Whistleblowing Portals
Case IQ Whistleblower Hotline
Rest of world Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Case IQ (formerly i-Sight) · www.caseiq.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Case IQ's Whistleblower Hotline, from Customer Expressions Corp. doing business as Case IQ in Ottawa, scores highest on reporting channels, which cluster at 7-8: a 24/7 live toll-free hotline alongside web, mail and email, 100+ languages, anonymous-by-default reporting, and two-way messaging that lets investigators follow up without revealing the reporter. Case management sits at 6 — a timestamped audit trail, auto-routing by type, region, severity and workload, hotline agents locked out after submission — though judges found no public information on statutory deadline clocks. Compliance alignment clusters at 2: the captured pages name FCPA, UK Bribery Act, Sapin II, HIPAA, PIPEDA, GLB and GDPR, and we found no public information on EU Directive 2019/1937 or any national transposition. Sovereignty scores sit at 0-1: we found no public information on EU hosting, a published data processing agreement, or a subprocessor list for report content. The widest spread, multi-entity scale at 3-5, reflects deployments across 4,100+ clinics and 90+ countries set against judges finding no public information on per-entity channels. Persona-weighted verdicts run from 3.5 to 4.6; no prices are published, as is normal in this market.
Speaks for it
- Multi-channel intake via phone, web, mail and email, with a 24/7 live toll-free hotline in 100+ languages
- Anonymous reporting is enabled by default, with two-way messaging that lets investigators follow up without revealing the reporter's identity
- Hotline agents are denied all other permissions and cannot see cases after they submit them
- A timestamped audit trail records every action, with auto-routing by type, region, severity and workload
- Annual independent audits attest SOC 2 Type II and ISO/IEC 27001:2022
Held against it
- We found no public information tying the product to EU Directive 2019/1937 or any national transposition such as the German HinSchG
- The vendor is Canadian — Customer Expressions Corp. doing business as Case IQ in Ottawa, with the pages also carrying Case IQ, Inc. — and we found no public information on EU hosting, data residency, a published data processing agreement, or a subprocessor list covering report content
- The privacy policy discloses hashed email identifiers shared with NextRoll for cross-device ad targeting
- We found no public information on statutory acknowledgment or feedback deadline clocks, on excluding implicated case handlers, or on per-case retention and deletion
- We found no public information on per-entity intake channels, delegated administration, or external ombudsman roles for corporate groups
Best for
- You need multi-channel anonymous intake — a 24/7 live toll-free hotline plus web, mail and email — across 100+ languages
- You must keep intake staff fenced off, since hotline agents cannot see cases after submitting them
- You answer to regulators or an audit committee and need a timestamped audit trail with one-click reporting
Avoid if
- You are an EU-obligated company whose counsel needs EU Directive 2019/1937 or a national transposition evidenced in the product — compliance alignment scores cluster at 2
- Your procurement requires a published data processing agreement, documented data residency, or a subprocessor list covering report content — sovereignty scores sit at 0-1
- You expect hotline reporters to receive updates on hotline-submitted cases under a one-way portal — the vendor documents that they cannot
- Your corporate group needs per-entity channels or delegated administration evidenced before signing — multi-entity scale scores spread from 3 to 5
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
Intake is genuinely multi-channel — phone, web, mail and email, with a 24/7 live-answer toll-free hotline in 100+ languages, anonymous reporting switched on by default, and two-way messaging that lets investigators ask follow-ups without unmasking the reporter. We found no public information on accessibility, and beyond a 'three levels of anonymity' claim the vendor does not publicly document how the reporter's identity is kept out of the channel itself, which keeps this off the top band. 1 2 5 6 7
The Reporter's Advocate
The frightened reporter is genuinely served: a toll-free line with live operators 24/7/365, anonymous reporting switched on by default, three levels of anonymity, follow-up questions that never reveal who reported, and more than a hundred languages with translatable pre-recorded greetings. The follow-up story is thinner than the intake story — on hotline cases a reporter only hears back if the operator activates a two-way portal and sets up a login account for them, and with a one-way portal they cannot receive updates at all; we also found no public information on accessibility or QR-style entry points. 1 2 5 6
The SME Operator
Phone with live operators around the clock plus web, mail and email, in 100+ languages with translatable hotline scripts and pre-recorded greetings, anonymous by default, and two-way messaging where investigators never see the reporter's identity — that is proper intake. Follow-up on hotline cases means a reporter account set up by the agent, and we found no public information on accessibility or on how the reporter's identity is kept out of the phone channel itself. 1 2 5 6
The Group Counsel
Intake is genuinely multi-channel — a 24/7/365 live-answer toll-free hotline alongside web, mail and email, in 100+ languages — with anonymous reporting enabled by default and two-way messaging that lets investigators follow up without revealing the reporter's identity. Three levels of anonymity and translatable pre-recorded hotline greetings show the reporter's experience was designed rather than bolted on. We found no public information on accessibility standards or on how the reporter's identity is kept out of the channel's own metadata. 1 2 5 6
The Security Auditor
Intake is genuinely multi-channel — a live-answered hotline around the clock plus web, mail and email — with 100+ languages and per-language translation of hotline scripts, anonymous reporting switched on by default, three anonymity levels, and a two-way anonymous dialog. The hotline agent role is fenced: intake staff cannot see cases after submitting them. We found no public information on accessibility (WCAG) or on how the reporter's identity is kept out of the channel metadata itself. 1 2 5 6
The Skeptic
Live 24/7 toll-free operators in 100+ languages with translatable scripts and pre-recorded greetings, anonymous-by-default intake, and a two-way portal with reporter accounts for follow-up without exposing identity — the anonymous dialog is engineered, not bolted on. The "three levels of anonymity" phrase appears with no definition of the three levels, and we found no public information on accessibility standards, QR entry points, or what the reporter's device gives away to the channel. 1 2 5 6
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The audit story is strong — timestamped history of every action, jurisdiction-scoped access roles, hotline agents locked out the moment they submit, auto-routing with escalation, and one-click regulator reporting — but the statutory clocks I answer for are nowhere evidenced. I found no public information on automated acknowledgment or feedback deadlines, exclusion of implicated case handlers, or retention and deletion rules applied per case, so for a 600-employee obligated company the deadline discipline would be my problem again. 4 6 7 8 9 10
The Reporter's Advocate
The handler's side is mature: auto-routing by type, region, severity and workload with escalation, a timestamped audit trail of every action, locked concurrent editing, system fields that cannot be altered, and hotline agents shut out of everything after they submit. We found no public information on automated statutory clocks such as acknowledgment and feedback deadlines, on excluding implicated handlers from a case, or on per-case retention and deletion rules. 4 6 7 8 9
The SME Operator
Every action, assignment and decision lands in a timestamped audit trail, roles are granular enough that hotline agents cannot see cases after submitting, and one-click reporting for leadership and regulators exists — strong worker-side machinery. We found no public information on statutory deadline tracking (the seven-day acknowledgment and three-month feedback clocks), on excluding implicated case handlers, or on per-case retention and deletion rules, so the legal clocks would land back on my desk. 4 6 7 8 9
The Group Counsel
The case side is credible: a timestamped audit trail over every action, assignment, document and decision; auto-assignment by type, region, severity and workload; edit locking; hardened separation where hotline agents cannot see cases after submission and access roles restrict personal information by jurisdiction; and one-click reporting for audit committees and regulators. What I did not find is statutory deadline discipline — no public information on automated acknowledgment or feedback clocks, on excluding implicated case handlers, or on per-case retention and deletion — with retention stated only as a general privacy-policy formula. 3 6 7 8 9 10
The Security Auditor
Routing by type, region, severity and workload, a timestamped audit trail of every action, a fixed and permission-restricted intake role, case locking and one-click regulator reporting give the casework side real bones. But we found no public information on statutory deadline clocks — the 7-day acknowledgment and 3-month feedback timers — on excluding implicated handlers from a case, or on per-case retention automation; the retention language we found stays at privacy-policy level. 4 6 7 8 9
The Skeptic
Auto-routing by type, region, severity and workload, a timestamped full audit trail with automatic recording of every action and escalation, edit locking, permission-gated case edits, jurisdiction-restricted access roles, and one-click reports for regulators — real case mechanics. But we found no public information on statutory acknowledgment or feedback deadline clocks, exclusion of implicated case handlers, or per-case retention and deletion automation; the captured compliance vocabulary is fraud analytics, not whistleblowing statutes. 7 8 9 10
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
The captured pages show GDPR processes and EEA complaint rights, but we found no public information on EU Directive 2019/1937 or any national transposition — no acknowledgment or feedback clocks as product features, no legal templates, no documented review. The laws they do name (HIPAA, PIPEDA, FCPA, UK Bribery Act, Sapin II) belong to their anti-bribery monitoring story, not whistleblower protection law, which leaves this close to a general case tool under a hotline label. 1 3 4 10
The Reporter's Advocate
The captured pages speak GDPR fluently — processes for deleting, amending and transferring personal data, an EEA complaint right, SOC 2 — but we found no public information on EU Directive 2019/1937 or any national transposition such as the German HinSchG: no acknowledgment or feedback clocks, no legal templates, no named counsel. What legal texture exists names FCPA, the UK Bribery Act and Sapin II as fraud-risk categories for transaction analytics, not whistleblowing law implemented as product features. 1 3 9 10
The SME Operator
The legal material on show points at other regimes — HIPAA, PIPEDA, GLB and GDPR as deletion and amendment processes, plus FCPA, UK Bribery Act and Sapin II on the fraud-monitoring side. We found no public information tying the product to EU Directive 2019/1937 or any national transposition: no acknowledgment or feedback clocks, no whistleblowing retention periods, no legal templates — for an obligated company the directive duties remain the customer's problem. 3 4 10
The Group Counsel
The pages speak FCPA, UK Bribery Act and Sapin II as risk categories and assert GDPR processes for deleting, amending and transferring personal data, but we found no public information tying the product to EU Directive 2019/1937 or any national transposition — no statutory clocks, no legal templates, no named counsel, no per-country rule sets. For a group buying one system for a dozen countries, the legal instrument I need is simply not in evidence. 4 9 10
The Security Auditor
Every legal reference we found is generic or North American: FCPA, UK Bribery Act and Sapin II appear as fraud-risk categories, and GDPR shows up as data-handling processes rather than whistleblower-procedure features. We found no public information on EU Directive 2019/1937 or any national transposition — no statutory clocks, no documentation duties mapped to product behaviour — so what is evidenced is general compliance tooling, not an implementation of the whistleblower-law obligations. 3 4 10
The Skeptic
The captured pages frame compliance as FCPA, UK Bribery Act, Sapin II, HIPAA, PIPEDA and GDPR; we found no public information on EU Directive 2019/1937 or any national transposition such as the German HinSchG — no deadline rules, no documentation duties, no named counsel, no legal update commitments. For an EU-obligated buyer this is a North American anti-corruption story with a hotline attached. 4 9 10
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
Annual SOC 2 Type II and ISO/IEC 27001:2022 audits are attested by named independent firms, which is more than a paragraph of adjectives, and case data masking is described. But we found no public information on encryption of report content, penetration tests, IP or metadata logging, or how the anonymity levels are engineered — and the privacy policy discloses sharing hashed identifiers with an advertising platform on their sites, which does not reassure me about metadata discipline around the hotline. 1 3 10
The Reporter's Advocate
SOC 2 Type II accreditation and ISO/IEC 27001:2022 certification with annual independent audits are attested, which is more than adjectives. But we found no public information on encryption of report content, published penetration tests, or IP and metadata logging — and the privacy policy discloses Google Analytics plus NextRoll hashed-email sharing for cross-device ad targeting, an uncomfortable neighbor for a promise of reporter anonymity. 1 2 3 10
The SME Operator
SOC 2 Type II and ISO/IEC 27001:2022 with annual independent audits is more certificate than much of this market shows, and a dedicated Privacy Officer is a nice touch. We found no public information on penetration tests, end-to-end encryption of report content, IP or metadata logging, or a security contact — and the privacy policy names advertising trackers, including NextRoll receiving hashed email identifiers. 3 10
The Group Counsel
Annual independent audits, SOC 2 Type II accreditation and ISO/IEC 27001:2022 certification are attested on the security page — more than adjectives. But we found no public information on end-to-end encryption of report content, penetration testing, IP logging or metadata handling, and the privacy policy discloses hashed-email identifiers shared with NextRoll for cross-device advertising, which cuts against metadata minimization for a whistleblowing channel. 1 3 10
The Security Auditor
Annual independent audits attesting SOC 2 Type II and ISO/IEC 27001:2022 are real evidence, not adjectives, and the anonymity structure — three levels, isolated intake role, follow-ups without revealing the reporter — is described in some operational detail. But the evidence stops there: we found no public information on end-to-end encryption of report content, penetration test results, IP or metadata logging, or a security disclosure policy, and the only third parties documented on the captured web estate are Google Analytics and NextRoll receiving hashed identifiers for ad targeting — a poor look for a metadata-minimization promise. 1 2 3 10
The Skeptic
Annual independent audits holding SOC 2 Type II and ISO/IEC 27001:2022 are named and specific — more than adjectives, and above an unaudited TLS paragraph. But we found no public information on penetration test reports, encryption architecture for report content, IP or metadata logging, or a security contact and disclosure policy — and the privacy policy discloses hashed emails shared with NextRoll for cross-device ad targeting, which a frightened reporter may not expect to find behind an anonymity promise. 1 3 10
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
Access roles that restrict personal information to appropriate jurisdictions, region-based routing, and deployments at 4,100+ clinics and 90+ countries show this can carry a global footprint with a consolidated dashboard view. We found no public information on per-entity channels, delegated administration, per-entity branding, or external ombudsman and counsel access roles, so I can see group scale but not the entity-boundary architecture a works council would ask about. 4 7 9 10
The Reporter's Advocate
What the pages show is regional plumbing — access roles that keep personal information inside its jurisdiction, auto-assignment by region — plus a Fresenius deployment spanning 4,100+ clinics, though that scale sits in fraud monitoring. We found no public information on separate channels per legal entity, per-entity branding, delegated administration, ombudsman access, or a group-level view that respects entity boundaries. 4 7 10
The SME Operator
Access roles that restrict personal information by jurisdiction and auto-routing by type, region and severity are real separation, and deployments across 4,100+ clinics and 90+ countries show it holds at group scale. We found no public information on per-entity channels, group-level reporting that respects entity boundaries, delegated administration or external ombudsman access — and for my single 60-person company, a group structure I cannot see documented is architecture I cannot lean on. 4 7 9 10
The Group Counsel
Real access separation exists — access roles restrict personal information to appropriate jurisdictions, hotline agents are denied everything after submission, cases route by region — and group-level one-click reporting for leadership and audit committees is evidenced, with deployments spanning 90+ countries and 4,100+ clinics. We found no public information on per-entity intake channels with per-entity branding, delegated administration, or external ombudsman roles, so the group architecture I require is only partially evidenced. 4 6 7 9 10
The Security Auditor
Group-scale operation is evidenced in practice: monitoring across 4,100+ clinics for one client, a rollout covering 90+ countries, access roles that gate personal information by jurisdiction, and case routing by region — so separation and consolidated oversight exist in the field. We found no public information on per-legal-entity channels under one contract, delegated administration per subsidiary, or white-label reporting pages per entity, which is what a corporate group would need to see before signing. 4 7 9 10
The Skeptic
We found no public information on per-entity channels, consolidated group oversight, delegated administration, white-labeling per entity, or ombudsman and external counsel roles. What is captured is jurisdiction-restricted access roles, routing by region and location, and very large single-client deployments across thousands of clinics — scale and geography, but no evidenced multi-tenant group structure. 4 7 9 10
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The vendor is a Canadian entity — Customer Expressions Corp. doing business as Case IQ, registered in Ottawa — and we found no public information on data residency, an EU hosting option, a published DPA, or a subprocessor list covering report data; the only subprocessors the pages name are site analytics and advertising platforms. For the most sensitive data a company holds, non-European by default with nothing documented to offset it puts this at the bottom of the scale. 3 9 10
The Reporter's Advocate
As captured this is a Canadian vendor end to end — Customer Expressions Corp. doing business as Case IQ in Ottawa — and we found no public information on where report data is hosted, on a published data-processing agreement, or on a subprocessor list; the only named processors are American advertising trackers. For the most sensitive data a European employer holds, the pages leave the jurisdictional question unanswered. 3 9 10
The SME Operator
The vendor is a Canadian company — Customer Expressions Corp. doing business as Case IQ, with the Ottawa address in the privacy policy — and we found no public information on where report data is hosted, an EU region, a published data processing agreement or a subprocessor list covering report content. The only named third parties are advertising tools including Google Analytics and NextRoll with hashed email identifiers; for the most sensitive data a company holds, that is not a chain I can defend to a regulator. 3 9 10
The Group Counsel
This is a Canadian vendor — the privacy policy names Customer Expressions Corp. doing business as Case IQ with a Data Privacy Officer at 300 March Road, Ottawa (the captured pages also carry Case IQ, Inc.), and we found no public information on EU hosting, data residency options, a published data processing agreement, or a subprocessor list for the service itself. The only subprocessors disclosed are Google Analytics and NextRoll for advertising purposes; for the most sensitive data a European group holds, that is decisive against it. 3
The Security Auditor
For the most sensitive data a company holds, the picture is a Canadian vendor — Customer Expressions Corp. doing business as Case IQ, with an Ottawa address — and we found no public information on where reports are hosted, on a data processing agreement, or on subprocessors for report content; the only named third parties in the privacy policy are US advertising trackers. GDPR processes and an EEA complaint right are stated, but nothing evidences EU hosting or a published subprocessor list, which is what this category actually demands. 3 10
The Skeptic
The vendor is a Canadian entity — Customer Expressions Corp. doing business as Case IQ, Ottawa address — and we found no public information on EU hosting, data residency, a public DPA, or a product subprocessor list; the only subprocessors named in the captures are Google Analytics and NextRoll. For the most sensitive data a company holds, this sits at the bottom of the scale. 3 9 10
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
We found no public prices at all — every tier is a sales conversation — so I cannot compute a year's invoice for a 600-employee company from the vendor's own pages. The only cost-related fact published is that hotline agents and external reporter accounts do not count towards user account limits, which shapes the math but produces no figure. 6
The Reporter's Advocate
We found no public prices in the captured pages — no tiers, no figures, only sales-contact channels, plus the note that hotline agents and external reporter accounts do not count towards user account limits. An obligated company cannot compute even a rough invoice from what is published; every tier is a sales conversation. 6 10
The SME Operator
We found no public information on prices anywhere in the captured pages — no tiers, no employee bands, no billing period, nothing to compute a real invoice from — and even activating the intake portal runs through a change request to Customer Support and questions to a Customer Success Manager. Every tier is a sales conversation, which my year-end review will not tolerate. 5 6
The Group Counsel
We found no public information on prices — no tiers, employee bands, setup fees or per-entity figures — and the only evidenced route is contacting sales or the customer success manager, even for portal enablement. An obligated company cannot compute any part of the invoice from these pages. 6 10
The Security Auditor
We found no public prices on any captured page — no tiers, employee bands, setup fees or billing terms — and hotline and portal activation runs through a Customer Success Manager or a change request to support. An obligated company cannot compute its invoice from public pages; the price is a conversation with sales. 1 5 6
The Skeptic
We found no public information on pricing — no tiers, no numbers, no employee bands, no setup fees; the only pricing-adjacent statement captured is that hotline agents and external accounts do not count towards user account limits, and the general contact is a sales address. No obligated company can compute an invoice from these pages. 6 10
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity, Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 29 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 support fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
Sources (10)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.caseiq.com Checked 15 Sep 2026 Details →
- 2 Whistleblower hotline product page www.caseiq.com Checked 15 Sep 2026 Details →
- 3 Privacy policy www.caseiq.com Checked 15 Sep 2026 Details →
- 4 Security / trust page www.caseiq.com Checked 30 Sep 2026 Details →
- 5 Reporting channels & reporter experience — found from sitemap help.caseiq.com Checked 1 Oct 2026 Details →
- 6 Reporting channels & reporter experience — found from sitemap help.caseiq.com Checked 1 Oct 2026 Details →
- 7 Case management & deadline discipline — found from sitemap www.caseiq.com Checked 1 Oct 2026 Details →
- 8 Case management & deadline discipline — found from sitemap help.caseiq.com Checked 1 Oct 2026 Details →
- 9 Legal compliance alignment — found from sitemap www.caseiq.com Checked 1 Oct 2026 Details →
- 10 Security & anonymity assurance — found from sitemap www.caseiq.com Checked 1 Oct 2026 Details →