Skip to main content
EU Whistleblower Directory

Edition I, 2026 · Tested June 2026

Whistleblowing software ranking — Belgium

Independent scored ranking of whistleblower-reporting tools for Belgium under the Law of 28 November 2022, the local transposition of EU Directive 2019/1937. 25-criterion rubric fixed before scoring; every score carries evidence.

Tools scored
3
Base max
50
Belgium bonus max
6
Rubric version
v2

Belgium is an unusual market: there is no Belgium-origin whistleblowing-software vendor. Belgian employers buy from pan-EU platforms — frequently introduced through a Belgian law firm — rather than from a domestic product. So this ranking is not “local vendors vs. imports”; it is a comparison of the directive-grade tools that actually serve the Belgian market, scored on the same rubric as every other country.

This edition uses two layers:

  • the 50-point base rubric, which stays country-agnostic and scores the product itself: legal workflow depth, reporter experience, handler workflow, security posture, and commercial clarity;
  • the 6-point Belgium modifier, which rewards explicit reference to the Law of 28 November 2022, a named Belgium-acceptable hosting posture, and a Dutch- or French-language reporter / handler surface (Belgium’s two main working languages).

That combination rewards tools that go beyond generic Directive 2019/1937 marketing to a real Belgian-law posture and Belgium’s bilingual reality.

This ranking is software-only. Belgian law firms and consultancies that resell or wrap a third-party platform are not listed in their own right; the underlying platform is what is scored. The Federal Ombudsman’s Integrity Centre is the external reporting coordinator and the FSMA covers the financial sector — those are reporting destinations, not products, and are out of scope here.

TOP 3 — summary

#ToolTierBase
/ 50
Belgium bonus
/ 6
TotalLast reviewed
1EthicsPortal logo EthicsPortalP+R+H475522026-06-21
2Whistleblower Software (Formalize) logo Whistleblower Software (Formalize)P275322026-07-19
3FaceUp logo FaceUpP264302026-05-24

Criterion-by-criterion matrix

fully meets partially meets does not meet / not verifiable

CriterionEthicsPortal logo EthicsPortalWhistleblower Software (Formalize) logo Whistleblower Software (Formalize)FaceUp logo FaceUp
Legal compliance · 16 pts max
A1 Local transposition law referenced with article numbers
A2 Directive 2019/1937 Article 2(1) categories in intake
A3 Anonymous reporting default-on or equal-status
A4 7-day acknowledgment + 3-month feedback deadline tracking
A5 Configurable retention with automatic deletion
A6 Report register / log
A7 Append-only handler audit trail
A8 DPA + DPIA support documented
Reporter experience · 10 pts max
B9 Web form, mobile-responsive, with file upload
B10 Two-factor reporter access (Case ID + passcode)
B11 Two-way anonymous communication
B12 Structured intake aligned to Article 2(1)
B13 Reporter form in local language
Handler experience · 10 pts max
C14 Case management dashboard with status workflow
C15 Assign cases to handlers (rotation or multi-handler)
C16 Deadline reminder notifications
C17 Internal notes (not visible to reporter)
C18 Role-based access control (≥3 roles)
Security and trust · 8 pts max
D19 ISO 27001 certified
D20 No EOL software components
D21 EU data residency with country disclosed
D22 Sub-processor list + right to object
Commercial · 6 pts max
E23 Published pricing
E24 Free trial available (self-serve)
E25 Monthly contract option
Belgium bonus · 6 pts max · modifier, not in base
BE·LAW Belgian whistleblower law (28 Nov 2022) referenced
BE·RESIDENCY Belgium or named EU residency
BE·UI Dutch- or French-language UI
Total523230

Per-tool reviews

#1
EthicsPortal logo

EthicsPortal

Poland · Whistleblower reporting portal hosted on Hetzner in Germany. Flat €60/month plan.

52 / 56
Base 47 · Bonus 5 · Tier P+R+H
Legal
16/16
Reporter
0/10
Handler
10/10
Security
6/8
Commercial
5/6

Strengths

  • Article-level legal framing: /compliance/ enumerates Directive 2019/1937 Articles 4, 6, 8, 9, 16, 18, 19–21 and links to a dedicated page for each of the 27 EU transpositions
  • All 27 EU national whistleblower laws are named on public /whistleblower-laws/<country>/ pages with official source citations
  • Oral reporting (Art 9(2)(b)) is built into the portal as in-browser voice recording and is privacy-engineered: the raw audio is automatically pitch-shifted, only the anonymized clip is ever served, and the original recording is purged after processing (fail-closed — nothing is exposed to handlers until anonymization succeeds)
  • Report categories are tagged to specific Directive Art 2(1) Union-law domains, with the article reference shown as a handler-side badge while reporters pick plain-language categories
  • Structured intake: five optional, Directive-aligned questions (relationship to org per Art 4, source of knowledge, incident timing, prior reporting, retaliation concern per Art 19) presented as a skippable guided step, surfaced to handlers and the PDF export with retaliation flagged as an urgency badge — a built-in default set where most tools leave these to per-org custom-field configuration
  • Three role tiers (member / admin / viewer): viewer is a read-only seat for auditors and external counsel that sees every report plus the full audit trail without any write or management path
  • GDPR Art 20 portability: admins can export the full organization dataset (reports, messages, attachments, with encrypted fields decrypted for portability) as a ZIP; export and download are audit-logged and the ZIP auto-purges after 7 days
  • Real deadline tracking: 7-day acknowledgement and 3-month feedback deadlines with overdue/due-soon tracking and a lifecycle stepper in both reporter and handler views
  • Configurable retention (12/24/36/48/60 months) with automatic purge of expired closed reports; open reports left inactive for 18 months auto-close so the retention clock starts (GDPR Art 5(1)(e) storage limitation), closing the open-forever gap
  • Two-factor reporter access: case reference (WB-XXXX-XXXX) plus a reporter-chosen 6-digit passcode, session-gated inbox. Reporters can also download a PDF copy of their own report from the follow-up portal (audit-logged)
  • Audit log surfaced to handlers on each report; append-only at the database level
  • Modern stack with no end-of-life liabilities
  • Transparent monthly pricing (€60/mo) with 13 live product locales (12 EU official languages — bg, de, el, en, es, fr, hr, it, nl, pl, pt, ro — plus Luxembourgish)
  • Multi-handler case assignment: each report can be assigned to a handler, admins see all reports and members see only assigned, assignment changes are audit-logged, and deactivated members are auto-unassigned from open reports
  • Handler-set case priority (low / normal / high / urgent) recorded at assessment as an audit-logged change and surfaced as a badge on the report list, plus a priority breakdown in the exportable compliance report
  • SCIM 2.0 provisioning so an identity provider (Okta, Microsoft Entra ID) can provision case handlers and — the core value — auto-deprovision them the moment someone leaves the directory; admins generate, rotate, and enable/disable a per-organization token and pick the default role
  • SAML 2.0 single sign-on so staff authenticate through the organization's identity provider (Okta, Microsoft Entra ID); configured per organization, covers one or more email domains, with optional enforcement (require SSO for those domains) and optional just-in-time account provisioning on first sign-in — the authentication half of the SSO + SCIM enterprise-identity pair
  • Published ISO 37002:2021 guidance-alignment map (/iso-37002/) walking the standard's operating clauses against shipped features, alongside the ISO 27001 Annex A self-assessment
  • Published DPA grants the Controller an explicit right to object to subprocessor changes (§6.4, 30-day notice + termination remedy) and commits to 72-hour breach notification (§6.6); /trust/ publishes contracting party, backups, RTO/RPO, and session lifecycle
  • Zero-AI commitment codified contractually: DPA §6.10 prohibits transmission of personal data to any LLM or AI inference provider; /subprocessors/ lists no AI sub-processor

Weaknesses

  • Audit log is append-only but not hash-chained
  • Only 13 portal-facing languages (12 EU official languages + Luxembourgish) against 24 EU official languages
  • No ISO 27001 certification of EthicsPortal itself (only Hetzner infrastructure is certified)
  • Pay-first with 30-day money-back rather than an upfront self-serve free trial
  • Role tiers are org-scoped, not per-case ACLs: the viewer role adds the auditor seat, but a handler's report visibility is still governed by assignment/participant scoping rather than a per-case permission model

Standout

Article-level Directive framing paired with a 27-page country-law reference and privacy-engineered oral reporting, all surfaced in the live product alongside working deadline, retention, two-factor passcode, audit-log, voice-anonymization, and subprocessor-notification flows.

#2
Whistleblower Software (Formalize) logo

Whistleblower Software (Formalize)

Copenhagen, Denmark · Whistleblower Software product from Formalize with public Core and Advanced annual pricing.

32 / 56
Base 27 · Bonus 5 · Tier P
Legal
7/16
Reporter
4/10
Handler
5/10
Security
7/8
Commercial
4/6

Strengths

  • Current pricing is public and materially different from the previous €70-€285 matrix.
  • Security page names ISO 27001:2022, ISAE 3000 Type 2, ENS, WCAG 2.1 AA, end-to-end encryption, and AWS Frankfurt hosting.
  • 80+ languages, anonymized reporting, case management, SSO/OAuth, SAML 2.0 and SCIM 2.0 are disclosed publicly.

Weaknesses

  • API access, DPA download, subprocessor list, retention configuration, and Directive article-level mapping were not disclosed on public pages reviewed.
  • Loi Waserman, Sapin II, and Greece Law 4990/2022 were not found on public pages reviewed.

Standout

Public pages show employee-band pricing and security claims; the previous pricing matrix and API claim were not supported by current pages.

#3
FaceUp logo

FaceUp

Czech Republic · Whistleblowing, employee-relations, and workplace-compliance platform from the Czech Republic.

30 / 56
Base 26 · Bonus 4 · Tier P
Legal
7/16
Reporter
7/10
Handler
5/10
Security
6/8
Commercial
1/6

Strengths

  • Current public pricing page no longer exposes the previously captured EUR/GBP/USD/CZK employee-band amounts in the page output reviewed.
  • Public feature/pricing pages support 113 languages, anonymous reporting, two-way chat, online form, voice recording, automated/live/AI hotline add-ons, iOS/Android apps, multiple forms, webhooks, API, Zapier, and Make.
  • Security/DPA pages support ISO 27001:2022, SOC 2, E2EE, no IP storage, metadata removal, SSO, 2FA, penetration testing, selectable AWS regions, subprocessor details, and OpenAI use limited to the AI-powered hotline.

Weaknesses

  • Pricing amounts were not found on the current public pricing page output reviewed.
  • Exact EU official-language list, article-by-article Directive mapping, Loi Waserman, Sapin II, and Greece Law 4990/2022 were not disclosed on public pages reviewed.

Standout

FaceUp has public trial, security, DPA, and integration disclosure; the main correction is removing the stale public price matrix.

Methodology

Scoring rubric

25 criteria across 5 categories, weighted by criterion count. Each criterion scores 0, 1, or 2 — rendered as ○ / ◐ / ●. Maximum base score is 50. Belgium-specific bonuses add up to 6 on top (modifier, not part of base).

Access tiers

Each tool carries an access tier reflecting what was testable:

  • P — public pages only (marketing, pricing, security, reporter URL).
  • P + R — above plus a test report submission.
  • P + R + H — above plus handler / admin dashboard (via free trial or demo).

Criteria that cannot be verified at the current tier score 0 with the evidence line "Requires handler tier" or "Not documented publicly". Scores depressed by tier, not by product quality, are explicitly flagged on each tool's profile.

Integrity guarantees

  1. The rubric was fixed before scoring. No criterion was added mid-test to favour or punish a specific tool.
  2. Every score carries evidence — a URL, a quote, or a file path — visible in each tool's profile.
  3. Tools operated by the publisher are scored by the same rubric. Placement is by score, not by construction.
  4. Each tool carries a Last reviewed date and is re-tested at least annually.
  5. Vendors can dispute a score or submit evidence of a shipped fix using the contact address in the site footer. Disputes and updates appear as dated addenda on the respective tool profile.

Law applied

Wet/Loi van 28 november 2022 (the Belgium transposition of EU Directive 2019/1937). Tools are scored against the Directive first and against the local law's specifics second.

Coverage note

This ranking covers 3 tools with a scoring block published. Additional tools are being added as scoring completes. Unscored tools will appear in the ranking once they have a published scoring block.

All tools Other country rankings