Whistleblowing Portals
konfidal
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by konfidal GmbH · www.konfidal.eu
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
konfidal is a whistleblowing platform from konfidal GmbH, with an imprint in Zossen, Brandenburg, aimed at companies from 50 employees under the HinSchG. Bench scores sit low with one clear peak: compliance alignment at 3-4, where a legal page names the HinSchG and the EU directive, the 50-employee scope, the duty to establish an internal reporting office, and a three-month feedback deadline carried into a four-step process. Reporting channels score a flat 3 for an intake that accepts anonymous or named reports; case management a flat 2 — the judges found no public information on deadline clocks, role separation or case histories. The weakest scores are security assurance and multi-entity scale, both 0-1: pentesting and cyber insurance are marked 'Demnächst' (coming soon), and the captured pages address single companies, not groups. One-point spreads on compliance, security and sovereignty reflect a difference over how much a correct legal page, the word 'sicher' and a German legal entity earn against absent product evidence. No price figures appear; a free consultation is offered.
Speaks for it
- A dedicated legal page names the HinSchG and the EU directive, spelling out the 50-employee applicability and the duty to establish an internal reporting office.
- Anonymous or named reporting is confirmed, with a published four-step process ending in feedback to the reporter within three months.
- The imprint places konfidal GmbH in Zossen, Brandenburg, putting the contracting entity in Germany.
- Internal, external or hybrid reporting-office models are offered, alongside a software and full-service choice.
- The vendor states readiness within 48 hours on its German-market pages.
Held against it
- Security assurance rests on the words 'Anonyme & sichere Meldung', with pentesting and cyber insurance marked 'Demnächst' (coming soon) and no certificates or encryption detail captured.
- The judges found no public information on case tooling — deadline clocks, reminders, role separation or tamper-evident case histories.
- The captured pages address single companies from 50 employees, with no public information on per-entity channels, separated case access or group-level oversight.
- Beyond the German legal entity, the judges found no public information on hosting location, subprocessors or a published data processing agreement.
- Supply-chain-act and data-protection modules are announced as 'Demnächst' (coming soon) on the roadmap.
Best for
- You are a single company from 50 employees that must establish an internal reporting office under the HinSchG and wants the compliance framing already published.
- You want to choose between an internal, external or hybrid reporting office, and to buy it as software or as a full service.
- You want the channel ready within 48 hours, as the vendor's German-market page states.
Avoid if
- You run a corporate group and need per-entity channels, separated case access for subsidiaries or a group-level view.
- You need evidenced security today — certificates, encryption detail or completed penetration tests — not items marked coming soon.
- Your case handlers need documented tooling with deadline clocks, reminders and role separation rather than a described process.
- Your procurement requires published hosting, subprocessor and data-processing details rather than a German legal entity alone.
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
The platform is confirmed to accept anonymous or named reports and the vendor describes a four-step process from submission through investigation to feedback to the reporter. We found no public information on a secured follow-up dialogue with an anonymous reporter, on languages, phone or voice intake, or on accessibility, so the evidence stops at an anonymous intake with a promised response. 6
The Reporter's Advocate
Anonymous reporting is confirmed on the compliance page ("Anonyme & sichere Meldung") with a documented process ending in feedback to the reporter within three months. We found no public information on a two-way anonymous mailbox, languages beyond German, phone or voice intake, mobile handling or accessibility, so the reporter's experience after submitting is a promise, not a documented channel. 6
The SME Operator
Anonymous reporting is confirmed, with a published process that ends in feedback to the whistleblower within three months — that is the whole intake story on the captured pages. We found no public information on a protected two-way mailbox for anonymous follow-up questions, on phone or voice intake, on language coverage, or on accessibility, so I am left with one anonymous web door and silence on everything a frightened reporter might need. 6
The Group Counsel
Anonymous intake is confirmed — the platform is described as accepting anonymous or named reports — but the evidence stops at the submission path. We found no public information on a secured follow-up mailbox, dialog with the reporter after first contact, language coverage, phone or voice intake, or accessibility. 6
The Security Auditor
Anonymous reporting is a stated capability ("Anonyme & sichere Meldung") with a four-step process ending in feedback to the reporter, but we found no public information on a secured two-way mailbox, language coverage, phone or voice intake, QR entry points, or accessibility. The three-month feedback promise is a process commitment, not an evidenced channel that survives first contact. 6
The Skeptic
The pages confirm a platform where reports can be submitted anonymously or by name, with feedback promised to the reporter within three months — and there the evidence ends. I found no public information on a secured two-way mailbox, language coverage, voice or QR intake, accessibility, or how the reporter's identity is kept out of the channel. 6
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The only statutory clock evidenced is the feedback to the reporter within three months, embedded in a described review-and-investigation process. We found no public information on the seven-day acknowledgment deadline, reminders, role separation among case handlers, or a tamper-evident case history — the tooling my office would actually run is undocumented. 6
The Reporter's Advocate
The captured pages describe a four-step process — submission, review, internal investigation, feedback — with the three-month feedback deadline stated, and that is the only deadline discipline visible. We found no public information on a case system, automated clocks, the seven-day acknowledgment, role separation, audit-proof history or caseload reporting, so I cannot tell a case worker what tool they would actually work in. 6
The SME Operator
The published workflow runs submission, review, internal investigation and an answer within three months, and that feedback clock is the only deadline the captured material shows. We found no public information on the seven-day acknowledgment duty, automated reminders, role separation between case handlers, or a tamper-evident case history — meaning I would still be running the legal clocks myself in a spreadsheet next door. 6
The Group Counsel
What is published is a four-step process description — submission, review, internal investigation, feedback to the reporter within three months — rather than an evidenced case system. We found no public information on deadline clocks and reminders, case lists, role separation between handlers, conflict-of-interest handling, or an audit-proof case history. 6
The Security Auditor
The only case-side evidence is a four-step process description and a three-month feedback commitment; we found no public information on deadline tracking, reminders, role separation, conflict-of-interest handling, or a tamper-evident case history. The full-service option might cover this, but nothing published shows the tooling. 6
The Skeptic
What the captured pages show is a prose description of a four-step process and the three-month answer duty, not a case system. I found no public information on deadline tracking or reminders, role separation, case histories, attachments, or retention rules — whether the statutory clock lives in software or in someone's calendar is not documented. 6
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
HinSchG and the EU directive are named with correct scope: companies from 50 employees, the duty to run an internal reporting office, internal/external/hybrid options, and the three-month feedback duty stated as the vendor's process. We found no public information on the seven-day acknowledgment clock, documentation duties, retention and deletion periods, or how the vendor keeps up when the law moves, so this is legal framing with one implemented clock rather than a full feature set. 6
The Reporter's Advocate
This is the strongest area: a dedicated page names the HinSchG and the EU Directive, the 50-or-more-employees scope since July 2023, the duty to run an internal reporting office, internal/external/hybrid models, and the three-month feedback deadline as a product promise. We found no public information on documentation duties, retention periods, per-country rule sets or the legal review behind the material, so the mapping covers one national law and stops short of demonstrated product implementation. 6 1
The SME Operator
The pages get the basics right for a shop my size: the HinSchG and the EU directive are named, the duty to run an internal reporting office from 50 employees is stated, the platform promises an answer within three months, and internal, external or hybrid setups plus a full-service offer and 48-hour readiness are on the table. But we found no public information on the seven-day acknowledgment, documentation duties or retention periods being implemented in the product, and further legal modules are marked coming soon. 3 6
The Group Counsel
The German-law page is more concrete than pure marketing: companies with 50 or more employees are named as in scope, the duty to establish an internal reporting office is spelled out, the three-month feedback duty is carried into the platform's own process description, and internal, external and hybrid setups are offered. We found no public information on the seven-day acknowledgment clock, documentation duties, retention and deletion rules, or any named counsel behind the mapping, and the data-protection module is marked as upcoming. 6
The Security Auditor
The pages name the HinSchG and the EU Directive, the 50-employee applicability, the internal reporting-office duty, and the three-month feedback clock, which is more concrete than generic marketing. We found no public information on the seven-day acknowledgment duty, documentation obligations, retention and deletion periods, or any legal review standing behind the implementation. 6
The Skeptic
HinSchG and the EU directive are named, and the 50-employee duty and the three-month feedback deadline are explained — but the mapping stops at marketing prose. I found no public information on statutory clocks implemented as product features, documentation or deletion duties, named legal counsel, or how legal updates are maintained, while data-protection and supply-chain-act modules are announced as 'Demnächst' (coming soon). 1 6
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
The confidentiality promise rests on the words "anonyme & sichere Meldung", while penetration testing and cyber insurance are both marked as coming soon — so no test reports exist today. We found no public information on certifications, encryption architecture, metadata handling, or a security contact; for a 600-employee operation that is adjectives plus a roadmap. 1 6
The Reporter's Advocate
The confidentiality promise rests on adjectives — "Anonyme & sichere Meldung" — with no certificates, encryption detail, penetration test reports, or metadata and IP-logging statements captured anywhere. The vendor's own homepage marks pentesting, cyber insurance and even the data protection section as "Demnächst" (coming soon), so there is nothing here a frightened reporter's lawyer could hold onto. 1 6
The SME Operator
The confidentiality promise is captured as 'Anonyme & sichere Meldung' — a line of adjectives — while pentesting and cyber insurance are marked 'Demnächst', i.e. planned rather than in place today. We found no public information on certificates, encryption architecture, test reports or metadata handling, so if a regulator asked me how a reporter stays anonymous, the captured pages hand me nothing. 1 6
The Group Counsel
Security assurance rests on the word "sicher" beside anonymous intake and an IT security checkup module, while pentesting and a cyber insurance are each marked "Demnächst" on the captured pages — a roadmap item is not assurance. We found no public information on certifications, encryption architecture, published test reports, or IP and metadata handling. 1 6
The Security Auditor
This is adjective security: "Anonyme & sichere Meldung" with nothing behind it — pentesting is published as "Demnächst", and we found no public information on certificates, encryption architecture, IP or metadata logging, or a security contact and disclosure policy. The IT Security Checkup is a service sold to customers, not assurance of the whistleblowing platform itself. 1 4 6 7
The Skeptic
'Anonyme & sichere Meldung' is a headline, not assurance: the vendor's own page lists pentesting as 'Demnächst' (coming soon), so the test is announced rather than attested. I found no public information on certificates, encryption architecture, penetration-test reports, or IP and metadata handling — a promise of anonymity with nothing auditable behind it. 1 6
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
We found no public information on per-entity channels, separated case access for subsidiaries, delegated administration, ombudsman access, or a group-level overview — nothing on the captured pages addresses a corporate group structure at all. The only structure-related statements are the 50-employee scope and a software-plus-full-service offering. 6
The Reporter's Advocate
We found no public information on separate channels per legal entity, group-level oversight, ombudsman access or white-labelling; the captured material addresses single companies from 50 employees with a software & full-service choice and internal, external or hybrid reporting-office models. As far as the public pages show, a corporate group would have to ask — and that conversation is not on the record. 6
The SME Operator
We found no public information on separate channels per legal entity, group-level oversight, ombudsman access or per-entity branding. The captured material speaks to a single company from fifty employees upward, which happens to fit me, but a corporate group would have nothing documented to buy. 6
The Group Counsel
We found no public information on per-entity channels, separated case access per subsidiary, delegated administration, external ombudsman roles, per-entity branding, or a group-level view. The only structural choice published concerns operating a single reporting office internally, externally, or as a hybrid — on this evidence I cannot roll one contract out to 25 subsidiaries with real access separation. 6
The Security Auditor
Everything published frames a single company from 50 employees upward; we found no public information on per-entity channels, separated case access per entity, group-level oversight, ombudsman roles, or white-labeling. The internal/external/hybrid reporting-office options describe operating models, not group architecture. 6
The Skeptic
I found no public information on separate channels per legal entity, separated case access per entity, group-level oversight, ombudsman roles, delegated administration, or white-labeling. The only configurability the pages show is choosing an internal, external, or hybrid reporting office — a service decision, not a group architecture. 6
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The vendor is a German GmbH with an imprint placing it in Zossen, Brandenburg, which at least puts the legal entity in Germany. We found no public information on where report data is hosted, on a published data processing agreement or subprocessor list, or on ownership, so the chain beyond the entity is undocumented for the most sensitive data we hold. 2 6
The Reporter's Advocate
The imprint confirms a German GmbH, which is the one jurisdictional fact in the captures; beyond that we found no public information on data residency, ownership, a published DPA or subprocessors — the privacy page captured nothing and the data protection section is listed as coming soon. For whistleblowing data, that silence is itself an answer: I cannot tell a reporter where their report would live. 2 1
The SME Operator
The imprint names a German GmbH, which is the one European signal on the captured pages. We found no public information on where report data is hosted, on data processing terms or on subprocessors — the data protection page itself is marked coming soon — so for the most sensitive data my company holds, the chain is undocumented in what was captured. 1 2
The Group Counsel
The imprint and trademark statement put the contracting entity in Germany, so at least the legal form is European. We found no public information on hosting locations, named data centers, data processing terms, or a subprocessor list — for report content this sensitive, the residency and jurisdictional-reach questions remain open. 1 2
The Security Auditor
The imprint confirms a German GmbH, the right jurisdiction for this data class, but that is where the chain ends: we found no public information on hosting location, named data centers, subprocessors, or a published DPA with TOMs. For the most sensitive data a company holds, silence on the rest of the chain earns almost nothing. 2 4
The Skeptic
The imprint names konfidal GmbH as the operator, and there the documentation ends: I found no public information on hosting location, data centers, subprocessors, or a public data processing agreement — for the most sensitive data a company holds. A data-protection module announced as 'Demnächst' (coming soon) is a roadmap item, not a DPA. 1 2 4
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
The only pricing-related statement we found is an invitation to request a free consultation; no tier prices, billing periods, employee-band boundaries, setup fees, or add-on prices appear on the captured pages. An obligated company cannot compute any invoice from what is public. 5 6
The Reporter's Advocate
The only pricing-adjacent item captured is a free-consultation call-to-action ("Jetzt kostenlose Beratung anfordern"); we found no public information on tier prices, employee bands, setup fees, billing period or VAT treatment, even on the dedicated pricing page. An obligated company cannot compute an invoice from what is public, so every price is a conversation. 5 6
The SME Operator
We found no public price figures on the captured pages — a German pricing page exists but no figures from it were confirmed — and the only commercial detail captured is an invitation to request a free consultation. For a 60-employee company like mine, the invoice begins with a sales call, which is precisely what my year-end review will not tolerate. 5 6
The Group Counsel
We found no public information on prices: the captured pricing pages yielded no figures, and the only pricing-adjacent statement is an offer of a free consultation. An obligated company cannot compute any invoice — not even a starting one — from the public pages. 5 6
The Security Auditor
No public prices at all: the captured pricing page yields no figures, and the route to a quote is "Jetzt kostenlose Beratung anfordern" — every tier is a sales conversation. An obligated company cannot compute any part of its invoice from what is published. 5 6
The Skeptic
The only pricing-adjacent sentence I could find is an invitation to request a free consultation ('Jetzt kostenlose Beratung anfordern'); I found no public information on any tier price, employee-band boundaries, billing period, VAT treatment, or setup fees — even on the captured pricing page. Every price is a sales conversation. 5 6
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors, Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any compliance information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 9 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 9 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 integrations fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
Sources (7)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.konfidal.eu Checked 15 Sep 2026 Details →
- 2 Imprint www.konfidal.eu Checked 15 Sep 2026 Details →
- 3 German-market site www.konfidal.de Checked 15 Sep 2026 Details →
- 4 Privacy policy www.konfidal.eu Checked 15 Sep 2026 Details →
- 5 Pricing page (DE) konfidal.de Checked 15 Sep 2026 Details →
- 6 Legal compliance alignment — found from sitemap www.konfidal.eu Checked 1 Oct 2026 Details →
- 7 Security & anonymity assurance — found from sitemap www.konfidal.eu Checked 1 Oct 2026 Details →