preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.
Choose EQS Integrity Line if
You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.
Choose preeco | hinweisgeberschutz if
You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Group Counsel
Rolls one system out to 25 subsidiaries in a dozen countries. Optimizes for per-entity channels with real access separation, per-country legal rule sets, external ombudsman roles and group reporting that respects entity boundaries. Rejects one-channel products multiplied by twenty-five contracts.
EQS Integrity Line
preeco | hinweisgeberschutz
This judge's pick
Criterion by criterion
Reporting channels & reporter experience
EQS Integrity Line
Anonymous two-way dialog that can even include external experts, 80+ languages with integrated machine translation and browser auto-detect, mobile-optimized, WCAG bronze, and an explicit no-tracking statement make the anonymous dialog first-class. But the 'multichannel' quote is about the caseworker manually creating a case from a letter, email or phone call — no anonymous voice or hotline intake by the product itself is evidenced, which a dozen-country rollout would need.
preeco | hinweisgeberschutz
Intake is genuinely engineered for the frightened reporter: fully anonymous reporting with a protected two-way dialog via Melde-ID and password even for anonymous reports, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG without a voice service provider, up to 26 languages, no install, and an explicit 'Keine Zugriffs-Logs, die Rückschlüsse auf Hinweisgebende ermöglichen'. Only the self-assessed 'weitgehend kompatibel' WCAG 2.1 AA/EN 301 549 conformance and the absence of any phone hotline keep this off the top anchor.
Case management & deadline discipline
EQS Integrity Line
Integrated case management with a per-activity revision log, granular need-to-know roles, configurable dual control, partial case anonymisation and dashboards is real. But the evidence is dead silent on statutory deadline tracking, conflict-of-interest exclusion and per-case retention/deletion — the anchor-5 requirement — and I do not buy deadline discipline on faith for 25 entities.
preeco | hinweisgeberschutz
Automatic statutory clocks (7-day acknowledgment / 3-month feedback, configurable per organization, auto-set deadlines shown in the case list), three-role separation where Sachbearbeiter see only assigned cases, immutable reporter messages plus an immutable old/new-value activity log, and per-case deletion scheduling — nearly the 8-anchor. But the evidence is silent on conflict-of-interest handling that locks out implicated case handlers, which I need before an external investigator can rely on the case file.
Legal compliance alignment
EQS Integrity Line
The directive appears once, as a marketing claim that the hotline 'fully complies' with it; no national transposition, no per-country rule set, no named counsel, no acknowledgment or feedback clocks as product features. Deadlines, documentation and retention are evidently the customer's problem — that is the anchor-3 definition verbatim.
preeco | hinweisgeberschutz
The duties of one national law are real product features — automatic acknowledgment 'gemäß HinSchG', 7-day/3-month clocks, § 16 Abs. 3 voice intake, GDPR-conform deletion after case closure — which is the 5-anchor exactly. But only HinSchG is evidenced: no second national transposition, no per-country rule sets, no named counsel or documented legal review maintaining templates; for my dozen countries this is one jurisdiction's tool.
Security & anonymity assurance
EQS Integrity Line
ISO 27001 covering EQS Group and its data centres, a PwC ISAE 3000 Type I+II audit, STAR Registry, 2FA as standard, OWASP threat analysis and a stated absence of tracking mechanisms, plus the vendor's claim it can at no time access report data. What keeps it off the 8 anchor: no named penetration-test attestations, no security contact or disclosure policy, and 'latest encryption algorithms and SSL certificates' is adjective-grade, not a documented architecture.
preeco | hinweisgeberschutz
SSL/TLS in transit and AES for essential data at rest, team-enforceable TOTP with brute-force protection, AES-256 off-site backups, and the no-access-log statement are real, but preeco itself holds no ISO 27001 (only the Hetzner data centers do), there is no pentest attestation, no end-to-end encryption claim, and no security contact or disclosure policy. A hostile auditor would walk away unconvinced.
Group & multi-entity capability
EQS Integrity Line
Granular need-to-know authorization, per-user rights and an anonymous dialog that includes external experts are hints of what I need, but nothing evidences per-entity channels, delegated administration, group reporting that respects entity boundaries, or ombudsman roles. The evidence shows me one channel with custom branding — and I reject one-channel products multiplied by twenty-five contracts.
preeco | hinweisgeberschutz
This is the architecture I look for: per-Mandant channels with strictly separated users, settings and languages ('Jeder Mandant erhält eigene Einstellungen, Dokumente und Nutzer'), central administration with one-click switching, new entities in under three minutes, whitelabel per organization, and external ombudspersonen managing hundreds of Mandanten through one login. It misses the 10-anchor because per-country legal rule assignment per entity does not exist (HinSchG only), own domains start only at Private Cloud, and consolidated group reporting that respects entity boundaries is only implied by central admin and XLSX statistics.
European sovereignty
EQS Integrity Line
A German GmbH with exclusive German hosting and a named Munich East data centre is a genuine sovereignty signal. But the chain is undocumented: no DPA, no subprocessor list, backups only 'geographically distributed', and the machine-translation service that touches case content has no jurisdiction stated — all under US PE ownership per the evidence's own provenance note.
preeco | hinweisgeberschutz
German entity (preeco GmbH, Ulm, HRB 737082), German law and venue Ulm, exclusive Hetzner hosting in Nürnberg/Falkenstein for Cloud and Private Cloud with 'keine Übermittlung in Dritländer', a public DPA naming its EU subprocessors (Hetzner, UpCloud-for-monitoring) with a two-week objection right, downloadable TOMs, and an on-premises option. The 10-anchor slips because ownership is undocumented and the optional, default-off AI path can push report content to US-based OpenAI if a tenant opts in.
Pricing transparency
EQS Integrity Line
Across five captured pages the only pricing fact is a 'Start free trial' button; no tier, employee band, entity rule or setup fee appears anywhere. An obligated company — much less a 25-entity group — cannot compute any invoice from public pages, which is the anchor-0 definition.
preeco | hinweisgeberschutz
The license and price model 'wird als separates, individuelles Angebot erstellt' — the factors (number of Mandanten, employees, hosting variant) and terms (no setup fees, no cancellation period, net prices, 30-day trial) are published, but not one euro figure is. A 60-employee company or my 5-entity group cannot compute anything from public pages; this is a sales conversation in writing.
Sovereignty, side by side
Dimension
EQS Integrity Line
preeco | hinweisgeberschutz
Legal entity
Not determined
Not determined
Ownership
Not determined
Not determined
Data residency
EU only
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.