whats-best.ai
Search Sign in

Methodology

How scores are made

Every number on this site comes from a published rubric, a named bench of AI judges, and public evidence you can open. This page is the whole method — weights included.

What this is — and is not

  • It is an AI-assisted analysis of public evidence. A panel of AI judges reads what a vendor publishes and scores it against a rubric anyone can read.
  • It is not a hands-on test. Nobody here has used the product. Every reading is made from the vendor’s own public pages, captured and dated. These are not hands-on tests, and they are not human reviews.
  • It is not a collection of user reviews. No stars from a crowd, no incentivized ratings, no vendor-submitted testimonials count towards any score.
  • Scores are opinions; facts are cited and correctable. A score is the panel’s judgement and is labelled as such. Every fact behind it cites the captured source it was read from, and anyone can report an error in any of them.

Where the facts come from

The evidence is the vendor’s own public surface: pricing page, security and compliance pages, legal terms, subprocessor lists, documentation. Each page is captured with its date and a content hash, and the capture is what the judges read — not a memory of it.

Facts are extracted from those captures and then verified in an independent second pass against the same source. A fact that does not survive that pass is not shown anywhere on this site and never reaches the judges:

  • a claim we could not find again in the source is removed — especially in the strict classes, pricing and compliance, where a wrong price or a wrong certification is not a rounding error;
  • a claim the operator has suspended after a report is out of the sheet until the report is decided;
  • evidence older than 90 days, or pricing older than 30 days, keeps its place and carries its date — age is a warning, not a reason to hide something.

What we remove is the claim, not the page. A product is only kept off the site when there is nothing to print: no proven fact, no judge, no verdict. Otherwise the page goes up without the unproven line, and a section called “What we left out” names every hole, with a button asking you for what we are missing. Send it with the page it can be read on and it goes through the same checks as anything else.

How a fact is proven

The vendor’s own page has to show it. Every page we capture is kept as a screenshot of the page as it rendered. Code, not a model, looks for a fact’s quoted passage in the visible text of that screenshot. A passage that is not visible on the page as captured proves nothing, and the fact is not shown.

An AI model has to confirm it. An AI model then reads the quoted passage and confirms that it supports the value we print. Where a mistake would hurt a vendor — pricing, compliance, legal, subprocessors and sovereignty, and any statement adverse to the vendor — that is not enough: a second, independent AI model from a different model family reads the same value off the cropped screenshot, and the two have to agree. If they do not agree, or either cannot tell, the fact is not shown. A sovereignty dimension without that agreement reads “Unknown”.

Judges score from the same proven facts the page prints. Where they found no public information on something, they say so — that is a statement about the evidence we hold, not about the product. Absence is never printed as a product fact. Names of people, read from an imprint or a privacy policy, are never shown at all; they serve only to tie a product to its legal entity.

Provenance is an editorial classification. The provenance class (EU-Made, EU origin foreign-owned, Rest of world) is our editorial classification by the registered seat and ownership of the vendor. It is separate from the sourced sovereignty dimensions below, and it can be reported like any fact.

What we leave out. A fact that is not proven is not shown — not hedged, not badged, not marked as doubtful. Absence is never printed as a product fact either. Where we found nothing about pricing or compliance, “What we left out” says that we found no public information on it on the pages we read, and lists those pages. Where facts were read but could not be confirmed on the vendor’s page as captured, it says that instead. The page itself stays up: leaving out one claim is not a reason to withhold everything else we can show.

Measured error rates

Every week a random sample of published facts from each class below is read once more, by a third AI model that took no part in publishing them and is told nothing about how they were read. It sees only the sentence we print and the screenshot passage it rests on, and marks it right or wrong. A wrong fact comes off the page at once, and the other facts on its page are checked again.

For each class we count the last 30 facts audited. When two or more of them are wrong, the whole class is left out of every page until a fresh 30 have been audited with at most one wrong. The same fresh audit is needed before launch and whenever the way facts are checked changes.

Class Wrong Audited Audited between
statements adverse to the vendor 0 30 21 Sep 2026 – 5 Oct 2026
pricing 0 30 21 Sep 2026 – 5 Oct 2026
compliance 0 30 21 Sep 2026 – 5 Oct 2026
legal 1 30 21 Sep 2026 – 5 Oct 2026
subprocessors 0 30 21 Sep 2026 – 5 Oct 2026
sovereignty 0 30 24 Sep 2026 – 5 Oct 2026

How the panel scores

Every criterion is scored from 0 to 10 against published anchors: the rubric says in words what a 0, a 3, a 5, an 8 and a 10 look like. The anchors are printed under every score on every product page.

Every judge is an AI persona with a name, a version and a published stance. Each one scores every criterion independently; only the weights differ. When two judges are 3 or more points apart on the same criterion, the page prints the disagreement instead of averaging it away.

A judge’s bottom line is the weighted mean of their criterion scores. The panel rating is the mean of every judge’s bottom line. Pricing transparency is skipped in that weighting when the vendor publishes no price at all — it is still reported, and the page says so. The category median printed beside a rating is the median panel rating of every rated product in that category.

How to read the stars

Stars are the panel’s opinion on a published scale. They run from 0 to 5 in half steps and are the 0–10 score halved. 5 means the rubric’s top anchor is met on the evidence we hold; 0 means the bottom anchor. Each star resolves to a score against written anchors, and each reason cites the page it was read from.

Not rated. A product is only given panel stars when its page rests on at least 1 captured source page and at least 3 proven facts. Below that, the page shows “Not rated — too little public evidence” instead of stars, the panel’s reasoning stays readable, and the product is left out of the category median. Few stars mean a weak reading of the evidence; they never stand in for missing evidence.

Sovereignty. Sovereignty is computed from four sourced dimensions: legal entity, data residency, subprocessor exposure and ownership. It is shown as stars only when all four are proven on the vendor’s own pages. Otherwise the page says how many of the four are proven. A dimension we could not prove is left open — it is never counted as zero.

The “European sovereignty” criterion in a judge’s scores is something else: that is the panel’s opinion, scored against the rubric like every other criterion.

Weights per judge

These are the weights in force, read from the same configuration the pipeline scores with. A higher number means that criterion moves that judge’s bottom line more.

Accounting rubric v1

Criterion The Bookkeeper v1.0 The Tax Adviser v1.0 The Auditor v1.0 The Founder v1.0 The Integrator v1.0 The Skeptic v1.0
Bookkeeping core 3.0 2.0 2.0 1.5 1.5 1.5
GoBD, immutability & audit 2.0 2.5 3.0 1.5 1.5 2.5
Tax handling & filings 2.0 2.5 2.0 2.5 1.5 1.5
Receipts, banking & matching 2.5 1.5 1.5 3.0 2.5 1.0
Tax adviser handoff 1.5 3.0 1.5 1.5 2.0 1.5
European sovereignty 0.5 0.5 1.5 0.5 1.0 1.5
Pricing transparency 1.0 1.0 0.5 2.0 1.0 2.0
The judges and the criteria

The Bookkeeper · Posts the month and closes it. Wants a real ledger with SKR03/04, recurring entries, cost centres and a close that locks. Judges receipt capture by how many exceptions are left after the automation, not by the demo video.

The Tax Adviser · Closes the year for forty clients and needs the books to arrive in a form DATEV accepts, receipts attached. Reads "export to CSV for your Steuerberater" as an admission that nobody asked one. Wants scoped access and a clean period handover.

The Auditor · Arrives with a Betriebsprüfung and asks for the data export and the Verfahrensdokumentation. Wants postings that cannot be altered after the fact, corrections booked as reversals, a complete change history, and retention that survives the full statutory period.

The Founder · Runs a twelve-person company and does the books on a Sunday. Wants bank feeds that match themselves, invoices out in a minute, and the VAT return submitted without learning ELSTER. Will pay for the hour saved, and notices when the headline price was not the invoice.

The Integrator · Connects the books to the shop, the payment provider and the payroll system. Wants a documented API, e-invoicing both directions, and imports that reconcile rather than duplicate. Reads a Zapier logo as an outsourced integration.

The Skeptic · Has seen "GoBD-konform" printed on pages that offer no documentation to back it, and wants the feature that makes it true. Also reads for the booking limit, the tier where DATEV export appears, and what an extra bank account costs.

Bookkeeping core · Double-entry, the chart of accounts (SKR03/SKR04), postings, journals, opening balances and period closing — the ledger underneath the pretty screens.

GoBD, immutability & audit · Whether the record survives a tax audit: unalterable postings, complete change history, retention across the statutory period, and a Verfahrensdokumentation the vendor actually supplies.

Tax handling & filings · VAT logic and the filings that follow: UStVA, ELSTER submission, EÜR or Bilanz, OSS for cross-border sales, and reverse-charge handling.

Receipts, banking & matching · How evidence and money get into the ledger: bank feeds, receipt capture, OCR, matching rules, and whether the digital receipt is legally sufficient on its own.

Tax adviser handoff · How the books reach the Steuerberater — DATEV above all — and whether the adviser can work in the system rather than around it.

European sovereignty · Where the books live and who could be compelled to produce them — plus, uniquely here, whether statutory retention survives leaving the vendor. Independently sourced by the sovereignty pipeline.

Pricing transparency · Whether a business can compute the real annual invoice — including the bookings, users, bank accounts and adviser access they actually need — from public pages alone.

Business Instant Messaging rubric v1

Criterion The Team Lead v1.0 The Security Officer v1.0 The Works Council Advocate v1.0 The Compliance Counsel v1.0 The Platform Engineer v1.0 The Skeptic v1.0
Channels, threads & search 3.0 1.0 1.0 1.0 1.5 1.5
Encryption & access control 1.0 3.0 1.5 1.0 1.5 1.5
Retention, discovery & co-determination 1.0 1.5 3.0 3.0 1.0 1.5
Deployment & data custody 0.5 2.0 1.5 1.5 3.0 1.5
Integrations & extensibility 2.5 0.5 0.5 0.5 2.5 1.0
European sovereignty 0.5 2.5 2.5 2.0 1.5 1.5
Pricing transparency 1.5 0.5 0.5 1.0 1.0 2.0
The judges and the criteria

The Team Lead · Runs a distributed team and needs the tool people actually open. Wants threads that stay readable, search that finds last spring's decision, and channels that can be tidied without losing history. Unmoved by feature lists that do not survive a busy Tuesday.

The Security Officer · Assumes the archive will one day be read by someone it was not meant for. Wants end-to-end encryption that ordinary users survive, device verification, sessions an admin can revoke, and a plain statement of what the vendor cannot decrypt.

The Works Council Advocate · Knows that a chat log is a record of who spoke to whom at what hour. Wants presence a person controls, no individual activity scoring anywhere, retention that deletes rather than hides, and analytics that can be switched off across the organisation.

The Compliance Counsel · Will one day have to produce this archive, edits and deletions included, to a regulator or a court. Wants legal hold, an export a lawyer can work from, retention per channel, and an audit trail that survives the admin who made the change.

The Platform Engineer · Would rather run it than rent it, and wants to know whether that is a supported deployment or a hobby build. Cares about open protocols, federation, a plugin system with real permissions, and an upgrade path that does not orphan the customisations.

The Skeptic · Reads for the message-history cap, the tier where SSO appears, and what "unlimited" excludes. Has seen "end-to-end encrypted" mean direct messages only, on request, with search disabled — and wants that sentence found rather than assumed.

Channels, threads & search · The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.

Encryption & access control · What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.

Retention, discovery & co-determination · The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.

Deployment & data custody · Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.

Integrations & extensibility · Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.

European sovereignty · Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

Pricing transparency · Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.

Conversion Optimization rubric v1

Criterion The Growth Lead v1.0 The E-Commerce Manager v1.0 The Product Engineer v1.0 The CRO Consultant v1.0 The Data Protection Officer v1.0 The Skeptic v1.0
Experiment types & delivery 3.0 2.5 2.5 2.0 0.5 1.0
Statistical method & guardrails 2.0 1.5 2.0 2.0 0.5 3.0
Consent & visitor tracking 1.5 1.5 1.0 2.0 3.0 1.0
Snippet performance & flicker 1.5 3.0 2.5 1.5 0.5 1.5
Analytics, data export & integrations 2.0 1.5 3.0 2.0 1.0 2.5
European sovereignty 1.0 1.0 1.0 1.5 3.0 1.0
Pricing transparency 1.0 1.5 0.5 2.0 0.5 1.0
The judges and the criteria

The Growth Lead · Runs the testing programme for a German marketing team and reports uplift to the board. Wants a visual editor the team can use without a developer, targeting that goes beyond the URL, and results she can defend when finance asks where the promised revenue went.

The E-Commerce Manager · Owns a shop where a tenth of a second of load time shows up in the conversion rate. Wants personalisation that can be tested against a control, a snippet that does not flicker the product page, and a traffic-based price that does not jump a tier every December.

The Product Engineer · Ships experiments behind feature flags and would rather not ship a third-party script at all. Wants server-side SDKs for the stack in use, edge delivery, metrics computed in the warehouse the team already trusts, and an API good enough to build internal tooling on.

The CRO Consultant · Sets up testing programmes for several clients and has to recommend a platform each can afford and defend. Reads for multi-project management, clean analytics integration, a consent setup a client's DPO will sign off, and a traffic metric she can estimate before the contract.

The Data Protection Officer · Has to answer whether the test script may run before the consent banner is answered, and usually finds the vendor has not said. Wants the storage keys listed, a documented consent-pending mode, visitor data processed in the EU, and a published subprocessor list that includes the CDN.

The Skeptic · A statistician who has watched too many "winners" regress to zero. Reads for the method by name, what stops a team from peeking, sample ratio mismatch checks and multiple-comparison corrections — and treats a "probability to beat" without documented assumptions as marketing.

Experiment types & delivery · What can be tested and where: client-side changes through an editor, server-side and feature experiments through SDKs, multivariate and multi-page tests, and personalisation — judged on what the documentation shows rather than on the feature grid.

Statistical method & guardrails · Which statistics decide the winner and what protects the customer from misreading them. Scored on what the vendor documents: the method by name, how peeking and multiple comparisons are handled, and whether sample ratio mismatch is detected.

Consent & visitor tracking · Whether the test script respects §25 TDDDG and the ePrivacy rules as evidenced on the vendor's own pages: when the script runs relative to consent, what it stores on the device, whether a cookieless or consent-free mode exists, and how visitor identifiers are handled.

Snippet performance & flicker · The cost the client-side snippet imposes on the page it tests: blocking load, flicker of original content, script weight and the effect on Core Web Vitals — scored on what the vendor measures and publishes, not on "lightning fast".

Analytics, data export & integrations · Getting results and raw data out: integration with analytics and tag management, export of visitor-level results, warehouse-native analysis, and an API — because an experiment result that cannot be checked in the customer's own data is a claim, not a finding.

European sovereignty · Where visitor data is processed and stored and who the contracting entity is. Independently sourced by the sovereignty pipeline; weighted higher here than in categories that hold only the customer's own data, because the script runs on every visitor to the customer's site and their behaviour is what the platform records.

Pricing transparency · A category priced by traffic — monthly tracked users, visitors or impressions — where the tier a site lands in depends on numbers the buyer has to estimate. Whether a buyer can compute the real annual cost including traffic limits, overage, server-side or personalisation modules and seats — from public pages alone.

CRM rubric v1

Criterion The Solo Seller v1.2 The Data Protection Officer v1.0 The Sales Ops Lead v1.0 The RevOps Integrator v1.0 The Migrator v1.1 The Skeptic v1.2
Contact & data model 2.0 1.5 1.5 1.0 1.0 1.0
Pipeline & forecasting 2.0 0.5 3.0 1.0 0.5 1.0
Automation & workflows 0.5 0.5 2.0 1.5 0.5 1.0
Integrations & API 1.0 1.0 1.5 3.0 1.5 1.0
European sovereignty 0.5 3.0 0.5 0.5 1.0 1.0
Import, export & exit 1.0 3.0 0.5 1.5 3.0 1.5
Pricing transparency 1.0 0.5 1.0 0.5 1.0 1.0
The judges and the criteria

The Solo Seller · Runs their pipeline between customer calls and pays with their own card. Optimizes for a CRM that is set up in an afternoon, priced honestly at 1-5 seats, and never asks them to configure an object model. Rejects seat minimums and features held hostage in enterprise tiers.

The Data Protection Officer · Knows a CRM is a database of other people's personal data before it is a sales tool. Optimizes for GDPR posture: EU hosting, DPA, subprocessor hygiene, consent fields, retention and deletion that actually delete. Rejects US-default hosting and enrichment features that scrape contacts from the open web.

The Sales Ops Lead · Owns the forecast a 40-seat team lives by. Optimizes for pipeline discipline: stage hygiene, required fields, routing, quota and forecast reporting the CFO will accept. Rejects freeform pipelines that cannot enforce a process and reporting that stops at a dashboard screenshot.

The RevOps Integrator · Treats the CRM as one system in a revenue stack. Optimizes for two-way email and calendar sync, a real API with webhooks, and native connections to the tools money already flows through. Rejects closed ecosystems and integrations that are one-way imports in disguise.

The Migrator · Has moved a company off a CRM twice and remembers every scar. Optimizes for clean import with dedupe, full export of every object including notes and activity history, and contract terms that permit leaving. Rejects export behind support tickets and per-record API metering that makes exit a project.

The Skeptic · Assumes the pricing page is the nicest thing the vendor will ever say. Hunts per-seat maths that explode at renewal, "unlimited" with footnotes, AI features priced by credits, dead changelogs and acquisition rumours. Exists to keep the rest of the bench honest.

Contact & data model · Depth and hygiene of the core records — contacts, companies, deals, custom fields, deduplication.

Pipeline & forecasting · Whether the pipeline enforces a process and produces reporting a finance department accepts.

Automation & workflows · Triggers, sequences and routing that remove manual work without a consultant.

Integrations & API · Two-way email/calendar sync, native connections, and an API that treats external systems as first-class.

European sovereignty · Where other people's personal data actually lives and under whose law — entity, hosting, subprocessors, DPA.

Import, export & exit · Getting in with history intact, and out with everything — the anti-lock-in criterion.

Pricing transparency · Whether a buyer can compute the real invoice — per seat, per month, at renewal — from public pages alone.

Customer Service & Helpdesk rubric v1

Criterion The Support Lead v1.0 The Agent Advocate v1.0 The Data Protection Officer v1.0 The Shop Operator v1.0 The Integrator v1.0 The Skeptic v1.0
Ticketing, queues & SLA 3.0 3.0 1.0 2.0 1.5 1.5
Channels in one queue 2.0 2.5 0.5 3.0 1.5 2.0
Knowledge base & deflection 2.0 2.0 0.5 2.5 0.5 1.0
Customer data protection 1.0 1.0 3.0 1.0 1.5 1.5
Integrations & API 1.5 1.0 0.5 2.5 3.0 1.0
European sovereignty 0.5 0.5 3.0 0.5 1.0 1.5
Pricing transparency 1.0 1.0 0.5 1.5 1.0 2.0
The judges and the criteria

The Support Lead · Runs a team of twelve against an SLA the sales team promised. Wants routing that reflects skill, timers that warn before they breach, and reporting she can take to a quarterly review. Reads "AI-powered" as a claim to be checked against the queue on a Monday morning.

The Agent Advocate · Has answered tickets for six years and judges every tool by the hundredth reply, not the first. Wants search that finds the old thread, macros that save real keystrokes, and one screen rather than four tabs. Treats agent-activity dashboards as a smell.

The Data Protection Officer · Sees a ticket archive for what it is: years of personal data customers typed themselves, including the things they should not have. Wants retention that executes, redaction, an audit of who read what, and an answer on whether vendor support can open a ticket.

The Shop Operator · Handles "where is my parcel" at volume and needs the order in front of the agent without a second login. Judges omnichannel by whether WhatsApp and the shop actually land in one queue, and deflection by whether the ticket count falls in December.

The Integrator · Has to wire the helpdesk into a CRM, a shop and an identity provider that all predate it. Wants a documented API with rate limits, webhooks that retry, SCIM, and a sandbox. Reads a partner-contact form on an integrations page as a missing API.

The Skeptic · Counts the channel logos on the marketing page, then asks which of them share one queue and one history. Reads for the tier where SLA policies begin, what a "light agent" may actually do, and whether the AI summariser is included or metered.

Ticketing, queues & SLA · The engine: how work is routed, prioritised, escalated and measured — and whether an agent can find the ticket they need among ten thousand.

Channels in one queue · Email, chat, phone, portal, messengers and social — judged on what actually lands in the same queue with the same history, not on how many channel logos the marketing page carries.

Knowledge base & deflection · Whether the product reduces the number of tickets as well as organising them: public help centre, article workflow, suggestions to agents and to customers.

Customer data protection · A ticket archive is personal data written by the data subject. Retention, deletion, access control, subject rights, and what the vendor does with attachments — judged on what executes rather than what is promised.

Integrations & API · The systems a helpdesk has to reach — CRM, shop, order management, identity — and whether the API is documented for building or gated behind a partner conversation.

European sovereignty · Where the ticket archive lives, who the contracting entity is, which subprocessors touch it, and whether vendor support can read customer data. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

Pricing transparency · Whether a support lead can compute the real annual invoice for their agent count — including the channels and features they actually need — from public pages alone.

Data Protection rubric v2

Criterion The External DPO v2.0 The In-House Counsel v2.0 The Drafted Generalist v2.1 The Lead Auditor v2.0 The IT Integrator v2.0 The Skeptic v2.1
Records & DPIA depth 3.0 2.0 1.5 1.5 1.5 1.0
Data subject rights & incidents 2.0 2.5 2.0 1.0 1.0 1.5
Privacy regime coverage 1.0 2.0 0.5 1.5 0.5 1.0
Audit readiness & evidence 1.0 1.0 1.0 3.0 0.5 1.5
Integrations & automation 1.0 0.5 0.5 0.5 3.0 0.5
European sovereignty 1.5 1.5 1.0 1.0 1.0 1.5
Pricing transparency 1.0 0.5 1.0 0.5 0.5 1.0
The judges and the criteria

The External DPO · Carries thirty client mandates and bills by the hour they save. Optimizes for multi-client capability, reusable templates, a RoPA that drives the rest, and client-ready reports. Rejects single-tenant tools that treat the consultancy as thirty separate customers.

The In-House Counsel · Answers personally when the authority writes. Optimizes for defensibility: request clocks that never slip, a breach workflow that produces the Art. 33 notification, regime coverage that matches where the company actually operates. Rejects tools whose legal content nobody maintains.

The Drafted Generalist · Office manager at an 80-employee firm who got compliance added to her job title, not her calendar. Optimizes for guided workflows in plain language and software that knows the law so she does not have to. Rejects consultant-shaped platforms that assume a compliance department.

The Lead Auditor · Audits management systems for a living and has seen every folder of screenshots. Optimizes for revision-safe history, evidence packs on demand, and a defensible answer to "show me the state on date X". Rejects systems where the audit trail is assembled the week before the audit.

The IT Integrator · Has to feed the compliance platform from the estate that already exists: Entra ID, Jira, the CMDB. Optimizes for directory import, a real API, webhooks and SSO — compliance data that stays current because it syncs, not because someone retypes it. Rejects data islands with a CSV drawbridge.

The Skeptic · Hunts certification logos that link nowhere, "AI-powered" features with no substance behind them, consulting bundled as software, legal-update promises with no named lawyer, and customer counts that disagree between pages. Exists to keep the rest of the bench honest.

Records & DPIA depth · The DSMS core: records of processing (RoPA/VVT), data protection impact assessments, processor/DPA management and TOMs — how deeply the legal artifacts are modeled and connected.

Data subject rights & incidents · The operational half of the DSMS: data subject request handling with statutory clocks, breach register and authority notification, deletion concepts that actually delete.

Privacy regime coverage · Which privacy regimes the product actually operationalizes — GDPR, BDSG, Swiss nDSG, UK GDPR, ePrivacy, EU AI Act privacy duties — and whether one record maps across them or each regime is a fresh island.

Audit readiness & evidence · Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

Integrations & automation · Whether the platform feeds from the real IT estate — directory import, ticketing, API — and automates the recurring privacy work instead of re-typing it.

European sovereignty · Where the compliance record of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. A platform that maps your processing is itself your most concentrated processing.

Pricing transparency · Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

E-Commerce Platforms & Shop Systems rubric v1

Criterion The Merchant v1.0 The B2B Seller v1.0 The Developer v1.0 The Operations Lead v1.0 The Data Protection Officer v1.0 The Skeptic v1.0
Catalogue & checkout 3.0 2.5 1.5 1.5 0.5 1.5
Tax & German legal correctness 1.5 3.0 1.0 1.5 1.5 1.5
Extensibility & developer surface 1.5 1.0 3.0 1.0 0.5 1.5
Order operations & back office 2.0 2.0 1.0 3.0 0.5 1.0
Data ownership & exit 1.0 1.0 2.5 1.5 2.5 2.0
European sovereignty 0.5 1.0 1.0 0.5 3.0 1.5
Pricing transparency 2.0 1.5 1.0 1.5 0.5 2.0
The judges and the criteria

The Merchant · Sells to consumers and lives on conversion. Wants a checkout that can be changed without a rebuild, the payment methods German shoppers expect including invoice, and promotions with rules. Judges price against contribution, not against a competitor's tier.

The B2B Seller · Sells to businesses across the EU: net prices, VAT-ID validation, reverse charge, customer-specific price lists and payment on account. Reads a shop that shows gross prices to a trade customer as one that has not met a trade customer.

The Developer · Will maintain this for five years. Wants local development, version control for themes, a plugin architecture with a dependency model, and upgrades that do not orphan the customisations. Reads a closed template editor as a future migration.

The Operations Lead · Ships the orders and handles the returns. Wants stock that is true across channels, partial shipments, carrier integrations with labels, and an ERP link the vendor maintains. A shop that cannot do a partial refund is a shop that has never had December.

The Data Protection Officer · The shop holds customers, addresses and buying histories, and the checkout is full of third parties. Wants the subprocessor list, consent handling that survives a complaint, deletion that executes against order history, and an answer on where the CDN and analytics sit.

The Skeptic · Knows the headline price is never the invoice here. Reads for the transaction fee, the apps that turn out to be mandatory, the hosting nobody mentioned, and what the platform charges to let a merchant leave with their own order history.

Catalogue & checkout · Products, variants, pricing rules and the path to payment — the part that either converts or does not.

Tax & German legal correctness · VAT determination, OSS, B2B reverse charge, and the checkout requirements German law actually imposes — judged on what the platform does, not on a plugin someone could buy.

Extensibility & developer surface · Themes, apps, APIs and headless — whether the shop can be shaped to the business, and at what cost in lock-in.

Order operations & back office · What happens after checkout: order management, stock, returns, shipping, and the link to ERP or accounting.

Data ownership & exit · Whether the catalogue, customers and order history remain the merchant's: export completeness, hosting choice, and what leaving actually costs.

European sovereignty · Where customer and order data live, who the contracting entity is, and which subprocessors sit in the checkout path. Independently sourced by the sovereignty pipeline.

Pricing transparency · Whether a merchant can compute the real annual cost — licence, transaction fees, apps, hosting — from public pages alone. The category where the headline price is least often the invoice.

Email Marketing & Newsletter rubric v1

Criterion The CRM Manager v1.0 The Deliverability Engineer v1.0 The Data Protection Officer v1.0 The Shop Owner v1.0 The Integrator v1.0 The Skeptic v1.0
Campaigns & automation 3.0 1.0 0.5 2.5 1.5 1.0
Deliverability infrastructure 2.0 3.0 1.0 2.0 1.5 1.5
Consent, proof & tracking limits 1.0 2.0 3.0 1.0 1.0 1.5
List ownership, import & exit 1.0 1.0 2.0 1.0 2.0 1.5
Integrations & API 2.0 1.0 0.5 3.0 3.0 1.0
European sovereignty 0.5 1.0 3.0 0.5 1.0 1.5
Pricing transparency 1.0 1.0 0.5 1.5 1.0 2.0
The judges and the criteria

The CRM Manager · Owns the lifecycle programme and measures it. Wants segmentation on real behaviour, journeys that branch, and testing that reports significance rather than a bigger number. Treats a tool that can only broadcast as a mailing list with invoicing.

The Deliverability Engineer · Cares about one number nobody publishes honestly: what reaches the inbox. Reads for authentication, IP and domain reputation, bounce discipline and sunsetting. Ignores every advertised delivery rate on principle — the infrastructure either is documented or it is not.

The Data Protection Officer · Signs off the tool that holds named people and records what each of them opened. Wants double opt-in with a proof that survives a complaint, tracking that can be switched off, and an answer to where the behavioural data lives that does not require a Schrems II argument.

The Shop Owner · Runs a shop where the newsletter is a revenue channel. Wants the shop connected properly — orders, carts, products flowing in, abandoned-cart and post-purchase flows out — and revenue attributed per campaign. Judges price against contribution, not against a competitor's tier.

The Integrator · Has to wire this into a stack that already exists. Wants a documented API with rate limits, webhooks that retry, a sandbox and a deprecation policy. Treats a partner-form integration page as a missing API, and reads "Zapier supported" as an outsourced one.

The Skeptic · Has seen every vendor claim 99% deliverability and GDPR compliance on the same page. Reads for the contact-tier staircase, the overage rate, the feature that begins two tiers up, and whether "EU hosting" covers the sending infrastructure or only the database.

Campaigns & automation · Building the mail and the journey around it: editor, templates, segmentation, triggered sequences, A/B testing.

Deliverability infrastructure · Whether the mail arrives — authentication, sending reputation, bounce and complaint handling — judged on what the vendor documents rather than the inbox rate it advertises.

Consent, proof & tracking limits · How subscribers arrive and what the sender can prove afterwards: double opt-in, logged consent, unsubscribe handling, and whether open and click tracking can be limited or switched off.

List ownership, import & exit · Whether the list and its history remain the sender's: import with attributes intact, full export including engagement history, deletion that executes, and no metering that prices leaving out of reach.

Integrations & API · The connection surface a newsletter lives on: shop and CRM systems, events in and out, webhooks, and an API somebody can build against without a partner agreement.

European sovereignty · Where subscriber data and behavioural tracking live, who the contracting entity is, and which subprocessors touch the send. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.

Pricing transparency · Whether a sender can compute the real invoice for their list size and send volume — including overage, extra domains and automation limits — from public pages alone.

Employee Scheduling rubric v1

Criterion The Shift Manager v1.0 The Operations Director v1.0 The Payroll Officer v1.0 The Works Council Advocate v1.0 The Frontline Employee v1.0 The Skeptic v1.0
Roster building & demand planning 3.0 3.0 1.0 1.0 1.0 1.5
Working-time law & collective agreements 2.0 2.0 2.5 2.5 1.5 2.5
Mobile self-service for deskless staff 2.5 1.5 0.5 1.5 3.0 1.0
Works council & employee data 1.0 1.0 1.0 3.0 2.0 1.5
Payroll handoff & integrations 1.0 2.0 3.0 0.5 0.5 1.5
European sovereignty 0.5 1.0 1.0 2.5 1.0 1.5
Pricing transparency 1.0 1.0 1.0 0.5 0.5 2.0
The judges and the criteria

The Shift Manager · Builds next week's roster for a restaurant or store on Thursday night and fields the sick calls on Saturday morning. Wants templates, qualifications that stop the wrong person landing on the till, open shifts staff can claim, and a rest period warning before publication rather than after the inspection.

The Operations Director · Answers for labour cost across thirty locations in retail, hospitality or care. Wants demand-based planning from real POS or occupancy data, labour cost against budget while the plan is still editable, and staff shared across sites. Reads "AI-powered scheduling" as a request to see the method.

The Payroll Officer · Turns the worked month into DATEV and answers for every surcharge. Cares about night, Sunday and holiday supplements from the Tarifvertrag, Minijob limits caught before the month closes, and corrections after the close. Treats "CSV export" as an admission that the handoff was never designed.

The Works Council Advocate · Co-determines how hours and overtime are distributed and how staff are monitored (BetrVG §87), and will not sign a works agreement for a system that watches more than it plans. Asks who sees absence reasons, what the app stores about location, what is logged and when it is deleted. Reads "performance insights" as a warning.

The Frontline Employee · Works part-time shifts next to a second job or a degree and never opens a laptop at work. Judges the product by its phone app: can she mark availability, swap a shift without three calls, see her hours, and read it in her own language. A roster she learns about from a photo in a group chat has failed.

The Skeptic · Has read a great many pages saying the product "supports" the Arbeitszeitgesetz and wants to know whether it blocks a violation, warns about it, or merely exports it. Reads for which tier the time clock and the DATEV export sit in, how seasonal staff are counted per employee, and what the forecasting "AI" actually uses as input.

Roster building & demand planning · How a plan gets built across locations, roles and qualifications — templates, staffing requirements, forecasting from sales or occupancy, and whether the product proposes a roster or only draws one.

Working-time law & collective agreements · Whether the roster knows the rules it is subject to — ArbZG rest periods and maximum hours, youth and maternity protection, Minijob earnings limits, Tarifvertrag and works-agreement rules, surcharges — and whether it enforces them, warns, or leaves them to the export.

Mobile self-service for deskless staff · What the employee on the shop floor actually gets: a mobile app to read the roster, enter availability, request and accept swaps, claim open shifts and clock in — in their language, on their own device or a shared one.

Works council & employee data · Whether the product can be introduced under co-determination (BetrVG § 87) — role-based visibility, what is logged, which monitoring can be switched off, retention of availability, absence and location data — and whether the vendor supplies what a works agreement needs.

Payroll handoff & integrations · How planned and worked hours, surcharges and absences reach payroll — DATEV, Lohn und Gehalt, the tax adviser — and how the roster connects to the POS, HR and time systems a shift business already runs.

European sovereignty · Where the employee data lives, who the contracting entity is, who the subprocessors are, and whether that is documented rather than assumed. Independently sourced by the sovereignty pipeline; weighted seriously here, because a scheduling tool holds availability, absence and often location data about employees who had no say in the vendor.

Pricing transparency · Whether a buyer can compute the real annual invoice for their headcount and locations — including the time clock, payroll export, forecasting and other modules sold as add-ons — from public pages alone.

HR Management rubric v1

Criterion The People Lead v1.0 The Payroll Officer v1.0 The Works Council Advocate v1.0 The Data Protection Officer v1.0 The IT Integrator v1.0 The Skeptic v1.0
Digital personnel file & data model 3.0 1.5 1.0 1.0 2.0 1.5
Payroll handoff 2.0 3.0 0.5 0.5 1.5 1.5
Absence & working-time 2.5 2.5 2.5 1.0 1.0 1.0
Recruiting & onboarding 1.5 0.5 1.0 1.5 2.0 1.0
Employee data protection & co-determination 1.0 1.0 3.0 3.0 1.5 1.5
European sovereignty 0.5 0.5 1.5 2.5 1.0 1.5
Pricing transparency 1.0 1.0 0.5 0.5 1.0 2.0
The judges and the criteria

The People Lead · Runs HR for 400 people with two colleagues and is replacing a shared drive and eleven spreadsheets. Optimizes for the record being true and the month closing without chasing anyone. Buys breadth that actually connects, and is unmoved by a beautiful org chart sitting next to a manual vacation calculation.

The Payroll Officer · Closes payroll every month and answers to the tax adviser when it is wrong. Cares about one thing above all: whether the month leaves this system clean, with backdated changes, mid-month leavers and variable pay handled. Treats "CSV export" as a confession, not a feature.

The Works Council Advocate · Sits on the Betriebsrat and has to approve this rollout under BetrVG §87. Reads every feature for whether it can monitor behaviour, and asks what is logged, who can read it and what can be switched off. A tool that cannot answer those questions does not get installed, however good it is.

The Data Protection Officer · Answers for the most sensitive personal data the company holds, about people who cannot decline the processing. Wants retention that executes rather than promises, a published subprocessor list, and applicant data that deletes itself on the stated date. Treats an unpublished DPA as a finding.

The IT Integrator · Owns identity and has to make the HR system the source of truth for accounts. Wants SCIM provisioning, SSO that is not an enterprise upsell, and an API with documentation rather than a partner form. Judges onboarding by whether it can create the account, not by whether it has a checklist.

The Skeptic · Has watched three HR suites promise one system and deliver five modules with a shared logo. Reads every claim for what it does not say: which module the feature lives in, what it costs on top, and whether "integration" means a maintained connector or a documented endpoint someone could build against.

Digital personnel file & data model · The system of record: employee master data, the digital personnel file, org structure, custom fields, and whether history is kept rather than overwritten.

Payroll handoff · Whether the month closes cleanly into payroll — DATEV, Lohn und Gehalt, an in-house system or an external tax adviser — and how much of that is automated rather than re-typed.

Absence & working-time · Vacation, sickness and working-time recording — including whether the product meets the German recording duty (BAG 2022, ArbZG) rather than merely offering a timer.

Recruiting & onboarding · The join path — vacancy to signed contract to a person who has an account, equipment and a plan on day one.

Employee data protection & co-determination · How the product handles the most sensitive personal data a company holds — retention, deletion, role separation, subject rights — and whether it can pass a works council (BetrVG §87) rather than merely a procurement checklist.

European sovereignty · Where the data lives, who the contracting entity is, who the subprocessors are, and whether the answer is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as the buyer would weigh it.

Pricing transparency · Whether an HR lead can compute the real annual invoice for their headcount — including the modules they actually need — from public pages alone.

Information Security rubric v1

Criterion The CISO v1.0 The GRC Consultant v1.0 The Drafted IT Officer v1.1 The Lead Auditor v1.0 The Evidence Integrator v1.0 The Skeptic v1.1
Asset & risk management depth 3.0 2.0 1.5 1.5 1.0 1.0
Controls, SoA & measures 2.0 2.5 1.5 2.0 0.5 1.0
Framework & standard coverage 1.5 2.0 0.5 1.5 0.5 1.5
Audit readiness & evidence 1.0 1.5 1.0 3.0 1.0 1.5
Integrations & automation 1.0 0.5 1.5 0.5 3.0 0.5
European sovereignty 1.0 0.5 1.0 0.5 1.0 1.5
Pricing transparency 0.5 1.0 1.0 0.5 0.5 1.0
The judges and the criteria

The CISO · Owns the ISO 27001 certificate and the NIS2 exposure of a 400-employee company. Optimizes for a real risk backbone: methodology, inheritance, incident clocks, a statement of applicability that is never stale. Rejects checklist theater and risk registers that cannot answer who accepted what.

The GRC Consultant · Builds and runs ISMSs for a dozen clients at once. Optimizes for reusable control catalogs, multi-framework mapping that answers a control once, and templates that make client twelve cheaper than client one. Rejects single-tenant tools and frameworks bolted on as checklists.

The Drafted IT Officer · SME IT admin who became the information security officer by an email from management. Optimizes for guided setup, sane defaults, plain-language controls and a tool that runs alongside the day job. Rejects platforms that assume a security team and a consultant on retainer.

The Lead Auditor · Certifies ISMSs for a living and has seen every folder of screenshots. Optimizes for revision-safe history, an SoA generated from live control status, and a defensible answer to "show me the state on date X". Rejects audit trails assembled the week before the audit.

The Evidence Integrator · Believes evidence that is typed is evidence that is stale. Optimizes for connectors to the live estate — directory, CMDB, ticketing, cloud — continuous control checks, and an API with parity to the UI. Rejects data islands with a CSV drawbridge.

The Skeptic · Hunts "100% audit success" claims, framework logos that link nowhere, "coming soon" integrations sold as shipped, consulting bundled as software, and customer counts that disagree between pages. Exists to keep the rest of the bench honest.

Asset & risk management depth · The ISMS core: asset inventory, risk methodology (identification, assessment, treatment), protection-needs inheritance, incident handling with statutory clocks.

Controls, SoA & measures · Control catalogs, statement of applicability, measure tracking and internal audit — whether the control side of the ISMS is operable or a checklist.

Framework & standard coverage · Which regimes the product actually operationalizes — ISO 27001, NIS2, TISAX/VDA ISA, DORA, BSI IT-Grundschutz, SOC 2 — and whether one control maps across them or each framework is a fresh island.

Audit readiness & evidence · Whether the system produces defensible proof: revision-safe history, evidence collection, reports for auditors, authorities and management.

Integrations & automation · Whether the platform feeds from the real IT estate — directory import, CMDB, ticketing, scanners, API — and automates evidence collection instead of re-typing it.

European sovereignty · Where the security posture of the whole company actually lives and under whose law — entity, hosting, subprocessors, DPA. The risk register is itself a target.

Pricing transparency · Whether a buyer can compute the real invoice — per module, per entity, per year, with consulting unbundled — from public pages alone. Unpublished pricing is the B2B norm in this market, so this criterion describes rather than condemns; the benches weight it accordingly.

Lead Generation rubric v1

Criterion The SDR Team Lead v1.0 The RevOps Manager v1.0 The Data Protection Officer v1.0 The ABM Marketer v1.0 The DACH Sales Director v1.0 The Skeptic v1.0
Coverage, accuracy & freshness 3.0 2.0 0.5 2.0 3.0 2.0
Data sources & lawful basis 1.0 1.5 3.0 1.0 2.0 2.0
Visitor identification & intent signals 1.5 1.0 2.0 3.0 1.5 1.0
Prospecting workflow & outreach rules 2.5 1.5 2.0 1.0 2.5 1.5
CRM sync, enrichment & export 2.0 3.0 1.0 2.0 1.0 1.0
European sovereignty 0.5 1.0 3.0 1.0 2.0 1.5
Pricing transparency 1.0 1.0 0.5 1.0 1.0 2.0
The judges and the criteria

The SDR Team Lead · Runs eight SDRs against a monthly meeting target. Wants filters that find the right buyer at the right company, emails that do not bounce, and direct dials that reach a person. Measures a database by connect rate, not by the record count on the homepage.

The RevOps Manager · Owns the CRM and cleans up after every tool sales buys. Wants sync with field mapping and deduplication, re-enrichment that updates rather than duplicates, objections that propagate into synced records, and exit terms that say what the company may keep.

The Data Protection Officer · Knows the company becomes controller the moment a list is exported. Wants the source and legal basis of every record stated, the Art. 14 notice actually sent, a removal route for the people in the database, and a visitor script that does not fire before consent.

The ABM Marketer · Works a list of three hundred target accounts and wants to know which of them are in market. Cares about company-level visitor identification, intent data with a named source, and alerts that reach the account owner while the signal is still warm.

The DACH Sales Director · Sells into German Mittelstand companies that are barely visible in US-built databases. Wants register-based company data, coverage stated for Germany, Austria and Switzerland rather than for "Europe", and a tool that knows a cold call under UWG §7 is not a growth hack.

The Skeptic · Has read "98% accuracy" and "GDPR-compliant data" on every homepage in the category. Reads instead for the refresh cadence, the credit-back rule for a bounced email, what a mobile number costs in credits, and the source the privacy notice admits to.

Coverage, accuracy & freshness · How much of the target market the database actually covers — judged on DACH and EU coverage as much as North American — and what the vendor documents about verification and refresh, because accuracy claims cannot be checked from outside.

Data sources & lawful basis · Where the personal data in the database comes from and on what legal basis it is processed — as evidenced on the vendor's own pages. Covers Art. 6(1)(f) legitimate interest, the Art. 14 notice to the people in the database, and whether they can find, object to and remove their record.

Visitor identification & intent signals · Identifying companies behind website visits and surfacing buying intent — scored on what is identified (company or person), how the tracking works, and whether the vendor states that its script needs consent under §25 TDDDG and how it behaves without it.

Prospecting workflow & outreach rules · Search, list building and outreach — and whether the product helps the buyer stay within UWG §7 and the GDPR once the list exists, rather than leaving the legal risk entirely with the customer.

CRM sync, enrichment & export · Getting the data into the systems where sales works — CRM sync, enrichment of existing records, API — and what happens to exported data, and to the buyer's access to it, when the subscription ends.

European sovereignty · Where a database of EU residents' personal data is held, who the contracting entity and controller are, and which subprocessors see it. Independently sourced by the sovereignty pipeline; weighted heavily here, because the product itself is personal data about people who never chose the vendor.

Pricing transparency · Whether a buyer can compute the real annual cost from public pages alone — including credits per email, phone number and mobile, credit expiry, seat pricing, visitor-identification tiers and the API — in a category where the unit of billing is often invented by the vendor.

Marketing Automation rubric v1

Criterion The Demand Gen Lead v1.0 The Sales Ops Manager v1.0 The Data Protection Officer v1.0 The Lifecycle Marketer v1.0 The Solution Architect v1.0 The Skeptic v1.0
Journeys & orchestration 3.0 1.0 0.5 3.0 2.0 1.5
Lead scoring, routing & lifecycle 2.5 3.0 1.5 1.0 1.5 1.5
Channels & personalisation 2.0 0.5 0.5 3.0 1.5 1.0
Consent, tracking & profiling 1.0 1.0 3.0 1.5 1.5 1.5
CRM integration & data model 2.0 3.0 1.0 1.5 3.0 1.5
European sovereignty 0.5 0.5 3.0 0.5 1.0 1.5
Pricing transparency 1.0 1.5 0.5 1.0 1.0 2.0
The judges and the criteria

The Demand Gen Lead · Owns pipeline contribution and is measured on it. Wants journeys that branch on real behaviour, scoring that sales trusts, and attribution that survives a quarterly review. Unmoved by a builder that demos beautifully and cannot say which journey sent yesterday's email.

The Sales Ops Manager · Owns the CRM and inherits every duplicate the platform creates. Wants field-level ownership defined, conflict rules that are configurable rather than folklore, and a sync error log somebody can act on before the pipeline report is wrong.

The Data Protection Officer · Sees a profiling system, not a mailing tool. Wants consent reproducible per person, tracking that can be switched off for someone who never agreed to it, deletion that removes derived scores as well as raw events, and scoring documented well enough to assess under Art. 22.

The Lifecycle Marketer · Thinks in cohorts and retention rather than in campaigns. Wants frequency capping across every journey, holdout groups so the effect is measurable, and personalisation drawn from the behavioural record rather than assembled by hand.

The Solution Architect · Has implemented three of these and knows where they fail: identity resolution, custom objects, and the API limit nobody mentioned. Wants a data model extensible without vendor services and a documented path from anonymous visitor to known contact.

The Skeptic · Reads for the contact-tier staircase, the tier where journeys actually begin, and the mandatory onboarding fee that never appears on the pricing page. Has watched "unlimited emails" mean unlimited within a sending limit described elsewhere.

Journeys & orchestration · Multi-step automation: triggers, branching, waits, and — the part that decides whether it survives contact with reality — what happens when journeys collide.

Lead scoring, routing & lifecycle · Scoring, qualification and handover to sales — including whether the customer can explain to a lead why the system decided what it decided.

Channels & personalisation · What the platform can actually send and personalise: email, SMS, push, on-site content, ads audiences — judged on what shares one profile and one suppression list.

Consent, tracking & profiling · The platform builds behavioural profiles of named people. Consent capture and proof, tracking that can be limited, retention, and whether automated decisions about individuals are documented and contestable.

CRM integration & data model · The join that decides the implementation: how the platform and the CRM stay in agreement about who a person is, and what happens when they disagree.

European sovereignty · Where behavioural profiles of named EU residents are processed, who the contracting entity is, and which subprocessors see them. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which given the profiling is heavily.

Pricing transparency · Whether a buyer can compute the real annual invoice for their contact base and send volume — including the tier where automation actually begins, overage, and mandatory onboarding — from public pages alone.

Payment rubric v1

Criterion The Finance Lead v1.0 The E-Commerce Lead v1.0 The SaaS Founder v1.0 The Payments Engineer v1.0 The Compliance Officer v1.0 The Skeptic v1.0
Payment methods & local coverage 1.0 3.0 1.5 1.5 0.5 1.0
Checkout, SCA & fraud 0.5 3.0 1.0 2.5 1.5 1.0
Subscriptions & recurring payments 1.0 1.0 3.0 2.0 0.5 1.0
Settlement, reconciliation & API 3.0 1.5 2.0 3.0 1.0 2.0
Licence, risk & account terms 2.5 1.0 2.0 1.0 3.0 3.0
European sovereignty 1.0 0.5 1.0 1.0 3.0 1.5
Pricing transparency 1.5 1.0 1.0 0.5 0.5 2.0
The judges and the criteria

The Finance Lead · Closes the month and owns the cash position. Wants payouts on a stated schedule, fees itemised per transaction rather than netted into a lump, reports that match the bank statement, and a rolling reserve written into the contract with a limit rather than discovered on a Tuesday.

The E-Commerce Lead · Sells to customers in eight EU countries and is measured on conversion. Wants the local methods each market actually uses named per country, a checkout that stays on her domain, and 3-D Secure that challenges only when it must. Reads "100+ payment methods" as a count, not a list.

The SaaS Founder · Runs a B2B subscription business where every failed renewal is churn nobody chose. Wants SEPA mandates as well as cards, dunning that recovers, proration that is correct, and the payment tokens exportable — because a provider that keeps the tokens keeps the customer base hostage.

The Payments Engineer · Integrates the provider and gets paged when webhooks stop arriving. Wants a versioned API with idempotency keys, a test mode that behaves like production, the PCI scope of each integration stated, and a status page that admits incidents rather than a green dot.

The Compliance Officer · Handles data protection and outsourcing risk, and wants the regulated entity named with its supervisor and register number, not "licensed in Europe". Asks where transaction and cardholder data are processed, who the subprocessors are, and where the provider acts as controller rather than processor.

The Skeptic · Knows the headline rate covers the cheapest card in the cheapest country. Reads for the currency conversion markup, the chargeback fee, the payout delay and the clause that lets the provider freeze funds without a reason — and treats a missing licence number as an answer.

Payment methods & local coverage · Which methods a European customer can actually pay with — cards and wallets, SEPA Direct Debit, and the local methods that decide conversion per country — judged on the named list per market rather than on a method count.

Checkout, SCA & fraud · The path from basket to authorised payment under PSD2: hosted and embedded checkout options, 3-D Secure and SCA exemption handling, fraud screening, and what the provider documents about keeping legitimate payments from failing.

Subscriptions & recurring payments · Charging the same customer again: card-on-file and merchant-initiated transactions, SEPA mandates, subscription logic and dunning — and whether the stored payment credentials can leave with the merchant.

Settlement, reconciliation & API · Getting the money and knowing what it was: payout cadence and currencies, fee itemisation per transaction, reports that match a bank statement, and an API and webhooks a team can build finance processes on.

Licence, risk & account terms · Who holds the merchant's money under which licence, and what the contract lets the provider do on a bad day: freezes, reserves, termination, chargebacks. Scored on what the terms and the imprint state, not on reputation.

European sovereignty · Who the contracting and regulated entity is, and where transaction and cardholder data are processed and stored. Independently sourced by the sovereignty pipeline. The card schemes are US-based for every provider, so the scheme layer is not held against any one vendor; the part the vendor controls is.

Pricing transparency · Whether a merchant can compute the effective fee for their own mix of cards, countries and methods — including cross-border and currency conversion markups, chargebacks, refunds, payouts and monthly fees — from public pages alone.

Project Management & Collaboration rubric v1

Criterion The Data Protection Officer v1.0 The Bootstrapper v1.2 The Enterprise Architect v1.0 The UX Purist v1.0 The Integrator v1.0 The Skeptic v1.2
Collaboration depth 0.5 1.5 1.0 1.5 1.0 1.0
Reporting 0.5 1.0 1.5 0.5 1.0 1.0
Integrations 1.0 1.0 2.0 0.5 3.0 1.0
Onboarding effort 0.5 2.0 0.5 3.0 0.5 1.0
European sovereignty 3.0 0.5 2.0 0.5 0.5 1.5
Support & documentation 1.5 0.5 1.5 1.0 1.0 1.0
Pricing transparency 0.5 1.0 1.0 0.5 0.5 1.0
The judges and the criteria

The Data Protection Officer · Reads the DPA before the feature list. Optimizes for GDPR posture: EU hosting, subprocessor exposure, deletion guarantees. Rejects anything that cannot answer where the data lives.

The Bootstrapper · Pays with their own card. Optimizes for price/value at 3 seats and at 30, a usable free tier, and a price page that answers instead of qualifying. Rejects hidden seat minimums and "contact sales".

The Enterprise Architect · Buys for two hundred seats and answers for it later. Optimizes for SSO/SCIM, permissions, audit trails, certifications and a clean exit. Rejects anything that cannot survive procurement.

The UX Purist · Measures time-to-first-value with a stopwatch. Optimizes for clarity, density and software that teaches itself. Rejects fourteen-step setups and empty screens that offer no way forward.

The Integrator · Lives in the API docs before the product tour. Optimizes for webhooks, import/export and a tool that plays well in a stack. Rejects closed ecosystems and CSV-only exits.

The Skeptic · Assumes the marketing is lying until the evidence says otherwise. Hunts lock-in, dark patterns, hidden cost and dead changelogs. Exists to keep the rest of the panel honest.

Collaboration depth · How much real multi-person project work the tool carries: shared planning, assignments, dependencies, workload, comments, guest access.

Reporting · Whether the tool can answer questions about the work: progress, time, budgets, utilization — and export the answer.

Integrations · How well the tool connects to the rest of the stack: native integrations, calendar/comms hooks, API and webhooks, import/export paths.

Onboarding effort · Time and friction from signup to first real value for a small team, without paid services.

European sovereignty · Where the company and the data actually sit: legal entity, ownership control, data residency, and subprocessor exposure to non-EU jurisdictions.

Support & documentation · Whether a stuck user gets unstuck: docs quality, support channels and their availability per plan, and the health of the learning surface.

Pricing transparency · Can a buyer determine the real, payable cost of the tool for their team before talking to anyone?

Property & WEG Management rubric v1

Criterion The WEG Administrator v1.0 The Advisory Board Member v1.0 The Accountant v1.0 The Portfolio Manager v1.0 The Data Protection Officer v1.0 The Skeptic v1.0
Wirtschaftsplan, Jahresabrechnung & Rücklage 3.0 2.5 3.0 2.0 1.0 2.0
Eigentümerversammlung & Beschluss-Sammlung 2.5 2.5 1.0 1.5 1.0 2.0
Owner & tenant self-service 1.5 3.0 1.0 2.0 2.0 1.0
Maintenance, defects & contractors 2.0 1.5 1.0 3.0 0.5 1.0
Documents, retention & handover 1.5 2.0 2.0 2.0 2.5 2.0
European sovereignty 0.5 1.0 1.0 0.5 3.0 1.5
Pricing transparency 1.0 1.0 1.0 1.5 0.5 2.0
The judges and the criteria

The WEG Administrator · Manages forty communities and personally carries the duties the WEG places on the Verwalter. Wants the statutory year — Wirtschaftsplan, Jahresabrechnung, Versammlung, Beschluss-Sammlung — discharged inside one system. Judges a product by the March settlement run, not the demo.

The Advisory Board Member · An owner, elected and unpaid, who checks the administrator's settlement before recommending it to the assembly — and is answerable to the neighbours if it is wrong. Wants to see the underlying records without asking, the resolution register current, and arithmetic that can be followed back to an invoice.

The Accountant · Prepares the settlement and answers for its form. Cares that the Abrechnungsspitze is shown separately, that the Rücklage is genuinely segregated trust money rather than a labelled balance, and that heating costs apportion per HeizkostenV without a spreadsheet.

The Portfolio Manager · Runs a firm managing several thousand units and lives on throughput. Wants statutory inspections scheduled with proof stored, defects that route to the right trade, multi-community reporting, and onboarding a new WEG that takes days rather than a quarter.

The Data Protection Officer · The system holds names, addresses, bank details and arrears for people who never chose the vendor. Wants owner and tenant visibility strictly separated, an access log over the archive, retention that executes, and an answer on where the AI invoice reader sends a document.

The Skeptic · Has read many pages claiming "WEG-konform" and wants the feature that makes it true — the post-2021 settlement form, the maintained Beschluss-Sammlung, the majority arithmetic. Also reads for the per-unit minimum, the setup fee, and what it costs a community to leave with its own records.

Wirtschaftsplan, Jahresabrechnung & Rücklage · The statutory financial cycle: business plan, annual settlement in the form the law and the BGH require, distribution keys, and the separate handling of reserve funds held in trust for the community.

Eigentümerversammlung & Beschluss-Sammlung · Convening, running and recording the owners' meeting — including the resolution register the law requires the administrator to maintain, and the majority arithmetic that decides whether a resolution stands.

Owner & tenant self-service · How an owner exercises their right to see the records, and how much routine correspondence the portal removes: statements, documents, meeting papers, defect reporting.

Maintenance, defects & contractors · The building side: defect intake and tracking, recurring maintenance obligations, contractor assignment, and the evidence trail when something goes wrong.

Documents, retention & handover · The archive and the exit. A Verwalter's appointment is finite by law, and the records belong to the community — so handover is a statutory event, not a support ticket.

European sovereignty · Where the community's financial and personal records live, who the contracting entity is, and which subprocessors touch them. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

Pricing transparency · Whether an administrator can compute the real annual cost for the units under management — including modules, per-community fees and setup — from public pages alone.

Recruiting rubric v1

Criterion The Talent Acquisition Lead v1.0 The Employer Branding Manager v1.0 The Data Protection Officer v1.0 The Works Council Advocate v1.0 The HR IT Integrator v1.0 The Skeptic v1.0
Applicant management & hiring workflow 3.0 1.5 1.0 1.5 1.5 2.0
Multiposting, career page & candidate experience 2.5 3.0 0.5 0.5 1.0 1.5
Retention, deletion & talent-pool consent 1.5 1.0 3.0 2.5 1.5 2.0
AI screening transparency & control 1.5 1.0 2.5 3.0 1.0 2.5
HR handover, integrations & API 1.5 1.0 1.0 0.5 3.0 1.5
European sovereignty 1.0 0.5 3.0 1.5 1.5 1.5
Pricing transparency 1.0 1.5 0.5 0.5 1.0 2.0
The judges and the criteria

The Talent Acquisition Lead · Fills sixty roles a year across three locations with a team of two. Wants pipelines hiring managers actually use, scorecards that make a decision defensible, and multiposting that reaches the German boards without a separate login. Unmoved by a match score she cannot explain to a candidate.

The Employer Branding Manager · Owns the career page and the job-ad budget. Wants a career site that works on a phone, applications without an account, and cost per applicant per channel rather than a logo wall of job boards. Reads a pricing page for what a posting on StepStone actually adds to the bill.

The Data Protection Officer · Answers for thousands of CVs from people who never chose the vendor. Wants deletion that runs on the stated date after rejection, talent-pool consent that expires, a subprocessor list that names the CV parser and the AI provider, and an access log over every applicant file.

The Works Council Advocate · Sits on the Betriebsrat, which co-determines selection guidelines and questionnaires. Asks what any ranking evaluates, whether it can be switched off, who sees which applicant, and whether an internal candidate's file leaks into their personnel record. No answer, no agreement.

The HR IT Integrator · Has to connect the ATS to the HR system, the calendar and identity. Wants a documented API, SSO that is not an enterprise upsell, and a hire that arrives in Personio or SAP with its documents rather than as a PDF someone retypes. Judges integrations by who maintains them.

The Skeptic · Has read "DSGVO-konform" and "AI-powered matching" on every page in this category. Reads instead for the deletion deadline that is actually configured, the AI feature that can actually be turned off, and what the invoice does when a job goes out to three paid boards.

Applicant management & hiring workflow · The daily work of hiring: pipeline stages per job, collaboration with hiring managers, structured evaluation, interview scheduling and candidate communication — judged on whether a decision is documented rather than merely made.

Multiposting, career page & candidate experience · Getting a vacancy in front of the right people and letting them apply: job-board distribution for the German market, the career page, and an application process that does not lose candidates on a phone.

Retention, deletion & talent-pool consent · What happens to the data of people who were not hired: automatic deletion on a configurable deadline, talent-pool consent that expires, data-subject requests, and access logging — the criterion the employer is actually liable for.

AI screening transparency & control · Whether any automated ranking, matching, parsing or rejection is disclosed, explained and switchable — recruitment is a high-risk use under the EU AI Act, and an undisclosed score next to a candidate's name is a co-determination matter. A product without AI features is judged on stating so.

HR handover, integrations & API · The hire does not end in the ATS: handover to the HR system and payroll, identity and calendar integration, e-signature for contracts, and an API a team can build on.

European sovereignty · Where applicant data lives, who the contracting entity is, who the subprocessors are — including the job boards, CV parsers and AI providers the system passes CVs to. Independently sourced by the sovereignty pipeline; weighted higher here than in categories holding the customer's own data, because every record belongs to a third party who never chose the vendor.

Pricing transparency · Whether a buyer can compute the real annual cost from public pages alone: the pricing model (per employee, per open job, per recruiter seat), job-board posting costs, add-ons for AI, career page or integrations, and the minimum term.

SEO rubric v1

Criterion The In-House SEO Lead v1.0 The Agency Owner v1.0 The Technical SEO v1.0 The Content Strategist v1.0 The Data Analyst v1.0 The Skeptic v1.0
Crawling & technical audit 2.5 2.0 3.0 1.0 1.5 1.5
Keyword research & content guidance 3.0 2.0 1.0 3.0 1.0 1.5
Rank tracking & index quality 2.5 2.0 1.5 2.0 2.5 2.5
Reporting, integrations & API 1.5 3.0 2.0 1.5 3.0 1.0
Data portability & exit 1.0 1.5 1.5 1.0 3.0 2.0
European sovereignty 0.5 0.5 0.5 0.5 1.0 1.0
Pricing transparency 1.0 2.0 1.0 1.5 1.0 2.0
The judges and the criteria

The In-House SEO Lead · Owns organic traffic for one large German site and reports on it monthly. Wants German-language keyword data that is not an afterthought, rankings she can defend when they disagree with Search Console, and audit findings specific enough to become a developer ticket.

The Agency Owner · Runs forty client sites and rebills the licence. Wants multi-client management, white-label reports a client can receive unedited, and per-seat costs that do not punish a growing team. Reads "contact us" on a pricing page as a margin problem.

The Technical SEO · Lives in crawl data and log files. Wants JavaScript rendering, crawl budget analysed, indexation diagnosed rather than listed, and regressions caught between crawls. Treats an issue list sorted by count rather than by traffic impact as busywork.

The Content Strategist · Decides what gets written and can only commission so much. Wants topic clusters, honest opportunity sizing, cannibalisation caught before it happens, and briefs scored against what actually ranks rather than against keyword density.

The Data Analyst · Wants the numbers in the warehouse, not in a PDF. Cares about a documented API with published credit costs, bulk historical export, and whether three years of ranking history leaves with the customer or dies with the subscription.

The Skeptic · Knows every vendor claims the largest index and the most accurate rankings, and that no buyer can check either. Reads instead for what can be held to: refresh frequency, stated limits, credit costs per endpoint, and what the invoice does when the team adds a seat.

Crawling & technical audit · Site crawling at real scale: what the crawler finds, how deeply it checks, whether Core Web Vitals and indexation problems are diagnosed rather than merely listed.

Keyword research & content guidance · Keyword discovery, intent classification, SERP feature analysis and on-page guidance — judged on the depth of the German-language data as much as the English.

Rank tracking & index quality · The proprietary data: ranking accuracy and frequency, backlink index size and freshness. Scored on what the vendor documents about their own data, because nothing here can be verified from outside.

Reporting, integrations & API · Getting the data out and in front of someone: dashboards, white-label reporting for agencies, Search Console and analytics integration, and an API a team can build on.

Data portability & exit · Whether the ranking and crawl history — the only thing a multi-year subscription actually accumulates — remains the customer's when they leave.

European sovereignty · Where the account and crawl data live and who the contracting entity is. Independently sourced by the sovereignty pipeline; weighted lower here than in categories holding personal data, because an SEO tool mostly holds the customer's own strategy rather than their customers' identities.

Pricing transparency · The category where the headline price is least often the invoice. Whether a buyer can compute the real annual cost including keyword limits, crawl credits, API units, extra users and client seats — from public pages alone.

Social Media Marketing rubric v1

Criterion The Community Manager v1.0 The Agency Lead v1.0 The Brand Governance Officer v1.0 The Analyst v1.0 The Data Protection Officer v1.0 The Skeptic v1.0
Publishing & calendar 2.5 2.5 1.0 1.0 0.5 1.5
Engagement & community inbox 3.0 1.5 1.0 1.0 1.5 1.0
Analytics & reporting 1.0 2.5 1.0 3.0 1.0 1.5
Approvals, roles & brand safety 1.5 3.0 3.0 1.0 2.0 1.5
Network coverage & API resilience 2.0 1.5 1.5 2.5 1.0 2.5
European sovereignty 0.5 0.5 2.5 1.0 3.0 1.5
Pricing transparency 1.0 2.0 0.5 1.5 0.5 2.0
The judges and the criteria

The Community Manager · Answers the comments, including the angry ones, and lives in the inbox. Wants every mention and message in one queue with ownership and history, saved replies that save real time, and a failed 3am post that tells her rather than silently not existing.

The Agency Lead · Runs twelve client brands from one tool and must keep them strictly apart. Wants client workspaces, approval chains that include the client, white-label reporting, and per-account pricing that does not make a small client unprofitable.

The Brand Governance Officer · Answers to the board for what appears on the corporate account. Wants enforced approval before anything publishes, an audit trail of who wrote and released it, granular permissions, and no shared credentials anywhere in the design.

The Analyst · Has to compare metrics the networks define differently and report a number the board believes. Wants history retained past the platforms' own windows, normalisation documented rather than hidden, and UTM attribution that reaches web analytics.

The Data Protection Officer · Notes that every comment and message arriving from a network is personal data the company now processes. Wants a DPA that addresses that squarely, retention on the conversation archive, and an answer on where the sentiment analysis sends the text.

The Skeptic · Counts the network logos, then asks which are official API integrations and what each one cannot do. Has watched a platform change break a feature overnight, and wants to know what the vendor did last time and whether the archive survived it.

Publishing & calendar · Scheduling across networks: per-network formatting, the calendar as a working surface, bulk operations, and what happens when a post fails at 3am.

Engagement & community inbox · Comments, mentions and messages in one queue — the half of the job that is customer service wearing a marketing badge.

Analytics & reporting · Measurement across networks with different metrics and retention windows, plus the reporting an agency hands a client.

Approvals, roles & brand safety · How a team of several people and an agency publish to a brand account without an accident — and who can be shown to have approved what.

Network coverage & API resilience · Which networks are supported through official APIs, how quickly the vendor follows platform changes, and what the customer keeps when a network breaks or leaves.

European sovereignty · Where the archive and the community conversations are processed, who the contracting entity is, which subprocessors touch them. Independently sourced by the sovereignty pipeline. Note that the networks themselves are non-EU by definition — this criterion judges the tool, not the platforms it talks to.

Pricing transparency · Whether a team can compute the real annual invoice for their account and user count — including the tier where approvals and the inbox begin — from public pages alone.

Time Tracking & Attendance rubric v1

Criterion The Operations Lead v1.0 The Payroll Officer v1.0 The Works Council Advocate v1.0 The Agency Owner v1.0 The Field Supervisor v1.0 The Skeptic v1.0
Capture in the real workplace 3.0 1.5 1.5 1.5 3.0 1.5
Working-time law & audit record 2.0 2.0 3.0 1.0 1.5 2.0
Absence & shift planning 2.5 1.5 1.5 1.0 2.0 1.0
Project, cost-centre & billing 1.0 0.5 0.5 3.0 1.5 1.0
Payroll handoff 1.5 3.0 1.0 1.0 1.0 1.5
European sovereignty 0.5 0.5 2.0 0.5 0.5 1.5
Pricing transparency 1.0 1.0 0.5 1.5 1.0 2.0
The judges and the criteria

The Operations Lead · Runs a 200-person operation with office, workshop and field staff, and has to record all of them since the BAG ruling. Wants capture that fits each of those groups and a roster that reflects reality. Unmoved by a beautiful desktop timer that half the workforce cannot use.

The Payroll Officer · Turns the recorded month into an payroll run and answers for it. Cares about surcharges for night, Sunday and holiday work, time accounts that reconcile, and corrections that arrive after the close. Treats "export to CSV" as an admission that the handoff was never designed.

The Works Council Advocate · Has co-determination over how working time is recorded (BetrVG §87 (1) 6) and will not approve a system that watches more than it measures. Asks what GPS actually stores, who can read an individual's day, what is logged and what can be switched off. Reads "productivity insights" as a warning.

The Agency Owner · Bills forty people's hours to clients and lives on the gap between recorded and billable. Wants project structure, rate cards that survive a mid-project change, budget warnings before the overrun, and an export the invoicing system takes. Attendance compliance is the floor, not the product.

The Field Supervisor · Supervises crews on sites with no reliable signal and no desks. Judges everything by whether it works in a basement at 6am: offline capture, a shared terminal, corrections a foreman can make without a support ticket. A cloud-only app is a tool that will be filled in from memory on Friday.

The Skeptic · Has read a great many pages claiming to be "BAG-konform" and wants to know which feature makes that true. Reads compliance claims for what they do not say: which module, at which tier, and whether the terminal in the photograph costs extra.

Capture in the real workplace · How time actually gets recorded across the workforces a buyer has — desk staff, field and site crews, shift and deskless workers — and what happens when the network is not there.

Working-time law & audit record · Whether the record satisfies the German recording duty (BAG 2022, § 3 ArbSchG) and the ArbZG rules around it — breaks, maximum hours, rest periods, retention — and whether it survives being inspected.

Absence & shift planning · Vacation, sickness and the shift or duty roster — the half of attendance that decides whether the time data means anything.

Project, cost-centre & billing · Whether recorded time can carry the allocation an agency, workshop or professional-services firm needs — project, task, cost centre, billable status — through to an invoice or a client report.

Payroll handoff · How the recorded month reaches payroll — DATEV, Lohn und Gehalt, an in-house system or the tax adviser — and how much of it is automated rather than retyped.

European sovereignty · Where the data lives, who the contracting entity is, who the subprocessors are, and whether that is documented rather than assumed. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

Pricing transparency · Whether a buyer can compute the real annual invoice for their headcount — including terminals, modules and minimums — from public pages alone.

Video Conferencing rubric v1

Criterion The IT Administrator v1.0 The Security Officer v1.0 The Works Council Advocate v1.0 The Educator v1.0 The Accessibility Advocate v1.0 The Skeptic v1.0
The meeting itself 3.0 1.0 1.0 2.5 1.5 1.5
Encryption & meeting access 1.5 3.0 1.5 1.0 0.5 2.0
Reach & accessibility 2.0 0.5 1.0 3.0 3.0 1.0
Recordings, retention & admin control 1.0 2.0 3.0 1.5 1.0 1.5
Integrations & deployment 2.5 1.0 0.5 1.0 0.5 1.0
European sovereignty 1.0 3.0 2.5 1.5 1.0 1.5
Pricing transparency 1.0 0.5 0.5 1.5 1.0 2.0
The judges and the criteria

The IT Administrator · Gets the call when the board meeting will not start. Wants capacity published rather than promised, room systems that work, SSO, and diagnostics after a bad call. Judges a product by its worst meeting, not its demo.

The Security Officer · Wants to know what the vendor can see, and reads "encrypted" as a question rather than an answer. Asks which meetings get end-to-end encryption, what stops working when they do, who holds the keys, and who can walk into a meeting with a link.

The Works Council Advocate · A recorded meeting is personal data about everyone in it. Wants to know who may record, who is told, how long it is kept, and whether attention tracking or attendance analytics can be switched off outright. Reads engagement scoring as surveillance with a chart.

The Educator · Teaches thirty people who join from whatever they have, half of them on a phone in a dead spot. Cares that the browser works without an install, that guests need no account, that breakout rooms are usable, and that nobody is excluded by bandwidth or by a missing caption.

The Accessibility Advocate · Judges the product by whether a deaf colleague and a screen-reader user can run the meeting, not merely attend it. Wants live captions, keyboard operation, a published conformance report, and dial-in for people with no usable connection. Treats an accessibility page with no report as a marketing page.

The Skeptic · Has read many pages claiming end-to-end encryption and wants the sentence that says which meetings, on which plan, with what turned off. Also reads for the participant cap, the dial-in minutes, and where recording storage stops being free.

The meeting itself · Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.

Encryption & meeting access · What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".

Reach & accessibility · Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.

Recordings, retention & admin control · A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.

Integrations & deployment · Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.

European sovereignty · Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.

Pricing transparency · Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.

Whistleblowing Portals rubric v1

Criterion The Compliance Officer v1.0 The Reporter's Advocate v1.0 The SME Operator v1.2 The Group Counsel v1.0 The Security Auditor v1.0 The Skeptic v1.2
Reporting channels & reporter experience 1.0 3.0 1.5 1.0 1.0 1.0
Case management & deadline discipline 3.0 1.0 1.0 1.5 1.0 1.0
Legal compliance alignment 2.5 1.0 2.0 2.0 0.5 1.0
Security & anonymity assurance 1.0 2.5 0.5 1.0 3.0 1.5
Group & multi-entity capability 0.5 0.5 0.5 3.0 0.5 0.5
European sovereignty 1.0 1.0 1.0 1.0 2.5 1.5
Pricing transparency 0.5 0.5 1.0 0.5 0.5 1.0
The judges and the criteria

The Compliance Officer · Runs the internal reporting office of a 600-employee company and answers for every missed statutory clock. Optimizes for case discipline: automated acknowledgment and feedback deadlines, role separation, documentation that survives a regulator. Rejects inbox-with-a-form products that make the deadlines her problem.

The Reporter's Advocate · Judges from the frightened side of the form. Optimizes for anonymity that survives contact, a two-way dialog without an account, languages the workforce actually speaks, and channels that work on a night-shift phone. Rejects login walls, app installs and anything that makes reporting feel like a deposition.

The SME Operator · Runs a 60-employee company that the law obligated, not convinced. Optimizes for compliance set up in an afternoon at a price the year-end review will not question, with the legal duties handled by the product. Rejects per-report fees, setup charges and anything that needs a compliance department to operate.

The Group Counsel · Rolls one system out to 25 subsidiaries in a dozen countries. Optimizes for per-entity channels with real access separation, per-country legal rule sets, external ombudsman roles and group reporting that respects entity boundaries. Rejects one-channel products multiplied by twenty-five contracts.

The Security Auditor · Pentests the anonymity promise for a living. Optimizes for evidenced security: current certificates with visible scope, published pentests, documented end-to-end encryption, metadata minimization, and hosting outside hostile jurisdictional reach. Rejects adjective security and "military-grade" anything.

The Skeptic · Assumes "audit-proof" and "100% anonymous" are marketing until the evidence says otherwise. Hunts certification claims without certificates, anonymity claims next to analytics scripts, per-report pricing traps and legal-update promises with no named lawyer. Exists to keep the rest of the bench honest.

Reporting channels & reporter experience · The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.

Case management & deadline discipline · The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.

Legal compliance alignment · How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.

Security & anonymity assurance · Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.

Group & multi-entity capability · Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.

European sovereignty · Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.

Pricing transparency · Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.

How lists are ordered

  • Category pages are alphabetical by default. They are an index, not a ranking: no product is first because of its vendor or anything paid. You can choose to sort a category by panel rating or by sovereignty, or to filter it by provenance; that choice is yours and follows the rules on this page — products without a rating, or with sovereignty not fully proven, sort last.
  • Search results are ordered by relevance to what you typed.
  • Autosuggest puts name matches first: a product whose name is exactly what you typed, then names that start with it, then names that contain it, then other matches. Within each of those groups, the higher panel rating comes first.
  • Comparisons are curated pairs, chosen by us, and a comparison refuses to render when the two were judged under unequal conditions — a different rubric or a different bench.

Published pages are re-checked. A page whose price evidence is older than 30 days is re-captured weekly; a page that cannot be refreshed stays up and shows the date its evidence was captured. A daily check applies the same freshness rules to every published product.

Conflicts of interest

whats-best.ai is operated by nelo digitalagentur GmbH & Co. KG. Companies connected to the operator develop software for data protection, whistleblowing, information security and property management, and those products are listed here like every other product in their category.

They get no special treatment, and we say so where it matters rather than only here: the same rubric, the same bench of judges, the same publish gate and the same evidence rules apply to them, nobody at those companies can see or influence the panel’s work before it is published, and no score, rank or placement is for sale. Their product pages, the four category pages concerned and every comparison one of them appears in carry this note.

If you think one of those pages reads too kindly, report it like any other error — it is read against the same sources, by the same check, as a report about anyone else’s product.

What money can and cannot do

There is nothing to buy. No paid tier, no booking, no invoice: vendors cannot pay for a score, a rank, a placement or a listing, and nothing on this site is an advertisement. The order form and the paid options this page once described were removed rather than switched off.

What a vendor can do, free: claim the listing, correct any fact, publish a reply, add screenshots and evidence links, fill in what our checks left out, and ask once a month for their pages to be read again. Everything a vendor supplies is labelled vendor-supplied, rendered outside the panel’s text and structurally excluded from the scoring.

A re-reading is the only thing a vendor can set in motion, and it buys a reading, not an outcome: the panel scores what it finds, and the score can go down.

Corrections and suspensions

Anyone can report an error, without an account. Every element of a product page — a fact, a score, a criterion, a verdict, a sovereignty dimension, a vendor reply — carries a “Report an error” link. Say what is wrong and, if you can, what the right value is and where it is published.

A report changes nothing by itself. Filing one does not take anything off this site: the reported fact, score or passage stands as it is while the report is read. That is deliberate — a form anyone can fill in must not be a way to edit the site — and it is why there are no limits on how many reports a product or a sender may file.

A model reads it, and the reading is the decision. A model checks your report against the source we cited and, where you named one, against that page too. What it finds decides the report, by rules we publish rather than by anyone’s mood on the day:

  • a source bears you out — the claim is replaced by what the source states, or removed where we have nothing to put in its place;
  • nothing we can read settles it — a disputed fact still comes off the page, because a claim we can no longer confirm is not one we print;
  • the source contradicts you — the page stays as it is;
  • a report about a score, a criterion or a verdict is different: it moves the panel only when a source bears it out, because a disagreement about judgement is not an error of fact.

The decision is usually made within minutes and always within 5 business days. If you left an address you get it in writing, with the reasons, the fact that it was automated, and how to object. The operator can overrule any of it, and may suspend a reported element while a report is open; they are not asked to approve one.

What an accepted correction does. A wrong fact is replaced by a new one, cited to the source that supports it, and the product is re-queued for scoring. Where the report concerns an opinion — a score, a rationale, a verdict — we add a dated editorial note to the page and, where warranted, have the panel re-evaluate. Opinions are never edited by hand.

AI disclosure

Every score, rationale and verdict on this site is generated by AI models, and every fact is read from its source by AI models. The label appears on every page, at the top, as Art. 50 of the AI Act asks.

Humans do not write the verdicts, and no person approves a fact before it is shown: a fact appears only when it is proven as described above. The weekly sample is read by a third model rather than by a person. Since 20 September 2026 the same is true of the decisions around the edges — a correction, a notice of unlawful content, a vendor’s listing, claim or reply are all decided automatically, by models reading them against these published rules. Every such decision says so in writing and can be objected to, and the operator can overrule any of them.

Versions

Judges and rubric are versioned, and the versions in force are printed on every product page under “Method and versions”. A changed anchor is a new rubric version; scores from different versions are never compared.