whats-best.ai

Whistleblowing Portals · head-to-head

EQS Integrity Line vs preeco | hinweisgeberschutz

EQS Integrity Line

EU origin, foreign-owned

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

preeco | hinweisgeberschutz

EU-Made

Panel rating

Sovereignty: not determined

Full evaluation →

The short answer

preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.

Choose EQS Integrity Line if

  • You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
  • Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
  • You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
  • Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.

Choose preeco | hinweisgeberschutz if

  • You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
  • Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
  • Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
  • You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
  • Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Reporter's Advocate

Judges from the frightened side of the form. Optimizes for anonymity that survives contact, a two-way dialog without an account, languages the workforce actually speaks, and channels that work on a night-shift phone. Rejects login walls, app installs and anything that makes reporting feel like a deposition.

EQS Integrity Line

preeco | hinweisgeberschutz

This judge's pick

Criterion by criterion

Reporting channels & reporter experience

EQS Integrity Line

Anonymous two-way dialog is claimed as first-class — whistleblower, case handler and external experts — with 80+ languages, browser auto-detect, in-system machine translation, mobile optimization, WCAG bronze and a written no-tracking statement. But the only 'telephone' channel is the caseworker creating a case from a call or letter; there is no evidenced reporter-facing hotline, voice intake or QR entry, and nothing promises the reporter needs no account or app install. Dialog and languages nearly reach 8; the night-shift phone channel and the identity-out-of-the-channel documentation are missing.

preeco | hinweisgeberschutz

This is intake built for the scared one: fully anonymous reporting with a protected two-way dialog (Melde-ID plus password) that explicitly works even when the report is anonymous, voice messages recorded in the browser under §16 Abs. 3 HinSchG with no phone call to trace, QR entry, 26 languages, no app install, and a stated 'no logs that allow inferences about whistleblowers'. Held below the top only because accessibility is self-assessed ('weitgehend kompatibel', not audited) and there is no telephone hotline at all for the reporter with a dumbphone.

Case management & deadline discipline

EQS Integrity Line

Integrated case management with a per-activity revision log, granular need-to-know rights, configurable dual control, partial case anonymisation and real-time dashboards — permissions and audit trail sit above rubric level 5. But the evidence is silent on the statutory clocks: no 7-day acknowledgment or 3-month feedback tracking, no retention/deletion per case, no conflict-of-interest exclusion — nothing on this page forces anyone to ever answer the reporter.

preeco | hinweisgeberschutz

The statutory clocks are real product behaviour — 7-day and 3-month deadlines set automatically per organisation, reminders, a due-date column — with three separated roles and a genuinely tamper-evident record (immutable reporter messages, immutable activity log with old/new values, actor and timestamp). What keeps it under the 8 anchor: no conflict-of-interest mechanism to exclude an implicated case handler is evidenced anywhere, and management reporting is a filterable XLSX export rather than caseload oversight.

Legal compliance alignment

EQS Integrity Line

The only legal facts are marketing sentences that the hotline 'fully complies' with the EU Whistleblowing Directive and GDPR. No feature mapping, no national transposition such as HinSchG, no legal templates or named counsel, and the deadline duties appear nowhere as product behaviour — the directive is invoked, the implementation is the customer's problem. That is rubric level 3 exactly.

preeco | hinweisgeberschutz

One national law, implemented properly rather than invoked: HinSchG clocks as features, automatic acknowledgment, an applicability-area checklist export, voice intake citing §16 Abs. 3 by paragraph. But the evidence shows Germany only — EU Directive 2019/1937 is never named, no second transposition, no named counsel or documented legal review — so 'at least one national law, with guidance for the rest' is met, and the rest is simply absent.

Security & anonymity assurance

EQS Integrity Line

ISO 27001 for EQS Group and its data centres, a PwC ISAE 3000 Type I & II audit, STAR Registry, OWASP threat analysis, WAF, 2FA as standard, and a written claim that EQS Group 'can at no time access' report data plus no user tracking. Held below 8: no published penetration test reports, no documented encryption architecture, no metadata/IP-logging detail and no disclosure policy to back the we-cannot-unmask promise — I have the vendor's word, not its homework.

preeco | hinweisgeberschutz

The anonymity line I care about is explicit — 'keine Zugriffs-Logs, die Rückschlüsse auf Hinweisgebende ermöglichen' — but the engineering evidence around it is thin: TLS plus AES on reporter correspondence is asserted, ISO 27001 covers only the Hetzner datacenters, and preeco itself states it holds no certification. No pentest, no end-to-end architecture, no disclosure policy, and nobody answers 'how would you unmask a reporter?' beyond that one no-logs sentence.

Group & multi-entity capability

EQS Integrity Line

Nothing evidences per-entity channels, separated entity case access, a consolidated group view or ombudsman roles; the only group-adjacent facts are single-instance branding, granular user rights and external experts joining the dialog. Not even 'multiple channels under one account' is on the page, so a corporate group cannot be scoped from this sheet.

preeco | hinweisgeberschutz

Mandanten are first-class architecture, not an account switcher: per-entity organisations with own settings, handlers and whitelabel branding (own domain from Private Cloud), ombudsperson access scoped to their organisations, per-tenant languages and module flags, central administration of 'hunderte Mandanten' created in under three minutes. Missing from the 10 anchor: no per-country legal rule assignment per entity and no documented group-level reporting that respects entity boundaries.

European sovereignty

EQS Integrity Line

Exclusive German hosting, a named Munich East data centre and a German vendor entity are solid anchor-8 material. But no DPA and no subprocessor list appear on any captured page, the vendor now sits under US private-equity ownership (Thoma Bravo), and 'geographically distributed' backup data centres leave open where copies of my report sleep — that pulls it back down.

preeco | hinweisgeberschutz

A German GmbH under German law (HRB 737082, venue Ulm), hosting exclusively at Hetzner Nürnberg/Falkenstein with 'keine Übermittlung in Dritländer', a published DPA, downloadable TOMs and a subprocessor list with objection rights — Hetzner (DE), UpCloud (FI, monitoring only). Two honest deductions from 10: the optional DeepL translation of report content has no documented jurisdiction in the evidence, and the AGB itself never states where the cloud data lives — the EU-only promise lives in the privacy policy.

Pricing transparency

EQS Integrity Line

Across five captured pages the only pricing fact is a 'Start free trial' button — no tier, employee band, entity rule or setup fee is public anywhere. An obligated company cannot compute anything from this sheet; rubric level 0 with a trial-button courtesy.

preeco | hinweisgeberschutz

Not one public price appears anywhere in the evidence; the Leistungsbeschreibung itself says the licensing and pricing model is created as a separate individual offer from named factors (mandanten, headcount, hosting variant, licence model). Every invoice is a sales conversation, so an obligated company can compute nothing from public pages — the 0 anchor, verbatim.

Sovereignty, side by side

Dimension EQS Integrity Line preeco | hinweisgeberschutz
Legal entity Not determined Not determined
Ownership Not determined Not determined
Data residency EU only Not determined
Subprocessors Not determined Not determined

Facts, side by side

Only facts both products carry under the same definition — anything else would not be a fair row.

Compliance · Encryption yes · yes1

captured 15 Sep 2026 · Report an error

AES · SSL/TLS2

captured 16 Sep 2026 · Report an error

Compliance · GDPR yes · yes3

captured 15 Sep 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Data · Export yes5

captured 15 Sep 2026 · Report an error

PDF · DOCX · ZIP · XLSX6

captured 5 Oct 2026 · Report an error

Hosting · Datacenter location München-Ost · ISO 14001 · 1007

captured 1 Oct 2026 · Report an error

Germany · yes8

captured 5 Oct 2026 · Report an error

Legal · Entity EQS Group GmbH · Stockerstrasse 33, CH-8002 Zürich, Schweiz9

captured 1 Oct 2026 · Report an error

preeco GmbH10

captured 5 Oct 2026 · Report an error

Legal · Entity name EQS Group GmbH · Karlstr. 47, 80333 München11

captured 15 Sep 2026 · Report an error

preeco GmbH · Magirus-Deutz-Straße 14, 89077 Ulm, Deutschland12

captured 5 Oct 2026 · Report an error

Product · Accessibility bronze · WCAG3

captured 15 Sep 2026 · Report an error

Maßnahmen zur Barrierefreiheit: Tastaturbedienung, semantisches HTML, Kontraste, skalierbare Schriftgrößen, Alternativtexte6

captured 5 Oct 2026 · Report an error

Product · Anonymous reporting yes · yes9

captured 1 Oct 2026 · Report an error

yes · yes6

captured 5 Oct 2026 · Report an error

Product · Availability unabhängig vom Land zugänglich, 24/7 Meldungen möglich13

captured 1 Oct 2026 · Report an error

24/7 grundsätzlich verfügbar14

captured 16 Sep 2026 · Report an error

Product · Encryption no · yes3

captured 15 Sep 2026 · Report an error

yes15

captured 5 Oct 2026 · Report an error

Product · Languages 8016

captured 15 Sep 2026 · Report an error

266

captured 5 Oct 2026 · Report an error