preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.
Choose EQS Integrity Line if
You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.
Choose preeco | hinweisgeberschutz if
You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Skeptic
Assumes "audit-proof" and "100% anonymous" are marketing until the evidence says otherwise. Hunts certification claims without certificates, anonymity claims next to analytics scripts, per-report pricing traps and legal-update promises with no named lawyer. Exists to keep the rest of the bench honest.
EQS Integrity Line
preeco | hinweisgeberschutz
This judge's pick
Criterion by criterion
Reporting channels & reporter experience
EQS Integrity Line
Anonymous two-way dialogue is first-class with 80+ languages, browser auto-detect, integrated machine translation and mobile optimization, and 'no tracking mechanisms' is at least stated. Docked below 8: the non-web channels in are cases created by the operator from a letter/phone call/meeting, not engineered anonymous reporter channels, and 'WCAG bronze level certification' is not a WCAG conformance level anyone audits to.
preeco | hinweisgeberschutz
Anonymous web form, QR entry, in-browser voice messages per § 16 Abs. 3 HinSchG, secured two-way dialog via Melde-ID/password that works even fully anonymously, 26 languages, no install, and an explicit no-access-logs statement — that is rubric level 8 nearly line by line. It stays below 9 because WCAG 2.1 AA is only a self-assessment hedged as 'weitgehend kompatibel', not verified.
Case management & deadline discipline
EQS Integrity Line
Granular need-to-know roles, configurable dual control, per-activity revision log and real-time dashboards are evidenced, exceeding basic role separation. But the evidence is entirely silent on the statutory 7-day/3-month clocks, conflict-of-interest exclusion and per-case retention/deletion — the 'deadline discipline' half of this criterion has zero supporting evidence.
preeco | hinweisgeberschutz
Automated statutory clocks (7-day/3-month) per organisation with visible deadlines, immutable messages and an admin-only, tamper-evident activity log with configurable retention, three-tier role separation and per-case deletion scheduling clear the 5-anchor comfortably. But there is not one word on conflict-of-interest handling — excluding an implicated case handler is a HinSchG basic, and deadline reminders are implied rather than evidenced, so it cannot reach 8.
Legal compliance alignment
EQS Integrity Line
The directive appears in exactly one marketing sentence — 'fully complies with... the EU Whistleblowing Directive (GDPR compliant)' — with no national transposition named, no deadline/documentation/deletion features, no legal templates and no named counsel. Directive invoked, mapping vague, statutory duties left to the customer: rubric level 3 verbatim.
preeco | hinweisgeberschutz
The HinSchG duties are real product features, not brochure text: automatic 7-day/3-month clocks, § 16 Abs. 3 voice intake, automatic acknowledgment, per-case deletion — that is exactly rubric level 5 for one national law. No evidence of any second transposition, no per-country rule sets, no named counsel or documented legal review behind the 1,200+ templates; 'HinSchG-konform entwickelt und betrieben' is an unaudited vendor assertion and the update promise ('DSGVO-Updates werden zeitnah umgesetzt') has no lawyer's name on it.
Security & anonymity assurance
EQS Integrity Line
ISO 27001 for 'EQS Group and our data centres', ISAE 3000 Type I and II by PwC, CSA STAR and regular external audits are real attestations, not adjectives. But the claim that EQS 'can at no time access your or your whistleblowers' data' is justified by 'SSL certificates' — transport security is not a documented end-to-end architecture — and there is no published pentest, no security contact/disclosure policy, and 'no tracking' is the only metadata statement.
preeco | hinweisgeberschutz
Credit where due: they admit plainly 'Aktuell keine eigene ISO 27001 Zertifizierung' — only the Hetzner datacenters are certified — and the no-logs pledge ('Keine Logs, die Rückschlüsse auf Hinweisgebende ermöglichen') is specific, with 2FA and AES-256 backups on top. But that is where it ends: no vendor ISMS, no penetration test ever mentioned, no security contact or disclosure policy, TLS+AES-at-rest instead of any end-to-end claim — and an optional OpenAI integration that would ship report content to a US model, off by default or not. That is a 3-anchor lifted one notch by honesty, not an 8.
Group & multi-entity capability
EQS Integrity Line
The evidence says nothing about per-entity channels, separated entity case access, group-level overview, delegated administration or ombudsman roles; only single-instance branding, generic granular permissions and 'external experts' joining a dialogue gesture at group use. '2,500 customers' is a count, not a multi-tenant architecture.
preeco | hinweisgeberschutz
Genuine multi-tenancy is documented: per-entity channels with strict data separation, per-tenant languages, modules and whitelabel branding, ombudsperson and per-report role scoping, hundreds of Mandanten manageable from one login in under 3 minutes. Missing for an 8-to-10: group-level consolidated reporting that respects entity boundaries is only implied by XLSX exports, delegated per-entity administration is not spelled out, and there is no per-country legal rule assignment whatsoever.
European sovereignty
EQS Integrity Line
German legal entity, hosting 'exclusively in Germany' and a named Munich East data centre are genuine strengths. But no published DPA or subprocessor list appears anywhere in the evidence, ownership sits with US PE firm Thoma Bravo per provenance, and daily backups are stored 'for several years in geographically distributed data centres' with no country named — the most sensitive data exits the documented chain precisely where scrutiny matters.
preeco | hinweisgeberschutz
German GmbH in Ulm with HRB number, German law and venue, Hetzner-only hosting in named German datacenters (Nürnberg/Falkenstein), a public DPA with TOMs, audit rights and EU subprocessors (Hetzner, UpCloud-Finland), plus an on-premises option — most of rubric level 8 is evidenced. Two things hold it back: an opt-in OpenAI (US) integration touches report content and appears nowhere in the published subprocessor list, and ownership/jurisdiction are flagged unknown in the evidence — a GmbH & Co. KG versus GmbH naming discrepancy I do not reward.
Pricing transparency
EQS Integrity Line
Not one price appears on any captured page: no tiers, no employee bands, no VAT treatment, no setup fees — only a 'Start free trial' button. Per the anchors, every tier being a sales conversation is a zero.
preeco | hinweisgeberschutz
The spec states outright: 'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — pricing factors are named (entities, employees, hosting variant, license model) but no tier, band or amount is public anywhere in the evidence. Premium support has a FAQ question about its cost with no captured answer; the contract mechanics are clean (no setup fees, VAT excluded, 30-day price-increase notice) but an obligated company cannot compute a single euro from public pages.
Sovereignty, side by side
Dimension
EQS Integrity Line
preeco | hinweisgeberschutz
Legal entity
Not determined
Not determined
Ownership
Not determined
Not determined
Data residency
EU only
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.