Whistleblowing Portals
Hintbox
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by lawcode GmbH · www.hintbox.de
Compare with EQS Integrity Line → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
No written verdict for this product
The panel scored Hintbox, but the summary our synthesizer wrote did not survive our own contradiction check — twice. Rather than print a paragraph we cannot stand behind, we print none. Every score, rationale and source below is unaffected; read them and draw the conclusion yourself.
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
Anonymous reporting with a generated post-submission login for two-way messages, file uploads and new reports is first-class, and 24–30 languages with AI translation is genuinely broad. But phone intake exists only as a €49/month voice-bot add-on, and the evidence is silent on accessibility, QR entry points and mobile use — the frightened reporter gets a solid form, not engineered intake. 1 2 3 5
The Reporter's Advocate
The dialog survives contact: an anonymous quick form, then generated post-box credentials with live chat inside the report — and metadata stripped before encryption, no IP/MAC or location stored, so a frightened reporter can keep talking without leaving a trail. 24–30 languages with AI translation covers a workforce, not just German lawyers. But voice intake hides behind a 49 €/month add-on and the evidence is silent on accessibility, mobile-friendliness and QR entry, which an 8 demands. 1 2 3 5
The SME Operator
Anonymous two-way dialog is genuinely first-class: the reporter gets generated login credentials after submitting and can keep messaging, uploading files and even file new reports anonymously, with 24-30 languages and automatic AI translation. But phone intake is a 49€/month add-on and email a 29€/month add-on, and the evidence says nothing about accessibility or app-free mobile design — that lands it between the anchors, dialog strong, channels paywalled. 2 3 5
The Group Counsel
Anonymous two-way dialog is first-class — generated post-submission login credentials for ongoing anonymous dialogue — with 24-30 languages plus AI translation and documented stripping of location/device metadata before encryption. Voice intake is only a paid add-on and the evidence says nothing on accessibility, QR entry points or mobile experience, so it sits between the 5 and 8 anchors. 1 2 3 5
The Security Auditor
Two-way anonymous dialog is first-class, not bolted on: generated post-submission login for follow-up messages, file uploads and new reports, live chat within a report, and 24–30 languages with automatic translation. But voice and email intake are optional add-ons rather than core channels, and the evidence is silent on accessibility, QR entry and mobile experience — the anchor-8 package isn't there. 1 3 5
The Skeptic
Anonymous two-way dialog is first-class: post-submission generated login lets the reporter come back, message and upload files anonymously, with 24–30 languages plus AI translation — though the site can't keep its own language count straight (30 in vs 24 in). Voice intake exists only as a paid add-on, and there is zero evidence on accessibility, mobile behavior or QR entry, so it stays short of the 8 anchor. 2 3 5
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The statutory clocks appear as product features — receipt confirmation and active support for the reporter-feedback deadline — with tamper-proof logging of every processing step and access rights steered per entity and per case. I stay below the top anchors because there is no evidence of automated clock reminders, conflict-of-interest exclusion of implicated handlers, or retention rules applied per case. 3 4 5
The Reporter's Advocate
Revisionssicher logging of every handler step, per-company/per-case permission steering, auto-triage and Excel/PDF caseload exports are genuinely there. But the statutory clocks are only 'actively supported' with no evidence of automated reminders, conflict-of-interest exclusion, or per-case retention automation — above rubric level 5, short of investigator-grade. 3 4 5
The SME Operator
Revisionssichere audit trail of every handling step, automatic triage and prioritization, Eingangsbestätigung, active deadline support for the reporter-feedback clock, and access rights steerable per company and case — more than a status list. What I don't see is conflict-of-interest handling (excluding an implicated case handler) or per-case retention automation, which is what separates this from the 8 anchor. 3 4 5
The Group Counsel
Genuine foundations: revisionssichere audit trail of every handler step, access rights controllable per company and per case, automatic triage and deadline support including the reporter feedback clock. But the statutory clocks are 'supported' rather than enforced, conflict-of-interest exclusion of implicated handlers is evidenced nowhere, and retention is a stated capability ('können gelöscht werden'), not per-case automation. 3 4 5
The Security Auditor
Revisionssichere logging of every compliance-officer step plus per-Gesellschaft, per-case permission control with external case participants and auto-triage exceed the anchor-5 baseline. But the statutory clocks are 'actively supported' rather than enforced-automated, deletion is merely possible, and I find no conflict-of-interest exclusion or per-case retention automation. 3 4 5
The Skeptic
Triage with automatic prioritization, deadline support explicitly including the feedback-to-reporter clock, receipt confirmation, a claimed tamper-proof ('revisionssicher') history and granular per-company/per-case permissions clear the 5 anchor. But conflict-of-interest exclusion of implicated handlers is nowhere, retention/deletion is a manual 'can be deleted' capability, not automation, and management reporting goes no further than export formats — that keeps it off 8. 3 4 5
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
The Directive's duties are implemented as features, not just marketing — acknowledgment of receipt, feedback deadline support, deletion per GDPR and the EU Whistleblower Directive — plus awareness of the 50-employee threshold and public-sector obligations. But the evidence never names a national transposition (HinSchG), no named counsel, no documented legal review or update process — one generic EU mapping, not per-country rule sets. 4 4 5
The Reporter's Advocate
The directive is more than marketing here: Eingangsbestätigung, feedback-deadline support, deletion per GDPR and 2019/1937, and audit-proof documentation exist as product features, and they know the 50-employee trigger and the public-sector duty. But no national transposition is ever named, there is no named counsel, no templates, no evidence the mapping is maintained when the law moves — rubric level 5, not 8. 4 6 4 5
The SME Operator
The 2019/1937 duties appear as product features, not slogans: receipt confirmation, active support for the feedback deadlines, deletion per the Directive, and even a public-sector compliance statement. But it's one German-sized shoe: no HinSchG named, no national transposition differences, no legal review or counsel documented — for my single-country obligation that's workable, but the evidence can't evidence more. 4 5
The Group Counsel
Directive 2019/1937 duties are implemented as features — Eingangsbestätigung, feedback deadlines, deletion per the Directive — which meets the anchor-5 bar. But it is one-jurisdiction framing (GDPR/BDSG, Germany): no HinSchG specifics, no other national transpositions, no named counsel or legal review, and no per-country rule sets, so for my dozen countries the legal mapping beyond Germany is entirely my problem. 4 4 5
The Security Auditor
Directive 2019/1937 shows up as product behavior — Eingangsbestätigung, feedback-deadline tracking, deletion per the directive, public-sector applicability — which lands on the anchor-5 definition for one national regime. Beyond that it thins out: HinSchG is never named, no per-country rule sets, no named counsel or documented legal review, and 'sämtliche Anforderungen erfüllt' is exactly the adjective compliance I discount. 6 4 5
The Skeptic
Directive 2019/1937 is not just marketing here: acknowledgment, feedback deadlines, tamper-proof documentation and deletion per the directive are named as product features. But the overall claim 'wir erfüllen sämtliche Anforderungen' is a blanket assertion — HinSchG is never named, there is no named counsel, no legal review documented, and no per-country rule sets, so it's one German implementation with guidance for nothing else. 4 4 5
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
ISO 27001 is claimed for the product and the ISMS, end-to-end encryption with TLS and a separately encrypted database is described with some technical detail, and the explicit no-IP/MAC statement plus metadata stripping before encryption is exactly the anonymity evidence I want. But regular professional pentests are asserted, never attested or published, and there is no disclosure policy or documented crypto architecture — a hostile auditor gets assertions, not artifacts. 1 2 3 4
The Reporter's Advocate
For my lens this is the core: data arrives already encrypted so 'neither we nor third parties can read it', no IP/MAC or location stored, metadata removed before encryption — the vendor effectively says it cannot unmask a reporter, backed by regular external pentests and ISO 27001. Missing for an 8: no public pentest summaries, no visible certificate scope, no security contact or disclosure policy, and the crypto story is prose rather than architecture. 2 3 4 4
The SME Operator
ISO 27001 certification, regular external penetration testing, and an explicit statement that no IP, MAC or location data is stored, plus metadata stripped before encryption and a real E2E story — data arrives pre-encrypted so 'neither we nor third parties can read it'. What's missing for an 8 is anything an auditor can read: no published pentest summaries, no security contact or disclosure policy in the evidence. 1 2 3 4
The Group Counsel
ISO 27001 claimed for both the ISMS and the product, regular professional penetration tests asserted, explicit no-IP/MAC/location-storage statements, metadata removal before encryption, and the vendor claims data arrives pre-encrypted so even it cannot read it — a 'we cannot unmask' posture in words. 1 3 4
The Security Auditor
The raw ingredients exist — ISO 27001 claimed, regular professional pentests asserted, E2E with a zero-knowledge claim ('data arrives already encrypted, neither we nor third parties can read') and an explicit no-IP/MAC/location-logging statement. 2 3 4
The Skeptic
The architecture story is genuinely good: data 'arrives already encrypted on our servers' so neither vendor nor third parties can read it, explicit no-IP/MAC/location-logging, metadata stripped before encryption, TLS and separate database encryption. But 'ISO 27001 zertifiziert' and 'regelmäßige Penetrationstests, positiv auditiert' are exactly the certification claims without certificates, scope statements, tester names or dates that I treat as marketing until shown — no security contact or disclosure policy either. 1 3 4
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
Groups can create entities, the whistleblower selects the entity at intake, and access rights are controlled per entity and per case with external persons invitable per case, plus a separate ombudsman platform and white-label offer. Missing: any consolidated group-level reporting that respects entity boundaries, delegated administration per entity, and group contracts are pushed to a custom quote. 3 6 5
The Reporter's Advocate
Groups can create entities, reporters pick the entity at intake, and handler access is steered per Gesellschaft and per case — plus an ombudsman platform and a white-label option. But there is no evidence of a consolidated group overview, delegated administration or per-entity language/branding rules, and group contracts collapse into a custom quote. rubric level 5 with one taste of 8's ombudsman piece. 2 3 6 5
The SME Operator
Groups can create per-entity companies, the whistleblower selects the affected entity at submission, and case-handler rights are steerable per company and case; there's also an ombuds solution and a white-label partner offering. But no delegated administration or consolidated group reporting is evidenced, and anything calling itself a group gets pushed into a custom quote — adequate for one company, unproven as group architecture. 3 6 5
The Group Counsel
The access separation I demand is real: entities can be created with reporters selecting their Gesellschaft at intake, and manager/handler rights are controllable per company and per case, with external persons invitable case-by-case. But there is no evidenced group-level consolidated view, no per-entity branding, no delegated administration and no per-country legal rule assignment; the 'Ombudslösung' is a separate white-label platform for ombudspersons, not an ombudsman role inside a group instance, and groups are pushed to custom offers. 1 3 5
The Security Auditor
Reporter-selects-entity intake with access rights steered per Gesellschaft and per case, external persons invitable to specific cases, an ombudsman platform and white-labeling give real separation bones. But group-level consolidated reporting, delegated per-entity administration and per-country rules per entity are all silent, and groups are pointed at a custom quote — that's anchor-5 territory with a bonus, not anchor-8. 6 4 5
The Skeptic
Groups can create additional entities, reporters pick the entity at intake, and access rights are controllable per company and case, with external persons invitable per case and a white-label partner program — that earns the 5 anchor. But there is no evidence of a consolidated group-level view or reporting, no delegated administration, and the 'Ombudslösung' is one marketing sentence with no functional detail; group contracts are custom quotes anyway. 3 6 5
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The chain is factually German end to end — lawcode GmbH registered at Amtsgericht Koblenz, hosting exclusively at Hetzner in an ISO-certified German datacenter with no hosting or data sharing outside the EU, and fully in-house development. But no DPA, no subprocessor list and no TOMs are published, so the clean chain is claimed on a webpage rather than documented — that gap keeps it below the 8. 1 4 6 7 4
The Reporter's Advocate
German GmbH in Koblenz, Hetzner datacenters in Germany, an explicit no-hosting-no-transfer-outside-the-EU statement and an isolated instance per customer — the right jurisdictional shape for the most sensitive data a company holds. But no published DPA, TOMs or subprocessor list appears anywhere in the evidence: the promise is asserted, the chain undocumented, which rubric level 5 explicitly requires and 8 builds on. 1 4 7 4
The SME Operator
A German GmbH with a Koblenz register number and German address, hosted by Hetzner in an ISO-certified German datacenter, with an explicit no-hosting, no-transfer-outside-EU statement. The gap is paperwork: no published subprocessor list and no public DPA document — the processor-on-documented-instruction sentence is a claim, not a contract I can inspect, so it stops short of the 8 anchor. 1 4 7
The Group Counsel
The chain that matters is German: lawcode GmbH seated in Koblenz, hosting exclusively at Hetzner in German ISO 27001-certified data centers with no transfer outside the EU. It cannot reach the 8 anchor because no published DPA, TOMs or subprocessor list exists in the evidence, and the AI translation of report content implies a content-touching processor nobody has accounted for. 1 2 4 6 7
The Security Auditor
The chain that matters is evidenced German: lawcode GmbH in Koblenz with HRB number and DE VAT ID, Hetzner-hosted ISO 27001 German datacenter, explicit no hosting and no transfer outside the EU, per-customer isolated instances and fully in-house development. What holds me at 6: no published subprocessor list and no public DPA/TOMs — 'no third-country transfer' is currently a sentence, not an auditable chain. 1 4 6 7
The Skeptic
The imprint settles what the evidence's attributes call 'unknown': lawcode GmbH, Amtsgericht Koblenz HRB 28116, German seat and VAT ID, with hosting exclusively at Hetzner in a German ISO 27001 data center and an explicit no-third-country-transfer statement. That is jurisdictionally clean but short of the 8 anchor: no published DPA document, no TOMs, no subprocessor list, and ownership is undocumented — for whistleblowing data I want that chain in public, not implied. 1 4 7
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
Every tier and every add-on carries a real net price with VAT treatment and billing period stated — €99/€149 base, €49 voice bot, €29 email and domain mapping, €390 onboarding, €199/hour training — and pricing is seat-independent, so a single-entity 600-person invoice is a two-minute exercise. The deduction: what separates Basis from Premium is not laid out, and corporate groups and Konzerne are explicitly moved to a custom quote. 1 2 5
The Reporter's Advocate
A single company can compute its invoice in two minutes: 99/149 € net monthly with VAT stated, unlimited users independent of seats, a priced 390 € onboarding, and the add-ons (voice bot 49 €, email, domain mapping) all carry real numbers. What keeps it from an 8: the Basis/Premium feature split is never itemised and group contracts fall into an individual offer, so a 5-entity group cannot compute anything. 1 2 5
The SME Operator
Both tiers carry public net prices with VAT treatment stated (99€ and 149€ monthly), pricing is independent of handler accounts with unlimited users, and every add-on is priced in the open — voice bot 49€/month, email 29€/month, domain mapping 29€/month, onboarding 390€ one-time. For my 60-employee company the invoice is genuinely a two-minute exercise; what keeps it from a 10 is that the premium tier's annual figure and what it actually adds over base are left vague, and the 390€ onboarding smells like a setup charge I'd have to justify even if it's optional. 1 2 5
The Group Counsel
Two plans with real numbers (€99/€149), net pricing with 19% VAT stated, every add-on priced (voice bot, email, domain mapping), onboarding as a stated one-time fee, and prices independent of user count — a single entity can compute its invoice quickly. But the entity dimension is a black box: no per-entity price anywhere and groups are explicitly routed to individual offers, and the premium plan's scope is not delineated on the pricing page. 1 2 5
The Security Auditor
A single-company invoice is a two-minute exercise: 99€/149€ net monthly tiers, 1188€ annual base, VAT treatment and billing period stated, seat-independent pricing with unlimited users, onboarding 390€ one-time, training 199€/hour — and the add-ons that competitors hide (voice bot, email, custom domain) all carry real numbers. Missing pieces: the premium tier's annual figure and feature boundary, and group/entity pricing is custom-quoted, which rubric level 8 tolerates only for genuine corporate groups. 1 2 5
The Skeptic
A single-entity invoice is fully computable: €99/month net plus 19% VAT, seat-independent, with every add-on priced on the page (voice bot €49, email and domain €29) and setup costs explicit (onboarding €390, training €199/hour). What keeps it off 8: the €149 Premium tier appears only in the FAQ with no published feature boundary against Basis, and multi-entity groups are pushed into custom quotes. 1 2 5
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 4 Report an error |
| Subprocessors | EU only ⚠ unverified | 2/2 pts | 1 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 11 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. Statement sits on the vendor's security/trust page rather than in a contractual data processing agreement.
- Weak sourcing — Subprocessors. Only the hoster is named; no complete subprocessor list is published, and the provider of the AI-based translation feature is not disclosed.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 9 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
- The panel’s written verdict is withheld: our own re-read found claims in it that the evidence does not carry, and a second synthesis did not fix them. The scores and the material below are unaffected. Know more? Tell us
Sources (9)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.hintbox.de Checked 15 Sep 2026 Details →
- 2 Pricing page www.hintbox.de Checked 15 Sep 2026 Details →
- 3 Features page www.hintbox.de Checked 15 Sep 2026 Details →
- 4 Security & privacy page www.hintbox.de Checked 15 Sep 2026 +1 earlier capture: 15 Sep 2026 Details →
- 5 FAQ www.hintbox.de Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
- 6 About / vendor entity www.hintbox.de Checked 15 Sep 2026 Details →
- 7 Imprint www.hintbox.de Checked 15 Sep 2026 Details →
- 8 Reporting channels & reporter experience — found from sitemap www.hintbox.de Checked 1 Oct 2026 Details →
- 9 Reporting channels & reporter experience — found from sitemap www.hintbox.de Checked 1 Oct 2026 Details →