Skip to main content
EU Whistleblower Directory
Witik logo

Witik

French GRC platform (GDPR + Sapin II + AI Act). Whistleblowing lives inside the Sapin II module; Premium from €100/month.

Part of Witik GRC platform

Witik homepage screenshot
Typical buyer

French organisations already deploying Witik for GDPR or Sapin II compliance who want the internal alert system in the same platform rather than a separate vendor.

Distinctive features

  • ISO 27001 and HDS (French healthcare data hosting) certified
  • Vendor states product data is hosted in France / Europe and not used to train AI models
  • Public REST API plus a webhook engine (rare among module-based GRC platforms)
  • Covers GDPR, Sapin II, and the EU AI Act from one platform
  • 3,000+ compliance teams across 7 languages (vendor claim)

Add-ons and conditions

Costs or terms not included in the headline price.

  • Whistleblowing is not a standalone product — bundled inside the Sapin II module
  • Premium plans require a 36-month commitment with annual payment
  • Sapin II Premium (€100/mo) and GDPR Premium (€240/mo) are separate subscriptions
  • Starter plans are free but feature-limited (e.g. 2 impact analyses, 10 rights requests per year)
  • Reporting-form EU language coverage not enumerated on public pages

Notable

  • Founded 2020; positions itself as a “100% French-made” GRC platform.
  • Modules: GDPR/RGPD, Sapin II (anti-corruption, including internal alerts), and EU AI Act compliance.
  • Sapin II module bundles four components: internal alerts (whistleblowing), anti-corruption controls, gifts & invitations, and conflicts of interest.
  • Whistleblowing features: ready-to-use alert form, anonymous reporting, secure two-way communication, private access portal, dashboard, and automated assignment/tracking claims.
  • Public API with webhook engine; integrations advertised via these hooks rather than a marketplace.
  • Certifications: ISO 27001, HDS (French health-data hosting accreditation), plus EcoVadis Bronze (sustainability rating, non-security).
  • Hosting: France / EU positioning is public; the privacy policy names OVH SAS for the platform and public forms, while commercial/prospecting tooling may involve international transfers.
  • Site UI available in 7 languages; the EU-language-coverage breakdown for the reporting form itself is not enumerated on public pages.
  • Starter (free) tier exists on both GDPR and Sapin II modules with sharp limits; Premium subscription is the production tier.
  • Fits the module-based pattern also represented in the directory by Clym (privacy suite) and osapiens (ESG suite).

Vendor-page evidence - 2026-05-24

  • Current pricing page shows Sapin II Starter at 0€ HT/mois, Premium from 100€ HT/mois, a 14-day trial claim, and a 36-month annual-payment default with monthly payment available at surcharge.
  • The whistleblowing feature page claims a ready-to-use alert form, anonymous reporting, confidential chat box, private access portal, dashboard, automatic assignment, timestamped documentation, and audit history.
  • Current homepage markets Witik as AI-native and states product data is not used to train Witik or third-party AI models; the privacy policy separately names an OpenAI-backed meeting/prospecting tool, not the whistleblowing module itself.
  • The privacy policy names multiple infrastructure/tooling providers; this improves the old sub-processor evidence, but no public objection workflow or DPA pack was found.
  • Witik’s public pages reviewed did not show a Directive 2019/1937 article-level taxonomy.

Scoring review - 2026-05-24

Scored under the 25-criterion rubric v2 at access tier P (public pages only; demo is sales-gated, no self-serve trial).

Base score: 20 / 50. France country bonus: 7 / 8.

CategoryScoreMax
A. Legal compliance416
B. Reporter experience610
C. Handler experience210
D. Security58
E. Commercial36

Unverified from public pages: public Art 2(1) taxonomy in intake, public 7-day / 3-month automation proof, and documented two-factor reporter access. Public whistleblowing copy is framed primarily through Sapin II, and the standard commercial model is anchored in a 36-month commitment even if shorter monthly billing is available at a surcharge.

Evidence supporting the score: French OVH/HDS hosting, ISO 27001 / HDS claims, a public Sapin II pricing page, a 14-day-trial mention, and surcharge-based monthly billing.

Buyer fit: French organisations already using Witik for RGPD that want to add Sapin II whistleblowing coverage. Buyers seeking a dedicated Directive-first whistleblower tool should confirm legal mapping and workflow evidence directly.

Similar to Witik

Other platforms in the directory with overlapping pricing model, certifications, or procurement path.

Frequently asked questions about Witik

Answers derived from vendor-published materials dated on this page.

Is Witik suitable for SMEs under 250 employees?
Witik does not publish entry-tier pricing, so SME buyers need to request a quote to assess fit. Procurement is demo_first. French organisations already deploying Witik for GDPR or Sapin II compliance who want the internal alert system in the same platform rather than a separate vendor.
Which national whistleblower laws does Witik explicitly reference?
Witik explicitly cites the following national transpositions of Directive 2019/1937 in its public materials: France (Sapin II / Loi Waserman), GDPR / RGPD, EU AI Act. Absence from this list does not mean the platform can't be used in other EU jurisdictions — all 27 member states have transposed the Directive. Verify jurisdictional fit with the vendor directly.
Does Witik process whistleblower report content with AI?
Yes — Witik processes report content with AI (typically for translation, summarisation, or classification). If your compliance posture requires keeping disclosures out of third-party LLMs or machine-translation services, confirm data-processing terms and vendor subprocessors before procurement.

Compare Witik with another platform

Direct side-by-side comparisons against other tools in this directory.