Skip to main content
EU Whistleblower Directory
IntegrityCounts logo

IntegrityCounts

Live-answer ethics hotline and case management from WhistleBlower Security, a Case IQ company, with data held in Canada and sales-led pricing.

Non-EU HQ Part of Case IQ

Non-EU headquarters — data sovereignty risk

West Vancouver, British Columbia, Canada. This vendor is headquartered outside the European Union. EU personal data processed by the vendor is a cross-border transfer under GDPR Chapter V and depends on an adequacy decision, Standard Contractual Clauses, or a derogation. Non-EU providers introduce jurisdictional exposure to third-country data-access regimes. For institutional buyers prioritising European data sovereignty, prefer an EU-headquartered provider.

Rubric score

24 / 50

Evidence tier P

Public pages only. No trial and no public handler environment; the reporter entry point at integritycounts.ca requires client-specific access, so no report was filed.

How this score is produced →

Facts

Website
www.whistleblowersecurity.com(opens in new tab)
Headquarters
West Vancouver, British Columbia, Canada
Hosting
Canada. Two Microsoft Azure data centres in Canada, geo-replicated to the second Canadian region (vendor-stated). No EU region is offered on public pages reviewed.
Pricing
Not published. No pricing page exists on the vendor site; the hotline comparison page states only "Our all-inclusive service has everything you need at a price you can afford." Procurement runs through Request a Demo and Contact Us.
No tier matrix, employee band, per-report price, or contract term is published. The implementation page describes a 4-to-6 week setup with data migration and training, which is a sales-and-onboarding motion rather than a self-serve one.
Languages on reporting form
Not published
Founded
2005
Domain registered
whistleblowersecurity.com
Ownership
Acquired by Case IQ (Ottawa, Ontario) on 19 October 2023; Case IQ is owned by Resurgens Technology Partners
Customers
106 countries, 107 industries, 3,695,000+ employees covered, 98% customer retention (vendor claims)
Product scope
Module of Case IQ
Encryption posture
At rest

Measured, not published

Established by checking the vendor's own infrastructure rather than by reading its marketing. Every figure here can be reproduced from the links given.

DMARC policy
Published but not enforcing
DNSSEC
Unsigned

Capabilities

  • Anonymous reporting
  • Multi-channel intake
  • Public API
  • Free trial
  • Two-factor authentication
  • Audit log
  • EU Directive 2019/1937 (vendor claim)

✓ published by the vendor · ✗ vendor states it is not offered · — not published either way

Certifications and national law

Certifications

  • ISO/IEC 27001:2013 (BSI certificate IS 777646, expiry date 2025-10-31)

National laws referenced

  • EU Directive 2019/1937
  • Canada (Bill 198 / Multilateral Instrument 52-110)
  • Canada (BC PIDA)
  • United States (Sarbanes-Oxley)
  • Australia (Corporations Act 2001)
IntegrityCounts homepage screenshot
Typical buyer

Multinational organisations that want live-answer telephone intake in many languages and are content to have report data held in Canada under the EU adequacy decision rather than in the EU.

Distinctive features

  • Live-answer hotline staffed 24/7 with agents who directly support English, French and Spanish, and interpretation for 150 further languages; the web form is described as multilingual but its language list is not published
  • Four intake routes documented for reporters: web, telephone, a per-client email address, and postal mail
  • Three anonymity levels documented, including one where the vendor itself does not learn the reporter's identity
  • Named case-scoped roles (Case Manager, Investigator, Restricted Manager) with permissions scoped by case type, location or department

Add-ons and conditions

Costs or terms not included in the headline price.

  • No price of any kind is published, and no trial exists; the only documented entry route is a demo request
  • Implementation is quoted at 4 to 6 weeks including data migration and training
  • The published ISO 27001 certificate is against the 2013 edition of the standard and expired on 31 October 2025, the close of the transition period to the 2022 edition
  • Report data is held in Canada, not the EU; GDPR position rests on the Canadian adequacy decision rather than on a published DPA
  • No retention period, sub-processor list, or DPA is published

Notable

  • IntegrityCounts is the ethics-hotline and case-management product of WhistleBlower Security Inc., West Vancouver, British Columbia. Case IQ (formerly i-Sight, Ottawa) acquired the company on 19 October 2023; Case IQ is owned by Resurgens Technology Partners.
  • The company page places the product inside a wider programme: IntegrityCounts “is part of an integrated compliance suite that offers you end-to-end compliance and risk management services that unifies real-time compliance monitoring, whistleblower solutions, third-party risk management, approvals and disclosures, and investigative workflows.”
  • The acquisition release sets out how the two products divide: Case IQ’s own case management “offers higher configurability and focuses on the needs of the investigator”, while IntegrityCounts “focuses on the needs of the incident reporter”. The same release says the pair between them “can cater to the unique needs of enterprise and SMBs, with tremendous value at different price points” — neither of which is published.
  • Telephone intake is the distinguishing channel. A live agent walks the reporter through a questionnaire, transcribes the case, reads it back for confirmation, and submits it. Agents directly support English, French and Spanish; 150 further languages come through an interpretation partner.
  • Reporters have four routes: the web form, the toll-free hotline, a per-client email address, and postal mail to a West Vancouver PO box.
  • Three anonymity levels are published, and they are genuinely distinct: strictly anonymous, anonymous to the organisation but known to the vendor, and identified to both.
  • Handler tooling is the most fully documented part of the product. Named roles, multi-investigator assignment, automatic case routing, restricted managers, per-case activity logs, internal messages with attachments, a task manager with due dates, an analytics dashboard, and scheduled automated reports are all described on public pages.
  • Report data is held in Canada across two Azure regions. No EU region is offered. The GDPR position is stated as compliance “by adequacy status” — the Canadian adequacy decision, which covers recipients subject to PIPEDA.
  • Nothing is published on retention or deletion. The only legal document on the site is a one-page Terms of Service covering the reporter’s confidentiality, not the controller’s obligations.
  • Commercial disclosure is nil: no price, no band, no contract term, no trial. Implementation is quoted at 4 to 6 weeks.

Vendor-page evidence - 2026-09-21

  • The certifications page publishes the ISO 27001 certificate as a PDF rather than describing it. The certificate is BSI IS 777646, against ISO/IEC 27001:2013, original registration 11 January 2023, expiry date 31 October 2025. Its scope names the IntegrityCounts platform. That date is not an ordinary lapse: 31 October 2025 was the end of the transition period from the 2013 edition of the standard to the 2022 edition, so every 2013-edition certificate expired then. What is published is therefore a certificate that has run out with nothing published in its place — no 2022-edition certificate, and no in-date certificate of any edition, was found on pages reviewed.
  • The same page notes that Microsoft Azure is “covered by SOC 2 TYPE II, ISO27000 Series, and CSAE 3416”. Those are the hosting provider’s attestations, so they are not recorded as vendor certifications.
  • The trust centre names Canada as the storage location twice, and describes two Canadian Azure data centres with geo-replication between them. Encryption is TLS 1.2 in transit and Transparent Data Encryption at rest, with attachments in encrypted Azure blob storage.
  • The EU Directive section of the regulatory-compliance page still describes transposition in the future tense. It states that “Each of the 27 EU member states will need to transcribe the directives into their own national law” and that “Companies with over 250 employees will need to ensure they are compliant with the new regulations by the end of the year” — both of which describe the position before the December 2021 transposition deadline.
  • Reading the French locale changed nothing about law coverage. The French regulatory page is a real translation, not English text on a /fr URL, and it names the same laws as the English one: RGPD, Sarbanes-Oxley, Bill 198, BC PIDA. Neither Loi Waserman nor Sapin II appears on either locale.
  • The reporter FAQ lists supported browsers as “Internet Explorer 11 Google Chrome Microsoft Edge Firefox Safari Opera”. IE11 was retired in June 2022.
  • whistleblowersecurity.com publishes SPF but no DNSSEC and no CAA record, and its DMARC policy is p=none — monitoring without enforcement, on the domain that sends reporters their case notifications. integritycounts.ca, the reporter entry point, is the same on all four.
  • The reporter entry point at www.integritycounts.ca answers 200 over HTTPS with HSTS, a content-security policy, X-Frame-Options, X-Content-Type-Options and a permissions policy set. It is a single-page application requiring client-specific access, so no report was filed and no intake fields were inspected.
  • No API documentation, sub-processor list, DPA, DPIA material, retention statement, or price was found on public pages reviewed.

Scoring review - 2026-09-21

Scored under the 25-criterion rubric v2 at access tier P (public pages only; no trial exists and the reporter entry point requires client-specific access).

Base score: 24 / 50. France country bonus: 1 / 8.

CategoryScoreMax
A. Legal compliance516
B. Reporter experience710
C. Handler experience910
D. Security38
E. Commercial06

What lifts the score: handler tooling, at 9 of 10, is among the highest handler scores in the directory, and it is earned rather than inferred — the feature pages name the roles, the routing behaviour, the internal-notes surface and the case states explicitly. Reporter intake is strong on channel breadth: four routes including a live-answer hotline, three published anonymity levels, and messaging that survives anonymity.

What caps it: the two categories a European buyer weighs most heavily. Legal compliance scores 5 of 16 because the product is documented against Canadian, US and Australian law, with the EU Directive named only generically and no national transposition law named on either locale — including the French one. Security scores 3 of 8 because data residency is Canadian with no EU option, the only published ISO 27001 certificate expired at the close of the 2013-edition transition period with no replacement published, and no sub-processor list or DPA is published. Commercial disclosure scores 0.

The shape of the product, not a defect in it: what the scores describe is an enterprise ethics-hotline programme — multilingual live-answer intake across 106 countries, investigator-grade case tooling, a 4-to-6 week implementation with training, sold by demo and quoted on request, inside a suite that also carries third-party risk management and approvals and disclosures. That is a coherent product with a coherent buyer. It is a poor fit for an organisation whose obligation is a single EU internal reporting channel receiving a handful of reports a year, which will pay for the hotline capacity, the implementation project and the suite regardless of volume, and will still need to establish its own EU legal and residency position because the vendor’s pages do not.

Buyer fit: multinationals with real report volume, a preference for telephone intake, and a compliance function able to accept Canadian residency under the adequacy decision and to write its own DPA. Organisations that need EU hosting, a named transposition law, published retention, a current ISO 27001 certificate, or a price before a sales conversation will not find them here.

Frequently asked questions about IntegrityCounts

Answers derived from vendor-published materials dated on this page.

Is IntegrityCounts suitable for SMEs under 250 employees?
IntegrityCounts does not publish entry-tier pricing, so SME buyers need to request a quote to assess fit. Buying path: Sales contact required. Multinational organisations that want live-answer telephone intake in many languages and are content to have report data held in Canada under the EU adequacy decision rather than in the EU.
Which national whistleblower laws does IntegrityCounts explicitly reference?
IntegrityCounts explicitly cites the following national transpositions of Directive 2019/1937 in its public materials: EU Directive 2019/1937, Canada (Bill 198 / Multilateral Instrument 52-110), Canada (BC PIDA), United States (Sarbanes-Oxley), Australia (Corporations Act 2001). Absence from this list does not mean the platform can't be used in other EU jurisdictions — all 27 member states have transposed the Directive. Verify jurisdictional fit with the vendor directly.
Does IntegrityCounts process whistleblower report content with AI?
No — IntegrityCounts does not process report content with AI or machine translation per its vendor materials. Verify the vendor's subprocessor list to confirm no downstream AI processing occurs.

Similar to IntegrityCounts

Other platforms in the directory with overlapping pricing model, certifications, or procurement path.

Sources and verification

Every fact on this page comes from IntegrityCounts's own published materials. These are the pages that were read, and the date they were read.

Last verified

Something out of date? Tell us →

Listed here? Show it on your own site →