whats-best.ai

Whistleblowing Portals

Falcony Whistleblowing Channel

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Falcony Oy · falcony.io

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Falcony Oy, part of the Wekomply group, offers whistleblowing as one of five named solutions on a multi-purpose platform whose features include Audit, Observe, Scheduling, Registries, BI dashboards and AI, with APIs for users, places, cost centers and webhooks and a claimed 300,000+ users worldwide. The bench's strongest scores land on sovereignty, multi-entity scale and case management, all running 1-2: rationales credit the vendor's European company form, the automation APIs and module names like Audit and BI dashboards, while finding no public information on hosting location, a data-processing agreement, subprocessors, per-entity channels or statutory deadline handling — and no sovereignty attributes are on record. Security assurance is the weakest criterion, topping out at 1: no public information on certifications, penetration tests, encryption of report content, or reporter IP and metadata logging. Reporting channels run 0-2 with no public description of how a reporter submits, stays anonymous or follows up. The bench recorded no significant disagreements; visible spread reflects how far signals such as the Ilmoituskanava acquisition earn credit versus documented evidence. Only the free trial is public.

Report an error

Speaks for it

  • Sovereignty scores run 1-2, credited to the vendor's European company form (Falcony Oy, part of the Wekomply group).
  • Multi-entity scale scores run 1-2, credited to the users, places and cost-center APIs and a claimed 300,000+ users worldwide.
  • A publicly noted acquisition of the existing whistleblowing channel Ilmoituskanava is described as strengthening the offering.
  • Case management scores run 1-2, with module names like Audit, Scheduling and BI dashboards and a Users API gesturing at workflow tooling.
  • A free trial is offered publicly.

Report an error

Held against it

  • We found no public information on any intake route, anonymous submission, two-way dialog, language coverage or phone reporting.
  • We found no public information on certifications, penetration tests, encryption of report content, or reporter IP and metadata handling.
  • We found no public information mapping the product to EU Directive 2019/1937 or any national transposition, or on acknowledgment and feedback deadlines.
  • We found no public information on hosting location, a data-processing agreement or subprocessors, and no sovereignty attributes are on record.
  • We found no public information on separate channels per legal entity, per-entity case separation, ombudsman access or group-level reporting.

Report an error

Best for

  • You want whistleblowing inside a broader multi-purpose platform you administer alongside observations, audits and risks.
  • You administer a large distributed organization and value the users, places and cost-center APIs for automating administration.
  • You are a European buyer for whom a Finnish company inside a European group is a starting point, and you will verify hosting and subprocessors during procurement.
  • You want to test the channel yourself through the free trial before any sales conversation.

Report an error

Avoid if

  • You must show an auditor documented security assurance — certificates, penetration tests, encryption of report content — before launch.
  • Your reporters' anonymity is the core requirement and employees must know in advance how to submit and stay anonymous.
  • You must demonstrate compliance with EU Directive 2019/1937 or a national transposition, including acknowledgment and feedback clocks, without building the mapping yourself.
  • You are a corporate group needing separate channels per legal entity, per-entity case separation and ombudsman access under one contract.

Report an error

The scores

Reporting channels & reporter experience

Show reasoning
How this is scored

The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.

0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.

3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.

5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.

8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.

10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.

Report an error

The Compliance Officer

The captured pages list whistleblowing among the platform's solutions and offer a free trial, but we found no public information on an anonymous reporting route, a secured two-way dialog with reporters, phone intake, or language coverage. I answer for every frightened reporter who abandons an intake, and I cannot assess — let alone trust — a channel the vendor does not describe. 1

Report an error

The Reporter's Advocate

The captured page names Whistleblowing among five solutions and stops there: I found no public information on any intake route, no anonymous form, no follow-up dialog, no phone or voice option, no languages and no accessibility. A night-shift worker on a phone has nothing here to trust and nothing to evaluate. 1

Report an error

The SME Operator

The captured page names whistleblowing as one of several solutions but shows nothing about how a reporter actually submits; we found no public information on anonymous submission, a follow-up dialog, language coverage or phone intake. For me that is the entire purchase question — if I cannot see that a frightened employee can stay anonymous and still be reached for questions, the channel fails its purpose. 1

Report an error

The Group Counsel

Whistleblowing is named as one solution among ideas, tenant portal and chemicals on a multi-purpose platform, but we found no public information on how a reporter actually submits — nothing on anonymous dialog, follow-up contact with the reporter, languages, or phone intake. I cannot even establish from public pages what one subsidiary's employee would encounter on first contact. 1

Report an error

The Security Auditor

Whistleblowing appears as one item in a solutions list alongside ideas, chemicals and tenant portals, and we found no public information on how a report is actually submitted, whether an anonymous two-way dialog exists, what languages are covered, or how a reporter's identity is kept out of the channel at first contact. Without any of that I cannot verify the anonymity promise even survives intake. 1

Report an error

The Skeptic

Whistleblowing is one of five named solutions on the platform and a free trial exists, but the captured page stops there: we found no public information on intake channels, anonymous two-way dialogue, language coverage, or accessibility. A reporter's actual path into the system is invisible from public evidence, and anonymity surviving first contact is a claim nobody has documented. 1

Report an error

Case management & deadline discipline

Show reasoning
How this is scored

The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.

0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.

3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.

5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.

8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.

10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.

Report an error

The Compliance Officer

Module names like Audit, Scheduling and BI dashboards, plus a Users API for user-right automation, gesture at workflow tooling, but we found no public information on statutory acknowledgment or feedback clocks, conflict-of-interest exclusion, or a tamper-evident case history. Undocumented deadlines become my missed clocks, so I score by what I can verify and on case discipline I can verify almost nothing here. 1

Report an error

The Reporter's Advocate

The platform lists Observe, Audit and BI dashboards, with APIs to generate observations and automate user rights — more than a shared inbox, but the captured pages say nothing about how cases are handled. I found no public information on statutory clocks, role separation, conflict-of-interest handling or tamper-evident history. 1

Report an error

The SME Operator

We found no public information on statutory deadline tracking, the acknowledgment and feedback clocks, role separation between case handlers, or tamper-evident case history — the page's feature names 'Audit' and 'BI dashboards' carry no detail on what a case worker actually does. That means I would be running the legal deadlines myself in a spreadsheet, which is exactly what I refuse to do. 1

Report an error

The Group Counsel

The platform advertises generic modules — audit, scheduling, BI dashboards — but we found no public information on statutory deadline clocks, acknowledgment and feedback duties, role separation between case handlers, or a tamper-evident case history. A users API that automates user right management hints that permissions exist, yet nothing is said about excluding implicated handlers or documenting who did what. 1

Report an error

The Security Auditor

The captured page lists platform-level features — audit, dashboards, scheduling — and an API to automate user and user-right management, which hints at structured administration, but we found no public information on statutory acknowledgment and feedback clocks, case notes, attachments, role separation for case handlers, or a tamper-evident case history. That earns a point for the faint signals and nothing more. 1

Report an error

The Skeptic

The named platform features — audit, scheduling, BI dashboards — plus a users API to automate user right management gesture at roles and reporting, but we found no public information on statutory deadline handling, conflict-of-interest exclusion, tamper-evident case history, or retention and deletion rules. Feature names on a menu are not a case system an investigator could rely on. 1

Report an error

Legal compliance alignment

Show reasoning
How this is scored

How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.

0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.

3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.

5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.

8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.

10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.

Report an error

The Compliance Officer

The vendor reports acquiring Ilmoituskanava to strengthen its whistleblowing offering, which signals genuine intent, but we found no public information mapping product features to EU Directive 2019/1937 or any national transposition — no acknowledgment clock, no feedback deadline, no retention handling. Until the homework is public, the statutory mapping is my problem rather than the product's. 1

Report an error

The Reporter's Advocate

Whistleblowing appears as one tile in a broad HSEQ/GRC catalogue and the captured pages make no reference to EU Directive 2019/1937 or any national transposition. This is the generic-feedback-software-wearing-a-whistleblowing-label case: no legal obligation is named, let alone mapped to a feature. 1

Report an error

The SME Operator

Whistleblowing sits as one label among Ideas, Chemicals, a Tenant portal and Risks, and we found no public information tying the product to EU Directive 2019/1937 or any national transposition such as the German HinSchG. No per-country rule sets, no legal templates, no named counsel — for my purposes this reads as generic feedback software wearing a whistleblowing label. 1

Report an error

The Group Counsel

We found no public information referencing EU Directive 2019/1937 or any national transposition such as the German HinSchG; whistleblowing simply sits in a solutions list next to ideas and tenant portal. The acquisition of an existing whistleblowing channel, Ilmoituskanava, is noted, but we found no public information on per-country rule sets, legal templates or documented counsel review. 1

Report an error

The Security Auditor

Whistleblowing appears as a solution label, and we found no public information referencing EU Directive 2019/1937, any national transposition, statutory deadline rules, documentation or retention duties, or named legal review. As far as the captured pages show, this is a general observation platform with a whistleblowing name attached. 1

Report an error

The Skeptic

Whistleblowing sits on the solutions menu next to ideas, chemicals and tenant portal in a general HSEQ/GRC platform, and we found no public information tying the product to the EU whistleblowing directive or any national transposition. With not one legal duty named in public — no acknowledgment clock, no feedback deadline, no retention period — the label rides on a general observation tool. 1

Report an error

Security & anonymity assurance

Show reasoning
How this is scored

Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.

0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.

3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.

5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.

8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.

10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".

Report an error

The Compliance Officer

We found no public information on certifications, penetration tests, encryption of report content, or IP and metadata handling; a status page and help center are operational hygiene, not assurance. For the most sensitive data a company holds, I cannot score that silence as anything but the bottom of the scale. 1

Report an error

The Reporter's Advocate

The captured material gives no certificate, no penetration test, no encryption statement and no word on IP or metadata logging. The confidentiality promise is implicit in the product name alone; I found no public information on how a reporter's anonymity would survive first contact. 1

Report an error

The SME Operator

The captured material contains no certificate, no penetration test, no encryption claim and no statement on IP or metadata logging — we found no public information on any of it. Confidentiality of the reporter's identity is the legal core of the channel, and I cannot put my company's name on a promise I cannot see evidenced. 1

Report an error

The Group Counsel

We found no public information on encryption, ISO 27001 or equivalent certification, penetration testing, or the handling of reporter IP and metadata. Nothing captured lets me assess whether the confidentiality promise is engineered, let alone evidenced to a hostile auditor. 1

Report an error

The Security Auditor

We found no public information on certifications, penetration tests, encryption architecture, security contact or disclosure policy, or metadata and IP-logging practices — not even adjective security to push back on. For a product whose entire value is confidentiality, the complete absence of verifiable assurance evidence settles this. 1

Report an error

The Skeptic

We found no public information on certificates, penetration tests, encryption of report content, or IP and metadata logging; a status page and help center are operational support, not assurance. By the evidence shown there is nothing here a hostile auditor — or anyone — could test. 1

Report an error

Group & multi-entity capability

Show reasoning
How this is scored

Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.

0 — One company, one channel; a group buys and administers N separate instances.

3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.

5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.

8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.

10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.

Report an error

The Compliance Officer

A claimed base of 300,000+ users plus APIs for user-right management and location or cost-center updates suggest the platform is built for large distributed organizations, but we found no public information on separate channels per legal entity, per-entity case-handler separation, ombudsman access, or a group-level consolidated view. Whether one contract can serve a corporate group is undocumented from where I sit. 1

Report an error

The Reporter's Advocate

APIs for locations, cost centers and user-right management, plus a 300,000-user claim, hint at scale tooling, but the captured pages give no evidence of per-entity channels, delegated administration, external ombudsman access or group-level reporting that respects entity boundaries. 1

Report an error

The SME Operator

We found no public information on per-entity channels, entity-level case separation, ombudsman or external counsel access, or a group-wide consolidated view. The only adjacent item is a users API for automating user rights, which does not evidence a multi-entity channel structure; for a group buyer this would mean administering parallel setups. 1

Report an error

The Group Counsel

This is the criterion I buy on and the evidence is thinnest here: we found no public information on per-entity channels, separated case access per subsidiary, external ombudsman roles, or group reporting that respects entity boundaries. The automation APIs for users, places and cost centers plus a claim of 300,000+ users worldwide hint at scale plumbing, but nothing evidences the per-entity channel separation my 25 subsidiaries would require. 1

Report an error

The Security Auditor

APIs that automate locations, cost centers, registries and user rights suggest the platform is built for multi-site administration, and an acquisition is noted as strengthening the offering, but we found no public information on per-entity channels, separated case access per legal entity, group-level oversight, external ombudsman access, or per-entity branding. Scaling infrastructure is not the same as group compliance structure. 1

Report an error

The Skeptic

APIs for places, cost centers and registries suggest organizational structure can be modeled, but we found no public information on separate channels per legal entity, delegated administration, ombudsman roles, or group-level reporting that respects entity boundaries. A corporate group cannot judge from public evidence whether one contract could serve many entities. 1

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The Compliance Officer

The only jurisdictional clue in the captured pages is the Finnish company form in the vendor's name; we found no public information on hosting location or data centers, a published data processing agreement, or subprocessors. For whistleblowing data, I stop reading when the chain of custody is undocumented. 1

Report an error

The Reporter's Advocate

Falcony Oy, part of the Wekomply group, looks at least European as an entity, and there the trail ends: I found no public information on hosting locations, a DPA, a subprocessor list or any jurisdictional commitment covering the report data itself. 1

Report an error

The SME Operator

The vendor is Falcony Oy, part of the Wekomply group, which looks European, but we found no public information on where report content is hosted, on a DPA, on subprocessors or on data-center jurisdiction — no sovereignty attributes are on record. For the most sensitive data my company would ever hold, that silence alone rules it out for me. 1

Report an error

The Group Counsel

The vendor presents itself as Falcony, part of the Wekomply group, but we found no public information on hosting location, named data centers, a DPA, or subprocessors for report content and metadata. For the most sensitive data a company holds, we found no public information to review against non-European jurisdictional reach. 1

Report an error

The Security Auditor

The vendor is presented as Falcony Oy, part of the Wekomply group, but we found no public information on hosting location or named data centers, a data-processing agreement, technical and organizational measures, or any subprocessor list. For the most sensitive data a company holds I want the whole chain documented publicly, and none of it is on the captured pages. 1

Report an error

The Skeptic

The vendor is Falcony Oy, shown as part of the Wekomply group, which points to a European company; beyond that, we found no public information on hosting location, named data centers, a published DPA, or the subprocessor list. For the most sensitive data an employer holds, an undocumented chain is itself a finding. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.

5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.

8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.

Report an error

The Compliance Officer

A free trial is offered publicly, but we found no public information on tier prices, employee bands, per-entity rules, setup fees, or VAT treatment. No obligated company can compute even a first-year invoice from these pages. 1

Report an error

The Reporter's Advocate

The only pricing-adjacent item is a free trial; no tier, band, billing period, VAT treatment or setup fee carries a number in the captured pages. An obligated company cannot compute any part of an invoice from what is public. 1

Report an error

The SME Operator

No prices are public at all: the captured page offers a free trial and a contact link, and we found no public information on tiers, employee bands, entity rules, setup fees or renewal terms. As a 60-employee obligated company I cannot even estimate the invoice, and unpriced everything is precisely the year-end conversation I refuse to have. 1

Report an error

The Group Counsel

A free trial is offered and that is the whole of the public commercial information: we found no public prices, tiers, employee-band boundaries, entity rules or renewal terms. With contact us as the only path beyond the trial, an obligated company cannot begin to compute an invoice from public pages, and a five-entity group starts every tier from a sales conversation. 1

Report an error

The Security Auditor

A free trial is offered, but we found no public prices for any tier and no information on employee bands, billing period, VAT treatment, setup charges, or per-entity costs. An obligated company cannot compute even a rough invoice from the public pages. 1

Report an error

The Skeptic

The only public commercial disclosure is a free trial; we found no public information on tier prices, billing period, employee-band boundaries, entity rules, or setup fees. An obligated company cannot compute even a rough invoice from what is published — every tier is a sales conversation. 1

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (5)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page falcony.io Checked 22 Sep 2026 Details →
  2. 2 Privacy policy — found from the homepage www.falcony.io Checked 30 Sep 2026 Details →
  3. 3 Reporting channels & reporter experience — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →
  4. 4 Reporting channels & reporter experience — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →
  5. 5 Security & anonymity assurance — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →