Confidly
EU-built anonymous whistleblowing channel from Confidly OU (Estonia), self-serve from EUR 39/month, EU-hosted with AI-assisted investigation.
This vendor applies AI or machine learning to whistleblower reports (for example summarisation, severity or category classification, drafting replies, or machine translation). Automated processing of disclosures can bring the deployment within scope of the EU AI Act and routes sensitive personal data through a third-party inference provider. Confirm the model provider, its data-retention terms, and whether report content can be excluded before relying on it. Vendor detail: AI summarises reports, classifies severity, suggests categories, translates 25+ languages, and drafts acknowledgement replies; all suggestions advisory and human-confirmed. Inference via AWS Bedrock eu-central-1 (Frankfurt), stated zero data retention.
Rubric score
42 / 50
Evidence tier P
Public pages only. No reporter submission or handler environment was reviewed.
Facts
- Headquarters
- Tallinn, Estonia
- Hosting
- Hetzner Online GmbH, Falkenstein, Germany (vendor-stated)
- Pricing
- Starter EUR 39/month billed annually (EUR 468/year, up to 100 employees); Pro EUR 124/month billed annually (EUR 1,488/year, 100-500 employees); Enterprise EUR 332/month billed annually (EUR 3,984/year, up to 2,000 employees / 5 channels). Monthly billing also offered; annual billing stated to save roughly 17%.Priced by total employee headcount, not per user. All plans include a 14-day free trial (full Pro features, no credit card). Prices are EUR plus VAT, reverse-charged for EU B2B. 10,000+ employees, on-prem, or custom integrations are quote-only via sales.
- Languages on reporting form
- 25
- Founded
- 2026
- Ownership
- Private, Confidly OU (Estonia)
- Product scope
- Standalone whistleblower product
Measured, not published
Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.
- DMARC policy
- Enforced (quarantine)
- DNSSEC
- Unsigned
- Legal entity
- Confidly OÜ VAT EE10XXXXXXXX · imprint
Capabilities
- Anonymous reporting ✓
- Multi-channel intake ✓
- Public API ✓
- Free trial ✓
- Two-factor authentication ✓
- Audit log —
- EU Directive 2019/1937 (vendor claim) ✓
✓ published by the vendor · ✗ vendor states it is not offered · — not published either way
Certifications and national law
Certifications
None published
National laws referenced
- EU Directive 2019/1937
- Germany (HinSchG)
- France (Loi Sapin II)
- Italy (D.lgs 24/2023)
- Spain (Ley 2/2023)
- Netherlands (Wbk)

EU companies of roughly 50 to 500 employees wanting a focused, self-serve, Directive-compliant reporting channel with anonymous intake and AI-assisted case handling, without a full GRC suite.
Distinctive features
- Published self-serve pricing across three tiers with a 14-day free trial and no credit card
- Anonymous-by-design intake (no IP, email, or device fingerprint; reporter gets a case code plus 6-digit secret)
- EU data residency named (Hetzner Falkenstein, Germany) with a public sub-processor list and 30-day objection window
- Automatic reporter status updates at 7 days and 3 months mapped to Directive Article 9
- Append-only, hash-chained audit log exportable as CSV or JSON for regulator inspection
- Country-specific intake templates referencing named national transposition laws across all 27 EU states plus EEA and UK
Add-ons and conditions
Costs or terms not included in the headline price.
- Pricing is banded by total employee headcount, not per user; crossing a band moves you to the next tier
- ISO 27001 and SOC 2 Type II are listed as in progress, not certified, on public pages reviewed
- REST API, webhooks, SCIM, BYOK encryption, and configurable per-channel retention are Enterprise-only
- AI classification and translation (beyond summaries) plus SSO require the Pro tier or higher
- The public imprint reviewed lists Confidly OU in Tallinn but shows registry and VAT numbers as placeholders
- Handler sign-in is delegated to Clerk (clerk.com), a US identity provider, so authentication and session identity are processed outside the EU even though report data is EU-hosted
- Vendor social links (LinkedIn, GitHub, X) were broken on the pages reviewed
Notable
- Operated by Confidly OU, a private limited company registered in the Estonian Business Register with a registered office in Tallinn, Estonia; the site footer states the product is built in Helsinki and hosted in the EU.
- Positioned as a focused, self-serve reporting channel for EU companies of roughly 50 to 500 employees, deliberately narrower than a full GRC or compliance suite.
- Reporter intake is anonymous by design: no account, no IP, no email, and no device fingerprint; the reporter receives a case code plus a 6-digit secret (stated to be stored only in hashed form) for two-way anonymous follow-up.
- Multiple intake channels are documented: web form, audio and video attachments, and mobile-first WhatsApp and SMS intake, plus printable QR-code posters in six EU languages.
- AI features (Pro and Enterprise) summarise reports, classify severity, suggest categories, translate 25+ languages, and draft acknowledgement replies; all AI output is stated to be advisory and human-confirmed. Inference runs on AWS Bedrock eu-central-1 (Frankfurt) with stated zero data retention.
- Compliance features include automatic reporter status updates at 7 days and 3 months (mapped to Directive Article 9), an append-only hash-chained audit log exportable as CSV or JSON, and an auto-generated country-tailored annual compliance report.
- The trust page states EU data residency with production data in Hetzner Falkenstein, Germany, TLS 1.3 and AES-256 encryption, a public sub-processor list with a 30-day objection window, and an annual third-party penetration test (summary under NDA).
- Handler authentication is delegated to Clerk (clerk.com), a US-based identity platform: report data is EU-hosted, but sign-in and session identity run through a US sub-processor, a cross-border transfer consideration under GDPR Chapter V.
- ISO 27001 and SOC 2 Type II are listed as in progress with target dates; ISO 27701 and TISAX are planned or on request. No certification was verified as complete on the public pages reviewed.
- Public legal artifacts include an Article 28 DPA with SCCs, a privacy policy, a pre-filled Article 35 DPIA template, and a RoPA entry; some pen-test, TIA, and BCP documents are stated to be available only under NDA.
- Pricing is published for all three standard tiers, banded by total employee headcount rather than per user, with a 14-day free trial (no credit card) and both monthly and annual billing. Deployments above 2,000 employees, on-prem, or custom integrations are handled via sales.
- The public imprint lists Confidly OU in Tallinn but shows the registry number and VAT identification number as placeholders as of the reviewed date; the stated supervisory authority is the Estonian Data Protection Inspectorate (AKI).
Frequently asked questions about Confidly
Answers derived from vendor-published materials dated on this page.
Is Confidly suitable for SMEs under 250 employees?
Which national whistleblower laws does Confidly explicitly reference?
Does Confidly process whistleblower report content with AI?
Similar to Confidly
Other platforms in the directory with overlapping pricing model, certifications, or procurement path.
TrueSpeak Italian-run multi-locale whistleblowing SaaS with published per-plan pricing from €19/month and a locale site for each of eight markets.
Firmsys Czech whistleblowing channel from SPWeb s.r.o. with fixed monthly tiers from 590 Kc and web plus automated telephone reporting.
Heimdal Swedish whistleblowing system from Heimdal Systems AB, free for organizations under 50 employees and EUR 499/year above that.
Sygnali Polish whistleblowing channel from MWC Sp. z o.o. with published PLN tiers, Poland-based hosting, and web, email, and phone intake.
Sources and verification
Every fact on this page comes from Confidly's own published materials. These are the pages that were read, and the date they were read.
- Last verified
8 of the vendor pages cited below has changed since this entry was verified. What this means
Cited pages last re-fetched
- confidly.eu/ (opens in new tab)
- confidly.eu/features (opens in new tab)
- confidly.eu/pricing (opens in new tab)
- confidly.eu/trust (opens in new tab)
- confidly.eu/eu-directive (opens in new tab)
- confidly.eu/legal/imprint (opens in new tab)
- confidly.eu/legal/dpa (opens in new tab)
- confidly.eu/legal/privacy (opens in new tab)