Skip to main content
EU Whistleblower Directory
Witik logo

Witik

French GRC platform (RGPD, Sapin II, AI Act, NIS 2, DORA). Whistleblowing lives inside the Sapin II module; Premium from €100/month.

Part of Witik GRC platform

AI processes report content — EU AI Act consideration

This vendor applies AI or machine learning to whistleblower reports (for example summarisation, severity or category classification, drafting replies, or machine translation). Automated processing of disclosures can bring the deployment within scope of the EU AI Act and routes sensitive personal data through a third-party inference provider. Confirm the model provider, its data-retention terms, and whether report content can be excluded before relying on it.

Rubric score

20 / 50

Evidence tier P

The tier records what could be examined to produce this score. Totals are only comparable within the same tier.

How this score is produced →

Facts

Website
www.witik.io(opens in new tab)
Headquarters
France
Hosting
France / EU vendor claim; Witik says product data is hosted in France, and the privacy policy names OVH SAS for compliance-platform public forms.
Pricing
Sapin II (incl. internal alerts / whistleblowing): Starter free; Premium from €100/month ex-VAT for SMEs. GDPR: Starter free; Premium from €240/month ex-VAT.
Premium plans require 36-month commitment with annual payment. 14-day free trial advertised on Premium.
Languages on reporting form
7
Founded
2020
Domain registered
witik.io
Customers
3,000+ compliance, risk, and legal teams worldwide (vendor claim)
Product scope
Module of Witik GRC platform

Measured, not published

Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.

DMARC policy
Enforced (reject)
DNSSEC
Signed

Capabilities

  • Anonymous reporting ✓
  • Multi-channel intake ✗
  • Public API ✓
  • Free trial ✓
  • Two-factor authentication —
  • Audit log —
  • EU Directive 2019/1937 (vendor claim) ✓

✓ published by the vendor · ✗ vendor states it is not offered · — not published either way

Certifications and national law

Certifications

  • ISO 27001
  • HDS (Hébergeurs de Données de Santé)

National laws referenced

  • France (Sapin II / Loi Waserman)
  • GDPR / RGPD
  • EU AI Act
  • NIS 2
  • DORA
Witik homepage screenshot
Typical buyer

French organisations already deploying Witik for GDPR or Sapin II compliance who want the internal alert system in the same platform rather than a separate vendor.

Distinctive features

  • ISO 27001 and HDS (French healthcare data hosting) certified
  • Vendor states product data is hosted in France / Europe and not used to train AI models
  • Public REST API plus a webhook engine (rare among module-based GRC platforms)
  • Covers RGPD, Sapin II, the EU AI Act, NIS 2 and DORA from one platform
  • 3,000+ compliance teams across 7 languages (vendor claim)

Add-ons and conditions

Costs or terms not included in the headline price.

  • Whistleblowing is not a standalone product — bundled inside the Sapin II module
  • Premium plans require a 36-month commitment with annual payment
  • Sapin II Premium (€100/mo) and GDPR Premium (€240/mo) are separate subscriptions
  • Starter plans are free but feature-limited (e.g. 2 impact analyses, 10 rights requests per year)
  • Reporting-form EU language coverage not enumerated on public pages

Notable

  • Founded 2020; positions itself as a “100% French-made” GRC platform.
  • Modules: RGPD, Sapin II (anti-corruption, including internal alerts), EU AI Act, NIS 2 and DORA, plus third-party management, risk management and online training.
  • Sapin II module bundles four components: internal alerts (whistleblowing), anti-corruption controls, gifts & invitations, and conflicts of interest.
  • Whistleblowing features: ready-to-use alert form, anonymous reporting, secure two-way communication, private access portal, dashboard, and automated assignment/tracking claims.
  • Public API with webhook engine; integrations advertised via these hooks rather than a marketplace.
  • Certifications: ISO 27001, HDS (French health-data hosting accreditation), plus EcoVadis Bronze (sustainability rating, non-security).
  • Hosting: France / EU positioning is public; the privacy policy names OVH SAS for the platform and public forms, while commercial/prospecting tooling may involve international transfers.
  • Site UI available in 7 languages; the EU-language-coverage breakdown for the reporting form itself is not enumerated on public pages.
  • Starter (free) tier exists on both GDPR and Sapin II modules with sharp limits; Premium subscription is the production tier.
  • Fits the module-based pattern also represented in the directory by Clym (privacy suite) and osapiens (ESG suite).

Vendor-page evidence - 2026-05-24

  • Current pricing page shows Sapin II Starter at 0€ HT/mois, Premium from 100€ HT/mois, a 14-day trial claim, and a 36-month annual-payment default with monthly payment available at surcharge.
  • The whistleblowing feature page claims a ready-to-use alert form, anonymous reporting, confidential chat box, private access portal, dashboard, automatic assignment, timestamped documentation, and audit history.
  • Current homepage markets Witik as AI-native and states product data is not used to train Witik or third-party AI models; the privacy policy separately names an OpenAI-backed meeting/prospecting tool, not the whistleblowing module itself.
  • The privacy policy names multiple infrastructure/tooling providers; this improves the old sub-processor evidence, but no public objection workflow or DPA pack was found.
  • Witik’s public pages reviewed did not show a Directive 2019/1937 article-level taxonomy.

Scoring review - 2026-05-24

Scored under the 25-criterion rubric v2 at access tier P (public pages only; demo is sales-gated, no self-serve trial).

Base score: 20 / 50. France country bonus: 7 / 8.

CategoryScoreMax
A. Legal compliance416
B. Reporter experience610
C. Handler experience210
D. Security58
E. Commercial36

Unverified from public pages: public Art 2(1) taxonomy in intake, public 7-day / 3-month automation proof, and documented two-factor reporter access. Public whistleblowing copy is framed primarily through Sapin II, and the standard commercial model is anchored in a 36-month commitment even if shorter monthly billing is available at a surcharge.

Evidence supporting the score: French OVH/HDS hosting, ISO 27001 / HDS claims, a public Sapin II pricing page, a 14-day-trial mention, and surcharge-based monthly billing.

Buyer fit: French organisations already using Witik for RGPD that want to add Sapin II whistleblowing coverage. Buyers seeking a dedicated Directive-first whistleblower tool should confirm legal mapping and workflow evidence directly.

Vendor-page evidence - 2026-09-25

Re-checked after a Witik sales representative described the current module line-up in person at DPO Forum Monaco on 2026-09-24. Everything below is confirmed against Witik’s own public pages; the conversation set the questions, it is not the source.

  • The regulation line-up has grown from three modules to five: NIS 2 and DORA now sit alongside RGPD, Sapin II and the AI Act, each with its own /legislations/ page.
  • Sapin II pricing is unchanged since 2026-05-24: Starter free, Premium from 100€ HT/mois, 14-day trial, 36-month commitment with annual payment the default.
  • The free Starter tier quantifies its limits in the units the module actually sells: 1 signalement form, 10 conflict-of-interest declarations a year, 10 gifts-and-invitations entries a year. Whistleblowing is metered as one feature among three.
  • Scoring was not re-run; scoring.last_reviewed still reads 2026-05-24. Nothing found here moves a criterion, because the new modules are adjacent regulations rather than whistleblowing capability.

Frequently asked questions about Witik

Answers derived from vendor-published materials dated on this page.

Is Witik suitable for SMEs under 250 employees?
Witik does not publish entry-tier pricing, so SME buyers need to request a quote to assess fit. Buying path: Sales contact required. French organisations already deploying Witik for GDPR or Sapin II compliance who want the internal alert system in the same platform rather than a separate vendor.
Which national whistleblower laws does Witik explicitly reference?
Witik explicitly cites the following national transpositions of Directive 2019/1937 in its public materials: France (Sapin II / Loi Waserman), GDPR / RGPD, EU AI Act, NIS 2, DORA. Absence from this list does not mean the platform can't be used in other EU jurisdictions — all 27 member states have transposed the Directive. Verify jurisdictional fit with the vendor directly.
Does Witik process whistleblower report content with AI?
Yes — Witik processes report content with AI (typically for translation, summarisation, or classification). If your compliance posture requires keeping disclosures out of third-party LLMs or machine-translation services, confirm data-processing terms and vendor subprocessors before procurement.

Similar to Witik

Other platforms in the directory with overlapping pricing model, certifications, or procurement path.

Sources and verification

Every fact on this page comes from Witik's own published materials. These are the pages that were read, and the date they were read.

Last verified

Cited pages last re-fetched

Something out of date? Tell us →

Listed here? Show it on your own site →