preeco | hinweisgeberschutz leads five criteria — reporting channels 8.5 vs 7.0 (judges split 8–9 over a self-assessed WCAG 2.1 AA conformance and no-access-logs statements), case management 7.0 vs 5.2, compliance alignment 5.2 vs 3.0, multi-entity scale 7.7 vs 3.2, sovereignty 7.8 vs 4.7 — each a 6–0 lean. EQS Integrity Line is ahead on one: security assurance, 6.7 vs 4.0, also 6–0, on ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II, and CSA STAR; preeco holds no own ISO 27001 (only its Hetzner datacenters are certified). Pricing transparency is the genuine split — 1 judge leans EQS, 3 lean preeco, 2 tie (0.7 vs 1.0); neither verdict found published prices, and pricing is not weighted. Weighted totals run 6.2–7.1 for preeco against 4.1–5.9 for EQS. Both list German jurisdiction and EU-only data residency, with subprocessor exposure 'none' for EQS and 'EU only' for preeco.
Choose EQS Integrity Line if
You need the hotline vendor's own certifications for your audit file — ISO 27001 covering EQS Group and its data centres, PwC ISAE 3000 Type I and II audits, and CSA STAR; security assurance is the one criterion where EQS Integrity Line leads, 6 judges to 0 (6.7 vs 4.0).
Your procurement rules disqualify a vendor that holds no own ISO 27001 — preeco's verdict records no own certificate, with only its Hetzner datacenters certified, and no pentest or disclosure policy appears.
You weight security assurance heavily enough that it outweighs the five criteria where the table leans preeco — reporting channels, case management, compliance alignment, multi-entity scale and sovereignty.
Your data-processing register requires recorded subprocessor exposure of 'none' — EQS Integrity Line's attributes list 'none', while preeco's list 'EU only'.
Choose preeco | hinweisgeberschutz if
You must evidence German Whistleblower Protection Act compliance — HinSchG is built into the product with automatic 7-day/3-month clocks; compliance alignment leans preeco 6–0 (5.2 vs 3.0), while EQS Integrity Line's verdict finds the EU directive in one marketing sentence with no transposition or deadline features.
Your team runs reporting across a group or multiple entities — multi-entity scale leans preeco 6–0 (7.7 vs 3.2).
Reporter intake quality decides your choice — reporting channels leans preeco 6–0 (8.5 vs 7.0) on anonymous two-way dialog via Melde-ID, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages.
You need statutory case clocks and tamper-evidence out of the box — case management leans preeco 6–0 (7.0 vs 5.2), while EQS Integrity Line's verdict shows nothing on the 7-day/3-month clocks.
Sovereignty drives your shortlist — the criterion leans preeco 6–0 (7.8 vs 4.7), its verdict noting the default-off OpenAI path, against EQS Integrity Line's verdict citing no published DPA and 'geographically distributed' backups.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The SME Operator
Runs a 60-employee company that the law obligated, not convinced. Optimizes for compliance set up in an afternoon at a price the year-end review will not question, with the legal duties handled by the product. Rejects per-report fees, setup charges and anything that needs a compliance department to operate.
EQS Integrity Line
preeco | hinweisgeberschutz
This judge's pick
Criterion by criterion
Reporting channels & reporter experience
EQS Integrity Line
Anonymous two-way dialog is first-class with no tracking mechanisms, 80+ languages with integrated machine translation, mobile-optimized and WCAG bronze — that earns most of the 8 anchor. But there is no reporter-facing voice, hotline or QR channel evidenced: the multichannel fact is my caseworker creating a case from a letter or phone call, not a frightened employee calling in.
preeco | hinweisgeberschutz
Fully anonymous form with genuine two-way dialog via Melde-ID and password even for anonymous reports, browser voice messages on a § 16 Abs. 3 HinSchG basis without any phone service, QR entry, 26 languages, WCAG 2.1 AA (self-assessed), no install, and an explicit 'keine Zugriffs-Logs' promise keeping identity out of the channel. Only a real hotline and independently audited accessibility are missing, so just under the 10 anchor.
Case management & deadline discipline
EQS Integrity Line
Integrated case management with a per-activity revision log, granular need-to-know rights with dual control, partial case anonymisation and dashboards are solid bones. But the evidence is silent on the two things I'm legally on the hook for — automated 7-day/3-month deadline clocks and per-case retention/deletion — and on excluding implicated handlers, so the statutory discipline is my problem, not the product's.
preeco | hinweisgeberschutz
The statutory clocks run themselves — automatic 7-day/3-month deadline setting per organization with reminders — and the three-role model confines Sachbearbeiter:innen to assigned cases, with immutable reporter messages and an immutable activity log for audit-proof history. No evidence of conflict-of-interest exclusion for implicated handlers, and management reporting is an XLSX export rather than built-in reporting, which holds it under the 8 anchor.
Legal compliance alignment
EQS Integrity Line
One marketing sentence claims full EU Whistleblowing Directive compliance with no mapping to actual duties: no national transposition (HinSchG et al.) named, no acknowledgment/feedback clock features, no documentation or retention rules in the product, no counsel review. That's the 3 anchor verbatim — the directive is invoked, the obligations stay mine.
preeco | hinweisgeberschutz
HinSchG is implemented as product, not marketing: automatic Eingangsbestätigung 'gemäß HinSchG', the 7-day/3-month clocks, § 16 Abs. 3 voice intake, an Anwendungsbereich-Checkliste export and 'HinSchG-konform entwickelt und betrieben'. That exceeds the single-law rubric level 5 in depth, but there is nothing on other national transpositions, named counsel or documented legal review, so it cannot approach 8.
Security & anonymity assurance
EQS Integrity Line
ISO 27001 covering both EQS Group and the data centres, a PwC ISAE 3000 Type I and II audit, CSA STAR registration and OWASP-based threat analysis, plus 2FA as standard and a vendor-cannot-access encryption claim — that is audited assurance, not adjectives. It stops short of 8 because there are no public pentest summaries, no explicit IP-logging statement (only a generic no-tracking claim) and no published security contact or disclosure policy.
preeco | hinweisgeberschutz
The vendor admits it plainly: 'preeco GmbH aktuell keine eigene ISO 27001 Zertifizierung' — only the Hetzner datacenters are certified — and the evidence shows no pentest report, no security contact or disclosure policy, and AES only on 'essentielle Daten' rather than end-to-end encryption. The explicit no-access-logs statement, enforceable TOTP-2FA and AES-256 backups earn it above rubric level 3, but nothing here is audited for the product itself.
Group & multi-entity capability
EQS Integrity Line
The evidence is entirely silent on multi-entity structure — no per-entity channels, no entity-separated case access, no group overview. What exists are building blocks: custom branding, granular user rights and external experts in the anonymous dialog, which is not the same as per-subsidiary separation or ombudsman roles.
preeco | hinweisgeberschutz
Mandanten are real architecture: strict data separation, per-entity settings, users and modules, whitelabel logo and colors (own domain from Private Cloud up), and an ombudsperson role scoped to their organizations; new Mandanten in under three minutes suits my afternoon-deployment instinct. Group-level consolidated reporting that respects entity boundaries and delegated administration are simply not evidenced, so it sits between the 5 and 8 anchors.
European sovereignty
EQS Integrity Line
Hosting is exclusively in Germany with a named data centre (Munich East) under a Munich-based GmbH — the core of the 8 anchor's facts. But nothing here shows a published DPA or subprocessor list, backups go to 'geographically distributed' centres of unstated location, and the vendor sits under US PE ownership (Thoma Bravo) — the chain is undocumented, which caps it at 5.
preeco | hinweisgeberschutz
German GmbH with Ulm register entry, hosting exclusively in named Hetzner datacenters in Nuremberg/Falkenstein with 'Speicherort Deutschland' for cloud and private cloud, no third-country transfer, plus a public DPA with downloadable TOMs and a 2-week subprocessor notice naming only EU processors (Hetzner, UpCloud for internal monitoring). It misses 10 because ownership is undocumented and the opt-in AI path can send report content to OpenAI if switched on.
Pricing transparency
EQS Integrity Line
The only pricing-related fact in the entire sheet is 'Start free trial' — no tiers, no numbers, no employee bands, no VAT treatment, no setup-fee disclosure. I cannot compute my invoice from these pages, and everything above entry implies a sales conversation, which is precisely what my year-end review will question.
preeco | hinweisgeberschutz
No public prices at all — the license and price model is a separate, individual offer — so my two-minute invoice exercise is impossible and every quote is a sales call. I credit the unusually clean terms: no setup fees, no cancellation periods, VAT treatment and billing period stated, free trial and free onboarding, but rubric level 3 requires at least an entry price and there isn't one.
Sovereignty, side by side
Dimension
EQS Integrity Line
preeco | hinweisgeberschutz
Legal entity
Not determined
Not determined
Ownership
Not determined
Not determined
Data residency
EU only
Not determined
Subprocessors
Not determined
Not determined
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.