Whistleblowing Portals
Falcony Whistleblowing Channel
Provenance unknown Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Falcony Oy · falcony.io
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Falcony Oy, part of the Wekomply group, offers whistleblowing as one of five named solutions on a multi-purpose platform whose features include Audit, Observe, Scheduling, Registries, BI dashboards and AI, with APIs for users, places, cost centers and webhooks and a claimed 300,000+ users worldwide. The bench's strongest scores land on sovereignty, multi-entity scale and case management, all running 1-2: rationales credit the vendor's European company form, the automation APIs and module names like Audit and BI dashboards, while finding no public information on hosting location, a data-processing agreement, subprocessors, per-entity channels or statutory deadline handling — and no sovereignty attributes are on record. Security assurance is the weakest criterion, topping out at 1: no public information on certifications, penetration tests, encryption of report content, or reporter IP and metadata logging. Reporting channels run 0-2 with no public description of how a reporter submits, stays anonymous or follows up. The bench recorded no significant disagreements; visible spread reflects how far signals such as the Ilmoituskanava acquisition earn credit versus documented evidence. Only the free trial is public.
Speaks for it
- Sovereignty scores run 1-2, credited to the vendor's European company form (Falcony Oy, part of the Wekomply group).
- Multi-entity scale scores run 1-2, credited to the users, places and cost-center APIs and a claimed 300,000+ users worldwide.
- A publicly noted acquisition of the existing whistleblowing channel Ilmoituskanava is described as strengthening the offering.
- Case management scores run 1-2, with module names like Audit, Scheduling and BI dashboards and a Users API gesturing at workflow tooling.
- A free trial is offered publicly.
Held against it
- We found no public information on any intake route, anonymous submission, two-way dialog, language coverage or phone reporting.
- We found no public information on certifications, penetration tests, encryption of report content, or reporter IP and metadata handling.
- We found no public information mapping the product to EU Directive 2019/1937 or any national transposition, or on acknowledgment and feedback deadlines.
- We found no public information on hosting location, a data-processing agreement or subprocessors, and no sovereignty attributes are on record.
- We found no public information on separate channels per legal entity, per-entity case separation, ombudsman access or group-level reporting.
Best for
- You want whistleblowing inside a broader multi-purpose platform you administer alongside observations, audits and risks.
- You administer a large distributed organization and value the users, places and cost-center APIs for automating administration.
- You are a European buyer for whom a Finnish company inside a European group is a starting point, and you will verify hosting and subprocessors during procurement.
- You want to test the channel yourself through the free trial before any sales conversation.
Avoid if
- You must show an auditor documented security assurance — certificates, penetration tests, encryption of report content — before launch.
- Your reporters' anonymity is the core requirement and employees must know in advance how to submit and stay anonymous.
- You must demonstrate compliance with EU Directive 2019/1937 or a national transposition, including acknowledgment and feedback clocks, without building the mapping yourself.
- You are a corporate group needing separate channels per legal entity, per-entity case separation and ombudsman access under one contract.
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
The captured pages list whistleblowing among the platform's solutions and offer a free trial, but we found no public information on an anonymous reporting route, a secured two-way dialog with reporters, phone intake, or language coverage. I answer for every frightened reporter who abandons an intake, and I cannot assess — let alone trust — a channel the vendor does not describe. 1
The Reporter's Advocate
The captured page names Whistleblowing among five solutions and stops there: I found no public information on any intake route, no anonymous form, no follow-up dialog, no phone or voice option, no languages and no accessibility. A night-shift worker on a phone has nothing here to trust and nothing to evaluate. 1
The SME Operator
The captured page names whistleblowing as one of several solutions but shows nothing about how a reporter actually submits; we found no public information on anonymous submission, a follow-up dialog, language coverage or phone intake. For me that is the entire purchase question — if I cannot see that a frightened employee can stay anonymous and still be reached for questions, the channel fails its purpose. 1
The Group Counsel
Whistleblowing is named as one solution among ideas, tenant portal and chemicals on a multi-purpose platform, but we found no public information on how a reporter actually submits — nothing on anonymous dialog, follow-up contact with the reporter, languages, or phone intake. I cannot even establish from public pages what one subsidiary's employee would encounter on first contact. 1
The Security Auditor
Whistleblowing appears as one item in a solutions list alongside ideas, chemicals and tenant portals, and we found no public information on how a report is actually submitted, whether an anonymous two-way dialog exists, what languages are covered, or how a reporter's identity is kept out of the channel at first contact. Without any of that I cannot verify the anonymity promise even survives intake. 1
The Skeptic
Whistleblowing is one of five named solutions on the platform and a free trial exists, but the captured page stops there: we found no public information on intake channels, anonymous two-way dialogue, language coverage, or accessibility. A reporter's actual path into the system is invisible from public evidence, and anonymity surviving first contact is a claim nobody has documented. 1
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
Module names like Audit, Scheduling and BI dashboards, plus a Users API for user-right automation, gesture at workflow tooling, but we found no public information on statutory acknowledgment or feedback clocks, conflict-of-interest exclusion, or a tamper-evident case history. Undocumented deadlines become my missed clocks, so I score by what I can verify and on case discipline I can verify almost nothing here. 1
The Reporter's Advocate
The platform lists Observe, Audit and BI dashboards, with APIs to generate observations and automate user rights — more than a shared inbox, but the captured pages say nothing about how cases are handled. I found no public information on statutory clocks, role separation, conflict-of-interest handling or tamper-evident history. 1
The SME Operator
We found no public information on statutory deadline tracking, the acknowledgment and feedback clocks, role separation between case handlers, or tamper-evident case history — the page's feature names 'Audit' and 'BI dashboards' carry no detail on what a case worker actually does. That means I would be running the legal deadlines myself in a spreadsheet, which is exactly what I refuse to do. 1
The Group Counsel
The platform advertises generic modules — audit, scheduling, BI dashboards — but we found no public information on statutory deadline clocks, acknowledgment and feedback duties, role separation between case handlers, or a tamper-evident case history. A users API that automates user right management hints that permissions exist, yet nothing is said about excluding implicated handlers or documenting who did what. 1
The Security Auditor
The captured page lists platform-level features — audit, dashboards, scheduling — and an API to automate user and user-right management, which hints at structured administration, but we found no public information on statutory acknowledgment and feedback clocks, case notes, attachments, role separation for case handlers, or a tamper-evident case history. That earns a point for the faint signals and nothing more. 1
The Skeptic
The named platform features — audit, scheduling, BI dashboards — plus a users API to automate user right management gesture at roles and reporting, but we found no public information on statutory deadline handling, conflict-of-interest exclusion, tamper-evident case history, or retention and deletion rules. Feature names on a menu are not a case system an investigator could rely on. 1
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
The vendor reports acquiring Ilmoituskanava to strengthen its whistleblowing offering, which signals genuine intent, but we found no public information mapping product features to EU Directive 2019/1937 or any national transposition — no acknowledgment clock, no feedback deadline, no retention handling. Until the homework is public, the statutory mapping is my problem rather than the product's. 1
The Reporter's Advocate
Whistleblowing appears as one tile in a broad HSEQ/GRC catalogue and the captured pages make no reference to EU Directive 2019/1937 or any national transposition. This is the generic-feedback-software-wearing-a-whistleblowing-label case: no legal obligation is named, let alone mapped to a feature. 1
The SME Operator
Whistleblowing sits as one label among Ideas, Chemicals, a Tenant portal and Risks, and we found no public information tying the product to EU Directive 2019/1937 or any national transposition such as the German HinSchG. No per-country rule sets, no legal templates, no named counsel — for my purposes this reads as generic feedback software wearing a whistleblowing label. 1
The Group Counsel
We found no public information referencing EU Directive 2019/1937 or any national transposition such as the German HinSchG; whistleblowing simply sits in a solutions list next to ideas and tenant portal. The acquisition of an existing whistleblowing channel, Ilmoituskanava, is noted, but we found no public information on per-country rule sets, legal templates or documented counsel review. 1
The Security Auditor
Whistleblowing appears as a solution label, and we found no public information referencing EU Directive 2019/1937, any national transposition, statutory deadline rules, documentation or retention duties, or named legal review. As far as the captured pages show, this is a general observation platform with a whistleblowing name attached. 1
The Skeptic
Whistleblowing sits on the solutions menu next to ideas, chemicals and tenant portal in a general HSEQ/GRC platform, and we found no public information tying the product to the EU whistleblowing directive or any national transposition. With not one legal duty named in public — no acknowledgment clock, no feedback deadline, no retention period — the label rides on a general observation tool. 1
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
We found no public information on certifications, penetration tests, encryption of report content, or IP and metadata handling; a status page and help center are operational hygiene, not assurance. For the most sensitive data a company holds, I cannot score that silence as anything but the bottom of the scale. 1
The Reporter's Advocate
The captured material gives no certificate, no penetration test, no encryption statement and no word on IP or metadata logging. The confidentiality promise is implicit in the product name alone; I found no public information on how a reporter's anonymity would survive first contact. 1
The SME Operator
The captured material contains no certificate, no penetration test, no encryption claim and no statement on IP or metadata logging — we found no public information on any of it. Confidentiality of the reporter's identity is the legal core of the channel, and I cannot put my company's name on a promise I cannot see evidenced. 1
The Group Counsel
We found no public information on encryption, ISO 27001 or equivalent certification, penetration testing, or the handling of reporter IP and metadata. Nothing captured lets me assess whether the confidentiality promise is engineered, let alone evidenced to a hostile auditor. 1
The Security Auditor
We found no public information on certifications, penetration tests, encryption architecture, security contact or disclosure policy, or metadata and IP-logging practices — not even adjective security to push back on. For a product whose entire value is confidentiality, the complete absence of verifiable assurance evidence settles this. 1
The Skeptic
We found no public information on certificates, penetration tests, encryption of report content, or IP and metadata logging; a status page and help center are operational support, not assurance. By the evidence shown there is nothing here a hostile auditor — or anyone — could test. 1
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
A claimed base of 300,000+ users plus APIs for user-right management and location or cost-center updates suggest the platform is built for large distributed organizations, but we found no public information on separate channels per legal entity, per-entity case-handler separation, ombudsman access, or a group-level consolidated view. Whether one contract can serve a corporate group is undocumented from where I sit. 1
The Reporter's Advocate
APIs for locations, cost centers and user-right management, plus a 300,000-user claim, hint at scale tooling, but the captured pages give no evidence of per-entity channels, delegated administration, external ombudsman access or group-level reporting that respects entity boundaries. 1
The SME Operator
We found no public information on per-entity channels, entity-level case separation, ombudsman or external counsel access, or a group-wide consolidated view. The only adjacent item is a users API for automating user rights, which does not evidence a multi-entity channel structure; for a group buyer this would mean administering parallel setups. 1
The Group Counsel
This is the criterion I buy on and the evidence is thinnest here: we found no public information on per-entity channels, separated case access per subsidiary, external ombudsman roles, or group reporting that respects entity boundaries. The automation APIs for users, places and cost centers plus a claim of 300,000+ users worldwide hint at scale plumbing, but nothing evidences the per-entity channel separation my 25 subsidiaries would require. 1
The Security Auditor
APIs that automate locations, cost centers, registries and user rights suggest the platform is built for multi-site administration, and an acquisition is noted as strengthening the offering, but we found no public information on per-entity channels, separated case access per legal entity, group-level oversight, external ombudsman access, or per-entity branding. Scaling infrastructure is not the same as group compliance structure. 1
The Skeptic
APIs for places, cost centers and registries suggest organizational structure can be modeled, but we found no public information on separate channels per legal entity, delegated administration, ombudsman roles, or group-level reporting that respects entity boundaries. A corporate group cannot judge from public evidence whether one contract could serve many entities. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The only jurisdictional clue in the captured pages is the Finnish company form in the vendor's name; we found no public information on hosting location or data centers, a published data processing agreement, or subprocessors. For whistleblowing data, I stop reading when the chain of custody is undocumented. 1
The Reporter's Advocate
Falcony Oy, part of the Wekomply group, looks at least European as an entity, and there the trail ends: I found no public information on hosting locations, a DPA, a subprocessor list or any jurisdictional commitment covering the report data itself. 1
The SME Operator
The vendor is Falcony Oy, part of the Wekomply group, which looks European, but we found no public information on where report content is hosted, on a DPA, on subprocessors or on data-center jurisdiction — no sovereignty attributes are on record. For the most sensitive data my company would ever hold, that silence alone rules it out for me. 1
The Group Counsel
The vendor presents itself as Falcony, part of the Wekomply group, but we found no public information on hosting location, named data centers, a DPA, or subprocessors for report content and metadata. For the most sensitive data a company holds, we found no public information to review against non-European jurisdictional reach. 1
The Security Auditor
The vendor is presented as Falcony Oy, part of the Wekomply group, but we found no public information on hosting location or named data centers, a data-processing agreement, technical and organizational measures, or any subprocessor list. For the most sensitive data a company holds I want the whole chain documented publicly, and none of it is on the captured pages. 1
The Skeptic
The vendor is Falcony Oy, shown as part of the Wekomply group, which points to a European company; beyond that, we found no public information on hosting location, named data centers, a published DPA, or the subprocessor list. For the most sensitive data an employer holds, an undocumented chain is itself a finding. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
A free trial is offered publicly, but we found no public information on tier prices, employee bands, per-entity rules, setup fees, or VAT treatment. No obligated company can compute even a first-year invoice from these pages. 1
The Reporter's Advocate
The only pricing-adjacent item is a free trial; no tier, band, billing period, VAT treatment or setup fee carries a number in the captured pages. An obligated company cannot compute any part of an invoice from what is public. 1
The SME Operator
No prices are public at all: the captured page offers a free trial and a contact link, and we found no public information on tiers, employee bands, entity rules, setup fees or renewal terms. As a 60-employee obligated company I cannot even estimate the invoice, and unpriced everything is precisely the year-end conversation I refuse to have. 1
The Group Counsel
A free trial is offered and that is the whole of the public commercial information: we found no public prices, tiers, employee-band boundaries, entity rules or renewal terms. With contact us as the only path beyond the trial, an obligated company cannot begin to compute an invoice from public pages, and a five-entity group starts every tier from a sales conversation. 1
The Security Auditor
A free trial is offered, but we found no public prices for any tier and no information on employee bands, billing period, VAT treatment, setup charges, or per-entity costs. An obligated company cannot compute even a rough invoice from the public pages. 1
The Skeptic
The only public commercial disclosure is a free trial; we found no public information on tier prices, billing period, employee-band boundaries, entity rules, or setup fees. An obligated company cannot compute even a rough invoice from what is published — every tier is a sales conversation. 1
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (falcony.io, falcony.io/privacy-statement, falcony.io/product/whistleblowing, falcony.io/modules/whistleblowing, falcony.io/suites/security). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 4 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (5)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page falcony.io Checked 22 Sep 2026 Details →
- 2 Privacy policy — found from the homepage www.falcony.io Checked 30 Sep 2026 Details →
- 3 Reporting channels & reporter experience — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →
- 4 Reporting channels & reporter experience — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →
- 5 Security & anonymity assurance — found from sitemap www.falcony.io Checked 1 Oct 2026 Details →