IntegrityCounts
Live-answer ethics hotline and case management from WhistleBlower Security, a Case IQ company, with data held in Canada and sales-led pricing.
Non-EU HQ Part of Case IQ
West Vancouver, British Columbia, Canada. This vendor is headquartered outside the European Union. EU personal data processed by the vendor is a cross-border transfer under GDPR Chapter V and depends on an adequacy decision, Standard Contractual Clauses, or a derogation. Non-EU providers introduce jurisdictional exposure to third-country data-access regimes. For institutional buyers prioritising European data sovereignty, prefer an EU-headquartered provider.
Rubric score
24 / 50
Evidence tier P
Public pages only. No trial and no public handler environment; the reporter entry point at integritycounts.ca requires client-specific access, so no report was filed.
Facts
- Headquarters
- West Vancouver, British Columbia, Canada
- Hosting
- Canada. Two Microsoft Azure data centres in Canada, geo-replicated to the second Canadian region (vendor-stated). No EU region is offered on public pages reviewed.
- Pricing
- Not published. No pricing page exists on the vendor site; the hotline comparison page states only "Our all-inclusive service has everything you need at a price you can afford." Procurement runs through Request a Demo and Contact Us.No tier matrix, employee band, per-report price, or contract term is published. The implementation page describes a 4-to-6 week setup with data migration and training, which is a sales-and-onboarding motion rather than a self-serve one.
- Languages on reporting form
- Not published
- Founded
- 2005
- Domain registered
- whistleblowersecurity.com
- Ownership
- Acquired by Case IQ (Ottawa, Ontario) on 19 October 2023; Case IQ is owned by Resurgens Technology Partners
- Customers
- 106 countries, 107 industries, 3,695,000+ employees covered, 98% customer retention (vendor claims)
- Product scope
- Module of Case IQ
- Encryption posture
- At rest
Measured, not published
Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.
- DMARC policy
- Published but not enforcing
- DNSSEC
- Unsigned
Capabilities
- Anonymous reporting ✓
- Multi-channel intake ✓
- Public API —
- Free trial ✗
- Two-factor authentication —
- Audit log ✓
- EU Directive 2019/1937 (vendor claim) ✓
✓ published by the vendor · ✗ vendor states it is not offered · — not published either way
Certifications and national law
Certifications
- ISO/IEC 27001:2013 (BSI certificate IS 777646, expiry date 2025-10-31)
National laws referenced
- EU Directive 2019/1937
- Canada (Bill 198 / Multilateral Instrument 52-110)
- Canada (BC PIDA)
- United States (Sarbanes-Oxley)
- Australia (Corporations Act 2001)

Multinational organisations that want live-answer telephone intake in many languages and are content to have report data held in Canada under the EU adequacy decision rather than in the EU.
Distinctive features
- Live-answer hotline staffed 24/7 with agents who directly support English, French and Spanish, and interpretation for 150 further languages; the web form is described as multilingual but its language list is not published
- Four intake routes documented for reporters: web, telephone, a per-client email address, and postal mail
- Three anonymity levels documented, including one where the vendor itself does not learn the reporter's identity
- Named case-scoped roles (Case Manager, Investigator, Restricted Manager) with permissions scoped by case type, location or department
Add-ons and conditions
Costs or terms not included in the headline price.
- No price of any kind is published, and no trial exists; the only documented entry route is a demo request
- Implementation is quoted at 4 to 6 weeks including data migration and training
- The published ISO 27001 certificate is against the 2013 edition of the standard and expired on 31 October 2025, the close of the transition period to the 2022 edition
- Report data is held in Canada, not the EU; GDPR position rests on the Canadian adequacy decision rather than on a published DPA
- No retention period, sub-processor list, or DPA is published
Notable
- IntegrityCounts is the ethics-hotline and case-management product of WhistleBlower Security Inc., West Vancouver, British Columbia. Case IQ (formerly i-Sight, Ottawa) acquired the company on 19 October 2023; Case IQ is owned by Resurgens Technology Partners.
- The company page places the product inside a wider programme: IntegrityCounts “is part of an integrated compliance suite that offers you end-to-end compliance and risk management services that unifies real-time compliance monitoring, whistleblower solutions, third-party risk management, approvals and disclosures, and investigative workflows.”
- The acquisition release sets out how the two products divide: Case IQ’s own case management “offers higher configurability and focuses on the needs of the investigator”, while IntegrityCounts “focuses on the needs of the incident reporter”. The same release says the pair between them “can cater to the unique needs of enterprise and SMBs, with tremendous value at different price points” — neither of which is published.
- Telephone intake is the distinguishing channel. A live agent walks the reporter through a questionnaire, transcribes the case, reads it back for confirmation, and submits it. Agents directly support English, French and Spanish; 150 further languages come through an interpretation partner.
- Reporters have four routes: the web form, the toll-free hotline, a per-client email address, and postal mail to a West Vancouver PO box.
- Three anonymity levels are published, and they are genuinely distinct: strictly anonymous, anonymous to the organisation but known to the vendor, and identified to both.
- Handler tooling is the most fully documented part of the product. Named roles, multi-investigator assignment, automatic case routing, restricted managers, per-case activity logs, internal messages with attachments, a task manager with due dates, an analytics dashboard, and scheduled automated reports are all described on public pages.
- Report data is held in Canada across two Azure regions. No EU region is offered. The GDPR position is stated as compliance “by adequacy status” — the Canadian adequacy decision, which covers recipients subject to PIPEDA.
- Nothing is published on retention or deletion. The only legal document on the site is a one-page Terms of Service covering the reporter’s confidentiality, not the controller’s obligations.
- Commercial disclosure is nil: no price, no band, no contract term, no trial. Implementation is quoted at 4 to 6 weeks.
Vendor-page evidence - 2026-09-21
- The certifications page publishes the ISO 27001 certificate as a PDF rather than describing it. The certificate is BSI IS 777646, against ISO/IEC 27001:2013, original registration 11 January 2023, expiry date 31 October 2025. Its scope names the IntegrityCounts platform. That date is not an ordinary lapse: 31 October 2025 was the end of the transition period from the 2013 edition of the standard to the 2022 edition, so every 2013-edition certificate expired then. What is published is therefore a certificate that has run out with nothing published in its place — no 2022-edition certificate, and no in-date certificate of any edition, was found on pages reviewed.
- The same page notes that Microsoft Azure is “covered by SOC 2 TYPE II, ISO27000 Series, and CSAE 3416”. Those are the hosting provider’s attestations, so they are not recorded as vendor certifications.
- The trust centre names Canada as the storage location twice, and describes two Canadian Azure data centres with geo-replication between them. Encryption is TLS 1.2 in transit and Transparent Data Encryption at rest, with attachments in encrypted Azure blob storage.
- The EU Directive section of the regulatory-compliance page still describes transposition in the future tense. It states that “Each of the 27 EU member states will need to transcribe the directives into their own national law” and that “Companies with over 250 employees will need to ensure they are compliant with the new regulations by the end of the year” — both of which describe the position before the December 2021 transposition deadline.
- Reading the French locale changed nothing about law coverage. The French regulatory page is a real translation, not English text on a
/frURL, and it names the same laws as the English one: RGPD, Sarbanes-Oxley, Bill 198, BC PIDA. Neither Loi Waserman nor Sapin II appears on either locale. - The reporter FAQ lists supported browsers as “Internet Explorer 11 Google Chrome Microsoft Edge Firefox Safari Opera”. IE11 was retired in June 2022.
whistleblowersecurity.compublishes SPF but no DNSSEC and no CAA record, and its DMARC policy isp=none— monitoring without enforcement, on the domain that sends reporters their case notifications.integritycounts.ca, the reporter entry point, is the same on all four.- The reporter entry point at
www.integritycounts.caanswers 200 over HTTPS with HSTS, a content-security policy,X-Frame-Options,X-Content-Type-Optionsand a permissions policy set. It is a single-page application requiring client-specific access, so no report was filed and no intake fields were inspected. - No API documentation, sub-processor list, DPA, DPIA material, retention statement, or price was found on public pages reviewed.
Scoring review - 2026-09-21
Scored under the 25-criterion rubric v2 at access tier P (public pages only; no trial exists and the reporter entry point requires client-specific access).
Base score: 24 / 50. France country bonus: 1 / 8.
| Category | Score | Max |
|---|---|---|
| A. Legal compliance | 5 | 16 |
| B. Reporter experience | 7 | 10 |
| C. Handler experience | 9 | 10 |
| D. Security | 3 | 8 |
| E. Commercial | 0 | 6 |
What lifts the score: handler tooling, at 9 of 10, is among the highest handler scores in the directory, and it is earned rather than inferred — the feature pages name the roles, the routing behaviour, the internal-notes surface and the case states explicitly. Reporter intake is strong on channel breadth: four routes including a live-answer hotline, three published anonymity levels, and messaging that survives anonymity.
What caps it: the two categories a European buyer weighs most heavily. Legal compliance scores 5 of 16 because the product is documented against Canadian, US and Australian law, with the EU Directive named only generically and no national transposition law named on either locale — including the French one. Security scores 3 of 8 because data residency is Canadian with no EU option, the only published ISO 27001 certificate expired at the close of the 2013-edition transition period with no replacement published, and no sub-processor list or DPA is published. Commercial disclosure scores 0.
The shape of the product, not a defect in it: what the scores describe is an enterprise ethics-hotline programme — multilingual live-answer intake across 106 countries, investigator-grade case tooling, a 4-to-6 week implementation with training, sold by demo and quoted on request, inside a suite that also carries third-party risk management and approvals and disclosures. That is a coherent product with a coherent buyer. It is a poor fit for an organisation whose obligation is a single EU internal reporting channel receiving a handful of reports a year, which will pay for the hotline capacity, the implementation project and the suite regardless of volume, and will still need to establish its own EU legal and residency position because the vendor’s pages do not.
Buyer fit: multinationals with real report volume, a preference for telephone intake, and a compliance function able to accept Canadian residency under the adequacy decision and to write its own DPA. Organisations that need EU hosting, a named transposition law, published retention, a current ISO 27001 certificate, or a price before a sales conversation will not find them here.
Frequently asked questions about IntegrityCounts
Answers derived from vendor-published materials dated on this page.
Is IntegrityCounts suitable for SMEs under 250 employees?
Which national whistleblower laws does IntegrityCounts explicitly reference?
Does IntegrityCounts process whistleblower report content with AI?
Similar to IntegrityCounts
Other platforms in the directory with overlapping pricing model, certifications, or procurement path.
osapiens
Complaint-management and whistleblower module of the osapiens HUB ESG/compliance platform.Ethicorp French lawyer-managed whistleblowing channel (EthiAlert) operated by ethics lawyers under Loi Sapin II and Loi Waserman, with the platform hosted in France.
Falcony Finnish whistleblowing module within the Falcony reporting platform, offering an anonymous online reporting form and case management; the vendor acquired the First Whistle whistleblowing product in 2026.
Safecall UK managed whistleblowing hotline and case-management software from Safecall Ltd, with former-police call handlers and UK-based data hosting; pricing is sales-led.
Sources and verification
Every fact on this page comes from IntegrityCounts's own published materials. These are the pages that were read, and the date they were read.
- Last verified
- www.whistleblowersecurity.com/ (opens in new tab)
- www.whistleblowersecurity.com/trust-center (opens in new tab)
- www.whistleblowersecurity.com/about/certifications (opens in new tab)
- www.whistleblowersecurity.com/about/company-and-team (opens in new tab)
- www.whistleblowersecurity.com/services/web-intake (opens in new tab)
- www.whistleblowersecurity.com/services/web-intake/features (opens in new tab)
- www.whistleblowersecurity.com/services/case-management/features (opens in new tab)
- www.whistleblowersecurity.com/services/global-ethics-hotline (opens in new tab)
- www.whistleblowersecurity.com/resources/regulatory-compliance (opens in new tab)
- www.whistleblowersecurity.com/resources/faq (opens in new tab)
- www.whistleblowersecurity.com/resources/implementation (opens in new tab)
- www.whistleblowersecurity.com/whistleblower-hotline-providers (opens in new tab)
- www.whistleblowersecurity.com/press/case-iq-strengthens-position-as-a-leader-in-governance-risk-and-compliance-with-the-acquisition-of-whistleblower-security (opens in new tab)
- www.whistleblowersecurity.com/fr/resources/regulatory-compliance (opens in new tab)