Whistleblowing Portals
ComplianceLine
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by ComplianceLine, Inc. · www.complianceline.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
ComplianceLine's public pages are strongest at intake: scores on reporting channels cluster at 6-7, crediting 24/7/365 phone, web and mobile intake, password-protected two-way follow-up that keeps reporters anonymous, and hotline metrics of under 1% call abandonment and 91% caller satisfaction. Case management scores of 4-5 rest on an immutable audit trail of all case activities and decisions, historical case import with trails preserved, and benchmarking against 1,500+ peer programs; we found no public information on statutory deadline clocks, role separation, or retention and deletion rules. Security assurance sits at a flat 4 on a SOC 2 Type II attestation of unstated scope, with no public information on penetration testing or encryption architecture. The weak areas are compliance alignment, multi-entity scale and sovereignty: visible legal signals are HIPAA, a GDPR badge and OIG/SAM screening, and we found no public information on EU Directive 2019/1937 or national transpositions, on per-entity channels for groups, or on hosting location, subprocessors or a data processing agreement. Scores span at most a point; no prices appear — only a proposal within 48 hours.
Speaks for it
- 24/7/365 intake across phone, web and mobile, with reports delivered to your queue in under 2 hours
- Password-protected two-way follow-up that keeps reporters anonymous is presented as a core feature
- Immutable audit trail of all case activities and decisions, preserved on import of historical cases
- Hotline operation shows under 1% call abandonment and 91% caller satisfaction
- SOC 2 Type II attestation provides audited third-party security assurance
Held against it
- No public information on EU Directive 2019/1937 or national transpositions such as the German HinSchG
- No public information on statutory deadline clocks, role separation, or retention and deletion rules
- SOC 2 Type II scope is unstated, with no public information on penetration testing or encryption architecture
- No public information on hosting location, subprocessors, or a published data processing agreement
- No public information on separate channels or separated case access per legal entity for corporate groups
Best for
- You need around-the-clock phone, web and mobile intake with anonymous two-way follow-up for a single organization
- You want a casework record built on an immutable audit trail, including historical cases imported with trails preserved
- You value fast setup, with the pages citing a 2-hour learning curve for investigators and 4 hours for administrators, and drag-and-drop configuration
Avoid if
- You are obligated under EU Directive 2019/1937 or a national transposition and need documented acknowledgment, feedback and retention features
- You run a corporate group needing separate channels and separated case access per legal entity
- You must verify hosting location, subprocessors and a data processing agreement before signing; we found no public information on any of these
- You need statutory deadline automation such as seven-day acknowledgment and three-month feedback clocks built into the product
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
Twenty-four-seven intake across phone, web, and mobile, with one-click reporting and a password-protected follow-up that keeps reporters anonymous — the two-way anonymous dialog is presented as a first-class feature rather than an add-on. I found no public information on language coverage, translation support, accessibility, or QR-style entry points, so I cannot credit the breadth an eight deserves. 1
The Reporter's Advocate
Phone, web and mobile intake run 24/7/365, and the live-operation numbers — under 1% call abandonment, 91% caller satisfaction — tell me a night-shift caller actually reaches a human. The two-way follow-up is password-protected rather than tied to an account, so anonymity can survive the conversation. But we found no public information on language coverage or accessibility, and a workforce that does not speak the default tongue is exactly who these channels must also serve. 1
The SME Operator
Around-the-clock intake across phone, web and mobile, with anonymous two-way follow-up through a password-protected route, is more than a form in disguise and the call-handling figures suggest a live hotline rather than an add-on. But I found no public information on languages, translation support or accessibility, which an obligated European company cannot simply skip. 1
The Group Counsel
Twenty-four-seven phone, web and mobile intake with a password-protected follow-up that keeps reporters anonymous gives me the channel mix and two-way dialog I need, and the hotline metrics — under one percent call abandonment, 91 percent caller satisfaction — suggest a live intake operation rather than a bolt-on form. I found no public information on language coverage, accessibility, or how the reporter's identity is kept out of the channel itself, which keeps this below the top band. 1
The Security Auditor
Phone, web, and mobile intake runs 24/7/365 with a real hotline behind it — under 1% call abandonment, 91% caller satisfaction — and anonymous two-way follow-up via password-protected dialog is core rather than bolted on. But we found no public information on language coverage, accessibility, or how reporter IP and device metadata are kept out of the channel, so anonymity surviving first contact rests on assertion alone. 1
The Skeptic
Intake runs on web, phone, and mobile around the clock with password-protected two-way follow-up that keeps reporters anonymous, and the hotline operation shows real metrics like 91 percent caller satisfaction. But we found no public information on language coverage, accessibility, or how the reporter's identity is kept out of the channel itself, which keeps this short of the top band. 1
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The immutable audit trail of all case activities and decisions, historical case import with trails preserved, and program benchmarking give documentation substance a regulator would recognize. But I found no public information on automated statutory clocks — the seven-day acknowledgment and three-month feedback — nor on role separation or conflict-of-interest exclusion of implicated handlers, and those decide whether the missed-deadline liability sits with the system or with me. 1
The Reporter's Advocate
An immutable audit trail of all case activities and decisions, preserved even when historical cases are imported, is a casework record that can be defended. We found no public information on statutory deadline clocks, role separation or conflict-of-interest handling, and no public information on retention and deletion rules — the 23.7-day average closure is a speed figure, not deadline discipline. 1
The SME Operator
An immutable audit trail of all case activities, preserved even on import of historical cases, plus benchmarking analytics, is a real case system — but I found no public information on statutory deadline tracking, role separation or per-case retention rules, the three things that decide whether my acknowledgment and feedback clocks are met. A queue and metrics are not yet a legally disciplined case file. 1
The Group Counsel
An immutable audit trail of all case activities and decisions, historical imports with trails preserved, and benchmarking against 1,500-plus peer programs are genuine case-worker substance. But I found no public information on statutory deadline clocks such as the seven-day acknowledgment and three-month feedback, role separation or conflict-of-interest handling, or retention and deletion rules — the deadline discipline I must have across a dozen jurisdictions. 1
The Security Auditor
An immutable audit trail of all case activities and decisions, historical import that preserves full trails, and analytics benchmarked against 1,500+ peer programs are the strongest evidence here. We found no public information on statutory deadline clocks, role separation between case handlers, conflict-of-interest exclusion, or per-case retention and deletion, so the deadline side of the discipline is invisible. 1
The Skeptic
The immutable audit trail of all case activities and decisions, preserved on historical case import, plus benchmarking analytics against 1,500+ peer programs, are genuinely evidenced strengths. We found no public information on statutory deadline automation, the acknowledgment and feedback clocks, role separation, conflict-of-interest exclusion of implicated handlers, or retention and deletion rules; the 23.7-day closure figure is operational speed, not legal deadline discipline. 1
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
Nothing in the captured pages references EU Directive 2019/1937 or any national transposition: no acknowledgment or feedback clocks, no retention or deletion rules, no legal templates or counsel. The compliance signals are SOC 2, HIPAA, and a GDPR badge — US ethics-and-compliance positioning, not an implementation of the statutory duties a 600-employee obligated company answers for. 1
The Reporter's Advocate
The captured pages carry SOC 2, HIPAA and GDPR badges, but we found no public information on EU Directive 2019/1937, on any national transposition, or on acknowledgment and feedback deadlines implemented as product features. For a portal in this category that is the homework I expect to see in public, and these pages do not show it. 1
The SME Operator
GDPR appears only as a compliance badge alongside HIPAA and US exclusion-list screening, which reads as an American ethics program, and I found no public information on EU Directive 2019/1937 or the German transposition — no acknowledgment clock, no feedback deadline, no retention duty implemented as a feature. For a company obligated by the law rather than persuaded by it, that silence is the whole story. 1
The Group Counsel
The captured pages claim GDPR compliance and lean heavily American — HIPAA, continuous OIG and SAM exclusion-list screening — while I found no public information on the EU Whistleblower Directive or any national transposition such as the German HinSchG. For a group operating in twelve countries this reads as general compliance software under a whistleblowing label, with the legal mapping left entirely to me. 1
The Security Auditor
The captured legal posture is three badges — SOC 2 Type II, HIPAA, GDPR — and the word 'directives' appears only in pricing copy about fees. We found no public information mapping any feature to EU Directive 2019/1937 or a national transposition: no acknowledgment or feedback clocks, no documentation duties, no retention periods. 1
The Skeptic
Every legal reference on the captured page is US-flavored: HIPAA and GDPR badges, and screening against OIG and SAM exclusion lists. We found no public information on EU Directive 2019/1937, national transpositions such as the German HinSchG, acknowledgment or feedback deadlines, or retention periods — a GDPR badge is a compliance claim, not an implemented legal rule set. 1
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
A SOC 2 Type II attestation is a real, audited assurance, and the anonymous mechanics are described (password-protected follow-up keeping reporters anonymous). I found no public information on the encryption architecture, penetration testing, IP or metadata logging, or a security contact and disclosure policy, so the promise that a reporter cannot be unmasked against the operator is asserted rather than evidenced. 1
The Reporter's Advocate
A SOC 2 Type II attestation is audited evidence, more than a paragraph of adjectives, and the follow-up dialog is described as keeping reporters anonymous. We found no public information on encryption architecture, on IP or metadata logging, on penetration testing or on a security contact — so I cannot verify how the anonymity promise is engineered, and the question of how a reporter could ever be unmasked goes unanswered on these pages. 1
The SME Operator
SOC 2 Type II is an audited attestation and worth more than a paragraph of adjectives. Beyond that badge I found no public information on penetration tests, encryption of report content, IP or metadata handling, or how the confidentiality promise is engineered. 1
The Group Counsel
SOC 2 Type II is an audited control attestation, which lifts the security story above adjectives. I found no public information on penetration testing, the encryption architecture for report content, or how metadata and IP logging are handled — the first questions my works councils will put to me. 1
The Security Auditor
SOC 2 Type II is the one piece of third-party-assured security, but the badge as captured carries no visible scope. We found no public information on ISO 27001, penetration tests, an encryption architecture for report content, or IP and metadata logging; password-protected follow-up is asserted while documented end-to-end encryption is not, and nothing analyses whether the operator itself could unmask a reporter. 1
The Skeptic
SOC 2 Type II asserted in a single badge line is more than adjectives, but we found no public information on the attestation's scope, penetration tests, encryption architecture, or IP and metadata logging. 'GDPR Compliant' sitting next to an unscoped attestation line is precisely the claim a skeptic wants the certificate for. 1
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
The positioning — one configurable system for the entire ethics and compliance program — is program-wide, not entity-aware. I found no public information on separate channels per legal entity, separated case handler access per entity, delegated administration, ombudsman or external counsel roles, or a consolidated group view; only configurability via drag-and-drop is shown. 1
The Reporter's Advocate
The pitch is one configurable system for an entire ethics and compliance program, backed by 1,500+ clients and HRIS and identity-provider integrations. We found no public information on separate channels per legal entity, on separated case access per subsidiary, or on group-level oversight and external ombudsman roles. 1
The SME Operator
The pitch is one configurable system for the entire ethics and compliance program, which suits my single company fine, but I found no public information on separate channels per legal entity, per-entity case separation, delegated administration or ombudsman access. Nothing here shows a group structure, only configurable forms. 1
The Group Counsel
The positioning — one configurable system for an entire ethics and compliance program — is precisely the single-channel promise I refuse to multiply across twenty-five contracts. I found no public information on per-entity channels, separated case access per subsidiary, delegated administration, external ombudsman roles, or group-level reporting that respects entity boundaries. 1
The Security Auditor
One configurable system for the entire ethics and compliance program is the framing, with third-party exit and stay interviews offered as services. We found no public information on per-entity channels, separated case access per legal entity, group-level oversight, delegated administration, ombudsman access, or white-labeling, so nothing shows a corporate group can operate under one contract. 1
The Skeptic
We found no public information on per-entity channels, separated case access per legal entity, group-level oversight, ombudsman access, or white-labeling — nothing on the captured page evidences that one contract could serve a corporate group. Single sign-on and HRIS integration are visible, but those serve one organization, not many. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
Every sovereignty attribute on the vendor's own pages is unstated: no legal entity jurisdiction, no hosting location, no published DPA, no subprocessor list, while the product language speaks HIPAA and US exclusion-list screening. For the most sensitive data a company holds, that silence is itself the finding, and it forecloses any score above the floor. 1
The Reporter's Advocate
We found no public information on the vendor's jurisdiction, ownership, hosting location or subprocessors, and no public information on a data processing agreement or an EU hosting region. A GDPR badge does not tell me where reports about people actually live, and for the most sensitive data a company holds, that silence decides this. 1
The SME Operator
I found no public information on the vendor's jurisdiction, ownership, hosting location, subprocessors or a published data processing agreement — the only signal is a GDPR compliance badge. Whistleblowing reports are the most sensitive data I hold, and the captured pages never show where they live or under whose law. 1
The Group Counsel
GDPR compliance is claimed, but I found no public information on where report content is hosted, the vendor's jurisdiction and ownership, subprocessor exposure, or a published data processing agreement. For the most sensitive data a company holds, I cannot sign off on a chain of custody the captured pages never document. 1
The Security Auditor
We found no public information on the vendor's jurisdiction, ownership, hosting location, data centers, subprocessors, or a data processing agreement — for the most sensitive data a company holds. The visible posture is SOC 2 and HIPAA, and nothing in the captured pages places report content or metadata under European jurisdictional protection. 1
The Skeptic
We found no public information on where the vendor is incorporated, where report data is hosted, which subprocessors touch it, or any published data processing agreement — silence on all four, for the most sensitive data a company holds. A GDPR badge with no published DPA or subprocessor list behind it is marketing, not jurisdiction. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
No public numbers exist; the closest is a promise of transparent pricing within 48 hours, which is a fast sales conversation, not a price page. The statements that one price covers software, configuration, training, and support — with configuration changes included rather than invoiced as professional services — tell me what would be invoiced, but not for how much, so the real invoice cannot be computed from public pages. 1
The Reporter's Advocate
There is not a single public price on these pages: pricing arrives as a proposal within 48 hours, which is a sales conversation with a stopwatch. The promise of one price covering software, configuration, training and support with configuration changes included is welcome, but an obligated company cannot compute a real invoice from it. 1
The SME Operator
The shape is exactly what my year-end review wants — one price covering software, configuration, training and support, configuration changes not invoiced as professional services, no surprise fees for reports — but I found no public prices; every figure arrives as a proposal within 48 hours. An obligated company cannot compute its invoice from the public pages alone, so this is a sales conversation with good manners. 1
The Group Counsel
There are pricing promises — one price covering software, configuration, training and support, no surprise fees, a proposal within 48 hours — but not a single public number, tier, employee band or per-entity rule. An obligated company cannot compute any invoice from these pages; every price is a sales conversation. 1
The Security Auditor
The captured pricing facts are structural only: one price covering software, configuration, training, and support; configuration changes 'not invoiced as professional services'; and a proposal 'within 48 hours'. No tier, band, or currency figure appears publicly, so an obligated company cannot compute an invoice without a sales conversation. 1
The Skeptic
'Transparent pricing within 48 hours' is a proposal timeline, not a price — an obligated company can compute nothing from the public pages. The 'one price covering software, configuration, training, and support' framing tells you the billing structure, but we found no public numbers on any tier, employee band, or setup charge. 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity, Data residency. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 2 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (2)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page www.complianceline.com Checked 29 Sep 2026 Details →
- 2 Privacy policy — found from the homepage www.ethico.com Checked 30 Sep 2026 Details →