whats-best.ai

Whistleblowing Portals · head-to-head

NAVEX One EthicsPoint vs SpeakUp

NAVEX One EthicsPoint

Rest of world

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

SpeakUp

EU-Made

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Skeptic

Assumes "audit-proof" and "100% anonymous" are marketing until the evidence says otherwise. Hunts certification claims without certificates, anonymity claims next to analytics scripts, per-report pricing traps and legal-update promises with no named lawyer. Exists to keep the rest of the bench honest.

NAVEX One EthicsPoint

SpeakUp

This judge's pick

Criterion by criterion

Reporting channels & reporter experience

NAVEX One EthicsPoint

Web, mobile and phone intake 24/7 in 60+ languages with anonymous reporting, two-way dialogue and machine translation is a real intake story. But the vendor's own privacy statement admits the Application collects personal information via cookies, beacons, tags and scripts, so nobody has shown anonymity survives first contact, and accessibility and QR entry points are entirely unevidenced.

SpeakUp

Reports can arrive by phone, voicemail, web browser or the SpeakUp app, with anonymous two-way follow-up the vendor says drives a 49% check-back rate, and the explicit statement that the platform collects no IP addresses, device fingerprints or identifying metadata is exactly the engineering detail an anonymity claim needs. Language coverage is stated as 100+ languages with human and machine translation in over 75. I found no public information on accessibility commitments such as WCAG, on QR entry points, or on whether the phone channel itself is anonymous-capable.

Case management & deadline discipline

NAVEX One EthicsPoint

Audit trails, activity logging, escalation automation, implicated-party screening and audit-ready export are genuinely evidenced. But 'reminders' is generic — no 7-day acknowledgment or 3-month feedback clock is ever named — and retention is explicitly pushed onto the customer ('retained as directed by our business customer'), so the statutory discipline is asserted workflow, not law-aware automation.

SpeakUp

The case worker's side looks real: structured triage-to-closure case management, an audit-ready trail, attachments, custom roles rather than all-or-nothing permissions, remediation tasks carrying owners and deadlines, investigation planning with logs and interviews, and dashboards exportable for regulators. But the statutory clocks appear only as a general remark that such software must support acknowledgment timelines and follow-up requirements — I found no public information on automated seven-day and three-month deadline handling, exclusion of implicated case handlers, or tamper-evidence for the case record.

Legal compliance alignment

NAVEX One EthicsPoint

The Directive appears only as a marketing checkbox — 'Confidently meet whistleblowing requirements like the EU Whistleblowing Directive and SOX'. No national transposition is named (HinSchG nowhere), no counsel or legal review is documented, and retention periods are literally the customer's problem: the mapping is vague, exactly the anchor-3 failure mode.

SpeakUp

The EU Directive, German Supply Chain Act, GDPR, NIS2 and DORA are all invoked, and the pages correctly note the Directive bites from 50 employees, but the mapping stays at the level of "we help you comply", with deadlines and follow-up duties named only as generic obligations such software must support. I found no public information on national transposition specifics, legal templates, named counsel, or any commitment to update the product when a law moves.

Security & anonymity assurance

NAVEX One EthicsPoint

No ISO 27001, no SOC 2, no pentest, no encryption architecture — just 'secure data hosting and encryption' plus MFA/RBAC, and silence on end-to-end encryption and IP logging. Worse, the vendor documents collecting personal information inside the Application through cookies, beacons, tags and scripts, including targeted-advertising cookies: 'anonymous reporting' sitting next to beacons is marketing, not engineering.

SpeakUp

The claims are unusually specific for this market — ISO 27001 and 27701, quarterly ISAE 3000 Type II plus SOC 2 and TISAX audits, MFA and SSO — and the explicit no-IP, no-fingerprint, no-identifying-metadata statement is the metadata minimization I hunt for. My discount: the captured pages assert certificates without showing them, describe encryption only as "highest standards" at rest and in transit, and I found no public information on an end-to-end encryption architecture, penetration test reports, or a security contact and disclosure policy. "100% Anonymität garantiert" is a slogan; the metadata statement is the part a buyer can hold them to.

Group & multi-entity capability

NAVEX One EthicsPoint

The product targets multinationals with investigations 'across multiple teams, regions and reporting channels' and regional custom workflows, but that is positioning, not architecture. The evidence is silent on per-legal-entity channels, entity-bound case separation, delegated administration, ombudsman roles and white-labeling — missing evidence is information, and none of it is here.

SpeakUp

Multi-country entities are claimed as supported and enterprise logos are everywhere, with analytics across locations, configurable teams and custom workflows — but the captured pages stop at "perfectly suited for international companies". I found no public information on per-entity channels, per-entity case-access separation, per-entity branding, delegated administration, or external ombudsman and counsel roles.

European sovereignty

NAVEX One EthicsPoint

The vendor is a US entity (Lake Oswego, Oregon) and every sovereignty attribute — ownership, residency beyond one bare 'Data is stored in the EU' sentence, subprocessors — is unknown; no published DPA or subprocessor list appears anywhere in the evidence. Targeted-advertising cookies hint at ad-tech exposure, and for the most sensitive data a company holds, one unverifiable hosting claim does not cut it.

SpeakUp

The Dutch contracting entity is verifiable down to KvK number, VAT number and an Olympisch Stadion address — the best-documented fact in this file. But the EU-only transfer statement expressly covers only the marketing website, with product data processing referred to a separate document not among the captured pages; I found no public information naming product data centers, product subprocessors, a DPA or TOMs, while a US sister entity and a US-visitor identity-resolution tool tying browsing to a known email address appear on the vendor's own pages.

Pricing transparency

NAVEX One EthicsPoint

Not a single number in the entire the evidence: three solutions exist (Essentials, Professional, WhistleB) and the closest thing to a price is 'a fast, affordable way'. An obligated company cannot compute any invoice from public pages — rubric level 0.

SpeakUp

Every price is a sales conversation: the pricing page says quotes are customized on company size and features such as SSO, and the stated audience starts at 500 employees — so an obligated 60-employee company cannot even establish it is in scope, let alone compute an invoice. "No hidden fees" and "case management always included in that price" are promises about a price nobody is shown; we found no public figures at all.

Sovereignty, side by side

Dimension NAVEX One EthicsPoint SpeakUp
Legal entity Incorporated in US Not determined
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors Not determined EU only

Facts, side by side

Only facts both products carry under the same definition — anything else would not be a fair row.

Compliance · GDPR yes1

captured 1 Oct 2026 · Report an error

yes · EU GDPR2

captured 5 Oct 2026 · Report an error

Data · Subject rights access · correction · update · deletion · object to processing · restrict processing · portability · opt out of marketing · withdraw consent · complain to DPA3

captured 16 Sep 2026 · Report an error

view · change · object · limit processing · delete · transfer (portability)2

captured 5 Oct 2026 · Report an error

Hosting · Data residency EU · customer-controlled1

captured 1 Oct 2026 · Report an error

no2

captured 5 Oct 2026 · Report an error

Product · Anonymity end-to-end encrypted communication guarantees technical anonymity for whistleblowers1

captured 1 Oct 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Product · Anonymous reporting yes · yes5

captured 16 Sep 2026 · Report an error

anonymous reporting channel6

captured 5 Oct 2026 · Report an error

Product · Case management two-way dialogue · translations · reminders · full audit trails · yes7

captured 16 Sep 2026 · Report an error

yes8

captured 5 Oct 2026 · Report an error

Product · Custom workflows 25

captured 16 Sep 2026 · Report an error

yes4

captured 5 Oct 2026 · Report an error

Product · Customer count 130009

captured 16 Sep 2026 · Report an error

750+ · Nestlé · Daimler Truck · Electrolux · Swarovski8

captured 5 Oct 2026 · Report an error

Product · Regulatory compliance EU Whistleblower Protection Directive · SOX5

captured 16 Sep 2026 · Report an error

yes · yes8

captured 5 Oct 2026 · Report an error

Product · Reporting channels web · phone · mobile · 24/75

captured 16 Sep 2026 · Report an error

phone · voicemail · web browser · mobile app4

captured 5 Oct 2026 · Report an error