preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.
Choose EQS Integrity Line if
You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.
Choose preeco | hinweisgeberschutz if
You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Security Auditor
Pentests the anonymity promise for a living. Optimizes for evidenced security: current certificates with visible scope, published pentests, documented end-to-end encryption, metadata minimization, and hosting outside hostile jurisdictional reach. Rejects adjective security and "military-grade" anything.
EQS Integrity Line
preeco | hinweisgeberschutz
This judge's pick
Criterion by criterion
Reporting channels & reporter experience
EQS Integrity Line
Anonymous two-way dialog is first-class with an explicit no-tracking statement, 80+ languages with auto-detect and integrated machine translation, and mobile optimization; but WCAG 'bronze' is the floor of accessibility and phone/letter intake is just the operator transcribing offline inputs into cases, not engineered anonymous voice intake.
preeco | hinweisgeberschutz
Web form with fully anonymous mode, QR-code entry, in-browser voice messages per §16 Abs. 3 HinSchG that work even anonymously, and two-way dialog via a protected area with Melde-ID and password — the anonymous dialog is first-class, not bolted on. 26 languages with optional DeepL translation and no install required round it out. Held below the top anchor because accessibility is only a self-assessed 'weitgehend kompatibel' with WCAG 2.1 AA and the 'no logs enabling conclusions about whistleblowers' claim is a one-line marketing statement, not documented engineering of how identity stays out of the channel.
Case management & deadline discipline
EQS Integrity Line
Granular need-to-know authorization with configurable dual control, per-case/per-activity revision logs, case anonymisation and live dashboards beat rubric level 5's basic role separation — but the evidence is dead silent on statutory deadline clocks, conflict-of-interest exclusion, tamper-evidence and retention automation.
preeco | hinweisgeberschutz
Automated statutory clocks per organization (7-day/3-month) with reminders, immutable reporter messages, a tamper-evident activity log recording old and new values with actor and timestamp, and configurable GDPR deletion scheduling after case closure are all evidenced. rubric level 8's conflict-of-interest handling — excluding implicated case handlers — appears nowhere in the evidence, and management reporting is XLSX exports plus a dashboard, so 7.
Legal compliance alignment
EQS Integrity Line
The directive appears exactly once, as a marketing adjective ('fully complies with... the EU Whistleblowing Directive (GDPR compliant)') with no feature mapping, no national transposition like HinSchG, no named counsel and no templates — the textbook anchor-3 invocation.
preeco | hinweisgeberschutz
HinSchG duties are implemented as product features: automatic deadline setting tied to the three-month rule, automatic acknowledgment, and voice intake citing §16(3) — one national law done properly, which is the anchor-5 definition. No mention of EU Directive 2019/1937 or any other national transposition, no named counsel, no documented legal review, and updates when the law moves is only asserted for other modules (NIS2/DORA).
Security & anonymity assurance
EQS Integrity Line
PwC's ISAE 3000 Type I/II attestation and ISO 27001 covering 'EQS Group and our data centres' are real artifacts, but there are no certificate dates, no published pentest reports behind the bare 'regular external security audits', no cryptographic architecture behind the 'latest encryption algorithms' claim, no explicit no-IP-logging statement, and no security contact or disclosure policy.
preeco | hinweisgeberschutz
The vendor states it holds no own ISO 27001 — the certificate covers only the Hetzner datacenters — and no penetration test is published anywhere in the registry; encryption is SSL/TLS plus AES on 'essential' database fields, meaning the operator can read report content, and no end-to-end architecture is documented. Credit for the explicit 'no logs that enable conclusions about whistleblowers' statement, team-enforceable TOTP 2FA with brute-force protection, and an AI path that by default never transmits reporter identity and deletes content in 7 days — enough to lift it just above unaudited adjectives.
Group & multi-entity capability
EQS Integrity Line
Granular case access and an anonymous dialog that includes external experts get partway to rubric level 5, and branding is customisable — but nothing evidences per-entity channels, group-level oversight, delegated administration or per-subsidiary white-labeling; the evidence speaks of 'your company', singular.
preeco | hinweisgeberschutz
Per-tenant channels with strict data separation and own users, per-organization branding with own domain from Private Cloud, central administration with one-click tenant switching, a dedicated ombudsperson role, and documentation that external DPOs and ombudspersons manage hundreds of Mandanten centrally. Missing only the anchor-10 items: per-country legal rule assignment per entity, and white-label/own domain is withheld below the Private Cloud tier.
European sovereignty
EQS Integrity Line
Germany-exclusive hosting with a named Munich East data centre and a German legal entity are concrete; but for the most sensitive data a company holds, the evidence publishes no DPA, no subprocessor list and no TOMs, and Thoma Bravo's 2024 take-private puts the vendor inside US jurisdictional reach.
preeco | hinweisgeberschutz
German GmbH in Ulm under German law with venue Ulm, hosting exclusively at named Hetzner datacenters in Nuremberg/Falkenstein with offsite backup in Falkenstein, and a public Art. 28 DPA naming subprocessors Hetzner (DE) and UpCloud (FI, monitoring only) plus downloadable TOMs. Ownership is undocumented, the AGB only vaguely reference 'von preeco genutzte Rechenzentren' while the Germany-only statements live in the product spec and privacy policy, and optional US AI endpoints (off by default) are the one content-touching wrinkle — 8, not 10.
Pricing transparency
EQS Integrity Line
Across five captured pages the only pricing artifact is a 'Start free trial' button — not one number, tier, employee band or setup fee; that is anchor-0 territory, softened by one point for the trial existing.
preeco | hinweisgeberschutz
'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — no public price for any tier, so an obligated company cannot compute anything; this is the anchor-0 situation of every tier being a sales conversation. The pricing dimensions (organizations, employee count, hosting variant, license model), no-setup-fee claim, billing periods and VAT treatment are at least disclosed, which is the only thing lifting it above zero.
Sovereignty, side by side
Dimension
EQS Integrity Line
preeco | hinweisgeberschutz
Legal entity
Not determined
Not determined
Ownership
Not determined
Not determined
Data residency
EU only
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.