Whispli
Enterprise whistleblowing, disclosure, hotline, and investigation platform operating in 60+ countries.
Non-EU HQ
Sydney, Australia (Paris office). This vendor is headquartered outside the European Union. EU personal data processed by the vendor is a cross-border transfer under GDPR Chapter V and depends on an adequacy decision, Standard Contractual Clauses, or a derogation. Non-EU providers introduce jurisdictional exposure to third-country data-access regimes. For institutional buyers prioritising European data sovereignty, prefer an EU-headquartered provider.
This vendor applies AI or machine learning to whistleblower reports (for example summarisation, severity or category classification, drafting replies, or machine translation). Automated processing of disclosures can bring the deployment within scope of the EU AI Act and routes sensitive personal data through a third-party inference provider. Confirm the model provider, its data-retention terms, and whether report content can be excluded before relying on it. Vendor detail: Voice AI hotline captures, structures, and routes hotline reports into cases.
Rubric score
31 / 50
Evidence tier P
Public pages only. No reporter submission or handler environment was reviewed.
Facts
- Headquarters
- Sydney, Australia (Paris office)
- Pricing
- Plan names are public (Essential, Standard, Advanced, Enterprise), but amounts are not published; pricing remains sales-led.
- Languages on reporting form
- 70
- Domain registered
- whispli.com
- Customers
- 300+ organisations; deployed in 60+ countries (vendor claim)
- Product scope
- Standalone whistleblower product
- Encryption posture
- Customer-held key (vendor cannot decrypt)
Measured, not published
Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.
- DMARC policy
- Published but not enforcing
- DNSSEC
- Unsigned
Capabilities
- Anonymous reporting ✓
- Multi-channel intake ✓
- Public API ✓
- Free trial ✗
- Two-factor authentication ✓
- Audit log ✓
- EU Directive 2019/1937 (vendor claim) ✓
✓ published by the vendor · ✗ vendor states it is not offered · — not published either way
Certifications and national law
Certifications
- ISO 27001
- SOC 2 Type II
National laws referenced
- EU Directive 2019/1937
- France (Loi Sapin II)
- France (Loi Waserman)
- Germany
- United States (SOX)
- Australia
- United Kingdom FCA rules

Large multinational organizations needing configurable workflows, Safe Inbox, Voice AI hotline, regional hosting, and customer-managed encryption keys.
Distinctive features
- Web, mobile app, email, QR code, and Voice AI hotline intake are disclosed publicly
- 70+ languages, anonymous two-way Safe Inbox, configurable workflows, SLAs, retention, routing, and audit logs
- ISO 27001, SOC 2 Type II, customer-managed encryption keys, API/integrations, and regional hosting/data-residency controls
Add-ons and conditions
Costs or terms not included in the headline price.
- Pricing page names packages but does not publish amounts
- No self-serve trial found
- Exact EU official-language coverage was not disclosed on public pages reviewed
Notable
- Whispli now uses current product paths such as
/use-case/whistleblowing,/whistleblowing-management-system, and/whistleblowing-hotline; the previously listed/solutions/whistleblower/URL returned 404. - Product pages state 300+ organisations, deployment in 60+ countries, 70+ languages, anonymous two-way Safe Inbox, web/mobile/email/QR/Voice AI intake, configurable forms, automated case creation, routing, SLAs, retention, and audit-ready logs.
- The security page states ISO 27001 certification, SOC 2 Type II certification, customer-managed encryption keys, 2FA, SSO, API/integrations, penetration testing, metadata removal, secure translation on Whispli infrastructure, regional hosting, and data-residency controls.
- France-specific pages name Loi Waserman and Sapin 2. Public pages also reference the EU Whistleblower Protection Directive, GDPR, SOX, UK FCA rules, Australian laws, and ISO 37002 principles.
- Whispli’s pricing page names Essential, Standard, Advanced, and Enterprise plans, but no public amounts were found. No public self-serve trial was found.
Frequently asked questions about Whispli
Answers derived from vendor-published materials dated on this page.
Is Whispli suitable for SMEs under 250 employees?
Which national whistleblower laws does Whispli explicitly reference?
Does Whispli process whistleblower report content with AI?
Similar to Whispli
Other platforms in the directory with overlapping pricing model, certifications, or procurement path.
FaceUp
Whistleblowing, employee-relations, and workplace-compliance platform from the Czech Republic.Confide End-to-end whistleblowing and GRC case-management platform from Confide Global Pte. Ltd., founded by Wirecard whistleblower Pav Gill, headquartered in Singapore with a planned European base in The Hague.
Elker Australian speak-up and case-management platform, ISO 27001 certified and SOC 2 attested, marketed to Australia and New Zealand only — no EU or UK market surface.
Fraud Line
Greek whistleblowing-services provider with ISO 27001, ISO 27701, and ISO 37002 certifications, deployed across multiple countries.
Sources and verification
Every fact on this page comes from Whispli's own published materials. These are the pages that were read, and the date they were read.
- Last verified
-
Re-verification due
8 of the vendor pages cited below has changed since this entry was verified. What this means
Cited pages last re-fetched
- www.whispli.com/use-case/whistleblowing (opens in new tab)
- www.whispli.com/whistleblowing-management-system (opens in new tab)
- www.whispli.com/whistleblower-platform-features (opens in new tab)
- www.whispli.com/whistleblowing-hotline (opens in new tab)
- www.whispli.com/security/ (opens in new tab)
- www.whispli.com/pricing/ (opens in new tab)
- www.whispli.com/fr/loi-waserman-protection-lanceur-alerte-2022/ (opens in new tab)
- www.whispli.com/data-processing-addendum-europe (opens in new tab)