whats-best.ai

Whistleblowing Portals · head-to-head

EQS Integrity Line vs preeco | hinweisgeberschutz

EQS Integrity Line

EU origin, foreign-owned

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

preeco | hinweisgeberschutz

EU-Made

Panel rating

Sovereignty: not determined

Full evaluation →

The short answer

preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.

Choose EQS Integrity Line if

  • You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
  • Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
  • You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
  • Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.

Choose preeco | hinweisgeberschutz if

  • You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
  • Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
  • Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
  • You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
  • Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Compliance Officer

Runs the internal reporting office of a 600-employee company and answers for every missed statutory clock. Optimizes for case discipline: automated acknowledgment and feedback deadlines, role separation, documentation that survives a regulator. Rejects inbox-with-a-form products that make the deadlines her problem.

EQS Integrity Line

preeco | hinweisgeberschutz

This judge's pick

Criterion by criterion

Reporting channels & reporter experience

EQS Integrity Line

Anonymous two-way dialog is first-class ("complete anonymity... anonymous dialogue between the whistleblower, case handler and external experts", no tracking mechanisms), with 80+ languages, integrated machine translation, browser auto-detect and mobile optimization — but voice/hotline or QR intake is never evidenced as an engineered anonymous channel; the "telephone call" in the multichannel fact is a handler manually creating a case, not reporter voice intake, and WCAG only at bronze.

preeco | hinweisgeberschutz

The frightened reporter is actually served here: fully anonymous submission with two-way dialog via a protected Melde-ID/password area that works even for anonymous reports, in-browser voice messages grounded in § 16 Abs. 3 HinSchG without a phone connection, and QR-code entry, with up to 26 languages plus AI translation reviewed by the team. Accessibility is self-assessed WCAG 2.1 AA / EN 301 549 ('weitgehend kompatibel') rather than audited, and the no-access-logs promise is a single line — good, but not the documented anonymity engineering of the top anchor.

Case management & deadline discipline

EQS Integrity Line

Integrated case management with a per-activity revision log, granular need-to-know permissions, configurable dual control and partial case anonymisation is a real permission model — but the evidence is entirely silent on the statutory clocks: no 7-day acknowledgment automation, no 3-month feedback deadline, no conflict-of-interest exclusion of implicated handlers, no per-case retention or deletion rules. The deadlines would be my problem again, and dashboards don't fix that.

preeco | hinweisgeberschutz

The statutory clocks are the product's, not mine: automatic 7-day/3-month monitoring with automatic Fristsetzung per organization, due dates shown in the case list, and reminders; reporter messages and system entries cannot be edited or deleted, and the admin-only activity log records every change with old/new value, timestamp and actor — documentation that would survive a regulator. Deletion is scheduled per case after closure, but there is not one word on conflict-of-interest handling or excluding implicated case handlers, which is why it stops short of the top anchors.

Legal compliance alignment

EQS Integrity Line

The EU Whistleblowing Directive appears exactly once, as a marketing assertion that the hotline "ensures that your organisation fully complies" — no national transposition (HinSchG or otherwise), no deadline or documentation duties implemented as features, no retention periods, no named counsel or legal review. The mapping is the customer's problem.

preeco | hinweisgeberschutz

The HinSchG is implemented as features, not marketing: automated deadline management, automatic acknowledgment 'gemäß HinSchG', a voice channel citing § 16 Abs. 3 HinSchG specifically, and configurable post-case deletion. But that is exactly one national law — no reference to Directive 2019/1937, no second transposition, no named counsel or documented legal review — so the single-law anchor is where it lands.

Security & anonymity assurance

EQS Integrity Line

Strong on attestations: ISO 27001 with stated scope ("EQS Group and our data centres"), PwC ISAE 3000 Type I and II, CSA STAR Registry, OWASP threat analysis, 2FA as standard. It falls short of the top anchors because the "EQS Group can at no time access your data" claim is asserted rather than documented — no published pentest summaries, no cryptographic architecture, and "no tracking mechanisms" is the only metadata statement we get.

preeco | hinweisgeberschutz

Two of the three mid-anchor elements are there: ISO 27001 (Hetzner data centers, Germany) and an explicit statement that no logs allow inferences about reporters, plus enforceable team-wide TOTP 2FA. But preeco itself admits it holds no ISO 27001 certification, encryption is TLS plus AES-at-rest for essential data — not end-to-end, with no architecture documentation — and there is no pentest attestation and no disclosure policy; I could not answer a hostile auditor with this file.

Group & multi-entity capability

EQS Integrity Line

Corporate branding and granular per-case access are evidenced, and external experts can join the anonymous dialogue — but there is not a single fact on per-entity channels, separated entity case stores, group-level consolidated oversight, delegated administration, or per-entity legal rules. Whether one contract can serve a corporate group is simply unanswered.

preeco | hinweisgeberschutz

This is a real Mandant architecture, not N instances in a trenchcoat: per-entity settings, users and strict data separation with one-click central switching, per-organization deadlines, notifications and languages, ombudsperson and Sachbearbeiter roles scoped per organization with assignment-only visibility, whitelabel branding and own domain from Private Cloud, and a claim of hundreds of Mandanten managed centrally with new ones in under three minutes. What is missing for the top is per-country legal rule assignment per entity and a true consolidated group-level statistics view.

European sovereignty

EQS Integrity Line

German legal entity (EQS Group GmbH, Munich) and hosting "exclusively in Germany" with a named Munich East data centre are anchor-grade facts on where reports live — but the registry contains no DPA, no subprocessor list and no TOMs at all, and the vendor has been owned by US PE firm Thoma Bravo since 2024. For the most sensitive data a company holds, the chain past the first data centre is undocumented, so I cannot go higher.

preeco | hinweisgeberschutz

The default chain is jurisdictionally clean: German GmbH in Ulm under German law, hosting exclusively in named Hetzner data centers in Nürnberg/Falkenstein, storage location Germany, no third-country transfer, and a published AVV listing only EU subprocessors (Hetzner DE, UpCloud FI) with downloadable TOMs. On-premises exists but is restricted to the public sector and Enterprise segment, and the optional AI endpoints can point at OpenAI — opt-in and default-off, but it means the clean chain is a configuration choice, not an architecture guarantee.

Pricing transparency

EQS Integrity Line

The only pricing fact in the entire registry is a "Start free trial" button — no tier prices, no employee bands, no entity rules, no VAT treatment, no setup fees. I could not begin to compute the invoice for a 600-employee company from these pages.

preeco | hinweisgeberschutz

'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — there is not one public number in the entire sheet, so no obligated company can compute anything; the pricing factors (Mandanten, headcount, hosting variant) tell me the axes of the invoice but never the amounts. The published contract mechanics — no setup fees, no cancellation period, VAT excluded, monthly or annual billing — are the only thing keeping this off an absolute zero.

Sovereignty, side by side

Dimension EQS Integrity Line preeco | hinweisgeberschutz
Legal entity Not determined Not determined
Ownership Not determined Not determined
Data residency EU only Not determined
Subprocessors Not determined Not determined

Facts, side by side

Only facts both products carry under the same definition — anything else would not be a fair row.

Compliance · Encryption yes · yes1

captured 15 Sep 2026 · Report an error

AES · SSL/TLS2

captured 16 Sep 2026 · Report an error

Compliance · GDPR yes · yes3

captured 15 Sep 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Data · Export yes5

captured 15 Sep 2026 · Report an error

PDF · DOCX · ZIP · XLSX6

captured 5 Oct 2026 · Report an error

Hosting · Datacenter location München-Ost · ISO 14001 · 1007

captured 1 Oct 2026 · Report an error

Germany · yes8

captured 5 Oct 2026 · Report an error

Legal · Entity EQS Group GmbH · Stockerstrasse 33, CH-8002 Zürich, Schweiz9

captured 1 Oct 2026 · Report an error

preeco GmbH10

captured 5 Oct 2026 · Report an error

Legal · Entity name EQS Group GmbH · Karlstr. 47, 80333 München11

captured 15 Sep 2026 · Report an error

preeco GmbH · Magirus-Deutz-Straße 14, 89077 Ulm, Deutschland12

captured 5 Oct 2026 · Report an error

Product · Accessibility bronze · WCAG3

captured 15 Sep 2026 · Report an error

Maßnahmen zur Barrierefreiheit: Tastaturbedienung, semantisches HTML, Kontraste, skalierbare Schriftgrößen, Alternativtexte6

captured 5 Oct 2026 · Report an error

Product · Anonymous reporting yes · yes9

captured 1 Oct 2026 · Report an error

yes · yes6

captured 5 Oct 2026 · Report an error

Product · Availability unabhängig vom Land zugänglich, 24/7 Meldungen möglich13

captured 1 Oct 2026 · Report an error

24/7 grundsätzlich verfügbar14

captured 16 Sep 2026 · Report an error

Product · Encryption no · yes3

captured 15 Sep 2026 · Report an error

yes15

captured 5 Oct 2026 · Report an error

Product · Languages 8016

captured 15 Sep 2026 · Report an error

266

captured 5 Oct 2026 · Report an error