preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.
Choose EQS Integrity Line if
You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.
Choose preeco | hinweisgeberschutz if
You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Reporter's Advocate
Judges from the frightened side of the form. Optimizes for anonymity that survives contact, a two-way dialog without an account, languages the workforce actually speaks, and channels that work on a night-shift phone. Rejects login walls, app installs and anything that makes reporting feel like a deposition.
EQS Integrity Line
preeco | hinweisgeberschutz
This judge's pick
Criterion by criterion
Reporting channels & reporter experience
EQS Integrity Line
Anonymous two-way dialog is claimed as first-class — whistleblower, case handler and external experts — with 80+ languages, browser auto-detect, in-system machine translation, mobile optimization, WCAG bronze and a written no-tracking statement. But the only 'telephone' channel is the caseworker creating a case from a call or letter; there is no evidenced reporter-facing hotline, voice intake or QR entry, and nothing promises the reporter needs no account or app install. Dialog and languages nearly reach 8; the night-shift phone channel and the identity-out-of-the-channel documentation are missing.
preeco | hinweisgeberschutz
This is intake built for the scared one: fully anonymous reporting with a protected two-way dialog (Melde-ID plus password) that explicitly works even when the report is anonymous, voice messages recorded in the browser under §16 Abs. 3 HinSchG with no phone call to trace, QR entry, 26 languages, no app install, and a stated 'no logs that allow inferences about whistleblowers'. Held below the top only because accessibility is self-assessed ('weitgehend kompatibel', not audited) and there is no telephone hotline at all for the reporter with a dumbphone.
Case management & deadline discipline
EQS Integrity Line
Integrated case management with a per-activity revision log, granular need-to-know rights, configurable dual control, partial case anonymisation and real-time dashboards — permissions and audit trail sit above rubric level 5. But the evidence is silent on the statutory clocks: no 7-day acknowledgment or 3-month feedback tracking, no retention/deletion per case, no conflict-of-interest exclusion — nothing on this page forces anyone to ever answer the reporter.
preeco | hinweisgeberschutz
The statutory clocks are real product behaviour — 7-day and 3-month deadlines set automatically per organisation, reminders, a due-date column — with three separated roles and a genuinely tamper-evident record (immutable reporter messages, immutable activity log with old/new values, actor and timestamp). What keeps it under the 8 anchor: no conflict-of-interest mechanism to exclude an implicated case handler is evidenced anywhere, and management reporting is a filterable XLSX export rather than caseload oversight.
Legal compliance alignment
EQS Integrity Line
The only legal facts are marketing sentences that the hotline 'fully complies' with the EU Whistleblowing Directive and GDPR. No feature mapping, no national transposition such as HinSchG, no legal templates or named counsel, and the deadline duties appear nowhere as product behaviour — the directive is invoked, the implementation is the customer's problem. That is rubric level 3 exactly.
preeco | hinweisgeberschutz
One national law, implemented properly rather than invoked: HinSchG clocks as features, automatic acknowledgment, an applicability-area checklist export, voice intake citing §16 Abs. 3 by paragraph. But the evidence shows Germany only — EU Directive 2019/1937 is never named, no second transposition, no named counsel or documented legal review — so 'at least one national law, with guidance for the rest' is met, and the rest is simply absent.
Security & anonymity assurance
EQS Integrity Line
ISO 27001 for EQS Group and its data centres, a PwC ISAE 3000 Type I & II audit, STAR Registry, OWASP threat analysis, WAF, 2FA as standard, and a written claim that EQS Group 'can at no time access' report data plus no user tracking. Held below 8: no published penetration test reports, no documented encryption architecture, no metadata/IP-logging detail and no disclosure policy to back the we-cannot-unmask promise — I have the vendor's word, not its homework.
preeco | hinweisgeberschutz
The anonymity line I care about is explicit — 'keine Zugriffs-Logs, die Rückschlüsse auf Hinweisgebende ermöglichen' — but the engineering evidence around it is thin: TLS plus AES on reporter correspondence is asserted, ISO 27001 covers only the Hetzner datacenters, and preeco itself states it holds no certification. No pentest, no end-to-end architecture, no disclosure policy, and nobody answers 'how would you unmask a reporter?' beyond that one no-logs sentence.
Group & multi-entity capability
EQS Integrity Line
Nothing evidences per-entity channels, separated entity case access, a consolidated group view or ombudsman roles; the only group-adjacent facts are single-instance branding, granular user rights and external experts joining the dialog. Not even 'multiple channels under one account' is on the page, so a corporate group cannot be scoped from this sheet.
preeco | hinweisgeberschutz
Mandanten are first-class architecture, not an account switcher: per-entity organisations with own settings, handlers and whitelabel branding (own domain from Private Cloud), ombudsperson access scoped to their organisations, per-tenant languages and module flags, central administration of 'hunderte Mandanten' created in under three minutes. Missing from the 10 anchor: no per-country legal rule assignment per entity and no documented group-level reporting that respects entity boundaries.
European sovereignty
EQS Integrity Line
Exclusive German hosting, a named Munich East data centre and a German vendor entity are solid anchor-8 material. But no DPA and no subprocessor list appear on any captured page, the vendor now sits under US private-equity ownership (Thoma Bravo), and 'geographically distributed' backup data centres leave open where copies of my report sleep — that pulls it back down.
preeco | hinweisgeberschutz
A German GmbH under German law (HRB 737082, venue Ulm), hosting exclusively at Hetzner Nürnberg/Falkenstein with 'keine Übermittlung in Dritländer', a published DPA, downloadable TOMs and a subprocessor list with objection rights — Hetzner (DE), UpCloud (FI, monitoring only). Two honest deductions from 10: the optional DeepL translation of report content has no documented jurisdiction in the evidence, and the AGB itself never states where the cloud data lives — the EU-only promise lives in the privacy policy.
Pricing transparency
EQS Integrity Line
Across five captured pages the only pricing fact is a 'Start free trial' button — no tier, employee band, entity rule or setup fee is public anywhere. An obligated company cannot compute anything from this sheet; rubric level 0 with a trial-button courtesy.
preeco | hinweisgeberschutz
Not one public price appears anywhere in the evidence; the Leistungsbeschreibung itself says the licensing and pricing model is created as a separate individual offer from named factors (mandanten, headcount, hosting variant, licence model). Every invoice is a sales conversation, so an obligated company can compute nothing from public pages — the 0 anchor, verbatim.
Sovereignty, side by side
Dimension
EQS Integrity Line
preeco | hinweisgeberschutz
Legal entity
Not determined
Not determined
Ownership
Not determined
Not determined
Data residency
EU only
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.