whats-best.ai

Whistleblowing Portals

konfidal

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by konfidal GmbH · www.konfidal.eu

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

konfidal is a whistleblowing platform from konfidal GmbH, with an imprint in Zossen, Brandenburg, aimed at companies from 50 employees under the HinSchG. Bench scores sit low with one clear peak: compliance alignment at 3-4, where a legal page names the HinSchG and the EU directive, the 50-employee scope, the duty to establish an internal reporting office, and a three-month feedback deadline carried into a four-step process. Reporting channels score a flat 3 for an intake that accepts anonymous or named reports; case management a flat 2 — the judges found no public information on deadline clocks, role separation or case histories. The weakest scores are security assurance and multi-entity scale, both 0-1: pentesting and cyber insurance are marked 'Demnächst' (coming soon), and the captured pages address single companies, not groups. One-point spreads on compliance, security and sovereignty reflect a difference over how much a correct legal page, the word 'sicher' and a German legal entity earn against absent product evidence. No price figures appear; a free consultation is offered.

Report an error

Speaks for it

  • A dedicated legal page names the HinSchG and the EU directive, spelling out the 50-employee applicability and the duty to establish an internal reporting office.
  • Anonymous or named reporting is confirmed, with a published four-step process ending in feedback to the reporter within three months.
  • The imprint places konfidal GmbH in Zossen, Brandenburg, putting the contracting entity in Germany.
  • Internal, external or hybrid reporting-office models are offered, alongside a software and full-service choice.
  • The vendor states readiness within 48 hours on its German-market pages.

Report an error

Held against it

  • Security assurance rests on the words 'Anonyme & sichere Meldung', with pentesting and cyber insurance marked 'Demnächst' (coming soon) and no certificates or encryption detail captured.
  • The judges found no public information on case tooling — deadline clocks, reminders, role separation or tamper-evident case histories.
  • The captured pages address single companies from 50 employees, with no public information on per-entity channels, separated case access or group-level oversight.
  • Beyond the German legal entity, the judges found no public information on hosting location, subprocessors or a published data processing agreement.
  • Supply-chain-act and data-protection modules are announced as 'Demnächst' (coming soon) on the roadmap.

Report an error

Best for

  • You are a single company from 50 employees that must establish an internal reporting office under the HinSchG and wants the compliance framing already published.
  • You want to choose between an internal, external or hybrid reporting office, and to buy it as software or as a full service.
  • You want the channel ready within 48 hours, as the vendor's German-market page states.

Report an error

Avoid if

  • You run a corporate group and need per-entity channels, separated case access for subsidiaries or a group-level view.
  • You need evidenced security today — certificates, encryption detail or completed penetration tests — not items marked coming soon.
  • Your case handlers need documented tooling with deadline clocks, reminders and role separation rather than a described process.
  • Your procurement requires published hosting, subprocessor and data-processing details rather than a German legal entity alone.

Report an error

The scores

Reporting channels & reporter experience

Show reasoning
How this is scored

The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.

0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.

3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.

5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.

8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.

10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.

Report an error

The Compliance Officer

The platform is confirmed to accept anonymous or named reports and the vendor describes a four-step process from submission through investigation to feedback to the reporter. We found no public information on a secured follow-up dialogue with an anonymous reporter, on languages, phone or voice intake, or on accessibility, so the evidence stops at an anonymous intake with a promised response. 6

Report an error

The Reporter's Advocate

Anonymous reporting is confirmed on the compliance page ("Anonyme & sichere Meldung") with a documented process ending in feedback to the reporter within three months. We found no public information on a two-way anonymous mailbox, languages beyond German, phone or voice intake, mobile handling or accessibility, so the reporter's experience after submitting is a promise, not a documented channel. 6

Report an error

The SME Operator

Anonymous reporting is confirmed, with a published process that ends in feedback to the whistleblower within three months — that is the whole intake story on the captured pages. We found no public information on a protected two-way mailbox for anonymous follow-up questions, on phone or voice intake, on language coverage, or on accessibility, so I am left with one anonymous web door and silence on everything a frightened reporter might need. 6

Report an error

The Group Counsel

Anonymous intake is confirmed — the platform is described as accepting anonymous or named reports — but the evidence stops at the submission path. We found no public information on a secured follow-up mailbox, dialog with the reporter after first contact, language coverage, phone or voice intake, or accessibility. 6

Report an error

The Security Auditor

Anonymous reporting is a stated capability ("Anonyme & sichere Meldung") with a four-step process ending in feedback to the reporter, but we found no public information on a secured two-way mailbox, language coverage, phone or voice intake, QR entry points, or accessibility. The three-month feedback promise is a process commitment, not an evidenced channel that survives first contact. 6

Report an error

The Skeptic

The pages confirm a platform where reports can be submitted anonymously or by name, with feedback promised to the reporter within three months — and there the evidence ends. I found no public information on a secured two-way mailbox, language coverage, voice or QR intake, accessibility, or how the reporter's identity is kept out of the channel. 6

Report an error

Case management & deadline discipline

Show reasoning
How this is scored

The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.

0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.

3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.

5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.

8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.

10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.

Report an error

The Compliance Officer

The only statutory clock evidenced is the feedback to the reporter within three months, embedded in a described review-and-investigation process. We found no public information on the seven-day acknowledgment deadline, reminders, role separation among case handlers, or a tamper-evident case history — the tooling my office would actually run is undocumented. 6

Report an error

The Reporter's Advocate

The captured pages describe a four-step process — submission, review, internal investigation, feedback — with the three-month feedback deadline stated, and that is the only deadline discipline visible. We found no public information on a case system, automated clocks, the seven-day acknowledgment, role separation, audit-proof history or caseload reporting, so I cannot tell a case worker what tool they would actually work in. 6

Report an error

The SME Operator

The published workflow runs submission, review, internal investigation and an answer within three months, and that feedback clock is the only deadline the captured material shows. We found no public information on the seven-day acknowledgment duty, automated reminders, role separation between case handlers, or a tamper-evident case history — meaning I would still be running the legal clocks myself in a spreadsheet next door. 6

Report an error

The Group Counsel

What is published is a four-step process description — submission, review, internal investigation, feedback to the reporter within three months — rather than an evidenced case system. We found no public information on deadline clocks and reminders, case lists, role separation between handlers, conflict-of-interest handling, or an audit-proof case history. 6

Report an error

The Security Auditor

The only case-side evidence is a four-step process description and a three-month feedback commitment; we found no public information on deadline tracking, reminders, role separation, conflict-of-interest handling, or a tamper-evident case history. The full-service option might cover this, but nothing published shows the tooling. 6

Report an error

The Skeptic

What the captured pages show is a prose description of a four-step process and the three-month answer duty, not a case system. I found no public information on deadline tracking or reminders, role separation, case histories, attachments, or retention rules — whether the statutory clock lives in software or in someone's calendar is not documented. 6

Report an error

Legal compliance alignment

Show reasoning
How this is scored

How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.

0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.

3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.

5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.

8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.

10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.

Report an error

The Compliance Officer

HinSchG and the EU directive are named with correct scope: companies from 50 employees, the duty to run an internal reporting office, internal/external/hybrid options, and the three-month feedback duty stated as the vendor's process. We found no public information on the seven-day acknowledgment clock, documentation duties, retention and deletion periods, or how the vendor keeps up when the law moves, so this is legal framing with one implemented clock rather than a full feature set. 6

Report an error

The Reporter's Advocate

This is the strongest area: a dedicated page names the HinSchG and the EU Directive, the 50-or-more-employees scope since July 2023, the duty to run an internal reporting office, internal/external/hybrid models, and the three-month feedback deadline as a product promise. We found no public information on documentation duties, retention periods, per-country rule sets or the legal review behind the material, so the mapping covers one national law and stops short of demonstrated product implementation. 6 1

Report an error

The SME Operator

The pages get the basics right for a shop my size: the HinSchG and the EU directive are named, the duty to run an internal reporting office from 50 employees is stated, the platform promises an answer within three months, and internal, external or hybrid setups plus a full-service offer and 48-hour readiness are on the table. But we found no public information on the seven-day acknowledgment, documentation duties or retention periods being implemented in the product, and further legal modules are marked coming soon. 3 6

Report an error

The Group Counsel

The German-law page is more concrete than pure marketing: companies with 50 or more employees are named as in scope, the duty to establish an internal reporting office is spelled out, the three-month feedback duty is carried into the platform's own process description, and internal, external and hybrid setups are offered. We found no public information on the seven-day acknowledgment clock, documentation duties, retention and deletion rules, or any named counsel behind the mapping, and the data-protection module is marked as upcoming. 6

Report an error

The Security Auditor

The pages name the HinSchG and the EU Directive, the 50-employee applicability, the internal reporting-office duty, and the three-month feedback clock, which is more concrete than generic marketing. We found no public information on the seven-day acknowledgment duty, documentation obligations, retention and deletion periods, or any legal review standing behind the implementation. 6

Report an error

The Skeptic

HinSchG and the EU directive are named, and the 50-employee duty and the three-month feedback deadline are explained — but the mapping stops at marketing prose. I found no public information on statutory clocks implemented as product features, documentation or deletion duties, named legal counsel, or how legal updates are maintained, while data-protection and supply-chain-act modules are announced as 'Demnächst' (coming soon). 1 6

Report an error

Security & anonymity assurance

Show reasoning
How this is scored

Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.

0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.

3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.

5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.

8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.

10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".

Report an error

The Compliance Officer

The confidentiality promise rests on the words "anonyme & sichere Meldung", while penetration testing and cyber insurance are both marked as coming soon — so no test reports exist today. We found no public information on certifications, encryption architecture, metadata handling, or a security contact; for a 600-employee operation that is adjectives plus a roadmap. 1 6

Report an error

The Reporter's Advocate

The confidentiality promise rests on adjectives — "Anonyme & sichere Meldung" — with no certificates, encryption detail, penetration test reports, or metadata and IP-logging statements captured anywhere. The vendor's own homepage marks pentesting, cyber insurance and even the data protection section as "Demnächst" (coming soon), so there is nothing here a frightened reporter's lawyer could hold onto. 1 6

Report an error

The SME Operator

The confidentiality promise is captured as 'Anonyme & sichere Meldung' — a line of adjectives — while pentesting and cyber insurance are marked 'Demnächst', i.e. planned rather than in place today. We found no public information on certificates, encryption architecture, test reports or metadata handling, so if a regulator asked me how a reporter stays anonymous, the captured pages hand me nothing. 1 6

Report an error

The Group Counsel

Security assurance rests on the word "sicher" beside anonymous intake and an IT security checkup module, while pentesting and a cyber insurance are each marked "Demnächst" on the captured pages — a roadmap item is not assurance. We found no public information on certifications, encryption architecture, published test reports, or IP and metadata handling. 1 6

Report an error

The Security Auditor

This is adjective security: "Anonyme & sichere Meldung" with nothing behind it — pentesting is published as "Demnächst", and we found no public information on certificates, encryption architecture, IP or metadata logging, or a security contact and disclosure policy. The IT Security Checkup is a service sold to customers, not assurance of the whistleblowing platform itself. 1 4 6 7

Report an error

The Skeptic

'Anonyme & sichere Meldung' is a headline, not assurance: the vendor's own page lists pentesting as 'Demnächst' (coming soon), so the test is announced rather than attested. I found no public information on certificates, encryption architecture, penetration-test reports, or IP and metadata handling — a promise of anonymity with nothing auditable behind it. 1 6

Report an error

Group & multi-entity capability

Show reasoning
How this is scored

Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.

0 — One company, one channel; a group buys and administers N separate instances.

3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.

5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.

8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.

10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.

Report an error

The Compliance Officer

We found no public information on per-entity channels, separated case access for subsidiaries, delegated administration, ombudsman access, or a group-level overview — nothing on the captured pages addresses a corporate group structure at all. The only structure-related statements are the 50-employee scope and a software-plus-full-service offering. 6

Report an error

The Reporter's Advocate

We found no public information on separate channels per legal entity, group-level oversight, ombudsman access or white-labelling; the captured material addresses single companies from 50 employees with a software & full-service choice and internal, external or hybrid reporting-office models. As far as the public pages show, a corporate group would have to ask — and that conversation is not on the record. 6

Report an error

The SME Operator

We found no public information on separate channels per legal entity, group-level oversight, ombudsman access or per-entity branding. The captured material speaks to a single company from fifty employees upward, which happens to fit me, but a corporate group would have nothing documented to buy. 6

Report an error

The Group Counsel

We found no public information on per-entity channels, separated case access per subsidiary, delegated administration, external ombudsman roles, per-entity branding, or a group-level view. The only structural choice published concerns operating a single reporting office internally, externally, or as a hybrid — on this evidence I cannot roll one contract out to 25 subsidiaries with real access separation. 6

Report an error

The Security Auditor

Everything published frames a single company from 50 employees upward; we found no public information on per-entity channels, separated case access per entity, group-level oversight, ombudsman roles, or white-labeling. The internal/external/hybrid reporting-office options describe operating models, not group architecture. 6

Report an error

The Skeptic

I found no public information on separate channels per legal entity, separated case access per entity, group-level oversight, ombudsman roles, delegated administration, or white-labeling. The only configurability the pages show is choosing an internal, external, or hybrid reporting office — a service decision, not a group architecture. 6

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.

0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.

3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.

5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.

8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.

10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.

Report an error

The Compliance Officer

The vendor is a German GmbH with an imprint placing it in Zossen, Brandenburg, which at least puts the legal entity in Germany. We found no public information on where report data is hosted, on a published data processing agreement or subprocessor list, or on ownership, so the chain beyond the entity is undocumented for the most sensitive data we hold. 2 6

Report an error

The Reporter's Advocate

The imprint confirms a German GmbH, which is the one jurisdictional fact in the captures; beyond that we found no public information on data residency, ownership, a published DPA or subprocessors — the privacy page captured nothing and the data protection section is listed as coming soon. For whistleblowing data, that silence is itself an answer: I cannot tell a reporter where their report would live. 2 1

Report an error

The SME Operator

The imprint names a German GmbH, which is the one European signal on the captured pages. We found no public information on where report data is hosted, on data processing terms or on subprocessors — the data protection page itself is marked coming soon — so for the most sensitive data my company holds, the chain is undocumented in what was captured. 1 2

Report an error

The Group Counsel

The imprint and trademark statement put the contracting entity in Germany, so at least the legal form is European. We found no public information on hosting locations, named data centers, data processing terms, or a subprocessor list — for report content this sensitive, the residency and jurisdictional-reach questions remain open. 1 2

Report an error

The Security Auditor

The imprint confirms a German GmbH, the right jurisdiction for this data class, but that is where the chain ends: we found no public information on hosting location, named data centers, subprocessors, or a published DPA with TOMs. For the most sensitive data a company holds, silence on the rest of the chain earns almost nothing. 2 4

Report an error

The Skeptic

The imprint names konfidal GmbH as the operator, and there the documentation ends: I found no public information on hosting location, data centers, subprocessors, or a public data processing agreement — for the most sensitive data a company holds. A data-protection module announced as 'Demnächst' (coming soon) is a roadmap item, not a DPA. 1 2 4

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.

5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.

8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.

10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.

Report an error

The Compliance Officer

The only pricing-related statement we found is an invitation to request a free consultation; no tier prices, billing periods, employee-band boundaries, setup fees, or add-on prices appear on the captured pages. An obligated company cannot compute any invoice from what is public. 5 6

Report an error

The Reporter's Advocate

The only pricing-adjacent item captured is a free-consultation call-to-action ("Jetzt kostenlose Beratung anfordern"); we found no public information on tier prices, employee bands, setup fees, billing period or VAT treatment, even on the dedicated pricing page. An obligated company cannot compute an invoice from what is public, so every price is a conversation. 5 6

Report an error

The SME Operator

We found no public price figures on the captured pages — a German pricing page exists but no figures from it were confirmed — and the only commercial detail captured is an invitation to request a free consultation. For a 60-employee company like mine, the invoice begins with a sales call, which is precisely what my year-end review will not tolerate. 5 6

Report an error

The Group Counsel

We found no public information on prices: the captured pricing pages yielded no figures, and the only pricing-adjacent statement is an offer of a free consultation. An obligated company cannot compute any invoice — not even a starting one — from the public pages. 5 6

Report an error

The Security Auditor

No public prices at all: the captured pricing page yields no figures, and the route to a quote is "Jetzt kostenlose Beratung anfordern" — every tier is a sales conversation. An obligated company cannot compute any part of its invoice from what is published. 5 6

Report an error

The Skeptic

The only pricing-adjacent sentence I could find is an invitation to request a free consultation ('Jetzt kostenlose Beratung anfordern'); I found no public information on any tier price, employee-band boundaries, billing period, VAT treatment, or setup fees — even on the captured pricing page. Every price is a sales conversation. 5 6

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (7)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage www.konfidal.eu Checked 15 Sep 2026 Details →
  2. 2 Imprint www.konfidal.eu Checked 15 Sep 2026 Details →
  3. 3 German-market site www.konfidal.de Checked 15 Sep 2026 Details →
  4. 4 Privacy policy www.konfidal.eu Checked 15 Sep 2026 Details →
  5. 5 Pricing page (DE) konfidal.de Checked 15 Sep 2026 Details →
  6. 6 Legal compliance alignment — found from sitemap www.konfidal.eu Checked 1 Oct 2026 Details →
  7. 7 Security & anonymity assurance — found from sitemap www.konfidal.eu Checked 1 Oct 2026 Details →