whats-best.ai

Whistleblowing Portals · head-to-head

NAVEX One EthicsPoint vs SpeakUp

NAVEX One EthicsPoint

Rest of world

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

SpeakUp

EU-Made

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Security Auditor

Pentests the anonymity promise for a living. Optimizes for evidenced security: current certificates with visible scope, published pentests, documented end-to-end encryption, metadata minimization, and hosting outside hostile jurisdictional reach. Rejects adjective security and "military-grade" anything.

NAVEX One EthicsPoint

SpeakUp

This judge's pick

Criterion by criterion

Reporting channels & reporter experience

NAVEX One EthicsPoint

Web, mobile and phone intake in 60+ languages with two-way dialogue and machine translation of follow-ups is genuinely broad. But nothing documents how the reporter's identity stays out of the channel, and the privacy statement admits beacons, tags, scripts and targeted-advertising cookies operating inside the application — tracking tech in the intake path actively undermines anonymity at first contact.

SpeakUp

Intake is documented across phone, voicemail, web browser and a mobile app, with 100+ languages plus machine and professional human translation and transcription, multi-device access, and an anonymous two-way follow-up dialog evidenced by a published 49% check-back rate. The platform states it collects no IP addresses, device fingerprints or identifying metadata, which is a concrete claim about the intake path. We found no public information on QR entry points, accessibility-standard conformance, or documentation of how reporter identity is kept out of the channels themselves.

Case management & deadline discipline

NAVEX One EthicsPoint

Full auditable case history, per-user view/edit visibility, implicated-party exclusion and audit-ready export are real, evidenced features. But statutory clocks surface only as vague "reminders", and retention is "as directed by our business customer" — no legally aware deadline or retention automation is demonstrated in the product itself.

SpeakUp

Structured triage with investigation planning, logs, interviews and findings is evidenced, alongside custom roles, remediation tasks carrying owners and deadlines, custom team workflows, an audit-ready trail from report to closure, and dashboards exportable for regulators. The acknowledgment-timeline and follow-up language is phrased as what such software must support rather than a documented automated clock. We found no public information on automated statutory deadlines, conflict-of-interest exclusion of implicated handlers, tamper-evidence of the case record, or per-case retention and deletion automation.

Legal compliance alignment

NAVEX One EthicsPoint

The directive appears as a marketing checkbox — "meet whistleblowing requirements like the EU Whistleblowing Directive and SOX" — with no acknowledgment/feedback clocks, no national transposition detail, no named legal review. WhistleB's "alignment with the EU Whistleblowing Directive and national legislation" is the same adjective pattern, and deadline/retention duties are explicitly delegated to the customer.

SpeakUp

The EU Whistleblower Directive is cited with the correct 50-employee obligation, and the vendor lists the Directive, the German Supply Chain Act, GDPR, NIS2 and DORA among supported regulations, with retention and localization duties claimed as fulfilled. The mapping stays at category level, and we found no public information on specific national transpositions such as the German whistleblowing act, legal templates, process guidance maintained by named counsel, or documented updates when a law changes.

Security & anonymity assurance

NAVEX One EthicsPoint

"Secure data hosting and encryption" is adjective security: no ISO 27001 or equivalent, no pentest, no documented E2E architecture, no no-IP-logging statement anywhere in the evidence. Worse than silence, the privacy statement discloses cookies, beacons, tags and scripts collecting personal information inside the application, including targeted-advertising cookies — metadata harvesting in the very channel sold as anonymous; MFA and role-based permissions are access control, not anonymity assurance.

SpeakUp

Certification is claimed for ISO 27001 and ISO 27701 with quarterly ISAE 3000 Type II audits plus SOC 2 and TISAX, and the platform states it collects no IP addresses, device fingerprints or identifying metadata — that is a minimization statement I can actually work with. Encryption is asserted at rest and in transit, but "highest encryption standards" and "100% anonymity guaranteed" are adjectives, not architecture. We found no public information on penetration tests, the visible scope of the certificates, end-to-end encryption of report content, or a published security contact and disclosure policy, so the question of whether the operator could unmask a reporter goes unanswered in public.

Group & multi-entity capability

NAVEX One EthicsPoint

Scale is marketed — 13,000+ customers and Fortune 500 penetration, workflows "for specific teams, departments or regions" — but nothing evidences per-legal-entity channels, case access separated per entity, delegated administration, external ombudsman roles, or group reporting respecting entity boundaries. Custom workflows cap at two, which is thin for a corporate group.

SpeakUp

The vendor states it is suited to organizations with entities in multiple countries, and dashboards show trends across locations with custom roles, custom team workflows and a multinational customer list. We found no public information on per-entity channels with separated case access, delegated administration, external ombudsman or counsel roles, or per-entity branding and white-label reporting pages.

European sovereignty

NAVEX One EthicsPoint

The vendor is a US company (Lake Oswego, Oregon; BC Partners-backed) and the evidence publishes no DPA, no subprocessor list, and no named data centers; the single jurisdictional fact is "Data is stored in the EU" on the WhistleB sibling page, while processing is governed by the parent's privacy statement as processor. That is US-jurisdiction-reachable processing of the most sensitive data a company holds, documented at adjective level.

SpeakUp

The European contracting entity is the Dutch People InTouch B.V. at an Amsterdam address, and the privacy statement says personal data is not transferred to processors outside the EEA — but that statement expressly covers only the marketing website, with the product's data processing documented separately. We found no public information on where the product's report data is hosted, on product subprocessors, on named data centers, or on a published data processing agreement and technical measures. A US sibling entity (SpeakUp US, Inc., New York) and offices in New York and Bengaluru sit alongside the Dutch entity.

Pricing transparency

NAVEX One EthicsPoint

Three solutions are named — Essentials, Professional, WhistleB — and not one carries a number; the closest the evidence gets to a price is "fast, affordable". Every invoice is a sales conversation, so an obligated company can compute nothing from public pages.

SpeakUp

Every tier is a customized quote based on company size and features needed, and we found no public price figures for any tier on the captured pricing page. The only disclosed terms are that case management is always included in the price and that support packages carry no additional costs or hidden fees, with the target market stated as 500 employees up to global enterprises — none of which lets an obligated company compute an invoice.

Sovereignty, side by side

Dimension NAVEX One EthicsPoint SpeakUp
Legal entity Incorporated in US Not determined
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors Not determined EU only

Facts, side by side

Only facts both products carry under the same definition — anything else would not be a fair row.

Compliance · GDPR yes1

captured 1 Oct 2026 · Report an error

yes · EU GDPR2

captured 5 Oct 2026 · Report an error

Data · Subject rights access · correction · update · deletion · object to processing · restrict processing · portability · opt out of marketing · withdraw consent · complain to DPA3

captured 16 Sep 2026 · Report an error

view · change · object · limit processing · delete · transfer (portability)2

captured 5 Oct 2026 · Report an error

Hosting · Data residency EU · customer-controlled1

captured 1 Oct 2026 · Report an error

no2

captured 5 Oct 2026 · Report an error

Product · Anonymity end-to-end encrypted communication guarantees technical anonymity for whistleblowers1

captured 1 Oct 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Product · Anonymous reporting yes · yes5

captured 16 Sep 2026 · Report an error

anonymous reporting channel6

captured 5 Oct 2026 · Report an error

Product · Case management two-way dialogue · translations · reminders · full audit trails · yes7

captured 16 Sep 2026 · Report an error

yes8

captured 5 Oct 2026 · Report an error

Product · Custom workflows 25

captured 16 Sep 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Product · Customer count 130009

captured 16 Sep 2026 · Report an error

750+ · Nestlé · Daimler Truck · Electrolux · Swarovski8

captured 5 Oct 2026 · Report an error

Product · Regulatory compliance EU Whistleblower Protection Directive · SOX5

captured 16 Sep 2026 · Report an error

yes · yes8

captured 5 Oct 2026 · Report an error

Product · Reporting channels web · phone · mobile · 24/75

captured 16 Sep 2026 · Report an error

phone · voicemail · web browser · mobile app4

captured 5 Oct 2026 · Report an error