 56. Spain and Belgium each gain from the in-language reporter UI now live. Across markets the remaining deltas are data-residency fit (Germany-only hosting, no per-country region) and the three base-capping gaps above. --- # EticAlert - Website: https://eticalert.com - Headquarters: Madrid, Spain - Hosting: Cloud infrastructure located in the European Union (vendor-stated); provider and specific country not named - Pricing: Starter EUR 9/month or EUR 81/year (up to 20 employees); Business EUR 19/month or EUR 190/year (21-49); Company EUR 39/month or EUR 390/year (50-150); Enterprise custom quote (150+). - Note: 15-day free trial with no credit card required. Monthly or annual billing via Stripe (card or SEPA), month-to-month with cancellation anytime. Annual billing saves roughly two to three months. No per-user fees; each tier includes a fixed number of handler seats (3 to 5). SSO/SAML and REST API are Enterprise-only. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: yes - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Spain (Ley 2/2023) - Last verified: 2026-07-19 - Sources: - https://eticalert.com - https://eticalert.com/funcionalidades - https://eticalert.com/precios - https://eticalert.com/como-funciona - https://eticalert.com/legal - https://eticalert.com/privacidad - https://eticalert.com/dpa Notable Operated by FONCAD GROUP, S.L. (CIF B70713532), registered at C/ Iglesia 12, 28019 Madrid, Spain. Positioned as proprietary self-service software for Spanish SMEs operating an internal reporting channel under Ley 2/2023; it is not a reseller of another platform. Four employee-band tiers: Starter (up to 20), Business (21-49), Company (50-150, marketed as the Ley 2/2023 mandatory band), and Enterprise (150+, custom quote). Published pricing starts at EUR 9/month (Starter), with a 15-day free trial requiring no credit card; billing is monthly or annual via Stripe (card or SEPA), month-to-month with cancellation anytime. No per-user pricing; each tier includes a fixed number of handler seats (3 to 5). REST API and SSO/SAML are limited to the Enterprise tier. Web-based online reporting form only; no phone, in-person, or postal channels are mentioned. Reporters follow up via a tracking code without registering. Statutory workflow features are explicit: automatic 7-day acknowledgment (tied to art. 18), 3-month expiration alerts, append-only audit log, and read traceability. Three case-management roles are documented (admin, coordinator, resolver) with compartmentalized access, plus a feature letting reporters exclude specific handlers. Security posture: AES-256 encryption at rest, TLS 1.2+ in transit, encrypted anonymous messaging, signed attachment URLs (30-minute TTL), and a public SHA-256 hash verification tool. Data is stored on cloud infrastructure in the EU (provider and specific country not named); a dedicated DPA lists sub-processor categories and grants a right to object with 30 days notice. No vendor ISO 27001 or SOC 2 certification is claimed; those reports are referenced only as artifacts EticAlert may provide instead of an on-site audit. No AI features are advertised. --- # FaceUp - Website: https://www.faceup.com - Headquarters: Czech Republic - Pricing: Not published — pricing page now uses quote/contact-sales CTAs instead of the previously embedded EUR/GBP/USD/CZK matrix. - Note: Pricing and security pages expose a 7-day free-trial form with all premium features; terms still describe trial subscriptions only when granted by the provider. - Languages on reporting form: 113 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: yes - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001:2022, SOC 2 - National laws referenced: EU Directive 2019/1937; Germany (HinSchG); California workplace-violence prevention - Last verified: 2026-05-24 - Sources: - https://www.faceup.com/en - https://www.faceup.com/en/whistleblowing-features - https://www.faceup.com/en/whistleblowing/hotline - https://www.faceup.com/en/whistleblowing-companies-pricing - https://www.faceup.com/en/whistleblowing-security - https://www.faceup.com/en/data-processing-addendum - https://www.faceup.com/en/privacy-policy - https://www.faceup.com/en/terms-and-conditions Notable FaceUp’s current pricing page output reviewed no longer exposes the previous EUR employee-band price matrix; visible CTAs are quote/contact-sales and free-trial oriented. Public pages support 3,500+ organizations in 70+ countries, 113 languages, anonymous reporting, two-way chat, case management, investigation workflows, audit traceability, webhooks/API, Zapier/Make, and iOS/Android apps. Pricing/security page forms advertise a 7-day free trial with all premium features. Hotline options are add-ons: automated phone hotline, live hotline, and AI-powered hotline. The security page states ISO 27001:2022, SOC 2, no IP storage, metadata removal, E2EE, SSO, 2FA, penetration testing, and flexible data hosting. The DPA publishes subprocessor details, including AWS regions in California, Ireland/EU, UAE, and Australia, plus OpenAI for the AI-powered hotline with API usage and no training on customer data. Current vendor pages reviewed did not disclose pricing amounts. Terms describe trial subscriptions only when granted by the provider, while the public pricing/security pages also display a 7-day trial form. --- # Falcony - Website: https://www.falcony.io - Headquarters: Finland - Hosting: Amazon Web Services European data centres (vendor-stated) - Pricing: Not published on vendor pages reviewed. FAQ states site-based pricing is available upon request, annual billing only, and credit-card payment is not accepted. Third-party listings cite a starting price around EUR 120/month, unverified on vendor pages. - Note: Annual billing only; no monthly contract option stated. A 30-day free trial is offered, but pricing is quote-on-request rather than a published tier table. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-07-19 - Sources: - https://www.falcony.io/use-cases/whistleblowing - https://www.falcony.io/product/whistleblowing - https://www.falcony.io/faq - https://www.falcony.io/press-releases/falcony-acquires-first-whistle - https://www.falcony.io/press-releases/falcony-joins-wekomply - https://help.falcony.io/en/articles/468631-whistleblowing-links Notable Falcony is a Finnish software company founded in 2012, offering HSEQ, security, ESG, facilities, risk, and GRC reporting suites; whistleblowing is one module within that platform. Falcony is part of the WeKomply group (a portfolio company of Danish private equity firm VIA equity); the WeKomply/Falcony partnership was announced in April 2025. In February 2026, Falcony acquired First Whistle, a Finnish whistleblowing product originally developed by business ethics consultancy Juuriharja Consulting Group Oy in response to the EU Whistleblowing Directive, aimed at organizations with 50 or more employees. The whistleblowing offering provides an anonymous online reporting form via branded open links, case-specific credentials for confidential follow-up, anonymous IDs, and two-way protected dialogue with predefined investigators. Case management includes customisable categories, evidence and attachment collection, linking of related reports, and role-based access rights for notifications. The vendor states data is hosted in Amazon Web Services European data centres, with AES-256 encryption at rest and TLS in transit, and daily/weekly/monthly backups. ISO 27001, PCI DSS, and SOC 2 references in the FAQ describe AWS infrastructure certifications, not a Falcony organizational certification; no vendor-held ISO 27001 was found on public pages reviewed. The FAQ states a 180-day post-contract data retention period, DPAs signed with subprocessors, and assistance with GDPR data subject requests. Pricing is not published as a tier table; the FAQ states site-based pricing on request, annual billing only, and that credit-card payment is not accepted. A starting price around EUR 120/month appears only in third-party listings. A 30-day free trial is offered; only web-based reporting was documented, with no phone or in-person channel found on public pages reviewed. --- # Firmsys - Website: https://firmsys.cz - Headquarters: Brno, Czechia - Hosting: Vendor's own data centre; no personal data transferred outside the EU (vendor-stated) - Pricing: ZAKLAD 590 Kc/month (1 handler); STANDARD 1,190 Kc/month (10 handlers); PRO 2,290 Kc/month (unlimited handlers). 10% discount on annual billing. - Note: Tiers are gated by number of handlers, not by employee count. STANDARD adds IP access restrictions, statistics, and an automated phone line; PRO adds 24/7 support and branding/custom subdomain. Prices shown are monthly. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Czechia (Act No. 171/2023 Coll.) - Last verified: 2026-07-19 - Sources: - https://firmsys.cz/ - https://firmsys.cz/whistleblowing.php - https://firmsys.cz/kontakt.php - https://firmsys.cz/gdpr.php - https://spweb.cz Notable Operated by SPWeb s.r.o., Brno, Czechia (ICO 29264782, registered at the Regional Court in Brno, Section C, Entry 69293). Firmsys is a Czech compliance vendor offering a whistleblowing module and a separate cookie-consent module; this profile covers the whistleblowing product only. The whistleblowing product references EU Directive 2019/1937 and the Czech whistleblower protection law, and targets organizations with 25+ employees, schools, municipalities, and other mandatory entities. Three published tiers: ZAKLAD (590 Kc/month, 1 handler), STANDARD (1,190 Kc/month, 10 handlers, IP restrictions, statistics, automated phone line), and PRO (2,290 Kc/month, unlimited handlers, 24/7 support, branding and custom subdomain). Annual billing carries a 10% discount. Offers web reporting plus an automated telephone line (STANDARD tier and above) with voice-message recording, so it is a multi-channel product. Documented features include anonymous reporting, two-way reporter-handler communication, file attachments, encrypted data and communication, administrator two-factor authentication, internal handler-only notes, automated deadline monitoring with email alerts, and case statistics. The vendor states it runs its own data centre and does not transfer personal data outside the EU; a specific data-centre country and a sub-processor list were not published for the whistleblowing product on pages reviewed. Setup is self-serve: an account can be registered and the service launched within about 5 minutes of payment, with a 14-day data download window after expiry. No free trial was found on public pages reviewed. No ISO 27001 or other security certification was found on public pages reviewed. Reporter-facing language coverage and multilingual support were not specified on public pages reviewed. --- # flustron - Website: https://www.flustron.eu - Headquarters: Vienna, Austria - Hosting: Stated only as ISO 27001-certified infrastructure in Europe. No provider, country or data-centre region is named anywhere on the public pages reviewed, including the page dedicated to European hosting. - Pricing: essentials €19.90/month annual or €21.90 monthly. advanced €24.90/month annual or €27.40 monthly. tailored €34.90/month annual or €38.40 monthly. - Note: The tiers differ only by the number of internal case handlers (2 / 10 / 100), support depth and interface customisation. The vendor states the intent is "kein künstlich abgespecktes Grundsystem" — the entry tier is the full system, not a cut-down one. A test account is offered; its duration is not published. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Austria (HinweisgeberInnenschutzgesetz, HSchG); Germany (HinSchG) - Last verified: 2026-09-21 - Sources: - https://www.flustron.eu/ - https://www.flustron.eu/preise/ - https://www.flustron.eu/impressum/ - https://www.flustron.eu/hosting-serverstandort-europa/ - https://www.flustron.eu/datenschutzerklaerung/ Notable Built and operated by Mauracher IT-Solutions GmbH of Vienna (FN 643230 b, UID ATU81524067). The site’s German-market framing makes flustron read as a German vendor; the imprint places it in Austria, which also explains the parallel HSchG coverage. Pricing is unusual in refusing to gate features. All three tiers carry the full reporting channel, end-to-end protected communication, archiving and GDPR-conformant operation; what scales is the number of internal case handlers (2, 10, 100), personal support and interface customisation. Go-to-market is content-led rather than product-led. The site carries roughly forty guide pages covering the obligation check for SMEs, works-council co-determination, procedural rules for an internal reporting office, anonymity mechanics, supply-chain complaint procedures, public-sector accessibility, and template policies. The one page where the argument turns back on the vendor is hosting. It explains at length why data-protection, IT, procurement and the works council ask about server location first, then answers the question for the reader without answering it for itself: no provider, no country, no region, on that page or in the privacy policy. The only claim anywhere is the homepage line that hosting runs exclusively on ISO 27001-certified infrastructure in Europe. Product documentation is published openly, including settings pages covering password change and backup of the encryption file, and accompanying-text templates written separately for Germany and Austria. Status: not yet scored flustron was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the Austria or Germany ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Fraud Line - Website: https://fraudline.gr/en/ - Headquarters: Greece (Athens) - Hosting: Microsoft Azure, Western Europe (specific country not disclosed) - Pricing: Not published — quote-based. - Note: Vendor operates as a services provider, not only a software supplier — case-handling support is included in the engagement. - Languages on reporting form: 14 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISO 27701, ISO 37002 - National laws referenced: EU Directive 2019/1937; National whistleblower protection laws in countries served (specific law names not disclosed on public pages reviewed) - Last verified: 2026-05-24 - Sources: - https://fraudline.gr/en/ - https://fraudline.gr/bg/ Notable Public pages claim ISO 27001, ISO 27701, and ISO 37002 certifications. ISO 37001 appears on the site as an anti-bribery framework requirement, but a vendor-held ISO 37001 certificate was not found on the public pages reviewed. Public materials document deployments across Germany, France, Austria, Malta, Portugal, Cyprus, Greece, Bulgaria, Romania, Kuwait, and Colombia. Reported scale is roughly 130 legal bodies and 10,000 employees. Services model distinguishes Fraud Line from pure-software peers — the provider supports case handling, not just hosting the reporting channel. Public pages position the product against EU Directive 2019/1937 and national whistleblower laws, but specific national statute names were not found in the pages reviewed. Language menu exposes 14 public site languages. Reporter and handler UI language coverage was not independently tested. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no reporter submission or handler account reviewed). Base score: 16 / 50 in the Bulgaria context. Bulgaria country bonus: 2 / 6. Category Score Max A. Legal compliance 5 16 B. Reporter experience (BG) 4 10 C. Handler experience 2 10 D. Security 5 8 E. Commercial 0 6 Evidence supporting the score: the Bulgarian page documents anonymous reporting, open communication, case management, Microsoft Azure hosting in Western Europe, and ISO 27001 / ISO 27701 / ISO 37002 claims. Unverified from public pages: pricing, trial access, clear handler-workflow disclosure, and explicit citation of the Bulgarian act. --- # GlobalSuite - Website: https://globalsuitesolutions.com/whistleblower-channel - Headquarters: Madrid, Spain - Hosting: Data centres within the European Union, described as three geo-distributed processing centres (vendor-stated) - Pricing: Not published. The whistleblowing channel is offered in Starter, Enterprise, and Plus versions; prices are quote-only via a demo request. - Note: No prices for any version are shown on the public pages reviewed. The three named versions are listed without a feature-by-feature or price comparison. Procurement runs through a demo/contact request. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001 (vendor-stated, company-level), ISO 22301 (vendor-stated, company-level), ISO 20000 (vendor-stated, company-level), ISO 9001 (vendor-stated, company-level), ISO 37001 (vendor-stated, company-level), UNE 19601 (vendor-stated, company-level), ENS (vendor-stated, company-level) - National laws referenced: EU Directive 2019/1937; Spain (Ley 2/2023) - Last verified: 2026-07-19 - Sources: - https://globalsuitesolutions.com/whistleblower-channel - https://www.globalsuitesolutions.com/es/canal-denuncias/ - https://www.globalsuitesolutions.com/es/canal-de-denuncias-ley-de-proteccion-de-informantes-en-espana/ - https://www.globalsuitesolutions.com/company/ - https://www.globalsuitesolutions.com/security-and-trust/ Notable GlobalSuite Solutions is a Madrid-based GRC software vendor that states it has been building GRC software since 2006; the whistleblowing channel is a module within its broader GlobalSuite platform. The whistleblowing channel was publicly launched in a partnership with WTW (Willis Towers Watson) but is developed and operated by GlobalSuite Solutions. The product supports anonymous, encrypted reporting through a simple questionnaire, plus an optional dedicated secure telephone number for oral reports. Case management covers report viewing, file review, manager collaboration, status reports, dashboards, and full traceability of actions taken. Deadline handling includes automatic alerts for receipt, acknowledgement of receipt, and monitoring of legal deadlines, with manager notifications for overdue cases. The channel is presented as fully customisable with corporate logos, colours, and linked policies, and offers native-language selection for reporters. Compliance positioning references Spain’s Ley 2/2023, EU Directive 2019/1937, GDPR (with automatic and manual data anonymisation), and related standards such as ISO 37001 and ISO 37301. The vendor states company-level certifications including ISO/IEC 27001, ISO 22301, ISO 20000, ISO 9001, ISO 37001, UNE 19601, and Spain’s ENS; this is vendor certification, not hosting-provider-only certification. Security pages state TLS 1.2/1.3 in transit, encryption at rest, multi-factor authentication, and data centres located within the European Union across geo-distributed processing centres; the specific EU country was not named. The channel is offered in Starter, Enterprise, and Plus versions, but no prices and no feature-by-feature version comparison were found on the public pages reviewed; procurement runs through a demo request. No sub-processor list, downloadable DPA/DPIA, self-serve trial, or public API documentation was found on the public pages reviewed. --- # GoComply Whistleblowing - Website: https://www.larcier-intersentia.com/nl/gocomply-whistleblowing-pro-9781109261806.html - Headquarters: Belgium - Hosting: Not disclosed on public pages reviewed - Pricing: Three annual-subscription tiers: PRO, PLUS, and EXPERT. Public listings cite one-time setup fees around EUR 500 to EUR 800 excluding VAT; the annual licence fee and the PLUS/EXPERT tiers are quote-based. - Note: Tiers are scoped by organization size and, for advisers, by the number of client files managed. Setup fees and tier scoping differ across public listings reviewed; annual licence pricing is not fully published, and PLUS/EXPERT offers are handled as custom quotes. - Anonymous reporting: no - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Belgium (Act of 28 November 2022) - Last verified: 2026-07-19 - Sources: - https://www.larcier-intersentia.com/nl/gocomply-whistleblowing-pro-9781109261806.html - https://www.larcier-intersentia.com/en - https://www.indicator-larcier.be/nl/gocomply-nl - https://www.gocomply.be/ - https://cdn.larcier-intersentia.com/terms/fr.pdf Notable GoComply Whistleblowing is a Belgian whistleblowing compliance product from legal and tax publisher Larcier-Intersentia (Lefebvre Belgium SA, part of the Lefebvre Group). It is positioned to help organizations set up and operate the mandatory internal reporting channel required under Belgian whistleblowing legislation transposing EU Directive 2019/1937. The product is marketed both to organizations directly and to advisers who set up and manage whistleblowing files for multiple client organizations. Stated target users include companies with 50 or more employees, organizations with annual turnover above EUR 10 million, and public-sector bodies such as municipalities, cities, and OCMW/CPAS. It is sold in three tiers named PRO, PLUS, and EXPERT, scoped by organization size and, for advisers, by the number of client files managed; exact scoping differs across public listings reviewed. Public listings cite a one-time setup fee reported around EUR 500 to EUR 800 excluding VAT plus an annual licence; PLUS and EXPERT are handled as custom quotes. A live online reporting form is served per organization through a public access link (dashboard.gocomply.be), reachable from the publisher’s own footer. The GoComply marketing site now redirects into the Larcier-Intersentia catalogue, and the standalone GoComply Whistleblowing product pages render most detail only after client-side loading. The product interface is offered in Dutch and French, matching the Belgian market; a specific count of reporter-facing languages was not disclosed on public pages reviewed. No ISO 27001 certification, data hosting location, free trial, or public API was found on the public pages reviewed. Larcier-Intersentia publishes general terms including data-processing conditions; a whistleblowing-specific DPA, DPIA, and sub-processor list were not verified on public pages reviewed. --- # GOWhistleblow - Website: https://www.gow.pt - Headquarters: São João da Madeira, Portugal - Pricing: Normal (shared SaaS) EUR 30/month, promo EUR 21/month for new subscriptions through 31/12/2026 (1 user/entity, unlimited employees, 1GB storage); Premium (dedicated SaaS) EUR 80/month, promo EUR 56/month (custom form and workflow, unlimited users, multi-entity, multi-language, 10GB storage); À Medida (custom SaaS) EUR 320/month, promo EUR 224/month (custom dashboard and reports, own domain, mobile app, 20GB storage). All prices exclude VAT. - Note: Monthly figures are billed on 1, 2, or 3-year terms; no month-to-month option found on public pages reviewed. No free trial found. Add-ons include an extra entity at EUR 10/month, an extra user at EUR 10/month (Normal), an extra 5GB at EUR 10/month, and the mobile app at EUR 80/month (Premium). - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Portugal (Lei 93/2021) - Last verified: 2026-07-19 - Sources: - https://www.gow.pt/pt - https://www.gow.pt/pt/canal-de-denuncias - https://www.gow.pt/pt/funcionalidades - https://www.gow.pt/pt/precos - https://www.gow.pt/pt/empresa - https://www.gofox.pt/pt Notable Operated by GoFox - Tecnologias de Informação, a São João da Madeira web and software development firm founded in 2003 and based at SanjoTec; the whistleblowing product is branded GOWhistleblow (Canal de Denúncias). Product pages describe it as compliant with Lei 93/2021, which transposes EU Directive 2019/1937, and reference Directive 2016/680 for GDPR; article-level mapping was not published. The pricing page lists three tiers: Normal (shared SaaS), Premium (dedicated SaaS), and À Medida (custom SaaS), each with a regular and a promotional price for new subscriptions through 31 December 2026. Monthly prices are billed over 1, 2, or 3-year terms; no month-to-month option and no free trial were found on public pages reviewed. Storage scales by tier (1GB Normal, 10GB Premium, 20GB À Medida), with an extra 5GB add-on at EUR 10/month; all prices exclude VAT. Native Android and iOS mobile apps are included on the À Medida tier and offered as an EUR 80/month add-on on Premium. Stated features include anonymous reporting, case management and resolution, customizable intake forms, custom branding, a custom subdomain, multi-entity support, multi-language (Premium and above), two-factor authentication, and manager training. Copy states managers see only necessary occurrence information and no personal reporter data unless the reporter chooses to disclose it. Security disclosures center on AES-256 encryption; no ISO 27001 or other certification was found on public pages reviewed. Hosting is described as external to the customer and able to run on the customer’s own subdomain, but no hosting provider, data center, or data-residency country was disclosed on public pages reviewed. Reporting is via web form and mobile app; no phone, in-person, or postal channel was documented, so this is scored as single-channel. The vendor states 200+ public and private entities as clients; the product markets to the Portuguese single-country market. --- # Heimdal - Website: https://heimdal.io - Headquarters: Stockholm, Sweden - Hosting: Servers within the EU/EEA (vendor-stated); specific country not named - Pricing: Free for non-profit organizations and companies with fewer than 50 employees; EUR 499/year for organizations with 50 or more employees (stated in Swedish as 4,995 SEK/year). - Note: Paid agreement runs annually (12 months) from order confirmation, with termination notice due no later than one month before the 12-month period ends. No monthly billing option documented on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Lag 2021:890) - Last verified: 2026-07-19 - Sources: - https://heimdal.io/en - https://heimdal.io/en/faq Notable Operated by Heimdal Systems AB, based at Kungsgatan 17, Stockholm, Sweden, founded in 2025 and part of the Aglander Nyman AB corporate group, with the technical platform developed together with Flowbic AB. Distinct from the well-known Danish cybersecurity brand Heimdal Security (heimdalsecurity.com); this is a separate whistleblowing SaaS at heimdal.io. Positioned as a low-cost Swedish whistleblowing system, marketed in Swedish as “Sveriges billigaste visselblasarsystem” (Sweden’s cheapest whistleblower system). Free for non-profit organizations and companies with fewer than 50 employees; EUR 499/year (4,995 SEK/year) for organizations with 50 or more employees. Paid plan runs on a 12-month agreement from order confirmation, with termination notice due no later than one month before the period ends; no monthly option was found on public pages reviewed. Reporting is via an online reporting form (implementation described as adding a link from the customer’s website), accessible 24/7 from any device, with support for uploading most file and document types. Anonymous reporting is the core feature: the reporter receives a unique key/link for an encrypted two-way chat, and the vendor states that no IP addresses or metadata are stored and no identity information is logged in the channel. Compliance framing references the Swedish Whistleblower Protection Act (Lag 2021:890), EU Directive 2019/1937, NIS2 obligations, and GDPR; statutory 7-day acknowledgment and 3-month feedback deadlines are stated with on-screen deadlines and reminders. Data is stated to be stored on servers within the EU/EEA and encrypted in transit and at rest, with automatic deletion no later than 2 years after a case is closed; the specific hosting country and any sub-processor list were not disclosed on public pages reviewed. Accessibility is stated to meet WCAG 2.2 AA. No ISO 27001 or other certification, two-factor handler access, role-based access detail, API documentation, DPA/DPIA materials, or a published count of reporting languages were found on public pages reviewed. --- # HinSchG Meldungen - Website: https://hinschg-meldungen.de - Headquarters: Troisdorf, Germany - Hosting: IONOS SE (Germany); vendor states German servers - Pricing: PaaS (self-managed) EUR 24.90/month on annual billing plus a EUR 990 one-time setup fee. Outsourcing (managed) EUR 24.90/month (1-49), EUR 53.90 (50-99), EUR 74.90 (100-249), EUR 89.90 (250-499), EUR 114.90 (500-1,000), all on annual billing; 1,000+ employees and municipalities of 10,000+ residents are quote-only. - Note: Prices are stated as monthly amounts on an annual billing basis. E-learning modules (compliance, data protection, information security, AI) cost EUR 49.90 each and are sold only to existing platform customers. A custom PaaS build is quote-only. A five-year price guarantee is noted for the 1-49 outsourcing tier. No free trial found; a free consultation booking is offered instead. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://hinschg-meldungen.de/ - https://hinschg-meldungen.de/pages/preise - https://hinschg-meldungen.de/pages/impressum - https://hinschg-meldungen.de/pages/datenschutzerklarung Notable Operated by HinSchG Meldungen GbR, a civil partnership based at Poststr. 67, 53840 Troisdorf, Germany, with partners Marco Fütterer, Darius Finocchietti, and René Dreiling; the Impressum shows no VAT ID or commercial-register number. Two delivery models are offered publicly: an outsourcing (managed) model where an external operator runs the platform and processes cases, and a self-managed white-label platform (described as PaaS) where the client handles cases on the vendor’s portal. Targets German organizations of 50-249 and 250+ employees (both now in scope of HinSchG), offers a 1-49 tier optionally, and highlights financial and AML-obligated (GwG) entities and public-law bodies. The reporting channel is offered in written, verbal, and (on request) in-person forms alongside the digital platform; anonymous reporting is supported where technically feasible and is strongly recommended. Positioning claims HinSchG and GDPR (DSGVO) compliance and implementation of EU Directive 2019/1937; the statutory 7-day acknowledgment and 3-month feedback deadlines are referenced. Self-managed platform pricing is EUR 24.90/month on annual billing plus a EUR 990 one-time setup fee including onboarding; features listed include a custom portal, anonymous reporting, multi-language support, encrypted communication, document templates, and file uploads. Outsourcing pricing is tiered by headcount: EUR 24.90 (1-49), EUR 53.90 (50-99), EUR 74.90 (100-249), EUR 89.90 (250-499), and EUR 114.90 (500-1,000) per month on annual billing; 1,000+ employees and municipalities of 10,000+ residents are quote-only. E-learning modules (compliance, data protection, information security, AI) cost EUR 49.90 each and are sold only to existing platform customers; a custom PaaS build is quote-only. The privacy policy names IONOS SE (Montabaur, Germany) as the hosting provider and references a data-processing agreement (AVV); the vendor states German servers. No ISO 27001 or other security certification, no two-factor reporter access, no configurable retention with automatic deletion, and no free trial were found on the public pages reviewed. --- # Hintbird - Website: https://hintbird.de - Headquarters: Stutensee, Germany - Hosting: ISO-certified servers claimed for the hoster, not a vendor certification; specific provider and country not disclosed on public pages reviewed - Pricing: Essential EUR 49/month (up to 3 user accounts, up to 50 employees); Advanced EUR 99/month (up to 10 user accounts, up to 250 employees); Enterprise EUR 249/month (up to 50 user accounts, 250+ employees, dedicated tenant). All prices exclude VAT. - Note: A 5% discount is stated for annual billing. Prices are quoted per organization, not per employee. No free trial or setup fee was found on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (Hinweisgeberschutzgesetz, HinSchG) - Last verified: 2026-07-19 - Sources: - https://hintbird.de/ - https://hintbird.de/funktionen/ - https://hintbird.de/preise/ - https://hintbird.de/datenschutz/ - https://hintbird.de/impressum/ - https://hintbird.de/hinweisgeberplattform Notable Operated by VELIT Consulting GmbH & Co. KG of Stutensee, Germany (USt-IdNr DE318795398; HRA 708184, Registergericht Mannheim); managing direction via W & W Verwaltungsgesellschaft mbH (Dr. Karl-J. Wack and Christian Wack). Distinct vendor from the similarly named Hintbox and Hintcatcher tools. Marketed as a DSGVO-compliant Hinweisgeberschutz solution for organizations subject to the German Hinweisgeberschutzgesetz (HinSchG), the German transposition of EU Directive 2019/1937. Three published tiers, all priced per organization and excluding VAT: Essential EUR 49/month (up to 3 user accounts, up to 50 employees), Advanced EUR 99/month (up to 10 user accounts, up to 250 employees), and Enterprise EUR 249/month (up to 50 user accounts, 250+ employees, with a dedicated tenant). A 5% discount is stated for annual billing. Features page states anonymous reporting, an anonymous mailbox for two-way protected communication, case management with status and deadline tracking, role-based review and read rights, online and telephone reporting, secure file upload, and clear categories for structured intake. Security copy states SSL/TLS encrypted transmission and DSGVO-compliant storage; the “ISO-certified servers” claim refers to the hosting infrastructure, not a vendor ISO 27001 certificate. No hosting provider or data-center country, subprocessor list, 2FA, public API, retention/deletion policy, reporting-language count, or free trial was found on the public pages reviewed. Summary: Hintbird is a German-domestic Hinweisgebersystem from VELIT Consulting GmbH & Co. KG with fully published per-organization pricing (EUR 49/99/249 per month) and the core HinSchG feature set of anonymous reporting, a two-way anonymous mailbox, and deadline-tracked case management. Scored tier P (public pages only) at 24/50, held back by undisclosed hosting location, no vendor ISO 27001 (only an “ISO-certified servers” hoster claim), and no disclosed 2FA, API, retention policy, or reporting-language coverage. Verified genuine and distinct from the similarly named Hintbox and Hintcatcher; last verified 2026-07-19. --- # Hintbox - Website: https://www.hintbox.de - Headquarters: Germany - Hosting: Germany; Hetzner-hosted ISO/IEC 27001-certified data centre (vendor-stated) - Pricing: Basic from EUR 49/month; Premium from EUR 69/month. Annual billing shown as EUR 588 / EUR 828. - Note: Free trial available. Prices exclude 19% VAT. Public pricing says prices are independent of employee count and number of agents; phone bot and email intake are optional add-ons. - Languages on reporting form: 30 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Germany (HinSchG); Austria - Last verified: 2026-05-24 - Sources: - https://www.hintbox.de/ - https://www.hintbox.de/preise/ - https://www.hintbox.de/hinweisgebersystem-datenschutz/ Notable Two product tiers: Basic and Premium; public pricing starts at EUR 49/month and EUR 69/month respectively. The pricing page reviewed says employee count and number of agents do not affect the monthly price. Reporting form available in 30 languages; AI-based translation between handler and reporter. End-to-end encryption; 2FA; isolated per-customer database (no shared multi-tenant DB). Automatic virus scanning and metadata removal from uploads. Multi-client capability for group companies operating multiple entities. Optional add-ons: phone bot intake, email intake, custom domain, onboarding, and training. Premium tier adds dynamic no-code forms, live chat for caseworkers, and granular external-editor permissions. Hosted by Hetzner in a German ISO-certified data centre, according to vendor copy reviewed. No public API documentation or subprocessor list was found on the public pages reviewed. --- # hintcatcher - Website: https://www.hintcatcher.com - Headquarters: Göppingen, Germany - Hosting: Germany; ISO 27001-certified hoster (hoster not named by vendor) - Pricing: LITE €39, PLUS €59, PREMIUM €99 per month (net of VAT). PARTNER multi-tenant tier quote-based. - Note: Free test/demo advertised; the trial runs 3 weeks (vendor-stated), a length the public pages do not state. 1-month contract with 14-day notice period. No setup fee. Monthly billing. Pricing is flat — not tied to employee count. - Languages on reporting form: 27 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Germany (HinSchG); EU Directive 2019/1937 - Last verified: 2026-09-19 - Sources: - https://www.hintcatcher.com/en/ - https://www.hintcatcher.com/en/#sectionpricing - https://www.hintcatcher.com/en/imprint/ Notable Operated by product kitchen GmbH (Göppingen, Baden-Württemberg). Flat pricing is independent of employee count. Four tiers: LITE, PLUS, PREMIUM (self-serve monthly) and PARTNER (multi-tenant reseller solution, quote only). End-to-end encryption; reports accessible only to the whistleblower and selected caseworkers. Anonymous two-way dialogue between whistleblower and caseworker. Case management with audit-proof audit log; monitoring of legal deadlines and email notifications. Corporate design and custom texts on the reporting office; custom domain available on request (optional / add-on). Oral hint reporting by voice recording is marked optional on every tier. Partner programme for law firms, external data protection officers, and ombudspersons. Hosted on servers in Germany at an ISO 27001-certified hoster; hoster not named in public materials. Reporting form available in 27 languages, listed by name on the pricing page; 22 of the 24 official EU languages are covered, Irish and Maltese are not. No public API, SSO, or subprocessor list was found on public pages reviewed. --- # hinweis.de - Website: https://hinweis.de - Headquarters: Kiel, Germany - Hosting: Hetzner Online GmbH data centres in Germany (vendor-stated) - Pricing: Basis EUR 38/month per mandant (up to 5 users); Plus EUR 98/month per mandant (unlimited users, phone channel and handler training included); Meldestelle S/M/L from EUR 168/month (outsourced reporting office with in-house legal review). Prices exclude VAT. - Note: Prices are quoted per month but billed annually with a minimum 12-month commitment. Optional phone reporting channel costs EUR 20/month extra on Basis. Meldestelle tiers include 1/3/6 annual hours, then EUR 140/hour. 20% discount for non-profit and education, and a 20% first-year switch bonus. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://hinweis.de/ - https://hinweis.de/preise/ - https://hinweis.de/datenschutz/ Notable Operated by digitalNORD GmbH in cooperation with KIEL-IT GmbH, based in Kiel, Germany. Positioned as a HinSchG-compliant internal reporting office (Section 12 HinSchG) for organizations with 50+ employees, with mandatory handler training offered under Section 15 HinSchG. Supports anonymous, chat-style two-way communication between the reporter and the internal reporting office, plus written and oral reporting. Multi-channel intake is offered: online report form, optional phone channel, post, secure email, and a GDPR-compliant video conference option. Handler-side features include audit-secure (revisionssicher) case documentation, deadline tracking with compliance reminders, role-based access, and selective attorney case visibility. Security copy states end-to-end encryption, AES-256-CBC at rest, TLS in transit, two-factor authentication for reporting-office officers, and regular OWASP penetration testing by Breaking-Labs GmbH. Data processing is stated to take place in a German data centre operated by Hetzner Online GmbH; the ISO/IEC 27001 certificate offered for download belongs to Hetzner, not to the vendor. Each organization gets a personalized subdomain in the form yourfirm.hinweis.de. Published packages are Basis (EUR 38/month, up to 5 users), Plus (EUR 98/month, unlimited users), and Meldestelle S/M/L (from EUR 168/month) with an outsourced reporting office and in-house legal review. Prices are quoted per month but billed annually with a minimum 12-month commitment; a 20% discount is offered for non-profits and education, and a 20% first-year switch bonus for customers migrating from competitors. No free trial or public API documentation was found on the pages reviewed; procurement runs through a consultation booking or demo request. --- # HiTrust - Website: https://hitrust.nl - Headquarters: Breda, Netherlands - Hosting: Not disclosed on public pages reviewed - Pricing: Standard EUR 45/month (scales with employee count); Plus EUR 75/month (adds external confidant); implementation support EUR 495 one-time. - Note: Two-month free trial with cancellation during the trial. Vendor states a reporting channel can be set up in about five minutes. Implementation package covers the internal procedure and a communication kit. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Netherlands (Wet bescherming klokkenluiders) - Last verified: 2026-07-19 - Sources: - https://hitrust.nl/ - https://hitrust.nl/meldkanaal-klokkenluiders/ - https://hitrust.nl/veelgestelde-vragen/ - https://hitrust.nl/wet-bescherming-klokkenluiders-wbk/ - https://hitrust.nl/over-hitrust/ - https://hitrust.nl/vertrouwenspersoon/ Notable HiTrust is a Dutch provider based in Breda that sells an external whistleblowing channel (meldkanaal) for the Wet bescherming klokkenluiders (Wbk), the Netherlands transposition of EU Directive 2019/1937. The product is aimed at SMEs and organizations with 50 or more employees, the threshold at which a reporting procedure became mandatory in the Netherlands from 17 December 2023. Reporters can submit anonymously or with their identity disclosed; access to reports is restricted to authorized confidants (vertrouwenspersonen). Two subscription tiers are published: Standard at EUR 45/month (scaling with employee count) and Plus at EUR 75/month, which adds an external confidant service; a one-time EUR 495 implementation fee covers the internal procedure and a communication kit. A two-month free trial is offered with cancellation during the trial, and the vendor states a channel can be set up in about five minutes. Security is described as encryption in transit and at rest, firewalls, intrusion detection, 2FA, and strict access controls, with no IP addresses or identifying data logged to preserve anonymity. Public content maps the statutory 7-day acknowledgement and 3-month feedback deadlines and outlines a multi-step handling process. No ISO 27001 certification was found on public pages reviewed; the platform is described as GDPR (AVG) compliant. Hosting location, specific EU data residency, a sub-processor list, API access, and reporter-facing languages beyond Dutch were not documented on public pages reviewed. HiTrust also runs a one-day confidant training (Stoomcursus vertrouwenspersoon) and works with the legal firm RIDE; it is unrelated to the US HITRUST security-certification body. --- # iBlow - Website: https://iblow.eu - Headquarters: Lisbon, Portugal - Hosting: Not disclosed on public pages reviewed; current privacy policy does not name a hosting provider - Pricing: Not published — all four tiers (Base, Value, Elite, Premium) quote-based. Tiers scale by collaborator count: 0–249, 250–499, 500–999, 1,000+. - Note: No free trial advertised. Premium tier priced on request. - Languages on reporting form: 4 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Portugal (Law 93/2021); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://iblow.eu/ - https://iblow.eu/features-packages/ - https://iblow.eu/services/ - https://iblow.eu/about/ - https://iblow.eu/faq/ - https://iblow.eu/privacy-policy/ - https://iblow.eu/terms-and-conditions/ Notable Operated by Contemporary Constellation Lda from Rua Mouzinho da Silveira, 32, 1250-167 Lisboa, Portugal. Phone +351 210 987 308. Entire product positioning anchored on Portuguese Law 93/2021; the site publishes a nine-point summary of the law. Four packages — Base, Value, Elite, Premium — differentiated primarily by: channels per customer (1 / 3 / 10 / request), team-manager seats (3 / 10 / 45 / request), support hours (1h / 4h / 6h / request), and collaborator band (0-249 / 250-499 / 500-999 / 1,000+). Communication languages capped at 4 across every tier. The FAQ says reports can be submitted in writing and/or verbally, with a face-to-face meeting if requested by the whistleblower. The package matrix includes SSO and 2FA-required rows, but public text extraction did not reliably show which tiers include each row. No published prices, hosting location, founding year, DPA, sub-processor list, or certificate documents were found on public pages reviewed. Complementary services mentioned: policies, screening, investigation, GDPR/DPIA work, RGPC/corruption-prevention support, training, and legal/HR guidance. Fills a geographic gap in vendor coverage: no other Portugal-specific whistleblowing tool is currently listed. Current privacy policy is dated 24 April 2026 and names Contemporary Constellation Lda as controller; hosting/subprocessors are not disclosed on public pages reviewed. --- # Ilmoituskanava - Website: https://ilmoituskanava.fi - Headquarters: Helsinki, Finland - Pricing: Setup fee EUR 300 (Chamber members) or EUR 500 (non-members). Monthly fee by employee band: up to 249 employees EUR 165 (member) / EUR 195 (standard); 250-1,000 employees EUR 315 / EUR 375; over 1,000 employees EUR 515 / EUR 615. All figures plus 25.5% VAT. - Note: Billing runs in 3, 6, or 12 month cycles, so the shortest commitment is three months rather than true month-to-month. Custom quotes are offered for multi-company groups. No free trial is advertised; procurement runs through a booked introduction/demo. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Finland (laki 1171/2022) - Last verified: 2026-07-19 - Sources: - https://ilmoituskanava.fi/ - https://ilmoituskanava.fi/en/frontpage-english/ - https://ilmoituskanava.fi/en/features/ - https://ilmoituskanava.fi/en/service-prices/ - https://ilmoituskanava.fi/en/why-set-up-a-notification-channel/ - https://ilmoituskanava.fi/en/terms-of-service/ - https://ilmoituskanava.fi/tietoturva/ - https://ilmoituskanava.fi/ilmoittajansuojelulaki/ Notable Operated by Keskuskauppakamarin Palvelu Oy, the service company of the Finland Chamber of Commerce (Keskuskauppakamari), Helsinki, Finnish VAT FI04277971. Positioned as an EU-Directive-compliant whistleblowing channel for organizations, noting the Finnish obligation for entities with at least 50 employees. The Finnish transposition law is named as laki 1171/2022; the law page lists 13 regulated report areas but cites no article or section numbers. Documented reporter features include fully anonymous reporting and two-way confidential communication without revealing either party’s identity. The channel can host one or more notification forms so reports on different topics can be routed to different handlers. Pricing is fully published: a one-off setup fee of EUR 300 (Chamber members) or EUR 500 (non-members), plus a monthly fee tiered by employee count, all plus 25.5% VAT. Billing runs in 3, 6, or 12 month cycles, so the minimum commitment is three months; no free trial or self-serve signup is advertised, and onboarding runs through a booked introduction/demo. The security page references regular external security testing with good results and a least-privilege access design; no ISO 27001 or other certification was found on public pages reviewed. Hosting location, data residency, and a subprocessor list were not disclosed on public pages reviewed, though a DPA and privacy statement are referenced. The public site is available in Finnish, Swedish, and English; no API access was documented on public pages reviewed. No indication on public pages that the product is a white-label of another listed vendor; it is sold as a distinct branded service by the Chamber of Commerce. --- # IntegrityCounts - Website: https://www.whistleblowersecurity.com - Headquarters: West Vancouver, British Columbia, Canada - Hosting: Canada. Two Microsoft Azure data centres in Canada, geo-replicated to the second Canadian region (vendor-stated). No EU region is offered on public pages reviewed. - Pricing: Not published. No pricing page exists on the vendor site; the hotline comparison page states only "Our all-inclusive service has everything you need at a price you can afford." Procurement runs through Request a Demo and Contact Us. - Note: No tier matrix, employee band, per-report price, or contract term is published. The implementation page describes a 4-to-6 week setup with data migration and training, which is a sales-and-onboarding motion rather than a self-serve one. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001:2013 (BSI certificate IS 777646, expiry date 2025-10-31) - National laws referenced: EU Directive 2019/1937; Canada (Bill 198 / Multilateral Instrument 52-110); Canada (BC PIDA); United States (Sarbanes-Oxley); Australia (Corporations Act 2001) - Last verified: 2026-09-21 - Sources: - https://www.whistleblowersecurity.com/ - https://www.whistleblowersecurity.com/trust-center - https://www.whistleblowersecurity.com/about/certifications - https://www.whistleblowersecurity.com/about/company-and-team - https://www.whistleblowersecurity.com/services/web-intake - https://www.whistleblowersecurity.com/services/web-intake/features - https://www.whistleblowersecurity.com/services/case-management/features - https://www.whistleblowersecurity.com/services/global-ethics-hotline - https://www.whistleblowersecurity.com/resources/regulatory-compliance - https://www.whistleblowersecurity.com/resources/faq - https://www.whistleblowersecurity.com/resources/implementation - https://www.whistleblowersecurity.com/whistleblower-hotline-providers - https://www.whistleblowersecurity.com/press/case-iq-strengthens-position-as-a-leader-in-governance-risk-and-compliance-with-the-acquisition-of-whistleblower-security - https://www.whistleblowersecurity.com/fr/resources/regulatory-compliance Notable IntegrityCounts is the ethics-hotline and case-management product of WhistleBlower Security Inc., West Vancouver, British Columbia. Case IQ (formerly i-Sight, Ottawa) acquired the company on 19 October 2023; Case IQ is owned by Resurgens Technology Partners. The company page places the product inside a wider programme: IntegrityCounts “is part of an integrated compliance suite that offers you end-to-end compliance and risk management services that unifies real-time compliance monitoring, whistleblower solutions, third-party risk management, approvals and disclosures, and investigative workflows.” The acquisition release sets out how the two products divide: Case IQ’s own case management “offers higher configurability and focuses on the needs of the investigator”, while IntegrityCounts “focuses on the needs of the incident reporter”. The same release says the pair between them “can cater to the unique needs of enterprise and SMBs, with tremendous value at different price points” — neither of which is published. Telephone intake is the distinguishing channel. A live agent walks the reporter through a questionnaire, transcribes the case, reads it back for confirmation, and submits it. Agents directly support English, French and Spanish; 150 further languages come through an interpretation partner. Reporters have four routes: the web form, the toll-free hotline, a per-client email address, and postal mail to a West Vancouver PO box. Three anonymity levels are published, and they are genuinely distinct: strictly anonymous, anonymous to the organisation but known to the vendor, and identified to both. Handler tooling is the most fully documented part of the product. Named roles, multi-investigator assignment, automatic case routing, restricted managers, per-case activity logs, internal messages with attachments, a task manager with due dates, an analytics dashboard, and scheduled automated reports are all described on public pages. Report data is held in Canada across two Azure regions. No EU region is offered. The GDPR position is stated as compliance “by adequacy status” — the Canadian adequacy decision, which covers recipients subject to PIPEDA. Nothing is published on retention or deletion. The only legal document on the site is a one-page Terms of Service covering the reporter’s confidentiality, not the controller’s obligations. Commercial disclosure is nil: no price, no band, no contract term, no trial. Implementation is quoted at 4 to 6 weeks. Vendor-page evidence - 2026-09-21 The certifications page publishes the ISO 27001 certificate as a PDF rather than describing it. The certificate is BSI IS 777646, against ISO/IEC 27001:2013, original registration 11 January 2023, expiry date 31 October 2025. Its scope names the IntegrityCounts platform. That date is not an ordinary lapse: 31 October 2025 was the end of the transition period from the 2013 edition of the standard to the 2022 edition, so every 2013-edition certificate expired then. What is published is therefore a certificate that has run out with nothing published in its place — no 2022-edition certificate, and no in-date certificate of any edition, was found on pages reviewed. The same page notes that Microsoft Azure is “covered by SOC 2 TYPE II, ISO27000 Series, and CSAE 3416”. Those are the hosting provider’s attestations, so they are not recorded as vendor certifications. The trust centre names Canada as the storage location twice, and describes two Canadian Azure data centres with geo-replication between them. Encryption is TLS 1.2 in transit and Transparent Data Encryption at rest, with attachments in encrypted Azure blob storage. The EU Directive section of the regulatory-compliance page still describes transposition in the future tense. It states that “Each of the 27 EU member states will need to transcribe the directives into their own national law” and that “Companies with over 250 employees will need to ensure they are compliant with the new regulations by the end of the year” — both of which describe the position before the December 2021 transposition deadline. Reading the French locale changed nothing about law coverage. The French regulatory page is a real translation, not English text on a /fr URL, and it names the same laws as the English one: RGPD, Sarbanes-Oxley, Bill 198, BC PIDA. Neither Loi Waserman nor Sapin II appears on either locale. The reporter FAQ lists supported browsers as “Internet Explorer 11 Google Chrome Microsoft Edge Firefox Safari Opera”. IE11 was retired in June 2022. whistleblowersecurity.com publishes SPF but no DNSSEC and no CAA record, and its DMARC policy is p=none — monitoring without enforcement, on the domain that sends reporters their case notifications. integritycounts.ca, the reporter entry point, is the same on all four. The reporter entry point at www.integritycounts.ca answers 200 over HTTPS with HSTS, a content-security policy, X-Frame-Options, X-Content-Type-Options and a permissions policy set. It is a single-page application requiring client-specific access, so no report was filed and no intake fields were inspected. No API documentation, sub-processor list, DPA, DPIA material, retention statement, or price was found on public pages reviewed. Scoring review - 2026-09-21 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no trial exists and the reporter entry point requires client-specific access). Base score: 24 / 50. France country bonus: 1 / 8. Category Score Max A. Legal compliance 5 16 B. Reporter experience 7 10 C. Handler experience 9 10 D. Security 3 8 E. Commercial 0 6 What lifts the score: handler tooling, at 9 of 10, is among the highest handler scores in the directory, and it is earned rather than inferred — the feature pages name the roles, the routing behaviour, the internal-notes surface and the case states explicitly. Reporter intake is strong on channel breadth: four routes including a live-answer hotline, three published anonymity levels, and messaging that survives anonymity. What caps it: the two categories a European buyer weighs most heavily. Legal compliance scores 5 of 16 because the product is documented against Canadian, US and Australian law, with the EU Directive named only generically and no national transposition law named on either locale — including the French one. Security scores 3 of 8 because data residency is Canadian with no EU option, the only published ISO 27001 certificate expired at the close of the 2013-edition transition period with no replacement published, and no sub-processor list or DPA is published. Commercial disclosure scores 0. The shape of the product, not a defect in it: what the scores describe is an enterprise ethics-hotline programme — multilingual live-answer intake across 106 countries, investigator-grade case tooling, a 4-to-6 week implementation with training, sold by demo and quoted on request, inside a suite that also carries third-party risk management and approvals and disclosures. That is a coherent product with a coherent buyer. It is a poor fit for an organisation whose obligation is a single EU internal reporting channel receiving a handful of reports a year, which will pay for the hotline capacity, the implementation project and the suite regardless of volume, and will still need to establish its own EU legal and residency position because the vendor’s pages do not. Buyer fit: multinationals with real report volume, a preference for telephone intake, and a compliance function able to accept Canadian residency under the adequacy decision and to write its own DPA. Organisations that need EU hosting, a named transposition law, published retention, a current ISO 27001 certificate, or a price before a sales conversation will not find them here. --- # IntegrityLog - Website: https://www.corporatesolutions.euronext.com/products/integritylog - Headquarters: Sweden - Hosting: Client data stored in the EEA; 2025 ComplyLog privacy factsheet references isolated AWS accounts and ISO/IEC 27001-certified infrastructure. - Pricing: Not published publicly; demo-led procurement. - Note: Production pricing is quote-led; current product page uses schedule-demo/contact CTAs and no public self-serve trial was found. - Languages on reporting form: 6 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: EU Directive 2019/1937; GDPR - Last verified: 2026-05-24 - Sources: - https://www.corporatesolutions.euronext.com/products/integritylog - https://www.corporatesolutions.euronext.com/hubfs/1.%20Euronext%20Corporate%20Solutions/Privacy%20Policy/ComplyLog_Factsheet_EN_2025.pdf Notable Sold inside the broader ComplyLog suite rather than as a whistleblowing-only product. Current public product surface is Euronext Corporate Solutions, not the older standalone ComplyLog URL. The 2025 ComplyLog privacy factsheet materially improves public trust evidence: EEA storage, ISO/IEC 27001, encryption, access logging, DPA, DPO contact, retention/deletion, and sub-processor controls are disclosed. Product language footprint is regional rather than pan-EU. Public product copy frames the tool around EU Whistleblowing Directive compliance rather than France-specific Waserman / Sapin II positioning. Vendor-page evidence - 2026-05-24 Current product page is on corporatesolutions.euronext.com/products/integritylog and describes IntegrityLog as secure whistleblowing software within Euronext Corporate Solutions. The 2025 ComplyLog privacy factsheet states that ComplyLog supports the EU Whistleblowing Directive, includes IntegrityLog for secure anonymous case handling, is ISO/IEC 27001 certified, stores client data in the EEA, and uses encryption in transit and at rest. No public self-serve trial entry or public production pricing was found in this pass; the current visible path is demo/contact-led. No France-specific Waserman or Sapin II product positioning was found on the public pages reviewed. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages and public factsheet only; no authenticated handler or reporter environment was reviewed). Base score: 33 / 50. France country bonus: 2 / 8. Category Score Max A. Legal compliance 12 16 B. Reporter experience 7 10 C. Handler experience 7 10 D. Security 7 8 E. Commercial 0 6 Evidence supporting the score: the 2025 ComplyLog privacy factsheet adds EEA storage, ISO/IEC 27001, encryption, access logging, DPA, DPO, retention/deletion, and sub-processor-process evidence. Unverified from public pages: reporter return-access mechanism, France-specific Waserman / Sapin II narrative, pricing, and public self-serve trial. Buyer fit: buyers who care more about a documented product and privacy surface than about France-law-native branding. Organisations that require explicit local-law posture or published pricing will need vendor confirmation. --- # Interaktiv Säkerhet - Website: https://www.interaktivsakerhet.se - Headquarters: Varberg, Sweden - Hosting: Sensitive whistleblowing data stated to be stored in Sweden (vendor-stated); reporting platform operated on Whistlelink - Pricing: Three fixed monthly tiers: Nivå 1 1,500 SEK/month, Nivå 2 2,500 SEK/month, Nivå 3 4,800 SEK/month. Each package includes 10 users and 10 languages. - Note: Prices published in SEK only; no EUR pricing or annual-billing terms shown. Nivå 1 is the reporting-channel platform; Nivå 2 adds external independent case reception and 24/7 phone availability with per-case advice at a fixed monthly cost regardless of volume; Nivå 3 adds independent investigation, expert participation in meetings, and evidence documentation. No free trial or self-serve signup found on public pages reviewed. - Languages on reporting form: 50 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Lag 2021:890) - Last verified: 2026-07-19 - Sources: - https://www.interaktivsakerhet.se/ - https://www.interaktivsakerhet.se/visselblasartjanst/ - https://www.interaktivsakerhet.se/visselblasartjanst-produkt/ - https://www.interaktivsakerhet.se/visselblasartjanst-pris/ - https://www.interaktivsakerhet.se/visselblasarlagen-eus-visselblasardirektiv/ - https://www.interaktivsakerhet.se/om-oss/ - https://clients.whistlelink.com/login/ Notable Interaktiv Säkerhet is a wholly owned subsidiary of Schottenius Partners AB (Sweden), based in Varberg; it has run content moderation since 2006 and whistleblowing services since 2012. The whistleblowing offering is a managed service delivered on the Whistlelink platform (client portal at clients.whistlelink.com); Interaktiv Säkerhet operates and, at higher tiers, staffs the service rather than developing the software. Three fixed monthly packages are published: Nivå 1 at 1,500 SEK, Nivå 2 at 2,500 SEK, and Nivå 3 at 4,800 SEK, each including 10 users and 10 languages. Nivå 1 provides the reporting-channel platform and external reporting site, encryption, an anonymous two-way communication module, policy templates, and launch materials. Nivå 2 adds external, independent case reception with 24/7 availability by system or phone and per-case advice, at a fixed monthly cost regardless of case volume. Nivå 3 adds independent investigation, participation by experts in meetings, and evidence documentation and reporting. The service states that sensitive whistleblowing data is stored in Sweden, going beyond the EU-wide hosting minimum, and claims GDPR compliance. A dedicated law page references the Swedish whistleblower law (Lag 2021:890) and EU Directive 2019/1937 and explains the one-week acknowledgment and three-month feedback deadlines, without article-level citation. The reporting website is stated to publish in about ten minutes and to be available in 50+ languages on the platform; live statistics and monthly/annual PDF exports are described. No ISO 27001 or other certification for Interaktiv Säkerhet was found on public pages reviewed; the underlying Whistlelink platform is separately ISO 27001 certified per Whistlelink’s own materials. No free trial, self-serve signup, API documentation, or sub-processor list was found on Interaktiv Säkerhet’s public pages reviewed. --- # ISWEB - Website: https://www.isweb.it - Headquarters: Italy (Avezzano + Roma) - Pricing: Private-sector pricing published: Small €40/month (€480/year), Medium €52/month (€624/year), Large €80/month (€960/year), each with a €160 activation cost. Public-administration procurement is sales/Cloud Marketplace led. - Note: The private-sector page lists Small and Medium as 'fino a 100 dipendenti' and Large as up to 250 employees; verify tier definitions before procurement. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ACN cloud-service qualification - National laws referenced: Italy (D.Lgs 24/2023); Italy (D.Lgs 231/2001 — Modello 231); Italy (ANAC guidelines); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.isweb.it/softwarewhistleblowing - https://www.isweb.it/archivio50_prodotti_0_16.html - https://www.isweb.it/pagina76_pawhistleblowing.html Notable ISWEB splits the offer into PAWhistleblowing for public administrations and a private-sector Whistleblowing page with published monthly pricing. The private-sector page publishes tiers at €40, €52, and €80/month plus a €160 activation cost, with the caveat that the Small and Medium headcount descriptions both read “up to 100 employees” on the reviewed page. The public-administration page says PAWhistleblowing is SaaS delivered through an ACN-qualified cloud provider and available through the Cloud Marketplace; this was treated as vendor-published evidence, not an independently verified ACN catalogue check. The vendor states the solution is based on GlobaLeaks and supports anonymous reporting, anonymous chat with the reporter, alerts, report registers, statistics, Excel exports, 2FA in the management area, and encrypted data. The private-sector page states that data are located in Italy in ACN-qualified data centers. Public pages reviewed did not disclose a public API, a free trial, DPA/subprocessor terms, or multi-country language coverage beyond the Italian product surface. --- # ithikios - Website: https://ithikios.com - Headquarters: Spain - Hosting: Germany (vendor security page) - Pricing: Whistleblowing channel: Basic €29/mo for up to 50 employees; Premium €49/mo for up to 500 employees; Business quote-based. Compliance all-in-one Grow from €99/mo; Enterprise quote-based. - Note: Prices exclude VAT and may vary by company size. Free-start CTA is public; privacy policy describes a 15-day free trial account. - Languages on reporting form: 7 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Spain (Ley 2/2023); ISO 37301 compliance alignment - Last verified: 2026-05-24 - Sources: - https://ithikios.com/ - https://ithikios.com/precios/ - https://ithikios.com/seguridad-de-ithikios/ - https://trust.ithikios.com/home - https://ithikios.com/politica-privacidad/ - https://ithikios.com/condiciones-generales/ Notable Whistleblowing is one module of a broader modular compliance suite: Incident Manager (DORA, GDPR, NIS2), Rights Manager (consent), Policy Manager, Third Party Manager, Trust Center. Interface languages: Spanish, English, French, German, Italian, Portuguese, Catalan. Security page states SSL 256, ISO 27001 certification since December 2021, hosting on servers in Germany, WAF protection, and optional two-factor authentication. Anonymous and confidential reporting modes; teams/roles defined per risk category; case management with consolidated documentation. Cloud SaaS deployment — no customer infrastructure required. Configurable without programming: colours, logo, messages, custom fields, multi-company, multiple integrated channels. Target customers include lawyers, consultants, and advisors through an affiliate partner program. Set-up and compliance achievable in hours (vendor-stated). Trust Center publishes a browser-verified subprocessor list: Cloudflare, DigitalOcean, and Pipedrive. Some Trust Center documents require corporate-email registration, and curl access to ithikios.com / trust.ithikios.com returned 403 during this pass. AI use in the whistleblowing channel is left undisclosed: public suite-level copy mentions AI, but the reviewed whistleblowing, pricing, security, privacy, terms, and Trust Center pages did not document AI for the channel. No public API documentation was found on the public pages reviewed. --- # Lantero - Website: https://lantero.se - Headquarters: Stockholm, Sweden - Hosting: GleSYS data centres in Falkenberg and Stockholm, Sweden (vendor-stated) - Pricing: Not published. Sold by tender and by license subscription; buyers request a quote. - Note: No public tiers, no self-serve signup, and no free trial were found on public pages reviewed. The license subscription is described as including assistance with alert evaluation. - Languages on reporting form: 4 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II); France (Loi Waserman / Loi 2022-401) - Last verified: 2026-07-19 - Sources: - https://lantero.se - https://lantero.se/visselblasning - https://lantero.se/about - https://objects.dc-sto1.glesys.net/falling-mountain/Privacy_Policy_April_2024.pdf - https://lantero-france.fr Notable Operated by Lantero AB, Drottninggatan 71c, Stockholm, Sweden, founded in 2014 and owned by three Swedish shareholders. Positions the whistleblowing channel as an externally hosted, independent service that reinforces trust in anonymity for reporters. Buyers can either handle reports themselves on the platform or have Lantero run investigations, with access to independent lawyers for case assessment. Public client references span Swedish municipalities, authorities, and companies (examples named include Attendo, Cancerfonden, Finansinspektionen, Trafikverket, and Region Norrbotten). Privacy policy states data is stored in secure, encrypted databases on GleSYS servers in Falkenberg and Stockholm, Sweden, and only while a case is active. GleSYS, the hosting provider, holds ISO 27001; Lantero itself is not stated to hold ISO 27001 on public pages reviewed. Reporter languages stated are French, Swedish, Danish, and English. A separate French entity, SAS Ethique et Conformite (trading as Lantero-France, La Valette du Var), offers the same platform and references Loi Sapin II, Loi Waserman, and Loi 2022-401. Pricing is not published; the product is sold by tender and by license subscription that includes assistance with alert evaluation. No self-serve signup, free trial, API documentation, or subprocessor list was found on public pages reviewed. --- # Legality Whistleblowing (DigitalPA) - Website: https://www.whistleblowing.software - Headquarters: Cagliari, Italy (offices in Milan, Rome, Sulmona, and Barcelona) - Pricing: Annual billing excluding VAT. Standard: from €29/month for <50 employees; Premium: from €41/month for <50 employees. Medium/Large/Enterprise tiers quote-based. - Note: Annual billing only. The reviewed pricing table publishes starting prices for the Small Business band and routes larger company-size bands to quote requests. One-time first-activation costs and a recurring service fee apply on top of listed plan prices and 'may vary'. - Languages on reporting form: 10 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 9001, ISO 27001, ISO 27017, ISO 27018, ISO 22301 - National laws referenced: Italy (D.Lgs. 24/2023); Spain (Ley 2/2023); Germany (HinSchG) - Last verified: 2026-06-05 - Sources: - https://www.whistleblowing.software/en/ - https://www.whistleblowing.software/en/pricing-software-whistleblowing/ - https://www.whistleblowing.software/en/security-whistleblowing-system/ - https://www.whistleblowing.software/en/app-legality-whistleblowing-software/ - https://www.whistleblowing.software/en/regulation/ - https://www.whistleblowing.software/en/about-us/ Notable Operated by DigitalPA, an Italian software company with offices in Cagliari, Milan, Rome, Sulmona, and Barcelona. Multi-channel intake: written reports, voice recording, phone reports, and in-person meeting requests. Mobile reporter app available (Legality Whistleblowing Mobile app). Strong 2-factor authentication; fully anonymous or confidential reporting modes. Automatic AI translator of reports and messages between handler and reporter. Transcription of voice and telephone reports. Configurable investigation templates and investigation reports (Release 6.0, 2026). Multi-company configuration for groups of companies in the Premium tier. Three tiers are shown publicly: Standard, Premium, and Enterprise. The reviewed pricing page publishes Small Business starting prices and routes larger company-size bands to quote requests. Companies with more than 1,000 employees are routed to a “Contact us” path. The platform is offered free of charge to Italian public administrations. Listed plan prices are starting points: the pricing page states first-activation costs (installation, custom configuration, user profiling, online training) and a periodic fee (maintenance, technical updates, help desk, managed hosting/SaaS) apply in addition and “may vary”. DigitalPA publishes ISO 9001, 27001, 27017, 27018, and 22301 certifications; ISO 37001, ISO 37002, and ISO 37301 are presented as compliance/alignment standards for adopters, not as audited product certifications on the public pages reviewed. Target market spans public authorities as well as private companies. Customer count, public API access, DPA, and subprocessor list were not disclosed on public pages reviewed. --- # LegalSending - Website: https://legalsending.com - Headquarters: Spain - Pricing: Essential from €25/month; Premium quote-based. Channel setup from €50. - Note: Essential tier public; Premium quote-based. Bundled with annual legal advice. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Spain (Ley 2/2023) - Last verified: 2026-06-10 - Sources: - https://legalsending.com - https://protecciondatos-lopd.com/empresas/compliance/canal-denuncias/software/ Notable By Grupo Atico34, a Spanish data-protection and compliance firm; whistleblowing product marketed as LegalSending. Low monthly entry price (Essential from €25/month); Premium tier quote-based; channel setup from €50. Integrates online, telephone, and in-person reporting channels — broader intake than most low-cost Spanish tools. Anonymous complaints with confidential two-way communication via tracking codes; customizable forms; role assignment; action history; reports and statistics; SMS alerts. Bundled with annual legal advice from a lawyer (part service-led); the underlying software is identifiable and independently reviewable, so it is included under the software-only rule. Hosting country, ISO 27001, DPA, retention configuration, and subprocessor list were not disclosed on the public pages reviewed. --- # LegalTegrity - Website: https://legaltegrity.com - Headquarters: Frankfurt am Main, Germany - Hosting: Deutsche Telekom Open Telekom Cloud, Germany - Pricing: Annual billing: Essential €588/year (€49/mo) for <50 employees; Professional 250 €1,188/year (€99/mo) for <250; Professional 1,000 €1,990/year (€165.83/mo) for <1,000; Enterprise on request for 1,000+. - Note: 12-month contract, auto-renews annually. 3-month money-back guarantee. - Languages on reporting form: 40 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (Open Telekom Cloud hosting) - National laws referenced: Germany (HinSchG) - Last verified: 2026-05-24 - Sources: - https://legaltegrity.com/en/home/ - https://legaltegrity.com/en/pricing/ - https://legaltegrity.com/en/terms-and-conditions/ - https://legaltegrity.com/en/who-we-are/ Notable 40+ languages available; 2 included in Professional plans, €29/month per additional language. Multi-channel intake: online reporting form and phone channel on every plan. Hosted on Deutsche Telekom’s Open Telekom Cloud (German data residency, ISO 27001-certified hoster). Chatbot defence on public reporting forms to filter automated submissions. Read-aloud function available from Professional tier upward. Corporate group / multi-entity configurations supported from Professional 250. 3 administrator accesses included in Professional tiers; €29/month per additional account. Premium add-ons: online trainings, OmbuTegrity (external ombudsperson / reporting-office operation). Bilingual customer service (German/English) via phone and email; premium phone support at Enterprise tier. 3-month money-back guarantee; cancellation requires 1 month notice before annual renewal. No public API, integration documentation, or subprocessor list was found on public pages reviewed. --- # Lumgo - Website: https://www.lumgo.com - Headquarters: Stockholm, Sweden - Hosting: EU-hosted in Nantes, France; vendor states it uses only EU-owned suppliers and does not use AWS or Azure (vendor-stated) - Pricing: Under 50 employees SEK 4,500/year; up to 250 employees SEK 9,500/year; over 250 employees SEK 15,000/year. VAT added. Vendor states this equals from about EUR 45/month. - Note: Billed annually by invoice or credit card. 14-day free trial with automatic account closure if not continued. Vendor states no contract is required. All tiers include unlimited users, SSO, all languages, secure communication, and support. - Languages on reporting form: 9 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Lag 2021:890) - Last verified: 2026-07-19 - Sources: - https://www.lumgo.com/eu - https://www.lumgo.com/se - https://lumgo.com/ Notable Operated by Lumgo AB, a Swedish company (org. nr 559380-4247) based in the Stockholm region, described as made in Stockholm and hosted in Nantes, France. Positioned as a modern whistleblowing application supporting the EU Whistleblowing Directive and the Swedish whistleblowing law (Lag 2021:890), with GDPR framed as a core design goal. Reporters can submit anonymously and follow their case with a PIN code, with a built-in secure chat for two-way follow-up questions. Organizations can create unlimited reporting channels with customizable, branded reporting pages. Sign-in for the organization side is delegated to Microsoft 365 or Google Workspace single sign-on; the vendor states it does not store usernames or passwords, and deleting a user in the identity provider automatically removes Lumgo access. Markets a legal AI assistant named Paige that provides guidance on incoming cases, and mentions external recipients such as partner law firms that can receive reports independently. States it encrypts all sensitive data, stores data within the EU, and uses only EU-owned suppliers, explicitly avoiding AWS and Azure to address Schrems II concerns. Nine reporting languages are listed: Swedish, Danish, Norwegian, Finnish, German, French, English, Italian, and Dutch. Pricing is published across three per-employee tiers billed annually (SEK 4,500 / 9,500 / 15,000 per year plus VAT), with a 14-day free trial and vendor statement that no contract is required. No ISO 27001 or SOC 2 certification, sub-processor list, DPA download, DPIA material, or API documentation was found on public pages reviewed. --- # MittVarsel - Website: https://digitaliq.no/en/myvoice - Headquarters: Bergen, Norway - Pricing: Not published. The product is presented through a contact form and a non-binding conversation. - Note: No public price list, tiers, or free-trial terms were found on public pages reviewed; procurement is contact-led. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001:2022 (vendor-certified, stated since 2023) - National laws referenced: EU Directive 2019/1937; Norway (Working Environment Act, Chapter 2) - Last verified: 2026-07-19 - Sources: - https://digitaliq.no/en/myvoice - https://digitaliq.no/en/myvoice/frequently-asked-question - https://digitaliq.no/en/myvoice/regulation-of-whistleblowing-in-europe - https://digitaliq.no/en/ - https://digitaliq.no - https://support.digitaliq.no/en/userguide/myvoice/whistleblower/ Notable Operated by DigitaliQ AS, Bergen, Norway (org.nr 918 266 917); the product is branded MittVarsel in Norwegian and MyVoice in English. Positioned as a secure digital reporting channel for safe reporting and compliant handling of misconduct, aimed at companies, municipalities, churches, and NGOs; named customers include Den Norske Kirke, Redd Barna, Fellesforbundet, and Infinitum. Reporters can submit with their name or anonymously (where the organization enables it) and receive login credentials to return to the case; anonymous reporters cannot recover lost credentials and must file a new referenced case. A dialogue function supports two-way communication with the case handler, including for anonymous reporters, who log in to check for new messages. Intake supports file attachments and oral reporting recorded as a voice message via microphone that is transcribed to text. Case handling includes targeted assignment to specific handlers, case-processing templates (checklists, interview invitations, conclusions), and three roles: Administrator, Case Handler, and Read-Only User. Security posture states connections are always end-to-end encrypted, with industry-standard server-level encryption and anti-malware, and encryption plus access control in line with GDPR. DigitaliQ AS states ISO/IEC 27001:2022 certification since 2023; this is vendor certification rather than a hosting-provider-only claim. Data residency for MittVarsel is not disclosed on the public pages reviewed; separately, the company’s Digitaliq.AI product is described as operated in Norway. The Regulation-of-whistleblowing page explains EU Directive 2019/1937 and notes Norway is not directly bound, referencing the Norwegian Working Environment Act Chapter 2; no article numbers or 7-day/3-month deadlines were stated. Digitaliq.AI is marketed as an AI support tool offering analysis, suggestions, and insights alongside MyVoice. No public pricing, tiers, free trial, API documentation, or sub-processor list was found on the public pages reviewed; procurement runs through a contact form and a non-binding conversation. --- # myETHOS - Website: https://www.myethos.eu - Headquarters: Chania, Crete, Greece - Hosting: Vendor privacy policy says personal data is stored on cloud servers within the EU and is not transferred outside the EEA; specific country and provider are not disclosed. - Pricing: SME tier €120/month plus VAT; Advanced tier custom quote. - Note: Vendor advertises a free trial via the app registration page. Trial length, included limits, and Advanced pricing are not disclosed on public pages reviewed. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Greece (Law 4990/2022); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.myethos.eu/en/ - https://www.myethos.eu/en/whistleblowing - https://www.myethos.eu/el/ - https://app.myethos.eu/account/register/en - https://app.myethos.eu/account/login/en - https://www.myethos.eu/en/privacy-policy - https://www.myethos.eu/en/terms-conditions Notable myETHOS is a Greek compliance suite rather than a whistleblowing-only product. Public pages list whistleblowing, labour-dispute resolution, incident and crisis management, and background-check services. The whistleblowing page explicitly names Law 4990/2022 and EU Directive 2019/1937, and describes reporting through the platform, telephone line, and physical meeting. The public pricing table lists an SME tier at €120/month plus VAT and an Advanced tier by custom quote. A free-trial/demo route is public, but the trial limits are not disclosed publicly. The public site is available in Greek and English. No additional product languages were found on public pages reviewed. EU/EEA hosting is vendor-stated in the privacy policy, but hosting country, provider, ISO certification, DPA, subprocessor list, API access, and two-factor authentication were not disclosed on the public pages reviewed. The authenticated report-link settings screen runs CKEditor 4.12.1, an end-of-life build that displays its own banner: “This CKEditor 4.12.1 version is not secure. Consider upgrading to the latest one.” Shipping a known end-of-life rich-text component on the surface where an organisation configures its whistleblowing intake is a frontend-maintenance and security signal. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no authenticated handler or reporter flow was reviewed in this pass). Base score: 19 / 50. Greece country bonus: 4 / 6. Category Score Max A. Legal compliance 5 16 B. Reporter experience 5 10 C. Handler experience 3 10 D. Security 1 8 E. Commercial 5 6 Evidence supporting the score: clear Greek-law positioning, a live Greek/English public surface, public SME pricing, and a free-trial route. Unverified from public pages: hosting country/provider, certification, subprocessors, DPA, API, two-factor authentication, retention controls, and audit-log semantics. --- # MyGovernance - Website: https://www.mygovernance.it - Headquarters: Italy - Pricing: Exact online-cart totals were not publicly reproducible in the reviewed dynamic store page. An official Zucchetti Store price-list PDF lists My Whistleblowing Starter Pack at €219, Small companies up to 100 employees at €825, and Medium companies up to 300 employees at €1,650. - Note: The live store page shows Smart/Flex selectors, 50/100/250 employee options, and mandatory starter-pack rows, but rendered €0 totals without client-side selection in this review. Holdings and organisations with more than 250 employees are directed to a custom configuration form. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Italy (D.Lgs 24/2023); Italy (D.Lgs 231/2001 — Modello 231); EU Directive 2019/1937 - Last verified: 2026-09-18 - Sources: - https://www.mygovernance.it - https://www.mygovernance.it/my-whistleblowing/ - https://www.mygovernance.it/whistleblowing/ - https://www.zucchetti.it/store/cms/software-whistleblowing-acquista.html - https://www.zucchetti.it/website/dms/Store/Listino_Zucchetti_Store.pdf - https://www.zucchetti.it/it/cms/soluzioni/obblighi-normativi/segnalazione-illeciti/my-whistleblowing/piattaforma-whistleblowing-vantaggi.html Notable Operated by MyGo S.r.l., a company within the Zucchetti Group. Positioned as legal tech: whistleblowing sits alongside related compliance and governance modules such as My 231, approvals, meetings, and litigation workflows. Primary Italian regulatory anchors: D.Lgs 24/2023 (whistleblower directive transposition) and D.Lgs 231/2001 (Modello Organizzativo di Gestione e Controllo). Site in Italian and English. The Zucchetti feature page states that Italian and English are native language versions and that German, French, and Spanish can be added, but the reviewed purchase table lists Italian for Smart and Italian/English for Flex. Product page states AES 256 encryption and storage/management on certified Microsoft Azure servers in the EU. The live Zucchetti Store page shows Smart/Flex options and 50, 100, and 250 employee selectors, but exact annual totals were not publicly reproducible without client-side selection in this review. The official Store price-list PDF separately lists My Whistleblowing price rows for a mandatory starter pack and company-size bands. Named customer roster on the homepage includes Stellantis, BNL, Humanitas, and ThyssenKrupp. Public pages reviewed did not disclose a public API, free trial, DPA/subprocessor list, or product-level ISO certificate text. --- # MySECway - Website: https://mysecway.com - Headquarters: Madrid, Spain - Hosting: Data centres within the European Union (vendor-stated); specific country not disclosed - Pricing: Básica EUR 7.95/month per manager (VAT excluded) on SaaS multi-tenant. Premium priced by configuration with annual billing, as a dedicated SaaS tenant (from 5 users) or On-Premises (from 10 users). - Note: Per-manager billing: each additional case manager is EUR 7.95/month. 7-day free trial with no charge before day 7. Premium adds visible and invisible watermarking, case delegation, SSO via ADFS, certified external timestamps, and IRM integration (Prot-On) as quote-only add-ons. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Spain (Ley 2/2023) - Last verified: 2026-07-19 - Sources: - https://mysecway.com/ - https://mysecway.com/canal-de-denuncias-para-empresas/ - https://mysecway.com/canal-de-denuncias-seguridad/ - https://mysecway.com/suscripciones/ - https://mysecway.com/aviso-legal/ - https://mysecway.com/politica-de-privacidad/ Notable Operated by IT zone, S.L. (Spanish NIF B86773397), registered at Calle Sombrerete 5, 28012 Madrid. Positioned as a fast-to-deploy internal whistleblowing channel for Spanish private companies and public entities to comply with Ley 2/2023 (the Spanish transposition of EU Directive 2019/1937). Two plans: Básica at EUR 7.95/month per manager (VAT excluded) on SaaS multi-tenant, and Premium priced by configuration with annual billing. Premium is delivered either as a dedicated SaaS tenant (from 5 users) or On-Premises (from 10 users), with no limit on the number of manager users. Reporting is web only, supporting text, audio, documents, and images; no phone or in-person channel is mentioned. Three reporter modes are offered: fully anonymous, registered with hidden identity, or identified, with no emails sent to anonymous reporters and identity/IP excluded from logs. Security page states user identity is encrypted in the database, case data uses dynamic keys, and system administrators cannot access identifying user data. Two-factor authentication is required for case managers (password plus 6-digit code); optional two-factor for whistleblowers is a premium feature. A non-public report register (libro de registro) of received reports and internal investigations is described, with logged document access and timestamps. Premium add-ons include visible and invisible watermarking, case delegation by document, SSO via ADFS, certified external timestamps, and IRM integration via Prot-On. Infrastructure is stated to reside in EU data centres certified as ENS, SOC 2 Type 2, ISO/IEC 27001:2013, and PCI-DSS; these are data-centre certifications, not vendor or product certifications, and no specific country or provider is named. A sub-processor list, DPA download, DPIA support, and API access were not found on public pages reviewed. --- # NAVEX - Website: https://www.navex.com - Headquarters: Lake Oswego, Oregon, United States - Pricing: EthicsPoint pricing not published. NAVEX's UK WhistleB page says new customers can get started from £75/month; other WhistleB and NAVEX One pricing remains sales-led. - Note: NAVEX positions EthicsPoint Essentials and Professional as demo-led products. WhistleB has a separate localized UK page with a published starting price. - Languages on reporting form: 150 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (WhistleB page), SOC 2 Type II (WhistleB UK page) - National laws referenced: EU Directive 2019/1937; France (Sapin II); United States (Sarbanes-Oxley, Dodd-Frank) - Last verified: 2026-05-24 - Sources: - https://www.navex.com/en-us/platform/whistleblowing-software-solutions/ - https://www.navex.com/en-us/products/navex-ethics-compliance/whistleb-whistleblowing-system/data-privacy-security/ - https://www.navex.com/en-gb/platform/employee-compliance/whistleblowing-solutions/whistleb/ - https://www.navex.com/en-us/service-hosting-providers/ethicspoint/ - https://www.navex.com/en-us/solutions/regulations/sapin-ii-compliance/ Notable NAVEX positions whistleblowing inside NAVEX One, with EthicsPoint Essentials for fast setup, EthicsPoint Professional for enterprise workflows, and WhistleB as a whistleblowing system page. Current EthicsPoint product copy supports web and phone reporting, straightforward case tracking, configurable intake, AI-powered compliance tools, multilingual reporting, and anonymous reporting. NAVEX’s UK WhistleB page says new customers can get started from £75/month and that WhistleB supports up to 150 languages; EthicsPoint pricing remains unpublished on public pages reviewed. The WhistleB privacy/security page states data is stored in the EU with customer-controlled encryption and that NAVEX and suppliers are unable to access sensitive customer data. WhistleB pages also list MFA, encrypted transmission/storage, activity logs, redundancy, Microsoft Azure hosting, Microsoft Translator localization, ISO 27001 adherence, and SOC 2 Type II on the UK page. The EthicsPoint service-hosting provider page publicly lists hosting, translation, interpretation, analytics, and platform service providers, including Europe-limited AWS processing for some services. Public pages reviewed did not disclose a free trial, API access, a DPA download, or article-level EU Directive mapping. --- # NorthWhistle - Website: https://www.northwhistle.com - Headquarters: Stockholm, Sweden - Hosting: Amazon Web Services within the EU (vendor-stated); specific region or country not disclosed - Pricing: Basic EUR 50/month (1 channel, 2 case managers, 1 language); Standard EUR 150/month (customisable forms, 3 languages, 15 case managers); Plus EUR 300/month (3 channels, unlimited languages and managers, routing/assignment groups); Enterprise custom quote (SSO, dedicated virtual private cloud, on-premise, legal counsel, custom integrations). - Note: Prices shown per month. Add-ons priced separately: case screening from EUR 100/month and telephone hotline EUR 50/month. Free trial offered on the three standard plans; Enterprise is contact-sales. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden - Last verified: 2026-07-19 - Sources: - https://www.northwhistle.com/ - https://www.northwhistle.com/product/ - https://www.northwhistle.com/pricing/ - https://www.northwhistle.com/security/ - https://www.northwhistle.com/about/ - https://www.northwhistle.com/app-privacy/ - https://www.northwhistle.com/list-of-sub-processors/ - https://www.northwhistle.com/swedish-government-on-support-for-whistleblowers/ Notable NorthWhistle is a registered brand of Nebulr AB (Stockholm, Sweden), which holds EU trademark 018494765; the platform runs at app.northwhistle.com. Marketed as a plug-and-play whistleblowing channel that generates a compliant reporter-facing website, with reporting by form, secure chat, and telephone hotline. Anonymity measures stated publicly include voice-message scrambling, file metadata stripping, end-to-end encrypted communication, and anonymous endpoints that remove IP and geolocation data. Three standard tiers are publicly priced per month (Basic EUR 50, Standard EUR 150, Plus EUR 300); Enterprise adds SSO, dedicated virtual private cloud, on-premise hosting, legal counsel, and custom integrations by quote. Add-ons are priced separately: case screening from EUR 100/month and a telephone hotline at EUR 50/month. The security page states hosting on Amazon Web Services with no personal or sensitive data leaving the EU; the specific AWS region or country is not disclosed. ISO 27001 (and ISO/IEC 27017 and 27018) are attributed to the AWS hosting platform, not to NorthWhistle itself; the footer ISO 27001 logo does not represent a vendor product certification. The app privacy policy states Nebulr AB acts as data processor, customers are data controllers, and case-specific data is automatically deleted 30 days after a case is closed. A named public sub-processor list is published (AWS, MongoDB, Twilio, Stripe, Mailgun for the product; plus operational tools), all stated as EU-located. Handler features documented include a case dashboard, routing and assignment groups, custom user roles, deadline monitoring with automatic reminders, and action logging described as tamper-free. Public pages reviewed did not disclose an API, two-factor reporter return access, a downloadable DPA, or article-level EU Directive mapping. Third-party market sources place NorthWhistle’s primary customer base in Sweden, Finland, and Norway; this was not confirmed on the vendor’s own public pages. --- # OhlasTo - Website: https://ohlasto.online - Headquarters: Brno, Czech Republic - Hosting: Domestic Czech servers on the vendor's QML platform (vendor-stated) - Pricing: Free for schools, kindergartens, and nonprofits (max 5 users); 149 CZK/month (excl. VAT) for companies and other organizations with unlimited users; free custom-SLA tier for existing QML information-system users. - Note: Prices are monthly and exclude VAT. No setup fee, annual billing option, or free trial found on public pages reviewed. Onboarding runs through Q-COM's implementation and training service. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Czechia (Act No. 171/2023 Coll.) - Last verified: 2026-07-19 - Sources: - https://ohlasto.online/ - https://ohlasto.online/whistleblowing/ - https://ohlasto.online/zachovani-anonymity/ - https://ohlasto.online/pro-oznamovatele/ - https://ohlasto.online/implementace/ - https://www.qcom.cz/it-sluzby/vnitrni-oznamovaci-system/ - https://www.qcom.cz/ Notable Operated by Q-COM, spol. s r.o. of Brno, Czech Republic (IČO 25538659), a Czech management-systems, IT, and consulting provider stating more than 25 years of activity. OhlasTo is offered both as a standalone reporting channel at ohlasto.online and as a module of Q-COM’s QML web information system. Public pages name Act No. 171/2023 Coll. (o ochraně oznamovatelů, effective 1 August 2023) and EU Directive 2019/1937, but do not cite specific article numbers. Intake channels consolidate web online form, email, and in-person reports into a single administration environment; phone intake was not stated on public pages reviewed. Anonymous reporting is supported with the reporter identity section optional; guidance pages also advise reporters on avoiding work networks and using private or Tor browsing. Case handling is browser-based with configurable user permissions and officer, investigator, and management access, plus automated deadline monitoring with notifications. Hosting is vendor-stated as domestic Czech servers on the QML platform; no specific data-centre or subprocessor disclosure was found. Interface languages found are Czech and Slovak only. Pricing is public: free for schools, kindergartens, and nonprofits (max 5 users); 149 CZK/month excluding VAT for companies with unlimited users; and a free custom-SLA tier for existing QML customers. No product ISO 27001 certification, DPA, DPIA, subprocessor list, API documentation, or free trial was found on public pages reviewed; onboarding is implementation-led via Q-COM. --- # OpenBlow - Website: https://www.openblow.it - Headquarters: Rome, Italy - Hosting: Runs on an unnamed Cloud Service Provider qualified under AgID/ACN SaaS requirements and enlisted in Cloud Security Alliance STAR (vendor-stated); on-premise install within the customer's own infrastructure is also offered. - Pricing: Not published. Procurement is contact-sales with custom implementation; a partner/reseller program is offered. - Note: No prices, tiers, or self-serve signup shown on public pages reviewed. The for-business page targets consultants, lawyers, and DPOs reselling to their clients. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: AgID/ACN SaaS qualification (vendor-stated), Cloud Security Alliance STAR registry (vendor-stated) - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs 24/2023); Italy (D.Lgs 231/2001) - Last verified: 2026-07-19 - Sources: - https://www.openblow.it/language/en/ - https://www.openblow.it/language/en/features-2/ - https://www.openblow.it/language/en/compliance-2/ - https://www.openblow.it/language/en/for-business-2/ Notable Operated by Laser Romae s.r.l., an ICT firm based at Viale Cesare Pavese 305, Rome; sales contact and phone are published on the site. Positioned as a whistleblowing platform to report and manage illegal conduct, available as an AgID-qualified SaaS service or as an on-premise install integrated into the customer’s own infrastructure. Compliance page states the platform is in line with D.Lgs 24/2023 (implementing EU Directive 2019/1937), D.Lgs 231/01 organizational models, and GDPR; none of these are cited with article numbers. The product is marketed elsewhere as an open-source whistleblowing platform (its own SEO page title and third-party directories), but the vendor content pages reviewed do not name GlobaLeaks or state a specific licence. Features page describes personalized workflow management with intermediate and final states, validation/transition logic, and phases for acceptance, first assessment, investigation, and corrective actions. Role model implements the operational roles foreseen by the legislation, plus customizable roles and clear separation of duties. Multi-engine architecture with plugins to connect to pre-existing systems (authorization, workflow, message-queue, and object-storage) is described; a public reporting API was not documented on pages reviewed. Homepage lists organizational logos (including RFI) as customers; the platform is used for public and private Italian deployments. Security posture: periodic VAPT sessions supported by security standards (ISO 27001, OWASP, CISA/CISM of ISACA); the service is provided on a Cloud Service Provider enlisted in Cloud Security Alliance STAR (CAIQ documented). No product-held ISO 27001 certificate, hosting provider, or data-centre country was named on public pages reviewed. No public pricing, self-serve trial, or monthly-contract terms were found; the for-business page targets consultants, lawyers, and DPOs reselling to their clients under a partner program. Encrypted transport and storage protecting report contents, documents, and whistleblower identity is stated; DPA/DPIA documentation was not found on public pages reviewed. --- # OpenSource Hinweisgeberportal - Website: https://opensource-hinweisgeberportal.de - Headquarters: Hamburg, Germany - Hosting: German data centres (vendor-stated); managed hosting of the open-source GlobaLeaks engine - Pricing: Company Bundle EUR 49/month or EUR 39/month annual (EUR 0 setup); Professional Bundle EUR 209/month or EUR 169/month annual (EUR 249 setup); Enterprise from EUR 249/month or EUR 199/month annual (from EUR 349 setup, dedicated hardware). All prices exclude VAT. - Note: Bundles are sized by storage, traffic, and hosting model, not by employee count. Paid add-ons include backups (EUR 79/month), monitoring (EUR 199/month), priority support (EUR 99/month), and SLA (from EUR 290/month); one-off setup/training services are listed separately. A free demo is offered and the homepage references a 30-day post-deployment money-back guarantee; no self-serve free trial was found on public pages reviewed. - Languages on reporting form: 90 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://opensource-hinweisgeberportal.de/ - https://opensource-hinweisgeberportal.de/preise - https://opensource-hinweisgeberportal.de/whistleblowing-software - https://opensource-hinweisgeberportal.de/interne-meldestelle - https://opensource-hinweisgeberportal.de/globaleaks - https://opensource-hinweisgeberportal.de/impressum - https://opensource-hinweisgeberportal.de/datenschutz Notable Operated by splice digital GmbH, Grevenweg 80, 20537 Hamburg, Germany (Amtsgericht Hamburg HRB 175006, VAT DE352385698, managing director Karl Ludwig Weise). The product is a managed, hosted deployment of GlobaLeaks, the open-source whistleblowing engine developed since 2011 and stated to be used by over 30,000 organisations worldwide; it is not a bespoke platform. Positioned for compliance with the German Hinweisgeberschutzgesetz (HinSchG) and EU Directive 2019/1937; public pages cite specific HinSchG sections (§ 16 Abs. 3 and § 17 Abs. 1 Nr. 1). The delivered product is a web-based online reporting form; phone, postal, and in-person channels are discussed as separate legal options an organisation must weigh, not features of the product. Anonymous reporting is central, with a 16-digit receipt for anonymous status tracking, integrated two-way chat, and Tor access. Case management includes automated deadline management aligned to the 7-day acknowledgment and 3-month feedback duties, configurable questionnaires, and configurable retention (default 3 years) with automatic deletion. Over 90 reporting languages are stated, along with WCAG 2.2 accessibility alignment and the AGPL 3.0 open-source licence of the underlying engine. Security and compliance copy claims the solution is “designed according to” ISO 27001 and ISO 37002:2021; these are design-conformance statements, not certifications. No ISO 27001 certificate for the vendor or product was found, and ISO 37002 is a whistleblowing-management guidance standard rather than an information-security certification. Hosting is stated to be German data centres; the DPA (AV-Vertrag), NDA, and SLA are optional paid add-ons, and the subprocessor list is provided on request via the DPA. The public Datenschutz page names only website-level subprocessors (Netlify for site hosting, Plausible for analytics, Whereby for video calls), not the whistleblowing-platform hosting stack. Pricing is fully published: Company Bundle (EUR 49/month, EUR 39/month annual, EUR 0 setup), Professional Bundle (EUR 209/month, EUR 169/month annual, EUR 249 setup), and Enterprise (from EUR 249/month, EUR 199/month annual, from EUR 349 setup with dedicated hardware), all excluding VAT, plus itemised add-ons and training services. A free demo is offered; the homepage references a 30-day post-deployment money-back guarantee, but no self-serve free trial was found on public pages reviewed. --- # OpenWhistle - Website: https://openwhistle.pt - Headquarters: Porto, Portugal - Hosting: Vendor states data is stored within the European Union; specific country and provider not named. Privacy policy notes data may be transferred to cloud providers outside the EEA under GDPR safeguards. - Pricing: Single plan: EUR 22/month, or EUR 17.60/month billed annually (EUR 211.20/year, described as 20% saving). VAT added on top. Price is per organisation with unlimited users. - Note: Includes 1 configured form, initial setup with up to 5 recipients, custom branding, interface in up to 3 languages, hosting, maintenance and updates, and email support within 1 business day. Additional recipients, forms and languages are self-managed after setup. All CTAs route to a demo request rather than self-serve signup. - Languages on reporting form: 90 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Portugal (Lei 93/2021) - Last verified: 2026-07-19 - Sources: - https://openwhistle.pt/en/ - https://openwhistle.pt/en/quem-somos/ - https://openwhistle.pt/en/funcionalidades-do-canal-de-denuncias/ - https://openwhistle.pt/en/como-funciona/ - https://openwhistle.pt/en/politica-de-privacidade/ Notable OpenWhistle is a brand of Canelinfinita, Unipessoal Lda, a Portuguese company (NIPC 518494128) with its registered office in Porto and a contact address in Águas Santas, Maia. Positioned as a whistleblowing channel for companies in compliance with Portugal’s Lei 93/2021, the GDPR, and EU Directive 2019/1937; the copy references the MENAC and RGPC obligation for organisations with 50 or more employees. Pricing is flat per organisation with unlimited users: EUR 22/month, or EUR 17.60/month billed annually (EUR 211.20/year), with VAT added on top. The vendor states the monthly fee stays the same whether the organisation has 30 or 300 employees. The included plan covers one configured form, initial setup with up to 5 recipients, custom branding, interface in up to 3 languages, hosting, maintenance and updates, and email support within one business day; additional recipients, forms and languages are self-managed afterward. The feature set is characteristic of the GlobaLeaks open-source platform: a 16-digit anonymous receipt, a custodian role authorising access to a whistleblower’s identity, Tor support, PGP email notifications, more than 90 languages, and an OSI-approved AGPL 3.0 licence are all listed. The platform is described as designed in accordance with ISO 27001:2022, ISO 37002:2021, CSA STAR and OWASP recommendations; these are framed as design references, not as held certifications, and no certification evidence was found on public pages reviewed. Security claims include full encryption of reports and communications, TLS 1.3, AES-256 at rest, RBAC, 2FA (TOTP RFC 6238), no IP address registration, and periodic penetration tests. The home page states data is stored within the European Union, while the privacy policy notes data may be transferred to cloud providers based outside the EEA under GDPR safeguards; no specific hosting country or named subprocessor list is published. The how-it-works page mentions submission via web, secure email or telephone, but the dedicated channel list shows only a web portal, so multi-channel intake beyond the online reporting form was not clearly confirmed. Onboarding is demo-led: pricing is public but every call to action routes to a demo request, and no free trial was found on public pages reviewed. The privacy policy cites specific GDPR legal bases (Art. 6(1)(b), (c) and (f)) and lists retention periods, but no separate DPA download or DPIA support was found on public pages reviewed. --- # osapiens - Website: https://osapiens.com/solutions/whistleblower-protection/ - Headquarters: Mannheim, Germany - Hosting: Not disclosed on public pages reviewed - Pricing: Not published — demo required. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (LkSG — Supply Chain Act grievance mechanism); EU CSDDD - Last verified: 2026-09-18 - Sources: - https://osapiens.com/solutions/whistleblower-protection/ - https://osapiens.com/platform/ - https://osapiens.com/imprint/ - https://osapiens.com/about/ Notable The product page positions osapiens HUB for Complaint Management as a secure, confidential channel for whistleblower protection and grievance mechanisms. Public copy supports anonymous reporting under a pseudonym or identified reporting, automated case management, custom forms/workflows, secure storage, time-stamped records, and audit-readiness. Official osapiens pages show inconsistent scale counters: the complaint-management page says 2,500+ enterprises, the platform page says 1,800 satisfied customers, and the newsroom about page says 1,300+ customers. The directory keeps all three as vendor claims rather than treating any as an independently verified customer count. AI-powered pre-grouping is disclosed publicly: incoming complaints are sorted by topic on arrival. Public compliance framing includes the EU Whistleblower Protection Directive, CSDDD, and Germany’s LkSG grievance mechanism. The product page did not explicitly cite HinSchG in the pages reviewed. The previous January 2026 Series C / unicorn claim was not supported by the vendor pages reviewed. The vendor newsroom instead references a $120M Series B led by Goldman Sachs Alternatives. Public pages reviewed did not disclose pricing, hosting location, certifications, public API access, DPA, subprocessor list, or reporting-language coverage. --- # otris - Website: https://www.otris.de/en/products/whistleblower-software/ - Headquarters: Germany (Dortmund) - Pricing: Standard from EUR 299/month for 50-249 employees; Enterprise from EUR 499/month for 250-999 employees; Enterprise plus quote-based for 1,000+ employees. Prices require at least 24 months. - Note: Legal-support add-on advertised at EUR 999/year. Free online demo advertised; sales contact available via vertrieb@otris.de. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Germany (HinSchG); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.otris.de/en/products/whistleblower-software/ - https://www.otris.de/en/products/otris-compliance-suite/ Notable otris is a Dortmund-based legal-tech suite vendor, not a whistleblower-only specialist. The whistleblower product has a dedicated page and is positioned alongside other otris products (contract management, compliance, document management). Vendor states ISO 27001-certified cloud operation and German data-centre hosting. ISO 37301 appears in broader compliance-management positioning, but no vendor-published whistleblower-product ISO 37301 certification was found on public pages reviewed. The whistleblower product page reviewed positions the public packages as SaaS; no current public evidence was found for full on-premises operation of the whistleblowing channel. WCAG 2.1 accessibility compliance is stated for the reporter system. Public package pricing is listed for two employee bands, with Enterprise plus available on request. No self-serve trial was found. Product pages mention SSO and interfaces, but no public API documentation was found. Public pages reviewed describe the product as multilingual, but do not disclose a language count. --- # Phoenix - Website: https://www.phoenix-whistleblowing.com/ - Headquarters: Switzerland - Hosting: Switzerland for standard hosting; Starter setup page lists Switzerland, Singapore, and Indonesia server-location options - Pricing: Starter free; Basic $65/month or $650/year; Premium $110/month or $995/year; Enterprise custom. - Note: Starter tier says no credit card required and no hidden fees. Public pricing also lists CHF, USD, and EUR as currency choices, but the English pricing page reviewed displayed USD plan prices. - Languages on reporting form: 50 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Whistleblower Directive (generic); GDPR - Last verified: 2026-05-24 - Sources: - https://www.phoenix-whistleblowing.com/ - https://www.phoenix-whistleblowing.com/pricing/ - https://www.phoenix-whistleblowing.com/bg/ - https://www.phoenix-whistleblowing.com/bg/pricing/ - https://www.phoenix-whistleblowing.com/ro/ - https://www.phoenix-whistleblowing.com/ro/pricing/ - https://www.phoenix-whistleblowing.com/product/starter-plan/ - https://www.phoenix-whistleblowing.com/multi-channels/ - https://www.phoenix-whistleblowing.com/case-management/ - https://www.phoenix-whistleblowing.com/confidentiality/ - https://www.phoenix-whistleblowing.com/features-and-functionality/ - https://www.phoenix-whistleblowing.com/compliance-and-standards/ - https://www.phoenix-whistleblowing.com/security/ - https://www.phoenix-whistleblowing.com/reporting-and-statistics/ - https://www.phoenix-whistleblowing.com/privacy-policy/ - https://www.phoenix-whistleblowing.com/terms-conditions/ Notable Public pricing was updated after the prior review. The English pricing page now lists Starter as free, Basic at $65/month or $650/year, Premium at $110/month or $995/year, and Enterprise as custom. Starter is a free self-serve plan, not a time-limited trial. Public pages say no credit card and no hidden fees, but no free-trial term was found on public pages reviewed. The Starter setup page asks for organisation name, server location, subdomain, and Phoenix domain. Server-location choices shown publicly are Switzerland, Singapore, and Indonesia; no EU option was found. Public pricing lists Starter with webform only, one Manager account, one language, a default theme, server choice, Phoenix web-domain choice, and self-serve knowledge base support. Public paid tiers add channels: Basic lists email, phone, instant messaging, and postal address; Premium adds online chat, customizable questionnaire, Operator and Agent accounts, custom domain, and theme library access. The multi-channel page describes web forms, phone numbers, short-message service numbers, chat, mobile app reporting, and a secure inbox for confidential exchanges. The confidentiality page describes three reporter identity modes: confidential, anonymous, and disclosed. It says secure-inbox access uses credentials provided by the system; user-chosen reporter passcodes were not disclosed on public pages reviewed. Case-management pages describe tags/categories, report sharing, comments, chronology/case tree, Kanban, triage, status reporting, PDF export, and dashboard reporting. Public FAQ material describes four roles: Administrator, Manager, Operator, and Agent. The public pricing page exposes Operator and Agent accounts only from Premium upward. No public DPA, sub-processor list, ISO 27001 certificate/scope, API documentation, AI documentation, file-upload disclosure, retention configuration, deadline timers, or Bulgaria/Romania-specific law page was found on public pages reviewed. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P+H (prior self-serve handler account plus 2026-05-24 public-page refresh; no new test submission was filed). Base score: 23 / 50 in Bulgaria and Romania contexts. Bulgaria country bonus: 1 / 6. Romania country bonus: 1 / 6. Category Score Max A. Legal compliance 4 16 B. Reporter experience (BG) 7 10 B. Reporter experience (RO) 7 10 C. Handler experience 6 10 D. Security 0 8 E. Commercial 6 6 Evidence supporting the score: public pages support the self-serve commercial path, free Starter tier, public BG/RO language surfaces, multiple reporting channels, secure inbox communication, case-management tooling, role separation, and monthly paid options. Unverified from public pages: EU residency, Bulgaria- or Romania-specific law posture, public DPA, sub-processor list, ISO 27001 certificate/scope, API documentation, and AI documentation. Switzerland / Singapore / Indonesia are the public server-location choices reviewed. --- # Portal das Denúncias - Website: https://portaldasdenuncias.com - Headquarters: Vila Nova da Barquinha, Portugal - Pricing: Starter EUR 47/month (up to 100 employees, 2 managers); Business EUR 67/month (up to 250 employees, 5 managers); Elite EUR 97/month (more than 250 employees, unlimited managers). All prices exclude VAT. - Note: Prices are stated per month and exclude VAT (mais IVA). No annual billing option is shown. A free demonstration environment is offered at demo.portaldasdenuncias.com; account setup directs buyers to contact the support team via the help center. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Portugal (Lei 93/2021) - Last verified: 2026-09-20 - Sources: - https://portaldasdenuncias.com/ - https://portaldasdenuncias.com/precos/ - https://portaldasdenuncias.com/politica-de-privacidade/ - https://portaldasdenuncias.com/termos-de-utilizacao/ - https://portaldasdenuncias.com/contactos/ Notable Operated by NoOperation, Lda., Portuguese NIF 515447650, based in Vila Nova da Barquinha, Portugal. Positioned as a whistleblowing channel for Portuguese public and private entities with 50 or more employees, addressing Lei 93/2021 and EU Directive 2019/1937. Public pages name Lei 93/2021 but do not cite specific article numbers. Offers both internal and external reporting channels through a web-based platform; no phone or in-person channels are described. States anonymous reporting with advanced encryption, plus support for uploading documents, images, and other files to corroborate a report. Reporters can track report status in real time and receive follow-up alerts, per public copy. Three published monthly tiers: Starter EUR 47 (up to 100 employees, 2 managers), Business EUR 67 (up to 250 employees, 5 managers), and Elite EUR 97 (more than 250 employees, unlimited managers); all prices exclude VAT. No annual billing option is shown, and account setup directs buyers to contact the support team rather than completing a fully self-serve purchase. A free demonstration environment is available at demo.portaldasdenuncias.com, which resolves and responds. The homepage “Entrar” link points at my.portaldasdenuncias.com, which has no DNS record and cannot be reached (checked 2026-09-20). The marketing site, the pricing pages and the demo host are all live and the company still lists a current address, so this reads as a broken login link rather than a closed business, but the route a buyer is told to use to reach the platform does not currently work. The privacy policy is built on GDPR (Regulation (EU) 2016/679) and references a data-protection and information-security impact assessment, but does not disclose hosting location, a sub-processor list, or specific retention schedules. No ISO 27001 or other certification was found on public pages reviewed. Public content and the reporter interface are Portuguese only. --- # preeco - Website: https://www.preeco.de - Headquarters: Germany - Hosting: Germany; hosting provider not named on public pages reviewed - Pricing: Not published on the public page. - Note: Product-specific licensing; SaaS subscription. Individual preeco modules can be licensed separately. - Languages on reporting form: 26 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Germany (HinSchG); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.preeco.de/en/products/preeco-whistleblower - https://www.preeco.de/en/products/preeco-whistleblower/preeco-whistleblower-reporting Notable preeco pre-populates the reporting form with German Whistleblower Protection Act breach categories and per-category example narratives. The product page reviewed states data hosting in Germany, but did not name the hosting provider or hosting certification. Public whistleblower page reviewed states GDPR compliance, 2FA, automatic anonymization on activation, and encrypted communication. Pricing is not disclosed on the public site. The vendor also licenses individual modules separately, so a full-stack quote may differ materially from a starter-module quote. Public product page states 26 languages. Phone, email, or other non-web intake channels were not disclosed on public pages reviewed. No vendor-published whistleblower-product ISO 27001 or BSI certification claim was found on public pages reviewed. No public API, integration documentation, or subprocessor list was found on public pages reviewed. --- # PRIMA Compliance - Website: https://prima-compliance.de - Headquarters: Niedererbach, Germany - Hosting: Byte Solution GmbH & Co. KG (developer, webhosting, and server infrastructure); data processed in Germany, otherwise within the EU (vendor-stated) - Pricing: Ombudsperson packages (net, per year): Starter EUR 1,500 (up to 150 employees, 6 ombudsperson hours), Business EUR 2,700 (up to 249 employees, 12 hours), Premium EUR 6,000 (250-1,000 employees, 20 hours); Individual quote for 1,000+ employees. Add-on telephone hotline EUR 15-25/month. - Note: Subscriptions are structured in three tiers: Basis (self-service cloud plan where the organisation handles cases), Business (vendor reviews and processes incoming reports through to reporting), and Premium (lawyer ombudsperson). The Basis self-service plan price was not published on the pages reviewed. Standard packages are ordered through an online form (bytesolution.de/prima-compliance) with annual billing. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (Hinweisgeberschutzgesetz, HinSchG) - Last verified: 2026-07-19 - Sources: - https://prima-compliance.de/ - https://prima-compliance.de/hinweisgeberschutz/ - https://prima-compliance.de/datenschutz/ - https://bytesolution.de/prima-compliance/ Notable Operated by Gebrueder Brands & Seehaus GbR, a German law firm (Rechtsanwaelte, Fachanwaelte, Wirtschaftsjuristen) in Niedererbach, under the brand PRIMA Compliance / PRIMA Hinweisgeber. Byte Solution GmbH & Co. KG (Niedererbach) is named in the privacy policy as the processor for webhosting and server infrastructure, and is the developer behind the platform. Marketed as HinSchG- and GDPR-compliant and aligned with EU Directive 2019/1937; the whistleblowing-protection page also references the ISO 37301:2021 compliance-management standard. Three subscription tiers are described: Basis (self-service cloud plan where the organisation handles case processing itself), Business (vendor reviews and processes incoming reports through to reporting), and Premium (adds a lawyer as impartial ombudsperson). Ombudsperson packages carry published annual net prices: Starter EUR 1,500 (up to 150 employees, 6 hours), Business EUR 2,700 (up to 249 employees, 12 hours), Premium EUR 6,000 (250-1,000 employees, 20 hours); an Individual package for 1,000+ employees is quote-only. A telephone hotline is offered as a paid monthly add-on (EUR 15-25/month); training, audits, and compliance-officer appointment are also offered. Standard packages are ordered through an online form at bytesolution.de/prima-compliance (“Jetzt zahlungspflichtig bestellen”); no free trial was found on the pages reviewed. The privacy policy states data is processed in Germany and, exceptionally, on servers within the EU, with no transfers to third countries outside the EU, and that data is transmitted using 256-bit SSL encryption. Reports can be made anonymously and confidentially; the price of the self-service Basis cloud plan was not published on the pages reviewed. No ISO 27001 certification for the product or its hosting provider was found on the pages reviewed. Identity note: the operator is PRIMA Compliance (Gebrueder Brands & Seehaus GbR). prima-vera.de is an unrelated grain-products company that merely uses a different third-party whistleblowing tool, and is not the operator of this product. --- # Pro Vastuullisuus - Website: https://www.whistleblower.fi - Headquarters: Harinjarvi, Finland - Pricing: Basic version EUR 299 (1-9 persons), EUR 399 (10-29), EUR 599 (30-49), EUR 799 (50-99) per year. Extended version EUR 399 (1-9), EUR 599 (10-29), EUR 799 (30-49), EUR 999 (50-99) per year. Organizations of 100+ persons by custom agreement. Prices exclude VAT. - Note: Pricing is annual and banded by organization size (employee count). No monthly option is offered. Some third-party listings cite an older entry figure of EUR 99 for the smallest tier, but current pages across whistleblower.fi, whistleblowing.pro, and anonyymiilmoituskanava.fi show EUR 299 as the entry price. A no-commitment demonstration is offered rather than a self-serve free trial. - Languages on reporting form: 3 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-07-19 - Sources: - https://www.whistleblower.fi/ - https://www.whistleblowing.pro/pro-vastuullisuus/ - https://www.anonyymiilmoituskanava.fi/pro-vastuullisuus/ - https://www.propilvipalvelut.fi/pro-sivustot/ Notable Operated by Pro PK-Pilvipalvelut Oy, a Finnish cloud-services vendor based in Harinjarvi, Finland. The whistleblowing channel is one module of Pro Vastuullisuus, a broader responsibility-management system that also covers ethics guidelines, sustainability and CSRD reporting, work safety, data protection, and DPIA/incident reporting. The same product is marketed across several Finnish-language domains, including whistleblower.fi, whistleblowing.pro, and anonyymiilmoituskanava.fi. Positioned for micro-enterprises, SMEs, associations, and public-sector bodies; pages cite the EU obligation for organizations with 50+ employees, municipalities over 10,000 residents, and anti-money-laundering entities. Anonymous reporting aligned to EU Directive 2019/1937 is the core function; the Finnish transposition law and article-level mapping were not named on public pages reviewed. Pricing is annual and banded by organization size: Basic from EUR 299 to EUR 799 per year and Extended from EUR 399 to EUR 999 per year, both excluding VAT, with 100+ persons by custom agreement. Some older third-party listings cite an entry figure of EUR 99 per year, but current vendor pages consistently show EUR 299 as the smallest-tier price. The extended version adds English and Swedish reporter forms plus multi-channel reporting; the basic version is Finnish-centric. Reports support mobile-friendly web submission and photo/file attachments; two-way anonymous follow-up communication was not documented on public pages reviewed. No ISO 27001 or other security certification, no disclosed hosting location or EU data-residency statement, no subprocessor list, and no public API documentation were found on the pages reviewed. Procurement is demo-first: a no-commitment demonstration and a named sales contact are offered rather than a self-serve trial or online checkout. --- # Qnister Whistle - Website: https://www.qnister.com/en/solutions/whistleblowing - Headquarters: Sweden (Jönköping) - Pricing: Swedish-market pricing: 695 SEK/month for 0-99 employees, 895 SEK/month for 100-249 employees, 1,295 SEK/month for 250-999 employees; 1,000+ quote-based. - Note: Prices and the external-receiver licence apply to the Swedish market; other EU markets are quoted separately. 12-month licence period; cancellation must be made at least 3 months before renewal. Implementation fee 4,995 SEK; additional channel 695 SEK/month; additional language 295 SEK/month; investigation add-on 2,895 SEK/hour. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Sweden (Lag om skydd för personer som rapporterar om missförhållanden); EU Directive 2019/1937 - Last verified: 2026-09-19 - Sources: - https://www.qnister.com/en/solutions/whistleblowing - https://www.qnister.com/en/prices-whistleblowing - https://www.qnister.com/en/privacy-policy Notable Qnister positions the product as a simple, directive-compliant tool rather than a broad ethics-and-compliance suite. Optional “external receiver” add-on routes incoming reports to an assigned lawyer at Qnister’s partner firm. ISO 27001 certified with Swedish server hosting; daily backups and penetration testing referenced. Starter packages include templates and policies on top of the platform. Public pricing is published in SEK and includes a separate implementation fee plus paid add-ons for extra channels and languages. The published prices and the external-receiver licence reflect the Swedish market; other EU markets are quoted separately. Public pages reviewed state several languages, but no language count was found. Qnister is now part of Aunetic. The Qnister Whistle page still sells the product under Qnister branding, but carries a notice directing buyers to aunetic.com, where the same product is listed as “Whistle” with no published pricing and a demo-only buying flow. The SEK rate card below is published by Qnister, not by Aunetic. No public API documentation or subprocessor list was found on public pages reviewed. --- # Raportare Avertizori - Website: https://raportare-avertizori.ro - Headquarters: Bucharest, Romania - Hosting: The public application and its API are served from Vercel; the data-hosting region and storage country are not disclosed on the public pages reviewed. - Pricing: Partly public. Plans are rendered by the client app from its own API and include monthly and annual billing plus a quote-based request-demo tier. The contract page cites a package price of 280 lei (RON) including VAT. - Note: The plan table is drawn from the app's API rather than shown in static page HTML, and the billing period for the 280 lei figure is not stated alongside it. Recurring monthly card billing is offered. No free trial was found on the public pages reviewed. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Romania (Law 361/2022) - Last verified: 2026-07-19 - Sources: - https://raportare-avertizori.ro - https://raportare-avertizori.ro/cum-functioneaza - https://raportare-avertizori.ro/planuri - https://raportare-avertizori.ro/contract - https://raportare-avertizori.ro/legislation - https://raportare-avertizori.ro/faq - https://raportare-avertizori.ro/contact Notable Operated by the Bucharest law firm Avocati CHIRIC & CHIRIC (CIF RO18569360), which is named as the service provider in the platform’s own service contract. Distinct vendor from the other Romanian listings in this directory: Whistleblow.ro / avertizori.eu (DOTCOM IT PRO SRL), WIBSO (Compliance Integrity Solutions SRL), Whistle UP, EthicLink (SELFSOFT TECH SRL), and Avertizori Integritate (SC LOCASIWEB SRL). Marketed as compliant with Romania’s Law 361/2022 on the protection of public-interest whistleblowers and with EU Directive 2019/1937. Self-serve flow: choose a plan, complete company details (auto-filled from the ANAF tax registry by CUI), and pay online by bank card; recurring monthly billing is offered. The customer-facing app generates an internal reporting procedure document and a service contract. Reporter features include anonymous reporting, a report tracker, and two-way anonymous messaging. Handler features include a centralized dashboard for managing reports, report-status handling, report export, and team invitations. Security copy states that all reports and communications are encrypted in transit and at rest; no ISO 27001 certification was found on the public pages reviewed. The public site and its API are served from Vercel; the data-hosting region and storage country are not disclosed on the public pages reviewed. The site and reporter/handler interface are in Romanian only; pricing plans are rendered by the client application from its API rather than shown in static page HTML. --- # Reler - Website: https://www.piattaformawhistleblowing.it - Headquarters: Treviolo (Bergamo), Italy - Hosting: Not disclosed on the public pages reviewed. - Pricing: €79/month, or €853.20 for the first year and €948/year thereafter. A 60-day free trial precedes either, cancellable at any point during the trial. - Note: One price, one feature set — the vendor's pitch is that everything required by law is included rather than tiered. Annual billing takes 10% off the first year only. Checkout runs through a storefront rather than a sales process, though the primary call to action across the site is a demo booking. - Languages on reporting form: undisclosed - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs. 24/2023) - Last verified: 2026-09-21 - Sources: - https://www.piattaformawhistleblowing.it/ - https://www.piattaformawhistleblowing.it/pages/il-nostro-software - https://www.piattaformawhistleblowing.it/collections/all Notable Reler is a brand of Yourbiz srl of Treviolo, Bergamo (P.IVA 02943820163, REA BG-0335829), sold on the domain piattaformawhistleblowing.it — an exact-match Italian keyword domain rather than the product name. The positioning is “Ready to Whistle”: a platform that arrives pre-configured, including the procedura di segnalazione and privacy notice that D.Lgs. 24/2023 obliges the organisation to have, with an option to swap in documents drafted for the company. The feature list is annotated by why each item exists, splitting “obbligo di legge” from “funzionalità avanzata”: written reporting, end-to-end encryption, notifications to reporter and supervisory body and the reporting procedure are marked as legal requirements; voice recording, in-person reporting, investigative registers, reporter chat, logs, handler roles and multilingual support as advanced. Return access for the reporter is by code, with notifications when a report is taken up and the ability to add further information to an existing submission. Members of the organismo di vigilanza each hold an account and are notified of new reports and approaching deadlines. Two claims on public pages will not survive a procurement review as written. “Piattaforma certificata” and “sicurezza certificata a norma di legge” name no certification, and one homepage banner gives the law as D.LGS 23/2024 where the transposition is D.Lgs. 24/2023 — cited correctly in the body copy of the same site. No hosting information of any kind appears on the public pages reviewed. Status: not yet scored Reler was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the Italy ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Safecall - Website: https://www.safecall.co.uk - Headquarters: London, United Kingdom - Hosting: UK-based data centres (vendor-stated); specific provider not named on public pages reviewed - Pricing: Not published. Procurement is sales-led; prospective clients are directed to contact the Safecall team. - Note: No public price tiers or self-serve signup were found. Reports are made by phone hotline or online form; follow-up is via a secure platform login. - Languages on reporting form: 175 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; United Kingdom (Public Interest Disclosure Act 1998) - Last verified: 2026-07-19 - Sources: - https://www.safecall.co.uk/ - https://www.safecall.co.uk/whistleblowing-solutions/ - https://www.safecall.co.uk/our-business/ - https://www.safecall.co.uk/faqs/ - https://www.safecall.co.uk/privacy-policy/ Notable Operated by Safecall Limited (UK company registration 03769031), registered office 8th Floor, 100 Bishopsgate, London EC2N 4AG, and wholly owned by The Law Debenture Corporation p.l.c. Established in 1999; the company states more than 20 years of operation covering 5 million+ employees across 1,000+ organizations worldwide. Positioned as a managed whistleblowing service plus case-management software, with all call handlers described as former UK police officers with at least 25 years of investigative experience. Reporting channels are a 24/7 phone hotline and an online form; whistleblowers can log in to a secure platform to receive updates and communicate two-way while remaining anonymous. Web reporting is offered in 68+ languages, with interpreting stated across 175+ languages and dialects in more than 150 countries. The FAQ states all data is hosted in UK-based data centres for GDPR compliance; the specific provider and any EU-region residency were not disclosed on public pages reviewed. Security claims include AES256 encryption, role-based access controls, two-factor authentication, encrypted transfer with VPNs and digital certificates, and regular independent penetration testing. ISO 27001, SOC 2, and other attestations are referenced as available under NDA during procurement rather than shown as public certificates; no current public certification was verified. Marketed as helping organizations comply with the EU Whistleblowing Directive where they fall within EU jurisdiction, alongside UK laws such as PIDA, the Market Abuse Regulation, and the Economic Crime and Corporate Transparency Act 2023. No pricing, self-serve signup, free trial, API documentation, or formal sub-processor list was found on public pages reviewed; procurement is sales-led. --- # Secure Blowing - Website: https://www.secureblowing.it - Headquarters: Rome, Italy - Pricing: From EUR 125/month, including unlimited handler and collaborator users (vendor-stated). Full tier structure not published. - Note: A starting price is shown on the homepage; the complete tier structure and any customization costs were not found on public pages reviewed. Procurement is demo-led (Prenota una DEMO), with no self-serve trial or online signup found. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs 24/2023) - Last verified: 2026-07-19 - Sources: - https://www.secureblowing.it/ - https://www.secureblowing.it/software-whistleblowing/secure-blowing-il-software-per-le-segnalazioni-di-whistleblowing-facile-e-intuitivo/ - https://www.secureblowing.it/whistleblowing-tutto-cio-che-ce-da-sapere-per-mettersi-in-regola/ - https://www.secureblowing.it/privacy-policy/ Notable Operated by MOTI-F srl (Consulenza direzionale), Via Benedetto Croce 34, 00142 Rome, Italy, P.IVA 09651941008. Secure Blowing is a standalone cloud whistleblowing channel delivered as SaaS, with the vendor framing third-party independence of the system as a benefit; MOTI-F also offers legal, compliance, and technical consulting around it. Marketed as multilingual and suitable for organizations of all types and sizes, including public bodies, private companies with 50+ employees, and adopters of the 231 Model. Reporters can submit written and oral reports, send voice messages, and access the channel from any fixed or mobile device with no registration required. Anonymous reporting is supported, and reporters receive a unique reserved PIN to track their report and communicate with handlers through confidential messaging. Handler features include multi-role management (for example OdV member and Internal Audit), work groups, assignment of reports to different handlers, and a dashboard with statistics and interactive charts. Stated security measures include encryption and separation of data and communications, daily backups and snapshots, HTTPS, regulated access, retention policy management, and administrator operation logs. The site references EU Directive 2019/1937, Italy’s D.Lgs 24/2023, ANAC oversight, and the statutory 7-day acknowledgment and 3-month feedback deadlines, but does not cite specific article numbers. No ISO 27001 or other product certification was found on public pages reviewed. Hosting location, cloud provider, and EU data residency were not disclosed; the privacy policy names Matomo for analytics and offers the subprocessor list on request. Pricing starts from EUR 125/month with unlimited handler and collaborator users; the full tier structure was not published, and procurement runs through a booked demo rather than a self-serve trial. --- # Segnala Sicuro - Website: https://segnalasicuro.org - Headquarters: Monfalcone, Italy - Hosting: EU or Italian data centres (vendor-stated) - Pricing: Whistleblowing base EUR 300/year; each additional report type (gender-equality PdR 125, SA 8000 ethics, ESG) adds EUR 200/year. Implementation and support included. - Note: Prices are published on the vendor site as annual fees. No monthly billing option was found on public pages reviewed. A free demo is offered by request, not a self-serve trial. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs 24/2023) - Last verified: 2026-07-19 - Sources: - https://segnalasicuro.org/ - https://www.ambient7.com/whistleblowing/ - https://www.ambient7.com/chi-siamo/ - https://www.ambient7.com/informativa-sulla-privacy/ Notable Operated by Ambient7 s.r.l., an Italian managed-service provider based in Monfalcone (GO), VAT IT01069960316, focused on IT security and regulatory compliance. Positioned for Italian companies with 50+ employees or a D.Lgs 231 organisational model that must provide an internal reporting channel under D.Lgs 24/2023. Marketed as compliant with ANAC guidelines, GDPR, and the EU Whistleblowing Directive; the site also references the earlier Law 179/2018, but no article-level mapping was found. Built on the open-source GlobaLeaks whistleblowing platform, with end-to-end encryption stated. Handles multiple report types in one platform: whistleblowing (D.Lgs 24/2023), gender-equality violations (PdR 125), SA 8000 ethics, and ESG/sustainability concerns. Anonymous reporting and anonymous two-way communication between reporter and designated handlers are described; the reporter’s identity is stated to remain protected throughout the process. Managed activation is stated to take place online within 48 hours, with implementation and support included. Pricing is published as annual fees: EUR 300/year for the base whistleblowing type, plus EUR 200/year for each additional report type; no monthly option was found on public pages reviewed. Hosting is stated to be in EU or Italian data centres; a single specific country and provider were not firmly disclosed. ISO 27001 is referenced, but public pages do not state whether Ambient7 itself or the hosting provider holds the certification, so no vendor certification could be verified. A free demo is offered by request; no self-serve trial, public API documentation, sub-processor list, or downloadable DPA was found on public pages reviewed. --- # SignalRH - Website: https://signalrh.fr - Headquarters: Strasbourg, France (offices in Reims and Lyon) - Hosting: Site hosting is OVH, Roubaix, France, named in the legal notice. The homepage states data is hosted in France. - Pricing: Signalement module from €159 HT/year. RPS & QVCT from €169 HT/year, Alerte SST from €149 HT/year. Two modules together take 25% off, three take 40% off. - Note: Each module activates independently, so the reporting channel can be bought without the occupational-health modules. Prices are annual and exclusive of VAT; the vendor also quotes a from-€29/month figure on the homepage. Deployment is stated at 24 to 48 hours. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II, Loi n° 2016-1691 du 9 décembre 2016); France (Loi Waserman, Loi n° 2022-401 du 21 mars 2022) - Last verified: 2026-09-21 - Sources: - https://signalrh.fr/ - https://signalrh.fr/solutions/signalement - https://signalrh.fr/tarifs - https://signalrh.fr/mentions-legales Notable Published by RPSRH - Risque Prévention Signalement RH SAS of Strasbourg (SIRET 92288807800016), with offices in Reims and Lyon, and registered as an IPRP with DREETS Grand Est. The Signalement module is sold as an independently activatable product, which is why it appears here rather than being treated as a feature of a wider suite. It can be bought on its own at €159 HT/year without the psychosocial-risk or occupational-safety modules. Legal framing is the strongest part of the module. The page sets out three legal blocks — Sapin II, Waserman and Directive 2019/1937 — with the statute numbers and dates, the 50-employee threshold, the requirement to name a référent, the removal of the mandatory internal-first route under Waserman, and the extension of protection to facilitators. Data is segmented by unité de travail and by service throughout the platform, so access rights, comparisons and risk mapping all follow the organisation’s own hierarchy rather than a single company-wide view. Deadline mechanics are described at a level most vendors do not publish: automatic calculation at intake, reminders before each legal deadline, status history visible to the reporter, and PDF exports for the CSE or management. Supporting services sit alongside the software — internal investigations after a report, occupational psychologist consultations, and IPRP-led diagnosis and action planning — which puts part of the handling capability outside the product itself. Status: not yet scored SignalRH was added from the September 2026 AI-citation coverage audit, after a check that the whistleblowing capability is a separately purchasable module rather than a feature bundled into an occupational-health subscription. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the France ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Soterna - Website: https://www.soterna.eu - Headquarters: Amsterdam, Netherlands - Hosting: Stated as entirely within the EU with European cloud providers; no country or provider is named. Data-residency arrangements are offered on the Enterprise tier. - Pricing: Quote-only. Three packages — Core, Trust and Enterprise — priced as a fixed annual fee per organisation based on headcount. No amounts published; the vendor commits to a proposal within two working days. - Note: The pricing page explains the absence of figures directly: a meaningful price depends on organisation size and configuration, and a "from" price "is fairer than a starting price that is right for almost nobody". The Neutral Line advice line is an add-on available only with Trust and Enterprise. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Netherlands (Wet bescherming klokkenluiders) - Last verified: 2026-09-21 - Sources: - https://www.soterna.eu/ - https://www.soterna.eu/en - https://www.soterna.eu/prijzen - https://www.soterna.eu/security Notable Positioned as “social safety” infrastructure rather than as a compliance channel: the Wbk reporting route sits alongside a vertrouwenspersoon (confidential adviser) module, a psychosocial-risk view, and a Reorganisatiekamer for anonymous questions during a restructuring. Reporters submit without an account or email address. Return access to an existing case is by case number plus an access code, and the vendor states identity, IP address and device stay shielded while two-way messaging continues. Aggregated board reporting enforces a minimum group size of seven before a figure is shown, and the works council receives its own signal pack. This is a stated k-anonymity threshold rather than a generic “anonymised dashboard” claim. Conflict-of-interest routing with customer-defined rules, retaliation check-ins that carry no content, and an evidence store with EXIF stripping, virus scanning and SHA-256 integrity are all Trust-tier or above. The security page states encryption in storage and transport, separation of reporter identity from report content, an immutable action log, and EU hosting with European cloud providers. It names no provider, no country and no certification, and says ISO 27001 work is prepared rather than complete. The marketing site is published in Dutch and English only, and every legal reference is to the Dutch transposition. There is no signal of a market outside the Netherlands. Status: not yet scored Soterna was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the Netherlands ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # SpeakUp - Website: https://www.speakup.com - Headquarters: Amsterdam, Netherlands - Pricing: Essential starts at €3,000/year for organizations up to 1,000 employees. Enterprise is custom-priced. - Note: Pricing page says custom pricing applies above 1,000 employees and invites contact for the Enterprise package. - Languages on reporting form: 99 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISO 27701, ISAE 3000 Type II / SOC 2 quarterly audit, TISAX - National laws referenced: EU Directive 2019/1937; Germany (Supply Chain Act / LkSG) - Last verified: 2026-05-24 - Sources: - https://www.speakup.com/ - https://www.speakup.com/sienna-ai - https://www.speakup.com/pricing - https://www.speakup.com/assurances - https://www.speakup.com/about-us/ Notable SpeakUp says it was founded in Amsterdam as People Intouch in 2004 and now has offices in Amsterdam, Bengaluru, and New York. Public pages support web, phone, and app reporting, 99+ languages, AI-powered compliance and ethics reporting, dashboards, case management, and disclosure/approval modules. The pricing page publishes Essential from €3,000/year for organizations up to 1,000 employees, with custom Enterprise pricing and custom pricing above 1,000 employees. The homepage states 750+ companies and 5M+ users; the about page also displays a 600+ companies metric. Assurance copy states SpeakUp is ISO 27001 certified, follows ISO 27002 and ISO 27701 guidance, is ISO 27701 certified in FAQ copy, and is audited to ISAE 3000 Type II / SOC 2 and TISAX quarterly. Public pages reviewed did not disclose EU data-centre location, public API access, a DPA, or a subprocessor list. --- # SygnaApp - Website: https://sygnaapp.pl - Headquarters: Poland - Hosting: Modern data centres in Poland (vendor claim) - Pricing: Annual billing in PLN. Standard 3,600 zł/year, Multi 5,900 zł/year, Premium 7,950 zł/year. Demo access is offered separately. - Note: Current annual prices are visible in the /rejestracja/1 package-selection step. The public /pakiety page lists feature differences but not price amounts in the HTML reviewed. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Poland (Ustawa o ochronie sygnalistów, 14 June 2024); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://sygnaapp.pl - https://sygnaapp.pl/aplikacja-dla-sygnalistow - https://sygnaapp.pl/pakiety - https://sygnaapp.pl/rejestracja/1 - https://odo24.pl/ranking-aplikacji-dla-sygnalistow Notable Placed first in the ODO24 2024 ranking of Polish whistleblower applications. Public-sector customers on homepage include Ministerstwo Aktywów Państwowych (Ministry of State Assets); private sector includes Polsat, Plus, eSky.pl and other recognisable Polish enterprises. Site in Polish and English. Product scope: online reporting form, configurable disclosure form, administrator panel, report register, reminders, exports, technical support, legal counsel, and specialist training. Fast implementation emphasised in marketing; specific timelines not published. Annual pricing is published inside the package-selection step at /rejestracja/1: Standard 3,600 zł/year, Multi 5,900 zł/year, Premium 7,950 zł/year. A Demo tier is still shown with text saying it is free until the law enters into force; because the Polish act entered into force on 25 September 2024, treat that line as stale until confirmed by the vendor. Vendor public pages state that data is stored in data centres located in Poland, that data and files are stored encrypted, and that 2FA is available. Founding year and formal certifications were not found on the vendor pages reviewed. --- # Sygnali - Website: https://sygnali.pl - Headquarters: Poznań, Poland - Hosting: Dedicated servers in Poland (Warsaw data centre), reporter traffic proxied through Cloudflare (vendor-stated) - Pricing: BASIC 160 PLN/month or 1,760 PLN/year (2 recipients); PRO 260 PLN/month or 2,860 PLN/year (4 recipients); PREMIUM 360 PLN/month or 3,960 PLN/year (6 recipients). - Note: First month free. Unlimited report volume on all tiers. Tiers differ by the number of report recipients (handlers). VAT treatment of the listed PLN prices is not stated on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Poland (Ustawa o ochronie sygnalistów, in force 25 September 2024) - Last verified: 2026-07-19 - Sources: - https://sygnali.pl - https://sygnali.pl/bezpieczenstwo_sygnalisty - https://pomoc.mwc.pl/sygnali/ - https://pomoc.mwc.pl/sygnalista/ Notable Operated by MWC Sp. z o.o., Kowalewicka 12, 60-002 Poznań, a Polish IT vendor that also publishes municipal document-distribution and secret-ballot systems. Positioned for Polish municipalities, regional government bodies, companies, and educational institutions subject to the Polish whistleblower law. Three reporting channels are documented: an online reporting form on a dedicated URL, an anonymous email relay that hides the sender address, and a PIN-protected phone line that uses AI audio-to-text conversion. Reports are anonymous by default; a reporter receives a generated identifier and password (shown on screen and as a downloadable PDF receipt) to log back in, read responses, and send follow-ups, with a 15-minute auto-logout. The administrator panel organises reports into New, Open, and Archived states, routes them to handler users by category, supports internal notes hidden from reporters, and keeps a system activity log. Notifications to authorised recipients are sent by email and SMS on new reports. Hosting is stated as dedicated servers in Poland (Warsaw data centre), with reporter traffic proxied through Cloudflare to mask IP addresses, submitted-document metadata stripped, and files encrypted with keys held separately; ESET and encrypted Veeam backups are also referenced. ISO 27001 is presented in relation to the hosting data centre; the pages reviewed do not establish an independent vendor or product ISO 27001 certification. The Overview section explicitly cites the Polish Ustawa o ochronie sygnalistów (in force 25 September 2024), EU Directive 2019/1937, and GDPR. Pricing is public: BASIC 160 PLN/month (1,760 PLN/year, 2 recipients), PRO 260 PLN/month (2,860 PLN/year, 4 recipients), and PREMIUM 360 PLN/month (3,960 PLN/year, 6 recipients), with a free first month and unlimited report volume on all tiers. No API documentation, formal sub-processor list with right to object, statutory deadline tracking, or retention/auto-deletion policy was found on public pages reviewed; the reporter interface is documented only in Polish. --- # Sygnalista - Website: https://www.sygnalista.com - Headquarters: Rzeszów, Poland - Hosting: Cloud deployment with SSL/TLS (SHA-256, 2048-bit RSA) and RDS databases, or on-premises on customer infrastructure; data-centre country and provider not disclosed (vendor-stated) - Pricing: Cloud 8 PLN per operator/month (7-day free trial). On-premises packages: Starter 400 PLN/month (2 operators), Standard 850 PLN/month (3 operators), Premium 1,400 PLN/month (6 operators). - Note: Package prices are stated per month but on 12 or 24-month contracts (Premium via dedicated agreement). Training is included with Standard and Premium. No month-to-month option found. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Poland (Ustawa o ochronie sygnalistów) - Last verified: 2026-07-19 - Sources: - https://www.sygnalista.com/ - https://www.sygnalista.com/dyrektywa - https://www.sygnalista.com/polityka-prywatnosci - https://www.itsmsoftware.pl/product/system-do-obslugi-sygnalistow - https://www.itsmsoftware.pl/product/mint-service-desk - https://www.itsmsoftware.pl/ Notable Operated by ITSM Software S.A., ul. Geodetów 1, 35-328 Rzeszów, Poland (KRS 0000908488, NIP 8133862101). The privacy policy names ITSM Software S.A. together with OPGK Rzeszów S.A. as joint data controllers at the same Rzeszów address. The product is a preconfigured whistleblowing channel built on the vendor’s own Mint Service Desk ticketing platform. Positioned as compliant with EU Directive 2019/1937; the directive page also references the Polish ustawa o ochronie sygnalistów, both named without article-level mapping. Deployment is offered as a cloud service (8 PLN per operator/month, 7-day free trial) or on-premises on customer infrastructure. On-premises packages are Starter (400 PLN/month, 2 operators), Standard (850 PLN/month, 3 operators), and Premium (1,400 PLN/month, 6 operators, dedicated agreement), all on 12 or 24-month contracts. Reporter features include full anonymity, a flexible violation catalogue, contextual intake forms, multi-format file attachments, unique ticket numbers, and two-factor return access via ticket number and password. Handler features include case management, moderation, configurable notifications, response-time monitoring, and full communication and processing history. Security page states SSL/TLS encryption with SHA-256 and 2048-bit RSA keys and RDS databases with SSL; the cloud data-centre country and hosting provider are not disclosed. No ISO 27001 or other ISO certification was found on public pages reviewed. Reporter interface is stated in Polish with an English version available; no wider EU-language coverage was documented. --- # Sygnalista 365 - Website: https://jeton.pl/oferta/sygnalista/ - Headquarters: Poland - Pricing: Three tiers billed monthly on annual contracts. Sygnalista 365: 110 PLN/month. Sygnalista 365 Pro: 150 PLN/month. Sygnalista 365 Pro+: 250 PLN/month. - Note: Special rate of 75 PLN/month for accounting offices and organisations with fewer than 75 employees. Placed #8 in the 2024 ODO24 ranking. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Poland (Act on the Protection of Whistleblowers, in force 25 September 2024); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://jeton.pl/oferta/sygnalista/ - https://jeton.pl/en/offer/signalman/ - https://odo24.pl/aplikacje-dla-sygnalistow/2024/sygnalista-365 Notable Sold via the parent brand Jeton. The standalone sygnalista365.pl domain was not kept as a source because it returned a DNS/browser-source error in this pass; the current Jeton offer page is the verified product page. The 75 PLN/month carve-out for accounting offices (biura rachunkowe) and organisations under 75 employees positions the product at the micro-SME floor of the Polish market. Jeton’s product page states that implementation is performed by an ISO 27001-certified partner. No public ISO 27001 certificate document or scope for Jeton/Sygnalista 365 was found on the pages reviewed. Public language evidence is limited to Polish and English product pages. German/Ukrainian reporter-interface coverage was not found on current public pages. Hosting location and data residency were not found on the current public product page reviewed. Placed #8 in the 2024 ODO24 independent ranking — not a podium finish, but validation versus a long tail of less-documented PL-domestic tools. Three-tier structure (Standard, Pro, Pro+) with prices published — rare among Polish vendors. --- # Sygnanet - Website: https://sygnanet.pl - Headquarters: Poland - Pricing: Annual billing, net of VAT. Standard: 4,000 zł/year (370 zł/month) for 2 report recipients. Premium: 7,000 zł/year (650 zł/month) for 4 recipients. Enterprise: 10,000 zł/year (920 zł/month) for 6 recipients; each additional recipient 1,000 zł/year. - Note: 25% discount for public bodies with fewer than 50 employees. Free trial available. - Languages on reporting form: 12 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Poland (Act on the Protection of Whistleblowers, in force 25 September 2024) - Last verified: 2026-09-18 - Sources: - https://sygnanet.pl/pl/ - https://sygnanet.pl/pl/price-list - https://sygnanet.pl/pl/questions-and-answers - https://sygnanet.pl/pl/polityka-prywatnosci Notable End-to-end encryption of reports and attachments; vendor states it has no access to report content. Two-factor authentication available as an option. Reporting form available in 12 languages; case-handler panel available in Polish, English, German, French (other languages possible on request). Anonymous, explicit, or optional-identity reporting modes; anonymous two-way correspondence between organisation and reporter. Report register, reports export, response templates, internal notes, delegation between handlers, full audit history. Periodic penetration testing. Automatic statutory deadline reminders (vendor-stated). Final investigation report generation (vendor-stated). Whistleblower identity data held separately from report content, with controlled disclosure logged against who accessed it and when (vendor-stated). External reporting channel for public authorities bundled free for public bodies that purchase the internal-reporting licence. Training materials provided for both case handlers and employees; sample internal procedure template included. Operator SpecFile Project Sp. z o.o. also operates specfile.pl. No ISO 27001 certification found on the public pages reviewed. No public API published. --- # tell it - Website: https://tell-it.eu - Headquarters: Hohen Neuendorf, Germany - Hosting: Servers in Germany (vendor-stated); specific hosting provider not named on public pages reviewed - Pricing: Essential EUR 40/month or EUR 480/year; Professional EUR 60/month or EUR 720/year; Enterprise on request. All prices plus 19% VAT. - Note: Each plan starts with a 30-day trial and no credit card is required. Tiers differ by case categories (10 vs 20), number of processors (2 vs 5), and per-file upload limit (15 MB vs 50 MB). The pricing page lists an 'ISO-27001 certified system' as an included feature. - Languages on reporting form: 30 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://tell-it.eu/en - https://tell-it.eu/en/pricing - https://tell-it.eu/en/whistleblower-system - https://tell-it.eu/en/whistleblower-system-for-companies - https://tell-it.eu/en/whistleblower-protection-act - https://tell-it.eu/en/imprint Notable Operated by Tell IT GmbH, Hohen Neuendorf, Germany (Amtsgericht Neuruppin HRB 13653 NP, VAT DE349655192); managing director Nico Werdermann. Positioned as a confidential, GDPR-compliant whistleblowing channel for meeting the German Whistleblower Protection Act (HinSchG); no HinSchG article/section numbers were cited on public pages reviewed. Standalone SaaS, not a reseller or white-label of another listed tool; separate landing pages address companies and law firms. Reporter features stated: anonymous reporting, two-way communication with the whistleblower through a protected login, and file upload (15 MB on Essential, 50 MB on Professional). Handler features stated: simple case processing from submission to conclusion, configurable case categories (10 or 20), multiple processors (2 or 5), and automated statutory deadline notifications. Multilingual reporting is stated as more than 30 languages. Public pricing shows three tiers: Essential (EUR 40/month or EUR 480/year), Professional (EUR 60/month or EUR 720/year), and Enterprise on request; all prices exclude 19% VAT. Every plan starts with a 30-day trial and no credit card is required. Hosting is stated as servers in Germany with SSL encryption; the specific hosting provider is not named on public pages reviewed. The pricing page lists an “ISO-27001 certified system” as an included feature, but no vendor certificate or certification scope is published on the pages reviewed; this most plausibly reflects the German hosting infrastructure rather than vendor/product certification. No public API documentation and no sub-processor list were found on public pages reviewed. --- # TELL US! - Website: https://tell-us.hu - Headquarters: Cakóháza, Hungary - Hosting: EU-based servers with no third-country transfers (vendor-stated) - Pricing: Single 'Quick easy' package at 29,000 HUF/month plus VAT (roughly EUR 73/month), including unlimited admin users and a free sample ethics and conduct code template. - Note: One flat package with no employee-based tiering. Purchase runs through sales@tell-us.hu, with a stated 2-day setup target after payment. A shared demo is available at demo.tell-us.hu. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Hungary (Act XXV of 2023) - Last verified: 2026-07-19 - Sources: - https://tell-us.hu - https://tell-us.hu/en - https://tell-us.hu/impresszum - https://demo.tell-us.hu Notable Operated by ARRABONA-WORK Kft., a Hungarian company (VAT 26355166-2-08, company registration 08-09-030073) based in Cakóháza, Hungary. Positioned as an anonymous whistleblowing channel compliant with EU Directive 2019/1937 and Hungary’s Act XXV of 2023, targeting organizations with 50+ employees. Reporting is web-based and works across desktop and mobile, with document and photo attachments and support for verbal reports. Reports are automatically routed to a predefined investigator with email notification, and investigators and reporters communicate two-way through the software using unique case identifiers. Configurable elements include report categories, branch locations, company logos, and organizational rules, and organizations can publish conduct or ethics policies on the reporting link. Statistics can be filtered and exported to Excel. Pricing is a single “Quick easy” package at 29,000 HUF/month plus VAT (roughly EUR 73/month) including unlimited admin users and a free sample ethics and conduct code template. Purchase runs through sales@tell-us.hu with a stated 2-day setup target after payment; a shared demo is available at demo.tell-us.hu. Data is stated to be stored on EU-based servers with no third-country transfers, but the specific EU country and a subprocessor list were not disclosed on public pages reviewed. No ISO 27001 certification was found on public pages reviewed, and API access was not advertised. Reporter-facing languages are Hungarian and English. --- # Tilkynna - Website: https://tilkynna.is - Headquarters: Iceland - Pricing: Grunnur ISK 15,900/month; Voxtur ISK 24,900/month; Sersnidid quote-only. All prices plus VAT, billed on annual commitment. - Note: Prices are in Icelandic krona (ISK), quoted per month but billed on an annual commitment, plus VAT. 30-day free trial on all tiers. Tiers scale by reporting areas, information pages, users, and storage rather than by employee count. The Custom (Sersnidid) tier is quote-only. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Iceland (Log nr. 40/2020 um vernd uppljostrara) - Last verified: 2026-07-19 - Sources: - https://tilkynna.is - https://tilkynna.is/en - https://tilkynna.is/eiginleikar - https://tilkynna.is/askriftarleidir - https://tilkynna.is/um-okkur - https://tilkynna.is/legal/privacy-policy Notable Operated by Slidesome ehf. (Icelandic company registration 410618-0790), which describes Tilkynna as the first Icelandic whistleblowing system. Positioned around Iceland’s whistleblower protection law (Log nr. 40/2020 um vernd uppljostrara, effective 1 January 2021), which the site links to on the Althingi (Icelandic Parliament) website; the vendor references the Icelandic law rather than EU Directive 2019/1937 directly, and Iceland applies whistleblower protection as an EEA state. Reporting is delivered through an online reporting form; organizations can run multiple reporting areas on per-department subdomains (for example separate areas for employees and contractors), each with its own questions, information pages, and access rules. Anonymous reporting is optional per organization, with an anonymous communication portal supporting two-way messaging and file sharing between the organization and the reporter. Reporter return access uses an identification number and password, with two-factor authentication and electronic-ID authentication available. Handler tooling includes case status (in process or completed), tagging, titles, internal comments, adding multiple managers to a case, and an immutable event log recording all actions. The privacy policy states all data is stored and transmitted encrypted, names a data protection officer, and states registered information is deleted from the database within 6 months of case closure. Pricing is published for two tiers: Grunnur at ISK 15,900/month and Voxtur at ISK 24,900/month, both plus VAT and billed on an annual commitment; a Custom (Sersnidid) tier is quote-only. A 30-day free trial is offered on all tiers. Listed clients include VIS, Perlan, Samherji, Oryggismidstodin, and Icelandair. No ISO 27001 certification, hosting-provider or data-residency disclosure, subprocessor list, or public API documentation was found on the pages reviewed. The whistleblower.is domain redirects to an access-protected deployment; tilkynna.is is the canonical public site and carries an English version at tilkynna.is/en. --- # Tissla - Website: https://tissla.se - Headquarters: Sundbyberg, Sweden - Pricing: Bas from 8,000 kr/year; Premium from 13,900 kr/year; Enterprise from quote. Currently no implementation fee on any tier. - Note: Prices are stated per year and marked as starting prices (från). Bas covers a single user, Premium up to 5 users, and Enterprise unlimited users. Purchase is initiated by booking a meeting; no self-serve signup or free trial was found on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-07-19 - Sources: - https://tissla.se/ - https://tissla.se/priser - https://tissla.se/omoss - https://tissla.se/info - https://tissla.se/kontakt Notable Operated by Tissla AB, Swedish organization number 559450-3970, registered at Sundbybergs Torg 1, C/O Helioworks, 172 67 Sundbyberg, Stockholm, Sweden. Contact is by email (hej@tissla.se or kontakt@tissla.se) and the primary call to action is to book a free meeting; no self-serve signup was found on public pages reviewed. Tagline is “Din globala plattform foer visselblaasning” (your global whistleblowing platform); the product is positioned for organizations of all sizes and marketed as multilingual and internationally usable. Named reference customers shown on the site include ICA, Hestra, and Elbit. Web-based, mobile-responsive SaaS with no local install; the pricing page states full anonymity and multilingual support from the entry tier. Three tiers: Bas (single user, self-managed case handling, whistleblower policy and communication materials, from 8,000 kr/year), Premium (up to 5 users, collaborative case handling, and an option to let Tissla handle cases, from 13,900 kr/year), and Enterprise (unlimited users and customizable whistleblowing forms, quote-only). All tiers currently state no implementation fee; pricing is quoted per year with starting-price (“från”) language and no monthly option was found. Premium adds an optional managed-service model where Tissla handles the organization’s cases, alongside the self-managed handling available on Bas. The site positions itself around whistleblowing compliance and legal guidance, but does not cite the EU Directive with article numbers or name Sweden’s transposition law (Lag 2021:890) on public pages reviewed. No ISO 27001 certification, hosting location, data-residency detail, sub-processor list, or DPA was found on public pages reviewed; the privacy policy URL returned 404 at time of review. --- # TrueSpeak - Website: https://truespeak.eu - Headquarters: Milan, Italy (Barcelona and Paris offices) - Hosting: The German locale states data is hosted in a Frankfurt am Main data centre. The English privacy policy says only that data is processed "mainly within the territory of the European Union" and names no provider or sub-processor. - Pricing: Starter €19/month or €190/year. Professional €39/month or €390/year. Voice €49/month or €490/year. Enterprise €119/month or €1,190/year. Annual billing is 17% cheaper than monthly. - Note: Both monthly and annual billing are offered on every tier. A 30-day money-back guarantee is advertised: "After registration, you have 30 days to request an instant refund." Plans differ by administrator seats, reporting languages and retention, not by compliance scope — only Starter is described as "No compliance". - Languages on reporting form: 8 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs. 24/2023, Modello 231 under D.Lgs. 231/2001); Germany (HinSchG, LkSG); France (Loi Sapin II) - Last verified: 2026-09-21 - Sources: - https://truespeak.eu/en - https://truespeak.eu/en/security-policy - https://truespeak.eu/en/privacy-policy - https://truespeak.eu/de - https://truespeak.eu/it - https://truespeak.eu/fr Notable Operated as a trade name of True Solutions S.r.l. (VAT IT14288140966, R.E.A. Milano 2772480), registered at Foro Buonaparte 59, Milan, with listed offices in Barcelona and Paris and a separate support number for each. The site ships in eight languages and each locale is positioned on its own national law rather than on the Directive alone: D.Lgs. 24/2023 and Modello 231 in Italian, HinSchG and LkSG in German, Loi Sapin II in French. The German locale is the only one that names a hosting location — a data centre in Frankfurt am Main. The English privacy policy states only that processing happens “mainly within the territory of the European Union”, names no sub-processor, and reserves the right to transfer to third countries under standard contractual clauses. Retention is set by plan rather than by the customer: 6 months on Starter, 5 years on Professional, Voice and Enterprise, counted from case closure, with a case auto-closing after 90 days of inactivity from both sides. The security page publishes a dated audit timeline (most recent 1 September 2026, next scheduled 1 October 2026) covering SAST, DAST, OWASP Top 10 and CVE cross-checks. Detailed reports are offered “upon request to qualified auditors”. No third-party certification is claimed. A mobile app for iOS and Android is documented, with on-device session storage, no analytics, and anonymous submission supported. The privacy policy discloses advertising-attribution processing and names opt-out endpoints for RB2B and Retention.com — website visitor-identification services that associate site activity with an email address. This applies to the marketing site, not the reporting surface. Status: not yet scored TrueSpeak was added from the September 2026 AI-citation coverage audit, where it was the single most-cited whistleblowing vendor absent from this directory. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in any country ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # TrustBox - Website: https://trustbox.report - Headquarters: Malzéville / Nancy, France - Hosting: OVHcloud, Roubaix, France, with backups in Strasbourg, Croix and Gravelines. Named on both the security page and the legal notice. - Pricing: €29, €59, €79 or €99 for 1-49, 50-249, 250-999 and 1,000+ employees. Every tier includes the full feature set; only headcount differs. The billing period is not stated on the pricing page. - Note: A 14-day free trial is advertised on the security page and self-serve registration is open at app.trustbox.report/register. The pricing page states the tiers differ only by company size, not by features: "La différence de prix entre les abonnements ne se base pas sur les fonctionnalités disponibles." No billing period, contract term or cancellation policy was published on the pages reviewed. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II, Loi Waserman) - Last verified: 2026-09-21 - Sources: - https://trustbox.report/fr/ - https://trustbox.report/fr/tarifs/ - https://trustbox.report/fr/securite/ - https://trustbox.report/fr/mentions-legales/ Notable One of the few profiles here where the hosting answer is complete: OVHcloud at Roubaix for primary data, with backups spread across Strasbourg, Croix and Gravelines, named consistently on the security page and in the legal notice. Pricing is deliberately flat on features. All four bands buy the same product and differ only by employee count, which removes the common pattern of putting two-way messaging or retention behind an upper tier. The security page describes AES-256 encryption in transit and at rest, TLS, firewalls and DDoS protection, continuous vulnerability assessment and penetration testing by security professionals, and optional two-factor authentication. Nothing is dated and no auditor or report is named. The ISO claims need reading carefully. The homepage prints ISO/IEC 27001, ISAE 3000 Type 1 and WCAG 2.1 as trust marks; the security page’s own wording is that “les serveurs de TrustBox sont configurés selon les normes ISO pertinentes, notamment ISO 27001, ISO 27017 et ISO 27018”, which is a statement about the hosting configuration rather than a certificate held by the vendor. No certificate number, scope or certification body is published. Intake covers a customisable category list that already includes harassment, fraud, conflict of interest, money laundering, corruption, environmental protection and influence peddling — close to the Article 2(1) set, though no article mapping is published. Two errors sit on public pages a buyer would read first: the Directive cited as “2019/19378”, and a legal notice that still carries its own template disclaimer telling the operator to adapt it. Status: not yet scored TrustBox was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the France ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Trustif - Website: https://trustif.ee - Headquarters: Tallinn, Estonia - Hosting: EU/EEA infrastructure via Render (privacy policy); the features page separately states Google Cloud Platform in the EU (vendor-stated) - Pricing: Basic EUR 69/month (0-49 employees); Premium EUR 119/month (50+); Business EUR 149/month (250+); Enterprise+ EUR 299/month (1,000+). Add-ons: extra reporting channel EUR 50/month, customisable form EUR 15/month. - Note: Pricing page has a monthly/annual toggle, but annual per-month figures were not shown in the static HTML reviewed. No free trial or setup fee stated. Enterprise+ includes one hour of partner (legal/accounting) services per month. - Languages on reporting form: 30 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Estonia (Whistleblower Protection Act, 2024) - Last verified: 2026-07-19 - Sources: - https://trustif.ee/ - https://trustif.ee/service/ - https://trustif.ee/pricing/ - https://trustif.ee/whistleblow/ - https://trustif.ee/whistleblow/estonia/ - https://trustif.ee/whistleblow/directive/ - https://trustif.ee/whistleblow/nis2/ - https://trustif.ee/privacy-policy/ - https://trustif.ee/terms/ - https://trustif.ee/contact/ Notable Operated by Trustif Solutions OÜ, Estonian registry code 17079460, at Valukoja tn 8/2, Tallinn; the site attributes development to Ernits OÜ. Positioned for private businesses, municipalities, and schools, and framed around Estonia’s whistleblower protection law (adopted 15 May 2024), the EU Directive 2019/1937, and NIS2, each with its own explainer page. The reporting channel supports anonymous submissions, two-way anonymous communication, attachment upload with identifying-metadata removal, report categorization and status tracking, and deadline reminders. Features page states more than 30 reporting languages, AES-256 encryption, a fully preserved system activity log, and admin SSO via Microsoft Azure and Google Workspace with MFA. Hosting is described inconsistently across pages: the privacy policy names Render for hosting infrastructure (EU/EEA), while the features page states all data is stored in the EU using Google Cloud Platform. ISO 27001 is presented as a property of the hosting servers rather than a Trustif vendor certification; the features page separately claims conformity with ISO 37002:2021 (whistleblowing management systems guidance) and GDPR. The privacy policy and terms publish a sub-processor list: Render (hosting), Resend (transactional email), and Cloudflare Turnstile (spam protection on public forms). Four tiers are publicly priced per month: Basic EUR 69 (0-49 employees), Premium EUR 119 (50+), Business EUR 149 (250+), and Enterprise+ EUR 299 (1,000+); Enterprise+ includes one hour of partner services per month. Add-ons are published: an extra reporting channel at EUR 50/month and a customisable form at EUR 15/month; higher tiers add company branding and unlimited administrators. The pricing page exposes a monthly/annual toggle, but annual per-month figures were not shown in the static HTML reviewed; no free trial or setup fee was stated. The vendor markets an optional partner network of legal and accounting advisers alongside the software. No public API documentation and no named EU hosting country were found on the public pages reviewed. --- # Trusty Compliance - Website: https://trusty.report - Headquarters: Hünenberg, Zug, Switzerland - Hosting: Hosted in an ISO 27001-certified Hetzner Online GmbH data centre in Germany (vendor-stated; the ISO certificate is the data centre's, not Trusty's). - Pricing: Three whistleblowing tiers, billed annually: LITE €29/month (1 user, 1 language, no case management or two-way dialogue), STANDARD €49/month (adds case management and two-way dialogue), ADVANCED €99/month (unlimited users, all languages, role-based permissions, NIS2 vulnerability reporting). Payable in credits: €1 each, from €0.80 at volume, valid 3 years, usable across Trusty tools. - Note: 7-day free trial. Vendor's own plans page says organizations subject to the EU Directive should select Standard or Advanced — Directive-grade compliance effectively starts at €49/month, not the €29 headline. Most Trusty tools are pay-as-you-go credits; whistleblowing is an annual service paid with credits. - Languages on reporting form: 6 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; NIS2 Directive (cybersecurity vulnerability reporting) - Last verified: 2026-06-06 - Sources: - https://trusty.report/ - https://trusty.report/pricing/ - https://trusty.report/plans/ - https://trusty.report/whistleblowing-solution/ - https://trusty.report/privacy-policy/ Notable Trusty publishes a three-tier whistleblowing matrix billed annually: LITE €29/month (1 user, 1 language, “a simple, secure channel for collecting and storing reports” — no case management or two-way dialogue), STANDARD €49/month (adds case management and secure two-way dialogue, marked “Recommended”), ADVANCED €99/month (unlimited users with role-based permissions, all languages, NIS2 vulnerability reporting). The plans page states: “Organizations subject to the EU Whistleblower Protection Directive should select Standard or Advanced” — by the vendor’s own framing, Directive-grade compliance starts at €49/month, not the €29 headline. Credits cost €1 each, from €0.80 at volume, are valid for 3 years, are prepaid and non-refundable, and can be used across screening, policies, training, and other Trusty tools. Whistleblowing is the exception called out as a standalone annual service (from the equivalent of €348/year in credits for LITE). No free plan: all plans carry a 7-day free trial only. (An earlier free whistleblowing channel appears discontinued.) Hosting is disclosed: “a high-security data centre in Germany, certified to the ISO 27001 standard”, operated by Hetzner Online GmbH. The ISO certificate is the data centre’s — no Trusty company/product certification is published. Homepage/footer language options are English, Spanish, German, French, Italian, and Portuguese; the reporting tool itself is limited to 1 language until the Advanced tier. Public pages reviewed did not disclose a DPA, subprocessor list, API access, company-level ISO/security certification, or AI use for the whistleblowing product. --- # Tu Canal de Denuncias - Website: https://tucanaldedenuncias.com - Headquarters: Plasencia, Caceres, Spain - Pricing: PYME: €150/year (up to 50 employees, maximum 3 handler/admin users). Empresa Plus: €450/year (50+ employees, maximum 10 handler/admin users). Prices exclude VAT. - Note: Annual billing only; both tiers public and quoted without VAT. Free trial offered ('Pruébalo gratis'). PYME covers a 100MB attachment limit, 25 email/SMS document signatures and 48-hour support; Empresa Plus adds 24-hour support, authority notifications and staff training. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Spain (Ley 2/2023) - Last verified: 2026-09-20 - Sources: - https://tucanaldedenuncias.com/ - https://tucanaldedenuncias.com/precio/ - https://tucanaldedenuncias.com/aviso-legal/ - https://tucanaldedenuncias.com/ejemplos-de-canal-de-denuncias-ley-2-2023/ Notable One of the few Spanish channels publishing both tiers’ pricing openly: €150/year for SMEs (≤50 employees) and €450/year for larger organisations. Fully anonymous reporting with encrypted bidirectional messaging once a report is validated. Handler tooling includes an action calendar, complaint statistics, and named handler roles (Responsables / Gestores). Explicit Ley 2/2023 positioning, with worked examples of canal-de-denuncias use cases. Operated by Me4Business, S.L. (CIF B10501450), a compliance consultancy whose legal notice gives Plasencia, Caceres; the Spanish commercial registry records a move of registered office to Badajoz in January 2025. The same entity also trades as Me4Equality, selling equality plans and pay audits, so the reporting channel sits alongside a consulting and training practice rather than being a standalone software business. The homepage counter claims 140 implemented channels and shows twelve client logos. The logos are unlabelled and the public pages carry no testimonials, named references, or case studies. Hosting country, ISO 27001, DPA, retention configuration, and subprocessor list were not disclosed on the public pages reviewed; reporter UI appears Spanish-only. The published privacy policy covers the marketing website rather than the reporting channel, naming only MailPoet and Google Analytics as processors. The handler app at app.tucanaldedenuncias.com advertises PHP 7.4.33 in its X-Powered-By response header. PHP 7.4 left security support in November 2022, so the runtime behind the reporting channel has been unpatched against new vulnerabilities for roughly four years. Running an end-of-life server runtime under an application that holds whistleblower identities is a maintenance and security signal. --- # UpTalkly - Website: https://uptalkly.com - Headquarters: Netherlands - Hosting: External secured EU server (vendor-stated); specific country and provider not disclosed - Pricing: Start EUR 59/month annual or EUR 69/month monthly (2-30 employees); Growth EUR 119/month annual or EUR 139/month monthly (31-60); Performance EUR 189/month annual or EUR 219/month monthly (61-200); Tailor-made quote-only (200+). - Note: All prices exclude VAT. Minimum contract term is 24 months. No implementation fee. Monthly billing costs more than the annual-equivalent monthly rate. No free trial found on public pages reviewed. - Languages on reporting form: 6 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Netherlands (Wet bescherming klokkenluiders) - Last verified: 2026-09-18 - Sources: - https://uptalkly.com/ - https://uptalkly.com/klokkenluidersoftware-functies/ - https://uptalkly.com/tarieven/ - https://uptalkly.com/Privacyverklaring/ - https://uptalkly.com/Gegevensverwerkingsovereenkomst/ Notable Operated by UpTalkly, a Netherlands-based vendor; the public site shows a 2025 copyright and no KvK or VAT number on the pages reviewed. Positioned as klokkenluiderssoftware for Dutch SMEs (MKB), non-profits, schools, and public organizations, marketed as compliant with the Wet bescherming klokkenluiders and the EU Whistleblowing Directive. The online reporting form supports anonymous and identified reporting, with submissions encrypted and routed to designated handlers rather than an inbox. Two-way communication (including anonymous) between reporter and handler is documented, along with file attachments. Case management is described with central handling, triage, assignment, priority, deadlines, and an audit trail showing who saw what and when. Security copy lists MFA, encryption, role-based access with fine-grained permissions, and separate authentication servers. Reporter interface is offered in six languages: Dutch, English, German, French, Polish, and Romanian; extra languages can be added. Hosting is described as an external secured EU server with privacy-by-design and data minimisation; the specific country, provider, and sub-processors were not disclosed on public pages reviewed. No ISO 27001 or other certification was found on the public pages reviewed. Pricing is published for three employee bands (Start, Growth, Performance) with annual and monthly billing; a Tailor-made tier for 200+ employees is quote-only. Terms state a 24-month minimum contract and no implementation fee; no free trial was found on public pages reviewed. A data processing agreement (Gegevensverwerkingsovereenkomst) is referenced as available. --- # Vispato - Website: https://www.hrworks.de/unternehmen/vispato/ - Headquarters: Germany - Hosting: DATEV-hosted servers, Germany - Pricing: Business: €79/month flat with unlimited users, cases, and storage. Enterprise: custom quote. - Note: 12-month minimum term. No free trial; demo required before signup. - Languages on reporting form: 18 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Germany (HinSchG / DCGK referenced); France (Sapin II); United Kingdom (FCA); United States (SOX Section 301) - Last verified: 2026-07-18 - Sources: - https://www.hrworks.de/unternehmen/vispato/ - https://vispato.com/en/home/ - https://vispato.com/en/pricing/ - https://vispato.com/en/our-security/ Status: not rated (acquired) Vispato is kept in the directory for the record but is not scored and is excluded from the rankings and comparison surfaces. Vispato GmbH was merged into HRworks GmbH (“Vispato GmbH wurde mit der HRworks GmbH verschmolzen”). As of 2026-07-18, vispato.com 301-redirects to an HRworks company page and www.vispato.com returns “Not Found”, so the standalone brand no longer exists. The whistleblowing product continues for existing customers under HRworks branding, with support handled through HRworks. But because it is no longer sold or operable as an independent Vispato product, a buyer cannot evaluate “Vispato” as a standalone option. Anyone considering it should evaluate the current HRworks Hinweisgebersystem instead. The public facts recorded below reflect the product as last reviewed on 2026-05-24, before the brand was retired. Notable Single flat price of €79/month regardless of organisation size; unlimited users, cases, and storage. Pricing page states no setup costs and no hidden fees. 18 languages available on the reporting form. Hosted on DATEV-managed servers in Germany; system can also be hosted in alternate regions to meet data-residency requirements. Vendor states ISO 27001 certification and WCAG 2.1 AA accessibility support. Part of HR WORKS, which the vendor describes as a DACH HR software group with 25 years of experience. Enterprise tier adds custom branding, multiple reporting portals, custom domain, custom reporting tools, SSO, and custom payment terms. Setup is described as immediate after signup. Partner program available. No public API documentation or non-web intake channel was found on public pages reviewed. --- # Visselblåsaren - Website: https://visselblasaren.se - Headquarters: Stockholm, Sweden - Hosting: Glesys data centre in Stockholm, Sweden (vendor-stated) - Pricing: Up to 49 employees SEK 7,000/year; 50-100 employees SEK 9,000/year; over 100 employees by quote (Begär offert). - Note: Annual billing only; no monthly option listed. No setup fee mentioned. Vendor offers to cover a competitor's remaining binding period when switching. No free trial found on public pages reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Lag 2021:890) - Last verified: 2026-07-19 - Sources: - https://visselblasaren.se - https://visselblasaren.se/visselblasartjanst - https://visselblasaren.se/priser - https://visselblasaren.se/sakerhet - https://visselblasaren.se/faqs - https://visselblasaren.se/partner-lawbox Notable Operated by Visselblåsaren SM AB, Swedish org. no. 559476-5538, based in Stockholm. Positioned as an independent, managed whistleblowing service where the vendor receives, reviews, and helps handle reports, with in-house lawyers assessing cases judged to be in the public interest. Marketed as compliant with the Swedish whistleblower law (visselblåsarlagen, Lag 2021:890) and GDPR; the underlying EU Directive 2019/1937 transposition is the legal basis. Reporting is offered through three channels: a 24/7 web form requiring no login, oral reports by phone, and documented in-person meetings. Anonymous reporting is supported, with encrypted two-way communication and a unique case code for reporters to follow their matter. Statutory timelines are referenced in the FAQ: a 7-day acknowledgment and a 3-month substantive feedback deadline. Personal data is stated to be deleted per GDPR at case closure, with a two-year maximum retention after a case is closed. Data is hosted at a Glesys data centre in Stockholm, Sweden; the vendor states Glesys holds ISO 27001 certification for its data centre and references ISO 37002 alignment for whistleblowing governance. No ISO 27001 certification of Visselblåsaren itself was found on public pages reviewed. Published pricing covers two annual tiers (SEK 7,000 for up to 49 employees; SEK 9,000 for 50-100 employees), with organizations over 100 employees directed to request a quote. Billing is annual only. The vendor states it will cover a competitor’s remaining binding period for customers switching to Visselblåsaren. Lawbox is described as a strategic partner offering digital legal support subscriptions, not the entity behind or the technology provider for Visselblåsaren. No free trial, API documentation, or full sub-processor list was found on public pages reviewed. --- # Visslan - Website: https://visslan.com - Headquarters: Sweden - Pricing: Banded by employee count: SEK 6,000/year (<50), SEK 8,000/year (50–249), SEK 11,000/year (250–499), SEK 15,000/year (500–999), quote for 1,000+. English page shows €600 / €800 / €1,100 / €1,500 equivalents. No startup fees or binding period. - Note: 14-day free trial. Unlimited users and reports; up to five system languages included free, with more available as add-ons. - Languages on reporting form: 5 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001-certified hosting (vendor-stated) - National laws referenced: Sweden (Lag 2021:890, visselblåsarlagen); EU Directive 2019/1937 - Last verified: 2026-06-06 - Sources: - https://www.visslan.com/en/home - https://www.visslan.com/en/price - https://www.visslan.com/pris - https://www.visslan.com/en/services - https://www.visslan.com/en/about - https://www.visslan.com/en-blog/visslan-gets-a-new-owner - https://www.visslan.com/en/agreements/privacy-policy Notable Acquired by Whistleblowing Solutions AB, the company behind Whistlelink, in June 2025; Visslan says existing customers keep the same platform, contracts, contacts, prices, and terms. Swedish domestic focus: headline law referenced is visselblåsarlagen (Lag 2021:890); EU Directive 2019/1937 also cited. Multi-channel intake: written reports, voice recordings, and in-person meeting option. Two-way anonymous communication via unique case codes. Included whistleblower policy templates; optional external case management by legal partners. Vendor-stated ISO 27001-certified hosting/infrastructure (AWS, servers in Sweden/EU). No public Visslan company/product ISO 27001 certificate document or certification scope was found. Vendor states alignment with ISO 37002; ISO 37002 is presented as a non-certifiable whistleblowing-management standard. Support response time advertised as under 2 hours average. Pricing covers <50 through 500-999 employees publicly; 1,000+ employees, non-profits, and custom requirements are handled by quote. Company registration: The Whistle Compliance Solutions AB, organisationsnummer 559327-2999. --- # VoxWel - Website: https://voxwel.com - Headquarters: Ilford, Essex, United Kingdom (footer also lists a Kuliyapitiya, Sri Lanka office); the privacy policy contact lists Lumora Ventures in San Francisco. - Hosting: Vendor-stated European hosting on the France-localized page; privacy policy names only generic cloud-provider categories and allows safeguarded international transfers. - Pricing: USD 1 per employee per month, billed as a single flat-rate plan with all features included; French page localizes this as approximately €0.92 per employee per month. - Note: 14-day free trial. Primary pricing is denominated in USD; France-localized page also presents an EUR equivalent. - Languages on reporting form: 200 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II, amended) - Last verified: 2026-06-05 - Sources: - https://voxwel.com - https://voxwel.com/fr/logiciel-lancement-alerte - https://voxwel.com/privacy-policy Notable VoxWel markets into France for Directive 2019/1937 and Loi Sapin II compliance, but its legal entity is not clearly disclosed on the public pages reviewed. The site footer (verified 2026-06-05) lists offices in Ilford, Essex (UK) and Kuliyapitiya (Sri Lanka) under “VoxWel by Lumora Ventures”, with no data-hosting location disclosed. Like other non-EU-headquartered vendors, EU customer data is exposed to third-country access regimes — the UK Investigatory Powers Act 2016 and the UK–US Data Access Agreement operating under the CLOUD Act framework. Pricing is a flat USD 1 per employee per month on the main page; the France-localized page presents approximately €0.92 per employee per month. 14-day trial is public; AES-256 / end-to-end encryption, GDPR readiness, EU Directive readiness, audit trail, QR onboarding, and a seven-stage workflow are public homepage claims. France page claims European hosting and 200+ languages. The privacy policy does not name hosting providers and separately describes international-transfer safeguards, so EU hosting is treated as vendor-stated and provider-unverified. Privacy policy processor disclosure is generic, not a named sub-processor list; no ISO certification or public DPA pack was found. Anonymous-reporting copy says identifying metadata is stripped, but the privacy policy still describes ordinary site/account log data including IP addresses. Treat the no-IP claim as specific to anonymous reports, not the whole website. --- # Walor - Website: https://www.walor.io - Headquarters: Copenhagen, Denmark - Pricing: Tiered by employee count, billed annually: €60/mo (1–49), €87/mo (50–249), €127/mo (250–499), €187/mo (500–999). Excluding VAT. - Note: All four tiers are published with no quote-only band up to 999 employees, and no per-report charge — the vendor states it would create the wrong incentive. Above 999 employees no price is published. A self-serve 14-day trial with full feature access is available at app.walor.io/register alongside a demo-booking path. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: undisclosed - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II) - Last verified: 2026-09-21 - Sources: - https://www.walor.io/ - https://www.walor.io/pricing - https://www.walor.io/security - https://www.walor.io/how-it-works - https://www.walor.io/legislation - https://www.walor.io/da Notable Walor ApS, Copenhagen. Acquired by the Danish software company Ziik in November 2024; the product continues under the name “Walor by Ziik” and is integrated with Ziik’s internal-communication platform. The pricing page is the most complete commercial surface of any Danish vendor in this directory: four employee bands published to 999 employees with no quote-only step, prices excluding VAT, and an explicit statement that reports are not charged per report because “it would create precisely the wrong incentive”. A self-serve 14-day trial with full feature access is offered at app.walor.io/register, alongside a demo-booking path. Setup is pitched at five minutes. Security page states EU-only hosting, end-to-end encryption, two-factor authentication as the login standard, and automatic deletion on GDPR time limits. It does not name a hosting country, a hosting provider, or any sub-processor. The ISO 27001 claim is worded as applying to the hosting rather than to Walor’s own information-security management system, and ISO 37002 is described as a standard the solution is “built on the principles of” rather than certified against. Neither is recorded as a vendor certification here. The Danish-language site cites EU Directive 2019/1937 but not Act No. 1436 of 29 June 2021, the Danish transposition — unusual for a Danish vendor selling into its home market. Loi Sapin II appears in the stated compliance coverage on both the English and Danish pages, although no French locale site was found among the five (UK, Denmark, Sweden, Netherlands, Germany). Public pages reviewed did not disclose a product language count, file upload, reporter return access, handler roles, internal notes, audit trail, API access, sub-processors, hosting country, or a customer count. --- # WeMoral - Website: https://wemoral.com - Headquarters: Poland - Hosting: EU-hosted case data in Frankfurt, Germany, per vendor feature page; privacy policy still describes safeguarded transfers outside the EEA for relevant personal-data processing. - Pricing: PRO plan €79/month net, or 20% less on annual billing. Enterprise custom. - Note: Public monthly pricing, self-serve free trial, and no cancellation fees are stated on the pricing page. - Languages on reporting form: 25 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Poland (Act on the Protection of Whistleblowers, in force 25 September 2024); EU Directive 2019/1937 (generic) - Last verified: 2026-09-18 - Sources: - https://wemoral.com/pricing - https://wemoral.com/whistleblower-software-features - https://wemoral.com/regulations/iso-37002 - https://wemoral.com/privacy-policy - https://wemoral.com/fr Notable Legally seated as WeMoral sp. z o.o. (Poland) — the pan-EU marketing positioning does not reflect a Swedish or Nordic legal presence. Dashboard and reporting page are marketed with 25-language coverage; the exact official-EU-language breakdown was not enumerated beyond the public language switcher. Free-trial signup path is self-serve, and the PRO plan is publicly priced at €79/month net with a 20% annual-payment discount. Enterprise customers can request a custom DPA, but a public sub-processor list was not found. Feature page states case data is stored in Frankfurt, Germany, inside the EU; privacy policy separately describes safeguarded transfers outside the EEA where necessary. ISO 37002 is discussed in educational content and WeMoral says it is not certifiable; no formal security certification was found. Vendor-page evidence - 2026-05-24 Current pricing page shows 79 € /mo net for PRO, 25 languages, Try for free, 2FA, antivirus protection, activity log, corrective-actions registry, no cancellation fees, and 20% discount for a 12-month subscription. Current feature page states EU data residency in Frankfurt, encrypted two-way communication, no IP logging on reporting forms, metadata stripping for uploaded files, one-time case-code follow-up, and irreversible deletion after the retention period. Pricing FAQ states Enterprise customers can sign a custom DPA and that Standard Contractual Clauses are included for cross-border transfer edge cases. The privacy policy identifies WeMoral sp. z o.o. in Lodz, Poland and discusses transfers outside the EEA, but it does not disclose a named public sub-processor list. Bulgarian, French, Romanian, and Romanian pricing pages returned live vendor pages during this pass. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no public handler environment reviewed). Base score: 29 / 50 in France, Bulgaria, and Romania contexts. France country bonus: 2 / 8. Bulgaria country bonus: 2 / 6. Romania country bonus: 3 / 6. Category Score Max A. Legal compliance 8 16 B. Reporter experience (BG) 7 10 B. Reporter experience (FR) 7 10 B. Reporter experience (RO) 7 10 C. Handler experience 4 10 D. Security 4 8 E. Commercial 6 6 Evidence supporting the score: buyers can see concrete monthly pricing, start a trial without a sales process, cancel without fees, and confirm core security/handling features. The feature page gives a concrete EU data-residency claim for case data. Unverified from public pages: explicit Bulgaria-law posture, explicit France Waserman / Sapin II posture, deeper Romania-law positioning, named sub-processors, and formal security certifications. Buyer fit: price-sensitive organisations that care about quick evaluation and do not require detailed Bulgaria, France, or Romania law posture. Buyers needing explicit country-law mapping or more complete public security posture should confirm directly. Romania addendum - 2026-05-24 WeMoral now qualifies for the Romania ranking because the Romanian-language homepage and pricing page are live, and the vendor publicly markets a self-serve evaluation path in Romanian. The Romania fit is still more commercial than legal: Law 361/2022 appears in public legal content, but not as a core Romania-law product position. Romania modifier set at 3 / 6: UI yes, law signal partial, residency still undisclosed. Bulgaria addendum - 2026-05-24 WeMoral now also qualifies for the Bulgaria ranking because the Bulgarian-language homepage is live, the login CTA deep-links into the product with lang=bg, and the public site says the dashboard and reporting page support 25 languages. The Bulgaria fit is commercial rather than legal: pricing, trial, and language signal are all real, but there is still no Bulgaria-specific law page or named hosting country. Bulgaria modifier set at 2 / 6: UI yes, law no, residency undisclosed. --- # Whiblo - Website: https://whiblo.pl - Headquarters: Poland (Kraków) - Pricing: Legacy public price page states Minimum 2,388 zł/year, Standard 5,988 zł/year, Premium 10,788 zł/year, net of VAT; two-year subscriptions reduce the monthly equivalent to 169 / 424 / 764 zł. Current navigation points buyers to kup.whiblo.pl. - Note: The live checkout subdomain is public, but package details are rendered client-side. Treat the legacy /cennikold/ prices as vendor-published but confirm current pricing directly before procurement. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Poland (Act on the Protection of Whistleblowers, in force 25 September 2024) - Last verified: 2026-09-18 - Sources: - https://whiblo.pl - https://kup.whiblo.pl - https://whiblo.pl/cennikold/ - https://odo24.pl/aplikacje-dla-sygnalistow/2024/whiblo Notable ODO24 ranking pages list Whiblo in the 2022, 2023, and 2024 editions. The main marketing site hands off to a separate checkout subdomain (kup.whiblo.pl) for package selection. The older /cennikold/ price page remains public and states Minimum / Standard / Premium annual subscriptions plus one-time installation fees. Sales contact is direct: phone +48 578 800 019, sprzedaz@whiblo.pl, Kraków office. Polish and English website toggle; no additional EU-language coverage confirmed. Vendor positions the product for the Polish Act on Protection of Whistleblowers rather than broader EU transpositions. --- # Whisly - Website: https://whisly.hu - Headquarters: Hungary - Pricing: Hungary pricing: 0-50 employees HUF 19,000/month, 50-500 HUF 29,000/month, 500-1000 HUF 39,000/month, 1000+ custom. Slovakia pricing: 0-50 employees €49/month, 50-500 €79/month, 500-1000 €119/month, 1000+ custom. - Note: Public employee-band pricing is published on Hungarian and Slovak pricing pages; Hungarian prices exclude VAT, while the Slovak page says VAT is not charged. Demo / reporter-surface trial links are public, but no full self-serve product trial was found. - Languages on reporting form: 5 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: undisclosed - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Hungary (2023. évi XXV. törvény); Slovakia (Zákon č. 54/2019, as amended); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://whisly.hu - https://whisly.hu/arak/ - https://whisly.hu/2023-evi-xxv-whistleblowing-torveny/ - https://whisly.hu/visszaeles-bejelentesi-iranyelv/ - https://whisly.hu/rolunk/ - https://whisly.sk - https://whisly.sk/cennik/ Notable Operated by Whisly Kft. Headline regulatory reference: 2023. évi XXV. törvény a panaszokról, a közérdekű bejelentésekről, valamint a visszaélések bejelentésével összefüggő szabályokról. Language selector covers Hungarian (primary), Slovak, English, French, Portuguese. Claimed feature set: custom-branded reporting links, automated investigation task lists, document templates, role-based access controls, statistics/analytics, unlimited users, unlimited report types/channels, attachments, notifications, and email send/receive. Hungarian and Slovak pricing pages publish monthly employee-band prices; larger organisations move to custom offers. The Slovak pricing page includes a 0-50 employee tier at €49/month; the older entry only listed tiers from 50 employees upward. Slovak market served through a separate whisly.sk domain. No hosting provider, data-residency statement, full self-serve trial, founding year, customer count, API documentation, AI posture, or formal certifications were found on the public pages reviewed. --- # Whisper - Website: https://thorsoft.it/soluzioni/whistleblowing/ - Headquarters: Legnano, Italy - Pricing: Whisper 100: €500/year + VAT for up to 100 employees; Whisper 250: €900/year + VAT for up to 250 employees; Enterprise: custom. - Note: The public page shows discounted prices from €700/year and €1,200/year respectively. Stripe checkout links are published for the 100 and 250 packages. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ACN certification (vendor-stated), ISO 9001, ISO 27001, ISO 27017, ISO 27018 - National laws referenced: Italy (D.Lgs 24/2023); Italy (ANAC directives); EU whistleblowing requirements - Last verified: 2026-05-24 - Sources: - https://thorsoft.it/soluzioni/whistleblowing Notable Thorsoft positions Whisper as an ACN-certified whistleblowing solution for Italian organisations, with package pricing published directly on the product page. The public page lists two standard packages: Whisper 100 at €500/year + VAT for up to 100 employees and Whisper 250 at €900/year + VAT for up to 250 employees. Enterprise remains custom. Included features listed publicly include Italian/English languages, custom URL, 2FA, activity register, end-to-end encryption, AES 256 encryption, QR code, automatic routing, email notifications, unlimited anonymous reports, and multi-company support. Thorsoft publishes ISO 9001, 27001, 27017, and 27018 badges and describes the software as ACN approved/certified; the linked ACN catalogue page was not accessible in this review, and the catalogue level, validity dates, hosting country, DPA, and subprocessor list were not disclosed on public pages reviewed. Public legal coverage is D.Lgs 24/2023, GDPR, ANAC directives, and general EU whistleblowing requirements. D.Lgs 231/MOG 231 coverage was not found on the public Whisper page reviewed. --- # Whispero - Website: https://whispero.cz - Headquarters: Prague, Czechia - Hosting: Data stated to remain within the EU (vendor-stated); provider and country not disclosed on public pages reviewed - Pricing: BASIC from 490 CZK/month; STANDARD from 990 CZK/month; PREMIUM from 2,490 CZK/month. - Note: Monthly prices only, all shown as starting-from (od) figures. BASIC includes unlimited users and 1 GB storage; STANDARD adds a recorded phone line, custom subdomain, and 10 GB storage; PREMIUM is a managed outsourcing tier with a qualified legal professional handling cases. A 14-day free trial is offered. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Czechia (Act No. 171/2023 Coll., zákon o ochraně oznamovatelů) - Last verified: 2026-07-19 - Sources: - https://whispero.cz - https://whispero.cz/cenik - https://whispero.cz/whistleblowing-software-funkce - https://whispero.cz/whistleblowing-zdarma - https://whispero.cz/ochrana-osobn-ch-daj-a-cookies Notable Operated by Parhesys s.r.o., a Czech company (IČO 09903534) registered at Kozí 853/19, Staré Město, 110 00 Praha 1. Positioned as a “smart” whistleblowing solution combining proprietary software with legal expertise, aimed at fulfilling the Czech whistleblower protection act (zákon o ochraně oznamovatelů, Act No. 171/2023 Coll., named by title on public pages, not by article number). Offers three reporting channels: an online reporting form, an email address, and an automated telephone line; STANDARD and above add a recorded phone line. Three published tiers, all as starting-from monthly prices: BASIC from 490 CZK, STANDARD from 990 CZK, and PREMIUM from 2,490 CZK per month. BASIC includes unlimited users, electronic archiving, form customization, export, legal templates, and 1 GB storage; STANDARD adds a recorded phone line, legal supervision, 24/7 priority support, a custom subdomain, and 10 GB storage. PREMIUM is a managed outsourcing tier where a qualified legal professional handles case resolution and regular reporting, described as compliant with ISO 37002. A 14-day free trial is offered, reachable through a self-serve “Začít ZDARMA” start; a free consultation reviewing existing solutions is also offered. Features page states reporting forms in any number of languages with AI-powered automatic translation, a centralized case-management dashboard, role-based access, and data remaining within the EU. Vendor claims compliance with ISO 37002 (whistleblowing management guidance); no ISO 27001 security certification was found on public pages reviewed. The privacy policy cites GDPR (Regulation 2016/679) and lists a DPO contact, but no hosting provider, specific EU country, or sub-processor list was disclosed on public pages reviewed. --- # Whispli - Website: https://www.whispli.com - Headquarters: Sydney, Australia (Paris office) - Pricing: Plan names are public (Essential, Standard, Advanced, Enterprise), but amounts are not published; pricing remains sales-led. - Languages on reporting form: 70 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: yes - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, SOC 2 Type II - National laws referenced: EU Directive 2019/1937; France (Loi Sapin II); France (Loi Waserman); Germany; United States (SOX); Australia; United Kingdom FCA rules - Last verified: 2026-05-24 - Sources: - https://www.whispli.com/use-case/whistleblowing - https://www.whispli.com/whistleblowing-management-system - https://www.whispli.com/whistleblower-platform-features - https://www.whispli.com/whistleblowing-hotline - https://www.whispli.com/security/ - https://www.whispli.com/pricing/ - https://www.whispli.com/fr/loi-waserman-protection-lanceur-alerte-2022/ - https://www.whispli.com/data-processing-addendum-europe Notable Whispli now uses current product paths such as /use-case/whistleblowing, /whistleblowing-management-system, and /whistleblowing-hotline; the previously listed /solutions/whistleblower/ URL returned 404. Product pages state 300+ organisations, deployment in 60+ countries, 70+ languages, anonymous two-way Safe Inbox, web/mobile/email/QR/Voice AI intake, configurable forms, automated case creation, routing, SLAs, retention, and audit-ready logs. The security page states ISO 27001 certification, SOC 2 Type II certification, customer-managed encryption keys, 2FA, SSO, API/integrations, penetration testing, metadata removal, secure translation on Whispli infrastructure, regional hosting, and data-residency controls. France-specific pages name Loi Waserman and Sapin 2. Public pages also reference the EU Whistleblower Protection Directive, GDPR, SOX, UK FCA rules, Australian laws, and ISO 37002 principles. Whispli’s pricing page names Essential, Standard, Advanced, and Enterprise plans, but no public amounts were found. No public self-serve trial was found. --- # WhistBoard - Website: https://whistboard.com - Headquarters: Poland - Pricing: Published monthly pricing: Standard PLN 399/month, Premium PLN 799/month, Enterprise PLN 1,199/month. Legal handling services are individually priced. - Note: Standard licence is normally one year. Public prices are promotional against stated previous 30-day prices. - Languages on reporting form: 7 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 (Deviniti technology partner), WCAG 2.1 AA - National laws referenced: Poland (whistleblower protection act); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://whistboard.com - https://whistboard.com/en/pricing/ - https://whistboard.com/en/faq-en/ - https://whistboard.com/cennik/ - https://olesinski.com/aktualnosci/whistboard-na-podium-w-rankingu-aplikacji-dla-sygnalistow/ Notable Joint product between a software house (Deviniti) and a law firm (Olesiński i Wspólnicy); public materials position legal review as part of the Poland-focused offer. Pricing is now public: PLN 399, PLN 799, and PLN 1,199/month for Standard, Premium, and Enterprise respectively, with legal handling quoted individually. FAQ says a 7-day test access is available after requesting it through the contact form. No self-serve checkout was found. Security and operations disclosures include Deviniti ISO 27001 certification, European AWS region hosting, encrypted browser/server transmission and storage, separate encrypted databases per account, and limited logs. WhistBoard states that the reporter form meets WCAG 2.1 AA accessibility standards. Language disclosures are inconsistent: the pricing page lists seven language versions, while the FAQ says the application is currently available in five languages and other languages can be ordered. Olesiński’s 2022 article reports an ODO24 second-place ranking; no current ranking claim was verified on the vendor pages reviewed, so this should not be read as a current rating. --- # Whistle UP - Website: https://whistleup.eu/ - Headquarters: Bucharest, Romania - Pricing: Published monthly pricing: €49/month + VAT for a single entity, €99/month + VAT for groups with up to 5 entities, custom quote for larger or outsourced-service use cases. - Note: Vendor says there is no minimum duration. No free trial was disclosed on the public pages reviewed. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Romania (Law 361/2022); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://whistleup.eu/ - https://app.whistleup.eu/ Notable Public monthly pricing remains clear: €49/month + VAT for one legal entity, €99/month + VAT for groups with up to five legal entities, and custom pricing for larger groups or outsourced-service providers. The public site directly cites EU Directive 2019/1937 and Romania Law 361/2022, and frames Whistle UP for private-sector employers with at least 50 employees, regulated private-sector entities regardless of headcount, and public-sector organisations. Reporter intake is described as link/QR based and available on desktop and mobile. The public app shell shows anonymous reporting, report-status checking, a handler login, and a public promise that the reporter will receive a response within three months. Public handler claims include configurable access rights, designated-person-only access to report contents, analysis and resolution inside the platform, and the ability to forward reports to competent authorities. Public pages reviewed did not disclose ownership/legal entity, hosting country, ISO certifications, DPA, DPIA template, subprocessor list, retention controls, public API, or a free trial. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages and public app shell only; no authenticated handler account or live reporter submission reviewed in this pass). Base score: 19 / 50. Romania country bonus: 4 / 6. Category Score Max A. Legal compliance 5 16 B. Reporter experience (RO) 5 10 C. Handler experience 3 10 D. Security 2 8 E. Commercial 4 6 Evidence supporting the score: public Law 361/2022 / Directive positioning, Romanian-first UI, anonymous reporting, status checking, configurable access-right claims, and transparent monthly pricing. Unverified from public pages: hosting country, certifications, retention controls, append-only audit, DPA/DPIA, subprocessor list, deadline-reminder automation, detailed register fields, and free-trial availability. --- # whistle.law - Website: https://whistle.law - Headquarters: Germany - Hosting: Germany; provider not named on public pages reviewed - Pricing: EUR 50/month for up to 99 employees, EUR 100/month for up to 249 employees, EUR 150/month for up to 999 employees; 1,000+ quote-based. - Note: 30-day free test advertised. Public pricing page says no hidden costs; add-on legal reporting channels such as ESG / LkSG are price-on-request. - Languages on reporting form: 24 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Germany (HinSchG); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.whistle.law/ - https://www.whistle.law/preise - https://www.whistle.law/funktionen/dsgvo-sicherheit - https://www.whistle.law/avv Notable whistle.law is operated by whistle.law GmbH according to the current pricing page footer. Public pricing is available from EUR 50 to EUR 150/month for organisations up to 999 employees; 1,000+ employees require an individual quote. The online reporting form can be configured in all official EU languages according to vendor copy reviewed. Security page documents German servers, ISO 27001, 2FA, encrypted storage, automated deadlines, and revision-safe documentation. Vendor publishes a DPA/AVV page. The public pages reviewed do not name the hosting provider or subprocessors and do not publish API documentation. I did not find public evidence for phone, email, or oral intake beyond the web portal and topical add-on channels such as ESG/LkSG. --- # Whistleblow.ro / avertizori.eu - Website: https://www.whistleblow.ro/ - Headquarters: Bucharest, Romania - Hosting: Avertizori security page says data is stored on EU servers in Germany; the DPA lists Romarg (Romania), Hetzner (Germany), and Netcup GmbH (Germany) among current subprocessors. - Pricing: Public pricing is split across two vendor domains: avertizori.eu lists RON 990/year excluding VAT for the annual software subscription plus RON 190 one-time documentation; whistleblow.ro lists RON 2,990/year including 19% VAT for the technical-implementation annual subscription plus RON 990 one-time documentation, invoiced in LEI. Outsourced handling is quote-based. - Note: Whistleblow.ro acts as the marketing shell; avertizori.eu carries the self-serve checkout and 14-day trial, while app.whistleblow.ro exposes a live software demo. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISO 37001 - National laws referenced: Romania whistleblower law (law number not disclosed on public pages reviewed); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.whistleblow.ro/ - https://www.whistleblow.ro/securitate-aplicatie-avertizori-integritate - https://www.whistleblow.ro/termeni-si-conditii-aplicatie-whistleblowing - https://avertizori.eu/ - https://avertizori.eu/abonamente/ - https://avertizori.eu/termeni-conditii/ - https://avertizori.eu/acordul-de-procesare-a-datelor-dpa/ - https://app.whistleblow.ro/ Notable whistleblow.ro exposes pricing and links its demo to app.whistleblow.ro, while avertizori.eu handles login, signup, checkout-style subscriptions, and the 14-day free account path. The product is sold under two parallel domains, and the pricing does not line up cleanly between them. whistleblow.ro behaves like the acquisition / marketing layer, while avertizori.eu is the actual self-serve SaaS commercial surface. That inconsistency is still relevant buyer information. The security and DPA pages state EU hosting in Germany, 2FA, audit logs, PGP-encrypted emails, end-to-end encryption claims, vendor-stated ISO 27001 / ISO 37001 certifications, and a public subprocessor list. The offer is not just software. DOTCOM IT PRO also sells documentation drafting, authorised-person designation support, and outsourced case administration. Market positioning is price-led: public copy uses “simplest”, “cheapest”, “safest”, quick implementation, and fast operational readiness as sales claims. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages, legal terms, and public app endpoint only; no authenticated handler review). Base score: 23 / 50. Romania country bonus: 5 / 6. Category Score Max A. Legal compliance 6 16 B. Reporter experience (RO) 4 10 C. Handler experience 3 10 D. Security 7 8 E. Commercial 3 6 Evidence supporting the score: buyers can see pricing on whistleblow.ro, reach a live demo at app.whistleblow.ro, and inspect hosting and security claims without waiting for sales. Unverified from public pages: deadline automation, detailed status workflow, internal notes, and role granularity. Public terms describe the 16-digit reporter access model, and the two-domain commercial surface requires buyer attention. --- # Whistleblower Software (Formalize) - Website: https://whistleblowersoftware.com - Headquarters: Copenhagen, Denmark - Pricing: Core: €99 / €149 / €199 / €249 / €349 per month for 0-49 / 50-149 / 150-249 / 250-499 / 500-999 employees. Advanced: €149 / €219 / €299 / €379 / €529 for the same bands. 1,000+ employees contact sales. Billed annually. - Note: Annual billing only: the pricing page states "We always charge one year at a time and the payment is made in advance for the whole year." Try For Free CTAs are present; trial length and credit-card requirement were not disclosed on public pages reviewed. - Languages on reporting form: 80 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001:2022, ISAE 3000 Type 2, ENS audited, WCAG 2.1 AA - National laws referenced: EU Directive 2019/1937; Germany (HinSchG); Spain (Ley 2/2023 de Protección al Informante); France (Loi Waserman / Sapin II); Greece (Law 4990/2022) - Last verified: 2026-09-21 - Sources: - https://whistleblowersoftware.com/en/prices - https://whistleblowersoftware.com/en/security - https://whistleblowersoftware.com/en/product - https://whistleblowersoftware.com/en/personal-data-policy - https://whistleblowersoftware.com/en/eu-whistleblowing-directive-summary - https://whistleblowersoftware.com/fr - https://whistleblowersoftware.com/el - https://whistleblowersoftware.com/es - https://formalize.com/en Notable Formalize presents Whistleblower Software as one product inside a broader compliance suite covering DORA, NIS2, GDPR, GRC, ISO 27001, SOC 2, ISMS, and AI Act workflows. The marketing site ships in 12 languages, and each locale names its own national transposition law rather than only the EU Directive: Loi Waserman (Sapin II) in French, Law 4990/2022 in Greek, Ley 2/2023 in Spanish, HinSchG in German. 80+ reporting languages are available, but the product page states only 10 are included as part of a standard setup. Core covers end-to-end encryption, SSO (OAuth 2.0), anonymized reporting and case management. SAML 2.0, SCIM 2.0, a custom DPA, a dedicated CSM and an SLA are Advanced-tier only. Hotline and international management are separate add-ons. The product page documents two-way messaging that continues to work when the reporter is anonymous, file upload, voice reporting, automatic case delegation and deadline reminders. The security page states data and backups are stored with AWS in Frankfurt, with end-to-end encryption, MFA, IP whitelisting, activity logs, and a June 2024 penetration test by Truesec. The personal data policy confirms sub-processors exist, including in third countries, but names none and describes no objection mechanism. Deletion is vendor-set at no later than 3 years after subscription termination. Public pages reviewed did not disclose API access, a downloadable DPA, DPIA support, or how a reporter returns to an existing case. --- # Whistleblowing24 - Website: https://www.whistleblowing24.it - Headquarters: Manziana (RM), Italy - Pricing: Not published. - Note: No self-serve pricing, checkout, or trial tier disclosed on the public site. - Languages on reporting form: 1 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Italy (D.Lgs 24/2023); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://www.whistleblowing24.it - https://www.whistleblowing24.it/privacy.html Notable The public site describes a web reporting channel for D.Lgs 24/2023 with an anonymous form, shareable link, printable QR code, reporter receipt, and tracking page. Handler functions disclosed publicly include viewing the history of reports, taking a report in charge, adding a corrective action, setting a resolution deadline, printing reports as PDF, viewing attachments, filtering by date, and exporting report data to Excel. The privacy page identifies MFFM SRLS, based in Manziana (RM), as technical controller/processor for the portal, states that data are not transferred to third countries, and gives retention only by reference to D.Lgs 24/2023 and applicable law rather than a specific product retention control. Public pages reviewed did not disclose pricing, hosting location, public API, certifications, DPA/subprocessor list, free trial, voice reporting, or languages beyond Italian. --- # whistlebox - Website: https://www.whistlebox.de - Headquarters: Dachau, Germany - Hosting: German data centre (vendor-stated); hosting provider not named on public pages reviewed - Pricing: Up to 50 employees EUR 69/year; 51-250 EUR 249/year; 251-500 EUR 499/year; 501-1,000 EUR 999/year; 1,000+ quote-only. Prices are annual on a 12-month contract. - Note: Billed annually on a 12-month contract with automatic renewal and a four-week cancellation notice. A 14-day free self-serve test account is offered with no automatic renewal and no credit card required at signup; a live demo/consultation is also available. - Languages on reporting form: 12 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://www.whistlebox.de/ - https://www.whistlebox.de/funktionen/ - https://www.whistlebox.de/hinweisgebersystem_software/ - https://www.whistlebox.de/kostenloser-testaccount/ - https://www.whistlebox.de/ueber-uns/ - https://www.whistlebox.de/impressum/ - https://www.whistlebox.de/datenschutz/ Notable whistlebox is a digital whistleblowing reporting system marketed to the German Mittelstand for implementing the EU Whistleblowing Directive and HinSchG (German Whistleblower Protection Act). The Impressum names DSM-Online GmbH (Fraunhoferstrasse 9, 85221 Dachau, Germany; managing directors Mirko Tasch and Oliver Sauer; VAT DE312905465; HRB 234478, Amtsgericht Muenchen); the “Ueber uns” page describes whistlebox as a product of DSM-Online GmbH while the site copyright credits CPExperts GmbH. Reporting is anonymous and end-to-end encrypted, with an anonymous two-way live chat so handlers can request follow-up information while preserving anonymity; reporters can voluntarily waive anonymity. Handlers get a central dashboard showing new, ongoing and closed cases with filter functions, status changes, PDF export, multi-tenant support, and customisable branding and questions. Reporters can upload documents, images and other evidence, and two-factor authentication is listed among the technical security measures. Deadline handling is supported through a calendar function that tracks cases against the Directive’s statutory deadlines, and processors are notified when new reports arrive. Reporter intake is stated in 12 languages: German, English, French, Spanish, Italian, Turkish, Dutch, Norwegian, Greek, Polish, Hungarian and Ukrainian. Pricing is published by headcount and billed annually: EUR 69 (up to 50), EUR 249 (51-250), EUR 499 (251-500) and EUR 999 (501-1,000) per year, with 1,000+ employees quote-only; contracts run 12 months with automatic renewal and a four-week cancellation notice. A 14-day free self-serve test account is available (first name, last name and email) with no automatic renewal; a live demo/consultation is also offered. Hosting is stated to be in a German data centre with daily backups and described as ISO 27001 certified; this certification is attributed to the data centre, not to the vendor, and the hosting provider is not named on public pages reviewed. No ISO 27001 vendor certification, configurable retention with automatic deletion, role-based access control, internal handler notes, or API access were found on the public pages reviewed. --- # Whistlechannel - Website: https://whistlechannel.eu - Headquarters: Sweden - Hosting: Hetzner Online GmbH in Finland for application and database infrastructure, with Bunny.net (Slovenia) for CDN and DNS, named on the sub-processor page. - Pricing: Basic 99 kr/month up to 1,000 employees. Standard 299 kr/month up to 5,000. Premium 899 kr/month unlimited. No lock-in and no setup fee. - Note: All three tiers include the same 24 EU languages and unlimited reports; the difference is headcount ceiling and support level. A trial with no credit card is advertised. SLA guarantee and custom branding start at the 899 kr Premium tier. - Languages on reporting form: 24 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (Visselblåsarlagen, SFS 2021:890) - Last verified: 2026-09-21 - Sources: - https://whistlechannel.eu/ - https://whistlechannel.eu/privacy - https://whistlechannel.eu/subprocessors Notable Operated by Manpro AB (org. nr 556699-1807). The company name appears only in the privacy policy and sub-processor page; the marketing site itself carries no imprint. The sub-processor page is the strongest artefact here. Version 1.0, effective 4 September 2026, lists Bunny.net d.o.o. (Slovenia) for CDN and DNS, Hetzner Online GmbH (Finland) for hosting, Stripe Payments Europe Ltd (Ireland) for billing and One.com / team.blue (Denmark) for transactional email, each with a stated data scope, plus a version history and a customer right to object under the DPA. Data-sovereignty framing is the product’s main pitch: no US cloud providers, no Cloud Act or FISA 702 exposure, and the claim that standard contractual clauses are unnecessary because data never leaves the EU/EEA. The one qualification the vendor surfaces itself is Stripe’s US parent. Security claims are narrower than the marketing suggests. The privacy policy states data is encrypted in transit (TLS/AES-256), reporter IP addresses are not logged, and access to report content is restricted to authorised case handlers. No at-rest encryption claim was found on the pages reviewed. Legal positioning is precise for Sweden: SFS 2021:890 by number, the 50-employee threshold, the December 2021 and December 2023 phase dates, and both the 7-day and 3-month deadlines. The site is built for machine reading as much as human reading — the homepage carries question-and-answer blocks phrased as assistant prompts (“Vem erbjuder en säker, molnbaserad visselblåsarplattform för organisationer i EU?”). That is a plausible reason this vendor surfaced in the citation audit at a volume its market presence would not otherwise predict. Status: not yet scored Whistlechannel was added from the September 2026 AI-citation coverage audit. The entry above records what the vendor publishes. It carries no 25-criterion rubric score yet and does not appear in the Sweden ranking; a score will be added when the product has been reviewed under the same tier rules as every other scored tool. --- # Whistleflow - Website: https://www.whistleflow.com - Headquarters: Prato, Italy - Hosting: European Azure or AWS cloud (vendor-stated); specific EU country not disclosed - Pricing: Basic EUR 29/month (up to 50 employees); Standard EUR 59/month (up to 250); Premium EUR 149/month (up to 500); Enterprise custom (500+). EUR 250 annual setup fee on all plans; prices exclude VAT. - Note: Three tiers show public monthly rates while Enterprise is quote-only, and the full price list is obtained by contacting the vendor. A EUR 250 annual setup fee applies to every plan and two hours of customization are included. No free trial; booking a demo is the entry path. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: yes - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001 (vendor Innovio SpA), ISO 9001 (vendor Innovio SpA) - National laws referenced: EU Directive 2019/1937; Italy (D.Lgs 24/2023) - Last verified: 2026-07-19 - Sources: - https://www.whistleflow.com/ - https://www.whistleflow.com/il-whistleblowing/ - https://www.innoviogroup.com/software/whistleblowing/whistleflow Notable Developed by Innovio SpA, an Italian IT company at Via Valentini 14, 59100 Prato (PO), Italy (P.IVA 04923180485), with additional offices stated in Milan and Catania. Innovio SpA states it holds ISO/IEC 27001 and ISO 9001 certifications itself, so the ISO 27001 claim rests on the vendor and developer rather than only on the underlying cloud host. Positioned explicitly on EU Directive 2019/1937 and Italy’s D.Lgs 24/2023, referencing the Italian transposition deadlines of 15 July 2023 (250+ employees) and 17 December 2023 (50 to 249 employees). Target segments are public administration, large enterprises, and small and medium businesses. Reporting supports anonymous submissions with no personal data required, plus voice reporting with a transcript; both are stated across all tiers. Handler side is a cloud dashboard with customizable workflows, custom fields, and role management. Blockchain notarization is stated to keep each report immutable; the database and communications are encrypted with daily backups. Hosting is described as a European Azure or AWS cloud environment, but no specific EU country or sub-processor list was disclosed on public pages reviewed. Custom API access is offered on higher tiers. Product is available in Italian and English versions. Public pricing shows Basic EUR 29/month (up to 50 employees), Standard EUR 59/month (up to 250), and Premium EUR 149/month (up to 500); Enterprise is custom for 500+ employees. A EUR 250 annual setup fee applies to all plans, prices exclude VAT, and two hours of customization are included. No free trial was found; a booked demo is the entry path and the full price list is obtained by contacting the vendor. --- # WhistleFox - Website: https://whistlefox.heuking.de - Headquarters: Düsseldorf, Germany - Hosting: Heuking's own servers in Germany (vendor-stated) - Pricing: Not published. WhistleFox is engaged as a managed legal service, so pricing is quote-only via the firm. - Note: No public pricing, tiers, or trial. The offering bundles legal case handling (initial assessment, risk analysis, investigations on request, deadline management, reporting) by Heuking lawyers, so it is contracted as a service rather than a self-serve subscription. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (LkSG, Supply Chain Due Diligence Act) - Last verified: 2026-07-19 - Sources: - https://whistlefox.heuking.de/ - https://whistlefox.heuking.de/en - https://www.heuking.de/ - https://www.heuking.de/de/impressum.html - https://www.heuking.de/de/datenschutzhinweise.html Notable WhistleFox is operated by Heuking Kühn Lüer Wojtek Partnerschaft mbB, a German full-service law firm of roughly 450 lawyers with offices in Berlin, Chemnitz, Düsseldorf, Frankfurt, Hamburg, Cologne, Munich, and Stuttgart; the registered seat is Düsseldorf (VAT DE 119 459 367). Heuking positions WhistleFox as the first German law firm to develop its own digital whistleblowing system, combining a technical reporting channel with the firm’s own legal case handling. This is a managed ombudsman service, not a self-serve SaaS: reports are received and processed by the firm’s confidential lawyers, who are bound by professional confidentiality obligations. Reporting channels include a 24/7 online reporting form, phone, email, postal mail, and in-person meetings. The firm states that anonymity is guaranteed on request and that no whistleblower-identifying metadata is stored, so identity cannot be inferred. Bundled legal services include statutory intake confirmation, a legal preliminary assessment by compliance specialists, risk analysis and recommendations for action, internal investigations on request, a deadline-management system, and individual, quarterly, and annual reporting for management. Data is hosted on Heuking’s own servers in Germany; the firm claims security that outperforms standard requirements but names no certification, and no ISO 27001 was found on public pages reviewed. Public materials reference the EU Whistleblower Directive 2019/1937 (organizations with 50+ employees) and the German Supply Chain Due Diligence Act (LkSG); the German whistleblowing transposition (HinSchG) is not explicitly named with article numbers on the pages reviewed. Target customers are businesses, public authorities, municipalities, and associations across all sectors, with national and international scope claimed. The service is offered in German (primary) and English; broader EU language coverage was not documented. No pricing, tiers, or free trial are published; because case handling by lawyers is included, WhistleFox is contracted as a service and priced by quote. --- # Whistlelink - Website: https://whistlelink.com - Headquarters: Sweden - Pricing: Tiered by employee count: €79 (0–49), €99 (50–149), €149 (150–249), €199 (250–499), €299 (500–999), contact for 1,000+. Annual subscription. - Note: 30-day free trial, no credit card required. Romania pricing page is public. - Languages on reporting form: 50 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Sweden; Denmark; Finland; Norway; Germany (HinSchG); France (Sapin II); Romania (Law 361/2022) - Last verified: 2026-06-05 - Sources: - https://www.whistlelink.com/ro/ - https://www.whistlelink.com/ro/produs/ - https://www.whistlelink.com/ro/preturi/ - https://www.whistlelink.com/ro/aliniere-legea-avertizorilor-de-integritate/ - https://www.whistlelink.com/ro/despre-whistlelink/ - https://www.whistlelink.com/ro/contract-de-prelucrare-a-datelor/ - https://www.whistlelink.com/ro/blog/studiu-de-caz-interviu-cu-sun-wave-pharma-romania/ - https://www.whistlelink.com/amcham/ - https://www.whistlelink.com/wp-content/uploads/2022/05/Whistlelink_Security_EN.pdf - https://www.whistlelink.com/wp-content/uploads/2022/05/Whistlelink_SaaS_Fact-sheet-3.pdf - https://www.whistlelink.com/en-us/become-a-whistlelink-partner/ - https://portal.whistlelink.com/en-us/explore/whistleblowing-platform Notable Signup provisions a working handler account in minutes. The register/ form asks for name, work email, phone, country, language, company, and password; after email confirmation the handler picks a subdomain (companyname.whistlelink.com) and a reporter-site language, and the dashboard opens immediately with a six-step start guide. The handler admin exposes the pieces buyers check in procurement, not just a brochure. Settings / Compliance configures retention time (default 12 months) and default case deadline (default 3 months). The dashboard has tiles for New cases, Open cases, Cases with new messages, Cases near deadline, and Cases to be deleted — the retention and deadline timers are observable on the landing page. Settings / Automations is a priority-ordered rules engine for auto-assignment; the default rule ships as Assign users with role Owner. User Management exposes a real five-role RBAC grid (Owner, Administrator, Case handler, Content Manager, Viewer) plus a per-user MFA status column and an org-wide Enforce two factor authentication toggle. Sub-processors are named at the consent point. Settings / Case Handling offers two opt-in AI features: Automatic Translation names DeepL (Germany) as a new sub-processor; AI: Case Summary names Mistral (France). Both are off by default. Settings / Action log records who changed what, when, with before-after values — timestamped and user-attributed. Romania-specific materials remain visible. Reporter-site language selector includes Romanian; the prior handler review found Romanian compliance categories out of the box (Achiziții, Mită, corupție, conflict de interese, Hărțuire sexuală, Economie, finanțe, bani, spălare de bani, etc.); public pages still include Romanian pricing, Law 361/2022 guidance, local territory-manager details, an AmCham offer page, and a Sun Wave Pharma Romania case study. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P+H (prior hands-on handler account plus 2026-05-24 public-page refresh; reporter portal was provisioned previously but a test submission was not filed). Base score: 39 / 50. Romania country bonus: 6 / 6. Category Score Max A. Legal compliance 11 16 B. Reporter experience (RO) 7 10 C. Handler experience 9 10 D. Security 8 8 E. Commercial 4 6 Evidence supporting the score: public materials and the prior handler review support the retention, case-deadline, auto-assignment, RBAC, 2FA, action-log, and sub-processor claims. Romanian product and pricing pages, Law 361/2022 positioning, a Romania case-study page, and local contact details are also public. Unverified from this pass: embedded article-by-article Law 361/2022 mapping, reporter return-access mechanics, and append-only audit semantics. Public pricing still describes annual subscription terms. --- # WhistleOn - Website: https://whistleon.com - Headquarters: Lisbon, Portugal - Hosting: Google Cloud Platform europe-west1 (Belgium) for European company data - Pricing: Tiered by employee count: €69 (1–49), €79 (50–149), €89 (150–199), €129 (200–499), €199 (500–999), quote for 1,000+. Billed annually. - Note: No free trial advertised on public pages reviewed; pricing CTAs route to contact. - Languages on reporting form: 5 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: Portugal (Law 93/2021); Portugal (Law 109-E/2021); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://whistleon.com - https://whistleon.com/product/?lang=en - https://whistleon.com/plans/?lang=en - https://whistleon.com/about-us/?lang=en - https://ouvidordigital.com.br/quem-somos/ Notable Dedicated whistleblower product, not bundled with HR or ERP suites. Explicit anchor on Portuguese Lei 93/2021 and Lei 109-E/2021 (implementation and penalty regimes), plus GDPR. Parent Ouvidor Digital publicly states 5,000+ companies served across 30+ countries; WhistleOn presents itself as the international brand of Ouvidor Digital Whistleblowing Company. Voice and WhatsApp reporting with AI transcription and end-to-end encryption; web portal available 24/7. Case management and task tracking; 20+ pre-configured reports and custom dashboards; BI system integration. White-label branding and marketing-campaign toolkit (vendor-stated 40+ items). Training available in five languages (not enumerated on site). Customer logos on homepage: ~10–12 visible, including recognisable Portuguese brands. EU data residency is disclosed at region level: European company data is stored on Google Cloud Platform europe-west1 in Belgium. ISO 27001 or other formal certifications were not found on the public page reviewed. The site has a “certifications” heading, but the text under it discusses EU privacy-law alignment and Google Cloud hosting rather than listing vendor-held certificates. No API presence or founding year disclosed publicly. --- # WhistlePort - Website: https://whistleport.de - Headquarters: Berlin, Germany - Hosting: German data centre in Nuremberg, stated as ISO/IEC 27001:2013 certified (certification held by the data-centre operator, not the vendor) - Pricing: Paket 1 (platform) EUR 69/month; Paket 2 (platform + employee training) EUR 69/month plus a one-time EUR 499 setup fee; Paket 3 (full-service) EUR 69/month plus EUR 79/month for attorney-run case handling. All prices plus 19% VAT. - Note: One-year minimum term with annual billing, auto-renewal, and a 3-month notice period; no month-to-month option. A free test version is advertised, but the stated availability date (until 01.01.2024) is stale on the public page reviewed. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO/IEC 27001:2013 (data-centre operator only; vendor not certified) - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - https://whistleport.de/ - https://whistleport.de/funktionen - https://whistleport.de/preise - https://whistleport.de/impressum - https://whistleport.de/datenschutz Notable Operated by VON RUEDEN Partnerschaft von Rechtsanwälten, a Berlin law firm at Leipziger Platz 9, 10117 Berlin (USt-IdNr DE-279218916, Amtsgericht Charlottenburg PR 732), with managing partners RA Johannes von Rüden and RA Fabian Heyse. Positioned as a hybrid product: a self-serve electronic reporting platform plus an optional external compliance-officer service where attorneys receive, review, and assess reports and give recommendations. Marketed to German SMEs and public-sector bodies subject to the HinSchG, referencing the 25+ and 50+ employee thresholds and the EU Whistleblower Directive. Web-based anonymous reporting is available 24/7 with no email address required, and two-way communication with the reporter is supported. Each customer gets its own subdomain (unternehmensname.whistleport.de) and can adapt the reporting form to its corporate design. Backend case handling supports unlimited handlers, user assignment, case linking, PDF export, and a follow-up/deadline function with email notifications. Hosting is stated as a German data centre in Nuremberg described as ISO/IEC 27001:2013 certified; the certification is the data-centre operator’s, not a vendor or product certification. Three published packages, all at EUR 69/month plus VAT for the platform: Paket 1 platform only; Paket 2 adds a one-time EUR 499 training fee for in-house case handling; Paket 3 adds EUR 79/month for attorney-run case handling. Contract terms are one year minimum with annual billing, automatic annual renewal, and a 3-month notice period; there is no month-to-month option. A free test version is advertised but the stated availability date on the public page reviewed (until 01.01.2024) is stale. Reporting-language count, file-upload support, retention/auto-deletion, an append-only audit trail, a DPA/AVV, and a subprocessor list were not documented on the public pages reviewed. --- # WhistleSecure - Website: https://whistlesecure.com - Headquarters: Stockholm, Sweden - Hosting: Google Cloud, EU region with data stored in Belgium (vendor-stated) - Pricing: SEK 280/month (0-49 employees); SEK 480/month (50-249); SEK 980/month (250+). Setup, policy, and weekday support included in all tiers. - Note: Prices are quoted per month but billed quarterly or annually. Free testing period stated with no payment details required and roughly 10-minute setup. Contracts described as flexible and cancellable by email or phone. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Sweden (visselblåsarlagen) - Last verified: 2026-07-19 - Sources: - https://whistlesecure.com - https://whistlesecure.com/pricing - https://whistlesecure.com/whistleblowing-system - https://whistlesecure.com/whistlesecure - https://whistlesecure.com/compliance - https://whistlesecure.com/resources/whistleblowing-law Notable Operated by Tech brows AB, a Swedish company (org. nr 559434-1967), with the product built in Stockholm. Positioned as a low-cost domestic whistleblowing channel; the home page claims “Europe’s lowest prices” and availability across more than 20 EU countries. Three per-employee tiers are published in plain HTML: SEK 280, SEK 480, and SEK 980 per month, with setup, policy help, and weekday support bundled into the license fee. A free testing period is stated with no payment details required and an approximately 10-minute setup; contracts are described as flexible and cancellable by email or phone. Reporting options described include a web form, submitting a report by email, and booking an in-person meeting; a dedicated phone hotline was not described on public pages reviewed. Anonymous reporting is offered as an option, with anonymous two-way communication and real-time follow-up. Hosting is stated as Google Cloud in the EU with all data stored in Belgium and never leaving the EU; encryption in transit and at rest is described. ISO 27001 and SOC I/II/III certifications referenced on the compliance page belong to Google (the hosting provider), not to WhistleSecure or Tech brows AB; no vendor-held certification was found on public pages reviewed. Compliance copy references EU Directive 2019/1937 and the Swedish whistleblowing law (“visselblåsarlagen”), but without a formal statute number or article-level citations. A DPA is stated as included as standard; a formal sub-processor list and DPIA support were not found on public pages reviewed. WhistleSecure is described publicly as a partner within the Fortnox software library, letting Fortnox customers activate a whistleblowing channel; a documented public API was not found on pages reviewed. --- # WhistleSystem - Website: https://whistlesystem.com - Headquarters: Albertslund, Denmark - Pricing: Tiered by employee count: €67/mo (0–250), €80/mo (250–500), €93/mo (500–750), from €107/mo (750+), plus a €200 one-time setup fee. Annual billing. - Note: All tiers include full functionality. A trial exists but is gated behind booking a demo; no trial length is published. Add-on report screening, processing, and legal full-service are priced in DKK. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, ISO 27701 - National laws referenced: EU Directive 2019/1937 - Last verified: 2026-06-05 - Sources: - https://whistlesystem.com/en/ - https://whistlesystem.com/en/prices/ - https://whistlesystem.com/en/platform/ - https://whistlesystem.com/en/privacy-policy/ - https://whistlesystem.com/en/eu-whistleblower-directive/ - https://whistlesystem.com/en/demo/ - https://whistlesystem.com/en/whistlesystem-extra-services-screening-and-full-service/ - https://whistlesystem.com/iso27001/ Notable WhistleSystem ApS (CVR 41576561), Roholmsvej 12 A, Albertslund, Denmark. Positioning is price- and speed-led: “the most secure and user-friendly whistleblower system in less than 20 minutes and at the best price.” Pricing is fully public and tiered by employee count: €67/mo (0–250), €80/mo (250–500), €93/mo (500–750), from €107/mo (750+), each plus a €200 one-time setup fee. All tiers include full functionality. Billed annually with a one-year subscription period; the “/mo” figures are presentational. A trial exists but is gated behind booking a demo, with no published trial length. Terms include a 14-day right of withdrawal and free cancellation during each one-year subscription period. Add-on services are priced in DKK while core plans are in EUR: report screening DKK 150/mo, report processing with action plan DKK 250/mo, and a full-service legal treatment via an external lawyer (~DKK 12,712 setup, DKK 7,712/yr ongoing). Security claims: ISO 27001 and ISO 27701 certification, full encryption, encrypted attachments with metadata removal, no IP-logging, and “ISO 27001-approved servers in Europe” — no hosting country, provider, certificate scope, or certification body named on the pages reviewed. Public pages reviewed did not disclose a language list, reporter return-access mechanism, RBAC roles, deadline tracking, audit trail, DPA/DPIA documents, sub-processor list, API access, or customer count beyond “over 500 happy users.” Scoring review - 2026-06-05 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no trial, reporter submission, or handler environment was reviewed). Base score: 20 / 50. Category Score Max A. Legal compliance 6 16 B. Reporter experience 6 10 C. Handler experience 2 10 D. Security 4 8 E. Commercial 2 6 Evidence supporting the score: published tier matrix and setup fee, anonymity-first product copy with anonymous two-way dialogue, ISO 27001/27701 claims, encrypted attachments with metadata stripping, and EU-region hosting language are all public. Unverified from this pass: intake taxonomy, reporter return access, handler workflow beyond status/assignment claims, audit-trail semantics, retention configuration, and the substance of the ISO certifications (no certificate number, scope, or body named). --- # whistly - Website: https://whistly.org - Headquarters: Berlin, Germany - Hosting: ISO 27001 certified servers in Germany (hosting-provider certification, provider not named; vendor-stated) - Pricing: Two published packages: Essential EUR 59/month and Pro EUR 99/month, charged regardless of employee count. - Note: 10-day free trial. Essential is stated to cover English and German; Pro is stated to cover five languages (English, German, French, Spanish, Chinese). Pricing is rendered inside a JavaScript app; package figures were corroborated via the pricing page meta description and a third-party review listing. - Languages on reporting form: 5 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (Hinweisgeberschutzgesetz, HinSchG); Germany (Lieferkettensorgfaltspflichtengesetz, LkSG) - Last verified: 2026-07-19 - Sources: - https://whistly.org/ - https://whistly.org/features - https://whistly.org/security - https://whistly.org/pricing - https://whistly.org/lksg - https://whistly.org/about - https://whistly.org/imprint - https://insights.whistly.org/hinweisgeberschutzgesetz/ Notable Operated by whistly digital GmbH, Berlin, registered at the District Court of Charlottenburg under HRB 249593 B. This is a distinct vendor from the Hungarian Whisly (whisly.hu). Standalone whistleblowing SaaS positioned first for German compliance: the Hinweisgeberschutzgesetz (HinSchG), the Supply Chain Due Diligence Act (LkSG), and the General Equal Treatment Act (AGG), alongside EU Directive 2019/1937. Public materials describe a customizable report page, automated case management, anonymous two-way communication with reporters, file upload, and an ombudsperson option. Two published packages: Essential at EUR 59/month (English and German) and Pro at EUR 99/month (five languages: English, German, French, Spanish, Chinese), both priced regardless of employee count. A 10-day free trial is advertised. Security messaging states end-to-end encryption and hosting on ISO 27001 certified servers in Germany; the certification is the hosting provider’s, not a whistly vendor certification, and the provider is not named. Customer-count claims are inconsistent across the site: the LkSG page says 100+ companies, the about page says over 200 businesses, and the vendor blog says 500+ European companies. No public API documentation, sub-processor list, DPA download, or article-level Directive/HinSchG mapping was found on pages reviewed; the site renders via JavaScript and exposes little static HTML. --- # whizzla - Website: https://whizzla.com - Headquarters: Bad Orb, Germany - Hosting: 934tel Media Networx GmbH servers in Germany (vendor-stated); data processing agreement executed with the hoster - Pricing: Starter EUR 49/month net (up to 50 employees, 1 organization, 2 languages, 2 user accounts); KMU EUR 149/month net (up to 500 employees, 3 organizations, 3 languages, 5 accounts); Konzerne EUR 249/month net (500+ employees, 5 organizations, 5 languages, 10 accounts). Enterprise on request. - Note: Prices are stated net and per month with no setup costs. Contract term, annual billing, and the enterprise tier price are not detailed on public pages reviewed. Ordering runs through a self-serve process with a shopping cart. - Languages on reporting form: 6 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (Lieferkettensorgfaltspflichtengesetz, LkSG); Germany (Geldwaeschegesetz) - Last verified: 2026-07-19 - Sources: - https://whizzla.com/ - https://whizzla.com/en/ - https://whizzla.com/datenschutz - https://whizzla.com/impressum Notable whizzla is a legaltech product of lexato GmbH, Bad Orb, Germany (Handelsregister Hanau HRB 98387, VAT DE348448837, managing director Stefan Kunz). Positioned as a plug-and-play, web-based whistleblowing channel for organizations to meet EU whistleblowing obligations, with LkSG (supply-chain due diligence) and Geldwaeschegesetz (anti-money-laundering) complaint handling also referenced. Public pages name the EU Whistleblower Directive 2019/1937 and the German LkSG and Geldwaeschegesetz; the German whistleblower transposition law (HinSchG) is not named with article numbers on the pages reviewed. Reporters submit through a predefined anonymous questionnaire and return via a PIN and case number to exchange encrypted two-way messages with the handling team. Case handling includes a dashboard with status and deadline tracking; public copy states confirmation within 7 days and a final remedial report after 3 months. Reports auto-delete after six months; the deletion period is presented as fixed rather than configurable on pages reviewed. Six reporter languages are offered: German, English, Spanish, Italian, French, and Dutch. Data is hosted in Germany by 934tel Media Networx GmbH, and the privacy notice states a data processing agreement (Auftragsverarbeitungsvertrag) is in place with the hoster; SSL/TLS transmission encryption is stated. No ISO 27001 or other vendor security certification was found on public pages reviewed. Three monthly tiers are published net (Starter EUR 49, KMU EUR 149, Konzerne EUR 249) with no setup fee and an enterprise tier on request; ordering runs through a self-serve cart, and no free trial is advertised. Appears to be a proprietary standalone product rather than a reseller or white-label of another listed tool. --- # WIBSO - Website: https://wibso.ro/ - Headquarters: Bucharest, Romania - Pricing: Not published. - Note: The site states 'transparent low pricing' and 'no long sales process', but no numeric pricing or live self-serve signup is published. - Languages on reporting form: 2 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001 - National laws referenced: Romania (Law 361/2022); EU Directive 2019/1937 - Last verified: 2026-05-24 - Sources: - https://wibso.ro/ - https://wibso.ro/ro/ - https://wibso.ro/about-us/ - https://wibso.ro/terms-and-conditions/ - https://www.corporateintelligence.ro/cine-suntem/compliance-integrity-solution-wibso/ Notable WIBSO’s public site cites Law 361/2022, references Article 9 and Annex 2, and frames the product around Romanian private-sector obligations rather than generic EU messaging. The public product copy is more operational than most local peers. WIBSO claims electronic register reporting, automatic acknowledgement of receipt, follow-up reminders, reporting status, 5-year retention, statistics, and automatic classifications. Ownership is disclosed on the corporate site: Corporate Intelligence Agency says it built WIBSO through Compliance Integrity Solutions SRL, which it owns 100%. Commercial facts remain limited. The site says “get setup today” and “transparent low pricing”, but there is no public price list, no public trial, and the commercial CTA is still a contact form / offer flow. Language coverage visible on the public site is Romanian and English only. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; no public reporter or handler environment reviewed). Base score: 21 / 50. Romania country bonus: 3 / 6. Category Score Max A. Legal compliance 10 16 B. Reporter experience (RO) 4 10 C. Handler experience 3 10 D. Security 4 8 E. Commercial 0 6 Evidence supporting the score: Romania-law posture. Public copy names Law 361/2022, cites article-level obligations, and exposes workflow claims including automatic acknowledgement, reminders, electronic register, statistics, and 5-year retention. Unverified from public pages: pricing, hosting country, and core product flows such as reporter access, assignment, RBAC, and structured intake. --- # Witik - Website: https://www.witik.io - Headquarters: France - Hosting: France / EU vendor claim; Witik says product data is hosted in France, and the privacy policy names OVH SAS for compliance-platform public forms. - Pricing: Sapin II (incl. internal alerts / whistleblowing): Starter free; Premium from €100/month ex-VAT for SMEs. GDPR: Starter free; Premium from €240/month ex-VAT. - Note: Premium plans require 36-month commitment with annual payment. 14-day free trial advertised on Premium. - Languages on reporting form: 7 - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: yes - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - Certifications: ISO 27001, HDS (Hébergeurs de Données de Santé) - National laws referenced: France (Sapin II / Loi Waserman); GDPR / RGPD; EU AI Act; NIS 2; DORA - Last verified: 2026-09-25 - Sources: - https://www.witik.io/legislations/conformite-nis-2/ - https://www.witik.io/ - https://www.witik.io/en/features/sapin-2/internal-whistleblowing-system/ - https://www.witik.io/tarifs/sapin-ii/ - https://www.witik.io/politique-de-protection-des-donnees/ Notable Founded 2020; positions itself as a “100% French-made” GRC platform. Modules: RGPD, Sapin II (anti-corruption, including internal alerts), EU AI Act, NIS 2 and DORA, plus third-party management, risk management and online training. Sapin II module bundles four components: internal alerts (whistleblowing), anti-corruption controls, gifts & invitations, and conflicts of interest. Whistleblowing features: ready-to-use alert form, anonymous reporting, secure two-way communication, private access portal, dashboard, and automated assignment/tracking claims. Public API with webhook engine; integrations advertised via these hooks rather than a marketplace. Certifications: ISO 27001, HDS (French health-data hosting accreditation), plus EcoVadis Bronze (sustainability rating, non-security). Hosting: France / EU positioning is public; the privacy policy names OVH SAS for the platform and public forms, while commercial/prospecting tooling may involve international transfers. Site UI available in 7 languages; the EU-language-coverage breakdown for the reporting form itself is not enumerated on public pages. Starter (free) tier exists on both GDPR and Sapin II modules with sharp limits; Premium subscription is the production tier. Fits the module-based pattern also represented in the directory by Clym (privacy suite) and osapiens (ESG suite). Vendor-page evidence - 2026-05-24 Current pricing page shows Sapin II Starter at 0€ HT/mois, Premium from 100€ HT/mois, a 14-day trial claim, and a 36-month annual-payment default with monthly payment available at surcharge. The whistleblowing feature page claims a ready-to-use alert form, anonymous reporting, confidential chat box, private access portal, dashboard, automatic assignment, timestamped documentation, and audit history. Current homepage markets Witik as AI-native and states product data is not used to train Witik or third-party AI models; the privacy policy separately names an OpenAI-backed meeting/prospecting tool, not the whistleblowing module itself. The privacy policy names multiple infrastructure/tooling providers; this improves the old sub-processor evidence, but no public objection workflow or DPA pack was found. Witik’s public pages reviewed did not show a Directive 2019/1937 article-level taxonomy. Scoring review - 2026-05-24 Scored under the 25-criterion rubric v2 at access tier P (public pages only; demo is sales-gated, no self-serve trial). Base score: 20 / 50. France country bonus: 7 / 8. Category Score Max A. Legal compliance 4 16 B. Reporter experience 6 10 C. Handler experience 2 10 D. Security 5 8 E. Commercial 3 6 Unverified from public pages: public Art 2(1) taxonomy in intake, public 7-day / 3-month automation proof, and documented two-factor reporter access. Public whistleblowing copy is framed primarily through Sapin II, and the standard commercial model is anchored in a 36-month commitment even if shorter monthly billing is available at a surcharge. Evidence supporting the score: French OVH/HDS hosting, ISO 27001 / HDS claims, a public Sapin II pricing page, a 14-day-trial mention, and surcharge-based monthly billing. Buyer fit: French organisations already using Witik for RGPD that want to add Sapin II whistleblowing coverage. Buyers seeking a dedicated Directive-first whistleblower tool should confirm legal mapping and workflow evidence directly. Vendor-page evidence - 2026-09-25 Re-checked after a Witik sales representative described the current module line-up in person at DPO Forum Monaco on 2026-09-24. Everything below is confirmed against Witik’s own public pages; the conversation set the questions, it is not the source. The regulation line-up has grown from three modules to five: NIS 2 and DORA now sit alongside RGPD, Sapin II and the AI Act, each with its own /legislations/ page. Sapin II pricing is unchanged since 2026-05-24: Starter free, Premium from 100€ HT/mois, 14-day trial, 36-month commitment with annual payment the default. The free Starter tier quantifies its limits in the units the module actually sells: 1 signalement form, 10 conflict-of-interest declarations a year, 10 gifts-and-invitations entries a year. Whistleblowing is metered as one feature among three. Scoring was not re-run; scoring.last_reviewed still reads 2026-05-24. Nothing found here moves a criterion, because the new modules are adjacent regulations rather than whistleblowing capability. --- # WorkInConfidence - Website: https://www.workinconfidence.com - Headquarters: East Grinstead, United Kingdom - Hosting: Amazon Web Services (AWS); data stored in the United Kingdom (G-Cloud service definition) - Pricing: G-Cloud service definition lists GBP 0.06 to GBP 1.13 per user per month. The vendor's own website does not publish pricing and is demo-led. - Note: The only published figure is the per-user range on the UK Digital Marketplace (G-Cloud); the vendor site routes buyers to a demo. No free trial is offered per the G-Cloud listing. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: yes - Public API: no - Free trial: no - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): no - Certifications: Cyber Essentials Plus (vendor site), IASME cyber assurance, NHS Data Security and Protection Toolkit - National laws referenced: United Kingdom (public whistleblowing guidance referenced; no statute named on public pages) - Last verified: 2026-07-19 - Sources: - https://www.workinconfidence.com/ - https://www.workinconfidence.com/anonymous-speak-up-culture-give-your-people-a-voice/ - https://www.workinconfidence.com/hr-case-management-software/ - https://www.workinconfidence.com/whistleblowing-why-your-organisation-should-embrace-it/ - https://www.applytosupply.digitalmarketplace.service.gov.uk/g-cloud/services/604232402844866 Notable Operated by WorkInConfidence Ltd, registered in England and Wales (company no. 08255296), with a registered office in East Grinstead and a stated client base of 100+ UK organisations and 200,000+ employees. The platform spans anonymous speak-up, HR case management, employee surveys, discussion forums, and an external speak-up phone line; this profile focuses on the anonymous speak-up and whistleblowing case-management product. Core differentiator is “truly anonymous, two-way conversations” where handlers can follow up with a reporter without the reporter’s identity being revealed unless they choose to disclose it. The product is a web-based application accessible on any device with a browser, with multiple language options stated for international organisations. Legal framing is UK-centric: public pages reference gov.uk whistleblowing guidance and do not name the Public Interest Disclosure Act 1998 or the EU Whistleblowing Directive 2019/1937. The G-Cloud service definition states hosting on Amazon Web Services with data stored in the United Kingdom, encryption of personally identifiable data and dialogues at rest, and TLS 1.2 or above in transit. Multi-factor authentication is offered as an optional client choice via mobile device; audit and system logs are retained for at least 12 months. The vendor claims Cyber Essentials Plus and IASME cyber assurance on its website and references the NHS Data Security and Protection Toolkit; no ISO 27001 certification was found on public pages reviewed. The G-Cloud listing reviewed indicated Cyber Essentials but not Cyber Essentials Plus, so the certification level is stated inconsistently across public sources. Pricing is demo-led on the vendor site; the only published figure is a per-user range of GBP 0.06 to GBP 1.13 per user per month in the G-Cloud service definition, which also states no free trial and no API. End-of-contract data deletion is stated to occur within three months of termination, with an optional paid 12-month run-off period. --- # Zateo - Website: https://www.zateo.de - Headquarters: Wietzen, Germany - Hosting: Germany-based hosting on an ISO/IEC 27001-certified provider (Hetzner, vendor-stated) - Pricing: Compliance Basic EUR 79/month, Compliance Pro EUR 119/month, Compliance Ultimate from EUR 399/month; all quoted monthly but billed annually, plus German VAT (zzgl. MwSt.). - Note: Prices are quoted per month but charged on annual billing (jaehrliche Abrechnung) plus VAT. Basic includes three languages of choice and unlimited reports; Pro adds multiple users, responsibilities and categories, prioritization of reports, and corporate design; Ultimate adds attorney review of reports. A free trial with no payment required is advertised. - Anonymous reporting: yes - Case management: yes - Multi-channel intake: no - Public API: undisclosed - Free trial: yes - GDPR (vendor claim): yes - EU Directive 2019/1937 (vendor claim): yes - National laws referenced: EU Directive 2019/1937; Germany (HinSchG) - Last verified: 2026-07-19 - Sources: - http://www.zateo.de/ - http://www.zateo.de/impressum - http://www.zateo.de/datenschutz Notable The product is marketed as “Zateo” and operated by Selfox UG (haftungsbeschraenkt), Am Kirchplatz 33, 31613 Wietzen, Germany, registered at Amtsgericht Walsrode under HRB 207827 (managing director Patrick Davis Busche). Positioned as an affordable German solution for meeting HinSchG (Whistleblower Protection Act) obligations, citing the 50+ employee deadline (July 2, 2023) and 250+ employee deadline, and referencing penalties of up to EUR 50,000. The reporting channel is an online reporting form supporting anonymous submissions, with a personal code issued for follow-up; phone support is a customer-support line, not a reporting channel, so intake is web-only. Uploaded images have their metadata automatically removed. Case management (responsibilities, categories, prioritization of reports) is available on Compliance Pro and above; corporate-design customization is also a Pro feature. Compliance Ultimate adds review of reports by an attorney (Rechtsanwalt). Three published tiers: Basic EUR 79/month, Pro EUR 119/month, and Ultimate from EUR 399/month, all quoted monthly but billed annually and shown plus VAT (zzgl. MwSt.). A free trial with no payment required is advertised, and signup is self-serve via the app. Hosting is stated to be in Germany on an ISO/IEC 27001-certified provider (Hetzner); this is a hosting-provider certification, not a vendor or product certification, and no vendor ISO certification was found on public pages reviewed. The privacy policy (Datenschutz) states SSL/HTTPS encryption and 14-day log-file deletion, cites GDPR articles including the right to object, but does not name specific sub-processors or reference a DPA (AV-Vertrag) or DPIA. GDPR compliance is claimed; no API access, statutory 7-day/3-month deadline tracking, or configurable report-retention policy was found on public pages reviewed. --- ## Guide # Whistleblowing failures on the record: regulator and court decisions Whistleblowing law rests on one promise: the person who reports can do so without being identified against their will. This register collects the decisions where a regulator or court found that promise broken, and the decisions where states were fined for not making it in the first place. Each entry links to the primary document: the regulator’s order, the court’s judgment, or the supervisor’s press release. Where press coverage and the primary source disagree, the entry follows the primary source and notes the difference. Inclusion rule: a published decision by a regulator, supervisory authority or court. Allegations, lawsuits without a ruling, and vendor marketing are left out. Summary Date Authority Who Sanction What failed Dec 2025 Oficina Antifrau de Catalunya (Spain) Nora, S.A. €600,000 and public reprimand Employee suspended about a month after reporting irregularities 6 Mar 2025 Court of Justice of the EU Germany, Czechia, Hungary, Estonia, Luxembourg €39m combined Directive transposed late or not at all Mar 2025 AEPD (Spain) Servicios Especiales, S.A. (Servisa) €200,000 (paid €120,000) Closure resolutions naming all complainants and accused emailed to the works council and all parties 25 Apr 2024 Court of Justice of the EU Poland €7m lump sum + €40,000/day Directive not transposed 7 Apr 2022 Garante (Italy) Azienda Ospedaliera di Perugia €40,000 Firewall logged the IP address and username of everyone opening the whistleblowing app 7 Apr 2022 Garante (Italy) ISWEB S.p.A. (the app’s vendor) €40,000 Hosted the app with an unauthorised sub-processor, no written contract 18 Dec 2018 NYDFS (New York) Barclays Bank PLC and New York branch $15,000,000 Governance and controls failed to stop the CEO’s attempt to unmask the writer 11 May 2018 FCA and PRA (UK) Jes Staley, CEO of Barclays £642,430 CEO directed internal security to identify an anonymous letter writer 3 Apr 2017 OSHA (US) Wells Fargo ~$5.4 million, reinstatement Branch manager forced out after reporting suspected fraud to superiors 12 Nov 2014 US Court of Appeals, Fifth Circuit Halliburton Ruling for the whistleblower General counsel named the whistleblower in a document-hold email to colleagues Channel and confidentiality failures Azienda Ospedaliera di Perugia: the logs around the app identified reporters Garante per la protezione dei dati personali, order of 7 April 2022. Fine: €40,000. The hospital ran a web-based whistleblowing application. The application itself was not the problem. Access to it went through the hospital’s firewall, and the firewall recorded browsing operations in log files, including the IP address of the device and the username of the person connecting. The logs were kept until the file reached 150 GB before being overwritten. Anyone with access to those logs could see who had opened the whistleblowing application, and when. The Garante also found that the hospital had given staff no privacy notice for the channel, had carried out no data protection impact assessment, had not listed the processing in its record of processing activities, and had left the credentials of a department head who resigned in May 2019 active for two months afterwards. Provisions breached: GDPR Articles 5(1)(a) and (f), 13, 14, 25, 30, 32 and 35. Lesson for buyers: encryption inside the application does not help if the network in front of it records who connected. Confidentiality has to cover the full request path, including proxies, firewalls and CDNs. Primary source: Garante order against Azienda Ospedaliera di Perugia (docweb 9768363) ISWEB S.p.A.: the vendor’s undisclosed hosting provider Garante per la protezione dei dati personali, order of 7 April 2022. Fine: €40,000. ISWEB supplied the hospital’s whistleblowing application. According to the order, the application used HTTPS and encrypted the content of reports. The Garante fined ISWEB anyway: it had hosted the system with Seeweb S.r.l. without the hospital’s prior written authorisation as controller, and without a data processing agreement governing Seeweb’s role. The hospital did not know its whistleblowing data sat with a third party. Provision breached: GDPR Article 28. ISWEB was given thirty days to regularise the hosting relationship. Lesson for buyers: ask for the complete sub-processor list for the whistleblowing service specifically, and make sure the contract requires your written authorisation before a new one is added. Primary source: Garante order against ISWEB S.p.A. (docweb 9768387) Barclays: the CEO who tried to find the letter writer FCA and PRA (UK), final notices of 11 May 2018. Fine: £642,430 against Jes Staley personally. NYDFS (New York), 18 December 2018. Fine: $15 million against Barclays. In June 2016 Barclays board members received anonymous letters raising concerns about a senior executive Staley had recruited. On 28 June 2016 Staley instructed Group Security to try to identify the author of the first letter. The bank’s whistleblowing team told Group Security that tracing an anonymous author was not acceptable. Staley then instructed Group Security to resume. The UK regulators found a breach of Individual Conduct Rule 2 (due skill, care and diligence), not of the integrity rule. It was the first case brought by the FCA and PRA under the Senior Managers Regime. Barclays separately reduced Staley’s bonus by £500,000, and now has to report annually to both regulators on its whistleblowing cases, with its whistleblowers’ champion attesting personally to the soundness of the bank’s whistleblowing systems and controls. New York’s Department of Financial Services fined the bank itself. Its consent order says Staley “personally directed the head of Barclays’ Group Security to attempt to identify the author(s) of two whistleblowing letters,” despite advice against it from the Group Chief Compliance Officer and the General Counsel. Note on the sources: the FCA notice says Staley pursued only the first letter, and left the second alone because it purported to come from an employee and so fell within the whistleblowing policy. NYDFS refers to two letters. Both are cited here as published. Primary sources: FCA final notice · Bank of England / PRA announcement · NYDFS press release Halliburton: naming the whistleblower in a routine legal email US Court of Appeals for the Fifth Circuit, Halliburton, Inc. v. Administrative Review Board, No. 13-60323, 12 November 2014. Anthony Menendez, a director in Halliburton’s accounting function, raised revenue-recognition concerns internally and filed a confidential complaint with the SEC. His internal complaint was sent from his company email address, under his name, and was forwarded to the general counsel. When the SEC notified Halliburton of an investigation and directed it to preserve documents, the general counsel inferred that Menendez was the source. He emailed Menendez’s manager and others to preserve documents because “the SEC has opened an inquiry into the allegations of Mr. Menendez.” The manager forwarded the email to fifteen members of Menendez’s work group. According to the opinion, colleagues then began “generally refusing to work and associate with him.” The court upheld the Department of Labor’s finding that disclosing a whistleblower’s identity was an adverse action under the Sarbanes-Oxley Act’s anti-retaliation provision. Lesson for buyers: a report submitted from a named work account is identified the moment it is forwarded. The channel has to keep the reporter’s identity separate from the case file that investigators circulate. Primary source: Fifth Circuit opinion, No. 13-60323 Servisa: closure letters that named every complainant Agencia Española de Protección de Datos, procedure PS/00505/2024, resolution of March 2025. Fine: €200,000, reduced to €120,000 paid. This case concerns an internal harassment procedure rather than a Directive reporting channel. It is included because the failure is the one a reporting channel most often suffers: identity leaking as the case file circulates. In May 2024 Servisa, a funeral services company in the Ocaso group, opened a harassment procedure with five complainants and ten accused. On 31 July 2024 it emailed the works council the closure resolution for each complainant. Each resolution named every complainant and every accused person, with their job positions. The same resolutions went to all fifteen people involved. One accused person then posted “Gracias por la denuncia” (“thanks for the complaint”) in a work WhatsApp group, and a complainant went on sick leave after an anxiety attack. The company’s own rules had promised confidentiality. The AEPD found a very serious breach of the confidentiality principle in GDPR Article 5(1)(f). The fine was reduced by 40% for acknowledgement of responsibility and voluntary payment. Primary source: AEPD resolution PS/00505/2024 · Corroboration: elDiario.es Nora, S.A.: Catalonia’s first retaliation fine under Ley 2/2023 Oficina Antifrau de Catalunya, sanction reported December 2025, confirmed final in its 2025 annual report. Fine: €600,000 plus public reprimand. According to press reports, an employee of Nora, S.A., the public waste company of the Consell Comarcal de la Selva and the town of Blanes, requested internal information on irregularities in hiring, bonuses and time recording, and reported to the Oficina Antifrau in 2023. About a month later the company suspended her without pay for six days. The Girona social court annulled the suspension as retaliation and awarded her €7,500. It is the first sanction the Oficina Antifrau has imposed for retaliation under Spain’s whistleblower protection law. Note on the sources: the Oficina Antifrau’s annual report confirms a final sanction for retaliation against a whistleblower but does not name the company, and the sanction resolution is not published. The company name and amount come from Catalan press. Primary source: Oficina Antifrau 2025 annual report press release, p. 9 · Corroboration: Nació Digital, 3Cat Wells Fargo: OSHA’s largest individual whistleblower award US Occupational Safety and Health Administration, order of 3 April 2017. About $5.4 million, plus reinstatement. OSHA found that a branch manager in Los Angeles was abruptly forced out in 2010 after telling superiors he suspected two subordinates of bank, mail and wire fraud, and that the report was a contributing factor in his termination. OSHA ordered reinstatement and about $5.4 million in back pay, compensatory damages and attorneys’ fees, the largest individual award in its whistleblower programme at the time. Wells Fargo said it would contest the order. This case concerns retaliation after an internal report to management. It is separate from the sales-practices scandal of 2016, in which former employees told CNNMoney they were fired after calling the bank’s ethics line. That reporting did not result in a regulator decision on the ethics line and is not listed here as a case. Primary source: US Department of Labor news release, 3 April 2017 · Corroboration: NPR State-level enforcement of Directive (EU) 2019/1937 The Directive set a transposition deadline of 17 December 2021. The European Commission took several member states to the Court of Justice for missing it. Case Member state Judgment Lump sum Daily penalty C-147/23 Poland 25 Apr 2024 €7,000,000 €40,000 until transposition C-149/23 Germany 6 Mar 2025 €34,000,000 none C-152/23 Czechia 6 Mar 2025 €2,300,000 none C-155/23 Hungary 6 Mar 2025 €1,750,000 none C-154/23 Estonia 6 Mar 2025 €500,000 €1,500 until transposition C-150/23 Luxembourg 6 Mar 2025 €375,000 none Germany argued that the 2021 federal election and the conciliation procedure between its two chambers had delayed the law. The Court rejected this: a member state cannot rely on its domestic legislative process to justify failing to meet an EU obligation. Primary sources: C-147/23 Commission v Poland (EUR-Lex) · C-149/23 Commission v Germany (EUR-Lex) · Summary of all five 2025 judgments: eucrim Regulator guidance that follows from these cases Email is not an adequate channel (Italy, 2025). In its opinion of 9 October 2025 on the national anti-corruption authority’s draft guidelines for internal reporting channels, the Garante stated that using email, ordinary or certified (PEC), is “di per sé non adeguato” (inadequate in itself) to guarantee the confidentiality of the reporting person’s identity. Mail systems generate and keep transmission logs that can identify the sender, especially on employer-provided accounts. Garante opinion, docweb 10184673 What the cases have in common None of the failures above involved an attacker. Each came from an ordinary part of the organisation or its supply chain: a firewall doing its job, a hosting arrangement nobody wrote down, a security team following the CEO’s instruction, a legal hold email forwarded to the team, closure letters sent to every party. Confidentiality depends on everything a report passes through, on its way in and as the case moves around the organisation. For the questions these cases suggest asking a vendor, see the what the enforcement cases teach buyers checklist. Corrections and additions This register is updated as new decisions are published. To propose a case, email the link to the primary decision to contact [at] whistleblowertools [dot] eu. Cases are added only once the primary document has been read. --- # EU Directive 2019/1937 on whistleblower protection A practical guide for organisations that need to understand and comply with the European Union's Whistleblower Protection Directive. Key compliance deadlines 17 December 2021 — Deadline for member states with 250+ employee threshold 17 December 2023 — Deadline extended to organisations with 50–249 employees All EU member states have now transposed the Directive into national law What is the Whistleblower Protection Directive? Directive (EU) 2019/1937 of the European Parliament and of the Council, adopted on 23 October 2019, establishes common minimum standards for the protection of persons reporting breaches of Union law. It requires organisations to set up secure, confidential reporting channels and prohibits retaliation against whistleblowers. The Directive covers a broad range of EU law areas, including public procurement, financial services, product safety, environmental protection, food safety, public health, consumer protection, data protection, and more. Who must comply? The Directive requires internal reporting channels for: Private sector organisations with 50 or more employees All public sector entities, including municipalities and government bodies Financial sector entities, regardless of size (banks, insurance, investment firms) Organisations in regulated sectors covered by EU law (AML, aviation safety, etc.) Note that individual member states may set broader requirements in their national transposition. Always verify the specific obligations in each jurisdiction where your organisation operates. Core requirements Organisations subject to the Directive must: 1. Establish internal reporting channels Provide secure channels that allow workers to report breaches confidentially. Channels must accept reports in writing (online platform, email, postal) and/or orally (telephone hotline, voice messaging). The channel must ensure the confidentiality of the reporting person’s identity. 2. Designate a responsible person or department Assign an impartial person or department to receive and follow up on reports. This function must have the authority to conduct investigations and must operate independently from management that could be subject to reports. 3. Follow prescribed timelines 7 days — Acknowledge receipt of the report to the whistleblower 3 months — Provide feedback to the whistleblower on the follow-up actions taken Maintain records of all reports in compliance with data protection requirements 4. Protect whistleblowers from retaliation The Directive prohibits any form of retaliation, including dismissal, demotion, intimidation, damage to reputation, and blacklisting. Member states must provide effective remedies and support measures for reporting persons who suffer retaliation. 5. Ensure data protection compliance All personal data collected through the reporting channel must be processed in accordance with the General Data Protection Regulation (GDPR). Data must be stored only as long as necessary and access must be limited to authorised personnel. Penalties for non-compliance Member states define their own penalty regimes in national transposition laws. Penalties may be imposed for: Failing to establish reporting channels Obstructing or attempting to obstruct reporting Retaliating against reporting persons Breaching confidentiality obligations Bringing vexatious proceedings against reporting persons In Germany, for example, the Hinweisgeberschutzgesetz (HinSchG) provides for fines of up to €50,000 for failing to establish a reporting channel and up to €100,000 for retaliation. Other member states have similar penalty ranges. National transpositions Each EU member state has transposed (or is in the process of transposing) the Directive into national law, often with additional requirements: Germany — Hinweisgeberschutzgesetz (HinSchG), in force since July 2023 France — Loi Sapin II (updated 2022), with broader scope than the Directive Sweden — Visselblåsarlagen, in force since December 2021 Denmark — Lov om beskyttelse af whistleblowere, in force since December 2021 Netherlands — Wet bescherming klokkenluiders, updated February 2023 Poland — Ustawa o ochronie sygnalistów, in force since September 2024 Outside the EU The Directive binds member states. Four European jurisdictions outside it come up constantly in multi-country buying, and each works on different terms: United Kingdom — outside the Directive since Brexit. The Public Interest Disclosure Act 1998 protects workers who make a protected disclosure, but imposes no general duty to operate an internal channel. Since 1 September 2025 the failure to prevent fraud offence gives large organisations a strong practical reason to have one anyway. Norway — an EEA state the Directive has not been extended to, and stricter than it on the point that matters: chapter 2 A of the Working Environment Act requires internal whistleblowing routines from five employees, not fifty. Switzerland — no general whistleblower protection law at all; the Code of Obligations reform was rejected by Parliament in March 2020. A Swiss group is still in scope through any EU subsidiaries. Moldova — an accession candidate whose Law 165/2023 is partially aligned with the Directive ahead of accession. A group operating in any of these cannot run one Directive-shaped policy everywhere: thresholds, reporting routes and remedies all differ. Full treatment with links to the statutes: United Kingdom, Norway, Switzerland, Moldova. Choosing a reporting channel solution When selecting a digital reporting platform to meet the Directive’s requirements, organisations should evaluate: Compliance coverage — Does the platform support all jurisdictions where you operate? Anonymous reporting — Can reporters submit reports without identifying themselves? Two-way communication — Can the designated person communicate with the reporter while maintaining anonymity? Deadline tracking — Does the platform enforce the 7-day and 3-month response deadlines? Data hosting — Is data processed and stored within the EU, in compliance with GDPR? Audit trail — Does the platform maintain a complete record of all actions for compliance documentation? Deployment speed — How quickly can the channel be operational? Compare reporting platforms We maintain an independent directory of whistleblower reporting tools evaluated against EU Directive 2019/1937 requirements. View platform comparison → Browse all platforms → ---