Whistleblower reporting tools for EU compliance
Verifiable facts about platforms that meet the requirements of EU Directive 2019/1937. Vendors headquartered outside the European Union are flagged for data-sovereignty risk. Every entry is sourced from vendor-published materials and dated at last verification.
Last updated:
- Platforms listed
- 53
- EU member states
- 27
- EU Directive
- 2019/1937
- Employees threshold
- 50+
Where each tool sits
Three buyer questions, answered by where each tool actually sits. Each plot is computed from vendor-published facts on the platform's detail page.
Can I buy this without talking to sales?
Self-serve, demo-led, and sales-led procurement are separated below. Quote-only, credit-based, and mixed pricing sit apart from genuinely flat published pricing.
Will it pass procurement and security review?
Certification depth and geographic reach are different questions. This plot separates local specialists from multi-EU and global tools, and distinguishes ISO-only claims from stronger audit or qualified-cloud postures.
What will I pay at my company size?
Entry price and cost trajectory diverge quickly. This plot separates flat published pricing from tiered, credit-based, quote-only, and mixed models.
Feature comparison
Side-by-side comparison of vendor-published information.
| Platform | HQ | Pricing | Model | Self-serve | Free trial | EU hosting | EU countries | EU languages | No AI | ISO 27001 | 2FA | Audit log | Encryption |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Poland | €60/month, or €41.67/month billed annually (€500/year) | Flat | ✓ | — | EU | All 27 | 8 of 24 | ✓ | ✓ | ✓ | ✓ | E2E | |
| France | Published annual pricing: Essentiel €300/year (<50 FTE), Standard €1,500/year (50+ FTE, 3 referents), Pro €4,600/year (unlimited referents). | Flat | Demo | — | EU | 1 of 27 | Partial | ✓ | — | — | — | — | |
| France | Not published publicly. | Quote | Sales | — | EU | 1 of 27 | Partial | — | ✓ | — | — | — | |
| Spain | €96/month (€116.16/month incl. 21% IVA). Annual plan available (saves €153/year). Enterprise plan quote-based. | Flat | ✓ | — | Undisclosed | 1 of 27 | Undisclosed | ✓ | — | — | — | At rest | |
| Spain | Not published — quote-based. | Quote | Sales | — | Undisclosed | 1 of 27 | Partial | — | — | — | — | E2E | |
| Sofia, Bulgaria | Public monthly pricing: BGN 295/month for 50-149 employees, BGN 395/month for 150-249, BGN 595/month for 250-499, BGN 995/month for 500+; under 50 employees by quote. | Tiered | Demo | — | Undisclosed | 1 of 27 | 2 of 24 | ✓ | — | — | — | — | |
| Sofia, Bulgaria | Annual subscription, tiered by employee count: 295 BGN/month (50–149 employees), 395 BGN/month (150–249), 595 BGN/month (250–499), 995 BGN/month (500+). Public-sector employers and private employers falling under EU-law scope are in-scope regardless of headcount. | Tiered | Sales | — | Undisclosed | 1 of 27 | 2 of 24 | ✓ | — | — | — | — | |
| Münster, Germany | Compliance Hub from €45/month for one core module, including the Hinweisgeberschutz/whistleblowing module. Separate managed services, including external whistleblower officer, are advertised from €125/month. | Flat | Demo | — | EU | 1 of 27 | Undisclosed | ✓ | ✓ | — | ✓ | — | |
| Finland | Starter EUR 69/month or EUR 468/year (0-49 employees); Medium EUR 119/month or EUR 948/year (50-249); Large EUR 149/month or EUR 1,308/year (250-1,000); Enterprise EUR 299/month or EUR 2,388/year (1,000+). | Tiered | ✓ | ✓ | EU | 1 of 27 | Partial | ✓ | — | ✓ | — | — | |
| Munich, Germany | English global package page does not publish prices. UK package page publishes Essential from £85/month and Professional from £170/month; Enterprise on request. | Mixed | Mixed | ✓ | EU | 1 of 27 | Undisclosed | — | ✓ | ✓ | — | E2E | |
| Estonia (Ethicontrol OÜ); offices listed in Tallinn, Berlin, Warsaw, and Kyiv | Starter €89/mo · Standard €174/mo · Advanced €369/mo · Pro €919/mo. Annual billing saves 8%. Standard plans cap at <2,000 employees; >2,000 routes to sales. On-premise license: €13,900 one-time (15-year, 36 months updates). | Tiered | ✓ | ✓ | EU | 2 of 27 | Partial | — | ✓ | — | — | — | |
| Czech Republic | Not published — pricing page now uses quote/contact-sales CTAs instead of the previously embedded EUR/GBP/USD/CZK matrix. | Quote | Sales | ✓ | Selectable | 2 of 27 | Undisclosed | — | ✓ | — | ✓ | E2E | |
| Greece (Athens) | Not published — quote-based. | Quote | Sales | — | EU | 9 of 27 | 12 of 24 | ✓ | ✓ | — | — | — | |
| Germany | Basic from EUR 49/month; Premium from EUR 69/month. Annual billing shown as EUR 588 / EUR 828. | Flat | ✓ | ✓ | EU | 2 of 27 | Partial | — | ✓ | ✓ | ✓ | E2E | |
| Göppingen, Germany | LITE €39, PLUS €59, PREMIUM €99 per month (net of VAT). PARTNER multi-tenant tier quote-based. | Flat | ✓ | ✓ | EU | 1 of 27 | Undisclosed | ✓ | — | — | ✓ | E2E | |
| Lisbon, Portugal | Not published — all four tiers (Base, Value, Elite, Premium) quote-based. Tiers scale by collaborator count: 0–249, 250–499, 500–999, 1,000+. | Quote | Demo | — | Undisclosed | 1 of 27 | 4 of 24 | — | — | ✓ | — | — | |
| Sweden | Not published publicly; demo-led procurement. | Quote | Demo | — | EU | 4 of 27 | Partial | ✓ | ✓ | — | — | — | |
| Italy (Avezzano + Roma) | Private-sector pricing published: Small €40/month (€480/year), Medium €52/month (€624/year), Large €80/month (€960/year), each with a €160 activation cost. Public-administration procurement is sales/Cloud Marketplace led. | Tiered | Sales | — | EU | 1 of 27 | Partial | ✓ | — | ✓ | — | E2E | |
| Spain | Whistleblowing channel: Basic €29/mo for up to 50 employees; Premium €49/mo for up to 500 employees; Business quote-based. Compliance all-in-one Grow from €99/mo; Enterprise quote-based. | Tiered | ✓ | ✓ | EU | 1 of 27 | 6 of 24 | — | ✓ | — | — | — | |
| Cagliari, Italy (offices in Milan, Rome, Sulmona, and Barcelona) | Annual billing excluding VAT. Standard: from €29/month for <50 employees; Premium: from €41/month for <50 employees. Medium/Large/Enterprise tiers quote-based. | Tiered | Demo | — | EU | 3 of 27 | Partial | — | ✓ | ✓ | ✓ | E2E | |
| Frankfurt am Main, Germany | Annual billing: Essential €588/year (€49/mo) for <50 employees; Professional 250 €1,188/year (€99/mo) for <250; Professional 1,000 €1,990/year (€165.83/mo) for <1,000; Enterprise on request for 1,000+. | Tiered | ✓ | — | EU | 1 of 27 | 2 of 24 | ✓ | ✓ | — | — | — | |
| Chania, Crete, Greece | SME tier €120/month plus VAT; Advanced tier custom quote. | Tiered | Sales | ✓ | EU | 1 of 27 | 2 of 24 | ✓ | — | — | — | — | |
| Italy | Exact online-cart totals were not publicly reproducible in the reviewed dynamic store page. An official Zucchetti Store price-list PDF lists My Whistleblowing Starter Pack at €219, Small companies up to 100 employees at €825, and Medium companies up to 300 employees at €1,650. | Tiered | ✓ | — | EU | 1 of 27 | 2 of 24 | ✓ | — | — | — | At rest | |
| Mannheim, Germany | Not published — demo required. | Quote | Sales | — | Undisclosed | 1 of 27 | Undisclosed | — | — | — | ✓ | — | |
| Germany (Dortmund) | Standard from EUR 299/month for 50-249 employees; Enterprise from EUR 499/month for 250-999 employees; Enterprise plus quote-based for 1,000+ employees. Prices require at least 24 months. | Tiered | Demo | — | EU | 1 of 27 | Undisclosed | ✓ | ✓ | ✓ | ✓ | E2E | |
| Germany | Not published on the public page. | Quote | Demo | — | EU | 1 of 27 | Partial | ✓ | — | ✓ | — | — | |
| Sweden (Jönköping) | 695 SEK/month for 0-99 employees, 895 SEK/month for 100-249 employees, 1,295 SEK/month for 250-999 employees; 1,000+ quote-based. | Tiered | Demo | — | EU | 1 of 27 | Undisclosed | ✓ | ✓ | — | — | — | |
| Amsterdam, Netherlands | Essential starts at €3,000/year for organizations up to 1,000 employees. Enterprise is custom-priced. | Tiered | Mixed | — | Undisclosed | 2 of 27 | Undisclosed | — | ✓ | — | ✓ | — | |
| Poland | Annual billing in PLN. Standard 3,600 zł/year, Multi 5,900 zł/year, Premium 7,950 zł/year. Demo access is offered separately. | Tiered | ✓ | ✓ | EU | 1 of 27 | 2 of 24 | — | — | ✓ | — | — | |
| Poland | Three tiers billed monthly on annual contracts. Sygnalista 365: 110 PLN/month. Sygnalista 365 Pro: 150 PLN/month. Sygnalista 365 Pro+: 250 PLN/month. | Tiered | ✓ | — | Undisclosed | 1 of 27 | 2 of 24 | ✓ | — | — | — | — | |
| Poland | Annual billing, net of VAT. Standard: 4,000 zł/year (370 zł/month) for 2 report recipients. Premium: 7,000 zł/year (650 zł/month) for 4 recipients. Enterprise: 10,000 zł/year (920 zł/month) for 6 recipients; each additional recipient 1,000 zł/year. | Tiered | ✓ | ✓ | EU | 1 of 27 | Partial | ✓ | — | ✓ | ✓ | Key | |
| Germany | Business: €79/month flat with unlimited users, cases, and storage. Enterprise: custom quote. | Flat | Demo | — | EU | 2 of 27 | Partial | ✓ | ✓ | — | ✓ | E2E | |
| Sweden | Banded by employee count: SEK 6,000/year (<50), SEK 8,000/year (50–249), SEK 11,000/year (250–499), SEK 15,000/year (500–999), quote for 1,000+. English page shows €600 / €800 / €1,100 / €1,500 equivalents. No startup fees or binding period. | Tiered | ✓ | ✓ | EU | 1 of 27 | Partial | — | ✓ | — | — | E2E | |
| Poland | PRO plan €79/month net, or 20% less on annual billing. Enterprise custom. | Mixed | ✓ | ✓ | EU | 1 of 27 | Partial | ✓ | — | — | — | — | |
| Poland (Kraków) | Legacy public price page states Minimum 2,388 zł/year, Standard 5,988 zł/year, Premium 10,788 zł/year, net of VAT; two-year subscriptions reduce the monthly equivalent to 169 / 424 / 764 zł. Current navigation points buyers to kup.whiblo.pl. | Tiered | ✓ | — | Undisclosed | 1 of 27 | Partial | ✓ | — | — | — | — | |
| Hungary | Hungary pricing: 0-50 employees HUF 19,000/month, 50-500 HUF 29,000/month, 500-1000 HUF 39,000/month, 1000+ custom. Slovakia pricing: 0-50 employees €49/month, 50-500 €79/month, 500-1000 €119/month, 1000+ custom. | Flat | Demo | — | Undisclosed | 2 of 27 | 3 of 24 | — | — | — | — | — | |
| Legnano, Italy | Whisper 100: €500/year + VAT for up to 100 employees; Whisper 250: €900/year + VAT for up to 250 employees; Enterprise: custom. | Tiered | ✓ | — | Undisclosed | 1 of 27 | Partial | ✓ | ✓ | ✓ | — | E2E | |
| Poland | Published monthly pricing: Standard PLN 399/month, Premium PLN 799/month, Enterprise PLN 1,199/month. Legal handling services are individually priced. | Tiered | Sales | ✓ | EU | 1 of 27 | Partial | ✓ | ✓ | — | — | — | |
| Bucharest, Romania | Published monthly pricing: €49/month + VAT for a single entity, €99/month + VAT for groups with up to 5 entities, custom quote for larger or outsourced-service use cases. | Tiered | ✓ | — | Undisclosed | 1 of 27 | Partial | ✓ | — | — | — | — | |
| Germany | EUR 50/month for up to 99 employees, EUR 100/month for up to 249 employees, EUR 150/month for up to 999 employees; 1,000+ quote-based. | Tiered | ✓ | ✓ | EU | 1 of 27 | All 24 | ✓ | ✓ | ✓ | ✓ | At rest | |
| Bucharest, Romania | Public pricing is split across two vendor domains: avertizori.eu lists RON 990/year for the annual software subscription plus RON 190 one-time documentation; whistleblow.ro lists RON 2,990/year for technical implementation plus RON 990 one-time documentation. Outsourced handling is quote-based. | Mixed | ✓ | ✓ | EU | 1 of 27 | Partial | ✓ | ✓ | ✓ | ✓ | E2E | |
| Copenhagen, Denmark | Core: €99 / €149 / €199 / €249 / €349 per month for 0-49 / 50-149 / 150-249 / 250-499 / 500-999 employees. Advanced: €149 / €219 / €299 / €379 / €529 for the same bands. 1,000+ employees contact sales. Billed annually. | Tiered | ✓ | ✓ | EU | 2 of 27 | Partial | — | ✓ | ✓ | ✓ | E2E | |
| Manziana (RM), Italy | Not published. | Quote | Sales | — | Undisclosed | 1 of 27 | Partial | ✓ | — | — | — | — | |
| Sweden | Tiered by employee count: €79 (0–49), €99 (50–149), €149 (150–249), €199 (250–499), €299 (500–999), contact for 1,000+. Annual subscription. | Tiered | ✓ | ✓ | EU | 6 of 27 | 10 of 24 | — | ✓ | ✓ | ✓ | At rest | |
| Lisbon, Portugal | Tiered by employee count: €69 (1–49), €79 (50–149), €89 (150–199), €129 (200–499), €199 (500–999), quote for 1,000+. Billed annually. | Tiered | Sales | — | EU | 1 of 27 | 4 of 24 | — | — | — | — | E2E | |
| Bucharest, Romania | Not published. | Quote | Demo | — | Undisclosed | 1 of 27 | 2 of 24 | ✓ | ✓ | — | — | — | |
| France | Sapin II (incl. internal alerts / whistleblowing): Starter free; Premium from €100/month ex-VAT for SMEs. GDPR: Starter free; Premium from €240/month ex-VAT. | Flat | Demo | ✓ | EU | 1 of 27 | Undisclosed | — | ✓ | — | — | — | |
| United States (exact legal seat not disclosed on public pages reviewed) Non-EU | Start $49/month (no whistleblowing); Grow $149/month (includes whistleblowing); Enterprise starts at $449/month with custom annual plan, data server choice, API integration, dedicated account manager, email/phone support, and SLA. | Flat | ✓ | ✓ | Undisclosed | — | Undisclosed | — | — | — | — | — | |
| Lake Oswego, Oregon, United States Non-EU | EthicsPoint pricing not published. NAVEX's UK WhistleB page says new customers can get started from £75/month; other WhistleB and NAVEX One pricing remains sales-led. | Mixed | Sales | — | Selectable | 2 of 27 | Undisclosed | — | ✓ | — | — | — | |
| Switzerland Non-EU | Starter free; Basic $65/month or $650/year; Premium $110/month or $995/year; Enterprise custom. | Mixed | ✓ | — | Undisclosed | — | All 24 | — | — | — | — | — | |
| Hünenberg, Zug, Switzerland Non-EU | Whistleblowing from €29/month billed annually; plans start from the equivalent of €348 in credits. Credits cost €1 each, from €0.80 at volume, are valid for 3 years, and can be used across Trusty tools. | Credits | ✓ | ✓ | Undisclosed | — | 6 of 24 | ✓ | — | — | — | — | |
| Undisclosed; vendor footer lists UK and Sri Lanka offices, while the privacy policy contact lists Lumora Ventures in San Francisco. Non-EU | USD 1 per employee per month, billed as a single flat-rate plan with all features included; French page localizes this as approximately €0.92 per employee per month. | Flat / employee | ✓ | ✓ | Undisclosed | 1 of 27 | Partial | ✓ | — | — | — | E2E | |
| Sydney, Australia (Paris office) Non-EU | Plan names are public (Essential, Standard, Advanced, Enterprise), but amounts are not published; pricing remains sales-led. | Quote | Sales | — | Selectable | 2 of 27 | Undisclosed | — | ✓ | ✓ | ✓ | Key |
HQ: location of the vendor's legal seat. A Non-EU flag marks vendors headquartered outside the European Union — EU customer data processed by these vendors is a cross-border transfer under GDPR Chapter V and is exposed to third-country jurisdictional access regimes (US CLOUD Act, UK Investigatory Powers Act, equivalents). For organisations prioritising European data sovereignty, prefer an EU-headquartered provider. Model: Flat (single published price), Tiered (per-employee bands), Quote (sales call required), Credits (credit-based). Self-serve: ✓ when you can create an account and launch a portal without a sales call, Demo when vendor requires a demo before purchase, Sales when the entire buying flow runs through a sales team. EU hosting: EU (data stored in named EU data centre), Selectable (customer chooses EU region), Undisclosed (vendor does not publish location). EU countries: count of EU-27 national-law jurisdictions the vendor explicitly references. EU languages: reporting-form coverage of the 24 official EU languages (Bulgarian, Croatian, Czech, Danish, Dutch, English, Estonian, Finnish, French, German, Greek, Hungarian, Irish, Italian, Latvian, Lithuanian, Maltese, Polish, Portuguese, Romanian, Slovak, Slovenian, Spanish, Swedish). No AI: ✓ when the vendor publishes no AI, ML, or machine-translation feature that processes report content — sensitive disclosures are not forwarded to third-party models (OpenAI, Google Translate, etc.). 2FA: ✓ when the vendor publishes two-factor or multi-factor authentication for handlers; ✗ when the vendor explicitly offers only single-factor access; — when not published. Audit log: ✓ when the vendor publishes a tamperproof audit log, audit trail, or equivalent operation-history feature; — when not published. Encryption: Key (customer holds the key; vendor states it cannot decrypt report content), E2E (end-to-end encryption between reporter and handler), At rest (specific at-rest posture such as AES-256 with vendor-held key), — when the vendor publishes no specifics beyond HTTPS. Each row reflects vendor-published information at the verification date listed on the platform's detail page. Verify directly with each vendor before procurement decisions.
Platform profiles
Each profile lists vendor-published facts, capabilities, certifications, and source URLs.
View all 53 platforms →Frequently asked questions
Buyer questions that recur across procurement and compliance reviews. All answers reference the Directive's text or vendor-published facts.
- What is the EU Whistleblower Directive?
- Directive (EU) 2019/1937 sets minimum EU-wide standards for protecting persons who report breaches of Union law. It requires covered organisations to operate secure internal reporting channels, prohibits retaliation against reporters, and obliges member states to transpose it into national law.
- Which organisations must have a whistleblower reporting channel?
- Private-sector organisations with 50 or more employees, all public-sector entities, and all financial-sector entities regardless of size. Some national transpositions extend the scope further — verify the obligation in each jurisdiction where your organisation operates.
- What counts as a compliant reporting channel?
- A secure, confidential channel that accepts reports in writing and orally, protects the reporter's identity, tracks acknowledgement within 7 days, and delivers follow-up feedback within 3 months. Most organisations deploy a digital platform backed by a designated handler; telephone hotlines and in-person meetings also qualify.
- Does whistleblower software have to be hosted in the EU?
- Directive 2019/1937 does not mandate EU hosting. The GDPR governs transfers of personal data outside the EU and most procurement teams treat EU-hosted processing as the default. This directory records each vendor's published hosting region.
- Can whistleblower reports be anonymous?
- The Directive leaves anonymous reporting to national discretion, but a reporter who is later identified still receives the full protections. Germany (HinSchG), France (Loi Waserman / Sapin II), and Italy (D.Lgs. 24/2023) explicitly accept anonymous reports.
- What deadlines apply once a report is received?
- Acknowledgement of receipt within 7 days, follow-up feedback to the reporter within 3 months, and retention of records under GDPR. Platforms in this directory vary in how they enforce and surface these deadlines.
- How much does whistleblower software cost?
- Published entry prices in this directory start around €40 per month for flat-rate EU SME plans. Per-employee tiered pricing reaches several hundred euros per month above 1,000 employees. Several enterprise vendors publish no price and require sales engagement.
- What are the penalties for non-compliance?
- Penalties are set in national transposition laws. Germany's HinSchG sets fines up to €50,000 for failing to establish a channel and up to €100,000 for retaliation against a reporter. Other member states publish similar ranges.
About this directory
EU Directive 2019/1937 requires organisations with 50 or more employees to operate a secure internal reporting channel. This directory lists platforms that vendors publicly market for that purpose.
Every fact on every platform page is sourced from the vendor's own published materials (pricing pages, product pages, press releases, security pages). Each entry shows the date it was last verified and links to the source URLs used.
No editorial recommendation is given. Verify any fact directly with the vendor before a procurement decision.