Whistleblowing Portals
NAVEX One EthicsPoint
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by NAVEX Global, Inc. · www.navex.com
Compare with SpeakUp → Compare with EQS Integrity Line → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
NAVEX One EthicsPoint, the flagship hotline product of US vendor NAVEX Global, Inc., is strongest at intake and casework: reporting channels & reporter experience runs 6-8 and case management & deadline discipline 6-7, built on 24/7 web, mobile and phone channels in 60+ languages with anonymous or named reporting, two-way dialogue, machine translation of follow-ups, auditable case history and implicated-party screening. Weaknesses are structural. Security & anonymity assurance sits at 2-3 on asserted 'secure data hosting and encryption' with no ISO 27001, SOC 2 or pentest in evidence, and the privacy statement discloses cookies, beacons, tags and scripts, including targeted-advertising cookies, inside the Application. Legal compliance alignment tops out at 4: the EU Whistleblowing Directive appears only as marketing, no national transposition is named, and retention is 'as directed by our business customer'. The real split is sovereignty: the compliance officer credits 'Data is stored in the EU' on the WhistleB page; the group counsel scores 1 because that claim attaches to the sibling, not the flagship, under a US processor with no published DPA or subprocessor list. Public pages carry no prices — pricing transparency is 0 — uncounted in these verdicts.
Speaks for it
- 24/7 web, mobile and phone intake in 60+ languages with anonymous or named reporting, two-way dialogue and machine translation of follow-ups
- Auditable case history with per-user view/edit visibility, role-based permissions and AI-enhanced implicated-party screening
- Audit-ready data export and Power BI dashboards for board-ready reporting
- Built-in AI case summaries, related-case surfacing and the Nira AI agent guiding report intake
- Reporting extended to contractors and suppliers, with integration into existing whistleblowing, HR and risk systems
Held against it
- No ISO 27001, SOC 2, pentest or documented encryption architecture appears anywhere in the evidence, only asserted 'secure data hosting and encryption'
- The privacy statement discloses cookies, beacons, tags and scripts collecting personal information inside the Application, including targeted-advertising cookies
- Statutory 7-day acknowledgment and 3-month feedback clocks are never named as automated features, and retention is 'as directed by our business customer'
- The EU Whistleblowing Directive appears only as marketing language, with no national transposition named
- No published DPA, subprocessor list or named data centers appears in the evidence, and the evidence's sovereignty attributes are all unknown
Best for
- You need broad speak-up intake — 24/7 web, mobile and phone channels in 60+ languages — for a large multilingual workforce
- You run complex investigations and need auditable case history, implicated-party screening and audit-ready export for leadership and regulators
- You want AI-assisted triage — case summaries, related-case surfacing and Nira AI intake guidance — inside an enterprise compliance platform
- You must extend reporting beyond employees to contractors and suppliers
Avoid if
- You need evidenced security assurance — ISO 27001, SOC 2 or pentest reports — before routing sensitive reports to a vendor
- You operate under a named national transposition of the EU Whistleblowing Directive and need automated 7-day/3-month statutory clocks
- You require documented sovereignty — a published DPA and subprocessor list — rather than a single 'Data is stored in the EU' claim on the WhistleB sibling page
- You are a corporate group needing per-legal-entity channels, entity-separated case access and delegated administration — ask the vendor: the public pages we read do not show it
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
Web, mobile and phone intake, anonymous or named, 60+ languages with two-way dialogue and machine translation of report details and follow-ups — that satisfies the 8 anchor almost fully. It stops short of 10 because the vendor documents nothing about keeping reporter identity out of the channel itself, and there is no accessibility or QR-entry evidence. 4 2 3
The Reporter's Advocate
Web, mobile and phone intake 24/7 in 60+ languages, anonymous or named, with machine translations for report details and follow-ups — that serves the night-shift caller well. But nothing shows the mobile route needs no app or account, accessibility is never mentioned, and the privacy statement admits cookies, beacons, tags and scripts collect personal information inside the Application — nobody documents that the reporter's identity stays out of the channel itself. 4 2 3 5
The SME Operator
Web, phone and mobile intake 24/7 in 60+ languages, anonymous or named, with two-way dialog and machine translations of follow-ups — the complete channel set an obligated company needs. It stops short of the top anchor: no accessibility statement, no QR entry, and nothing documenting how the reporter's identity is kept out of the channel itself. 4 3
The Group Counsel
Web, mobile and 24/7 phone intake, anonymous by default across channels, 60+ languages with machine translation for reports and follow-ups, and two-way dialogue — that is the intake footprint my subsidiaries' workforces need. It stops short of the top anchor because nothing addresses accessibility, QR or low-friction entry, and no documentation explains how the reporter's identity is kept out of the channel itself. 4 2 3
The Security Auditor
Web, mobile and phone intake in 60+ languages with two-way dialogue and machine translation of follow-ups is genuinely broad. But nothing documents how the reporter's identity stays out of the channel, and the privacy statement admits beacons, tags, scripts and targeted-advertising cookies operating inside the application — tracking tech in the intake path actively undermines anonymity at first contact. 4 2 3 5
The Skeptic
Web, mobile and phone intake 24/7 in 60+ languages with anonymous reporting, two-way dialogue and machine translation is a real intake story. But the vendor's own privacy statement admits the Application collects personal information via cookies, beacons, tags and scripts, so nobody has shown anonymity survives first contact, and accessibility and QR entry points are entirely unevidenced. 4 3 5
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
Implicated-party screening, complete auditable case history with per-user view/edit visibility, and genuine management reporting are evidenced — that is real discipline, not an inbox. But the statutory clocks surface only as generic 'reminders' with no 7-day/3-month automation named, and retention is 'as directed by our business customer', so per-case deletion rules remain my problem. 4 2 3 5
The Reporter's Advocate
Complete auditable case history, per-user view/edit visibility, role-based permissions with safeguards that keep implicated parties out of case files, and Power BI management reporting. It falls short of the top anchors because 'reminders' is the only nod to deadlines — no evidenced 7-day/3-month statutory clocks — and retention is explicitly 'as directed by our business customer', so deletion discipline is outsourced. 2 3 5
The SME Operator
Complete auditable case history, per-user view/edit visibility, role-based permissions with implicated-party exclusion, automated escalations and board-ready reporting are genuinely there. But the statutory 7-day/3-month clocks are never named as automated features, and retention is 'retained as directed by our business customer' — the deadline and deletion duties stay on my desk, not the product's. 4 2 3 5
The Group Counsel
Implicated-party screening that blocks access, complete auditable case history with per-user view/edit logging, and audit- and board-ready reporting (Power BI) are all evidenced. But the statutory machinery is absent: no 7-day acknowledgment or 3-month feedback clock anywhere in the evidence, and retention is whatever the business customer directs rather than legally aware automation — so it sits below the anchor it almost reaches. 2 3 5
The Security Auditor
Full auditable case history, per-user view/edit visibility, implicated-party exclusion and audit-ready export are real, evidenced features. But statutory clocks surface only as vague "reminders", and retention is "as directed by our business customer" — no legally aware deadline or retention automation is demonstrated in the product itself. 4 2 3 5
The Skeptic
Audit trails, activity logging, escalation automation, implicated-party screening and audit-ready export are genuinely evidenced. But 'reminders' is generic — no 7-day acknowledgment or 3-month feedback clock is ever named — and retention is explicitly pushed onto the customer ('retained as directed by our business customer'), so the statutory discipline is asserted workflow, not law-aware automation. 4 2 3 5
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
'Alignment with the EU Whistleblowing Directive and national legislation' is marketing mapping, not implementation: no national transposition named, no legal templates, no counsel review, and the privacy statement confirms deadline, documentation and retention duties are the customer's to direct. The dedicated EU-focused product line keeps this just above pure label-wearing. 4 2 5
The Reporter's Advocate
The directive appears only as marketing: 'meet whistleblowing requirements like the EU Whistleblowing Directive and SOX' and WhistleB's 'alignment with the EU Whistleblowing Directive and national legislation' name no transposition, no implemented deadline rule, no legal review. Retention periods are delegated to the customer, which is exactly the anchor-3 pattern of vague invocation and shifted burden. 2 5
The SME Operator
The EU Whistleblowing Directive appears as a marketing bullet and WhistleB claims alignment with 'national legislation', but no transposition is named, no acknowledgment/feedback clocks are evidenced, and retention is customer-directed. The mapping is exactly what rubric level 3 describes — invoked, vague, and my problem. 2 3 5
The Group Counsel
The directive exists here only as marketing vocabulary — 'Confidently meet whistleblowing requirements like the EU Whistleblowing Directive and SOX' — with no national transposition named (HinSchG et al. nowhere), no deadline features, no legal templates and no counsel review. WhistleB's 'alignment with the EU Whistleblowing Directive and national legislation' is the same vagueness in regional packaging, and retention duties are explicitly the customer's problem. 4 2 3 5
The Security Auditor
The directive appears as a marketing checkbox — "meet whistleblowing requirements like the EU Whistleblowing Directive and SOX" — with no acknowledgment/feedback clocks, no national transposition detail, no named legal review. WhistleB's "alignment with the EU Whistleblowing Directive and national legislation" is the same adjective pattern, and deadline/retention duties are explicitly delegated to the customer. 4 2 3 5
The Skeptic
The Directive appears only as a marketing checkbox — 'Confidently meet whistleblowing requirements like the EU Whistleblowing Directive and SOX'. No national transposition is named (HinSchG nowhere), no counsel or legal review is documented, and retention periods are literally the customer's problem: the mapping is vague, exactly the anchor-3 failure mode. 2 3 5
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
Encryption, MFA and role-based permissions are asserted, but nothing is audited — no ISO 27001, no pentest, no encryption architecture. And it is worse than metadata silence: the privacy statement discloses cookies, beacons, tags and scripts collecting personal information within the Application, which is an anonymity problem for a whistleblowing channel. 4 3 5
The Reporter's Advocate
Encryption and 'privacy protections built into AI-supported tools' are asserted words, and MFA plus role-based access are real, but there is no certificate, no pentest, no no-IP-logging statement anywhere in the registry. Worse, the privacy statement affirmatively discloses collection of personal information via cookies, beacons, tags and scripts inside the Application — for a product promising anonymity, silence on metadata plus an affirmative collection statement is the opposite of assurance. 4 3 5
The SME Operator
'Secure data hosting and encryption' plus MFA is assertion, not assurance: no ISO 27001, no pentest, no word on IP or metadata logging. The privacy statement admits cookies, beacons, tags and scripts 'within the Application' and targeted-advertising cookies in the preferences tool — the opposite of metadata minimization next to an anonymous hotline. 4 3 5
The Group Counsel
Encryption, MFA and role-based permissions are asserted, but nothing is audited — no ISO 27001, no pentest, no statement on IP logging. Worse than silence: the privacy statement admits cookies, beacons, tags and scripts collect personal information inside the Application, with targeted-advertising cookies governed by a preference tool — a whistleblowing channel that tracks sessions in its own app is an anonymity problem, not just a gap. 4 3 5
The Security Auditor
"Secure data hosting and encryption" is adjective security: no ISO 27001 or equivalent, no pentest, no documented E2E architecture, no no-IP-logging statement anywhere in the evidence. Worse than silence, the privacy statement discloses cookies, beacons, tags and scripts collecting personal information inside the application, including targeted-advertising cookies — metadata harvesting in the very channel sold as anonymous; MFA and role-based permissions are access control, not anonymity assurance. 4 3 5
The Skeptic
No ISO 27001, no SOC 2, no pentest, no encryption architecture — just 'secure data hosting and encryption' plus MFA/RBAC, and silence on end-to-end encryption and IP logging. Worse, the vendor documents collecting personal information inside the Application through cookies, beacons, tags and scripts, including targeted-advertising cookies: 'anonymous reporting' sitting next to beacons is marketing, not engineering. 4 3 5
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
Regional custom workflows, role-based permissions and multinational enterprise positioning are evidenced, but the evidence never mentions per-entity channels, delegated administration, or a group overview that respects entity boundaries. The Fortune-500 customer base implies scale; the evidence does not show the multi-tenant mechanics. 2 3
The Reporter's Advocate
'Global collaboration across languages and regions' and up to two custom workflows for regions hint at groups, and 13,000+ customers with 75% of the Fortune 500 prove big companies buy it. But the evidence never evidences per-entity channels, per-entity branding, ombudsman access or case-access separation along legal-entity lines — I see the customer list, not the architecture. 2 3 1
The SME Operator
Enterprise positioning with region-specific workflows, role permissions and giant scale claims (88M employees, 75% of Fortune 500), but the evidence never documents per-entity channels, separated case access per legal entity, or a group-level view. Scale claims are not multi-tenant architecture, and nothing on delegated administration or ombudsman access. 2 3
The Group Counsel
This is the make-or-break for a 25-subsidiary rollout, and the evidence is silent on per-entity channels, delegated administration, external ombudsman roles and group reporting that respects entity boundaries — nothing beyond 'enterprise organizations meeting multinational regulatory requirements'. 'Up to two custom workflows' for teams, departments or regions plus 'global collaboration' and a central dashboard is single-tenant phrasing, not a multi-tenant group structure. 2 3
The Security Auditor
Scale is marketed — 13,000+ customers and Fortune 500 penetration, workflows "for specific teams, departments or regions" — but nothing evidences per-legal-entity channels, case access separated per entity, delegated administration, external ombudsman roles, or group reporting respecting entity boundaries. Custom workflows cap at two, which is thin for a corporate group. 2 3 1
The Skeptic
The product targets multinationals with investigations 'across multiple teams, regions and reporting channels' and regional custom workflows, but that is positioning, not architecture. The evidence is silent on per-legal-entity channels, entity-bound case separation, delegated administration, ombudsman roles and white-labeling — missing evidence is information, and none of it is here. 2 3
European sovereignty
panel opinion
panel disagrees
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
'Data is stored in the EU' is stated for the EU product line, but the vendor is a US entity acting as processor for the most sensitive data we hold, and no DPA, subprocessor list or TOMs appear anywhere in the evidence. Subprocessor exposure to non-EU jurisdictional reach is entirely undocumented. 4 5
The Reporter's Advocate
WhistleB promises 'Data is stored in the EU', but this is a Lake Oswego, Oregon vendor, and every sovereignty attribute in the evidence is unknown: no DPA, no subprocessor list, no named data centers, with NAVEX acting merely as the customer's processor. EU storage asserted by a US entity over an undocumented chain is barely a step above the floor. 4 5
The SME Operator
NAVEX Global, Inc. is an Oregon company, and 'Data is stored in the EU' on the WhistleB page is the only sovereignty fact offered — no published DPA, no subprocessor list, no named data centers, and the evidence's own attributes are all unknown. For the most sensitive data a company holds, undocumented beats only total silence. 4 5
The Group Counsel
The vendor is a US entity (NAVEX Global, Inc., Lake Oswego, Oregon, BC Partners-backed), and the only EU-hosting claim — 'Data is stored in the EU', GDPR-first architecture — attaches to the acquired WhistleB sibling, not to the flagship. No public DPA or subprocessor list is in evidence, and the application runs targeted-advertising cookies; for the most sensitive data a group holds, that is anchor-zero territory with one sibling-product credit. 4 5
The Security Auditor
The vendor is a US company (Lake Oswego, Oregon; BC Partners-backed) and the evidence publishes no DPA, no subprocessor list, and no named data centers; the single jurisdictional fact is "Data is stored in the EU" on the WhistleB sibling page, while processing is governed by the parent's privacy statement as processor. That is US-jurisdiction-reachable processing of the most sensitive data a company holds, documented at adjective level. 4 5 1
The Skeptic
The vendor is a US entity (Lake Oswego, Oregon) and every sovereignty attribute — ownership, residency beyond one bare 'Data is stored in the EU' sentence, subprocessors — is unknown; no published DPA or subprocessor list appears anywhere in the evidence. Targeted-advertising cookies hint at ad-tech exposure, and for the most sensitive data a company holds, one unverifiable hosting claim does not cut it. 1 4 5
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
Three solutions, one described as 'fast, affordable', and not a single number anywhere — no tiers, bands, billing periods or setup fees. No obligated company can compute any invoice from these pages; everything is a sales conversation. 2 3
The Reporter's Advocate
The pages sell three solutions and a 'fast, affordable way', and a professional tier for enterprises, but not a single number — no prices, bands, entity rules or setup fees — appears anywhere in the registry. Every tier is a sales conversation, which is the definition of the zero anchor. 2 3
The SME Operator
'Fast, affordable' is the entirety of the pricing language; not one number, band boundary or setup fee appears anywhere in the evidence. Every tier is a sales conversation plus a Professional Services team to buy — I cannot compute the invoice for a 60-employee company, and my year-end review needs an invoice, not a negotiation. 2 3
The Group Counsel
There is not a single number in the evidence: three named solutions with 'fast, affordable' positioning and sales-led Professional Services, and every tier routed to a conversation. Neither a 60-employee subsidiary nor my 25-entity group could compute one line of the invoice from public pages. 2 3
The Security Auditor
Three solutions are named — Essentials, Professional, WhistleB — and not one carries a number; the closest the evidence gets to a price is "fast, affordable". Every invoice is a sales conversation, so an obligated company can compute nothing from public pages. 2
The Skeptic
Not a single number in the entire the evidence: three solutions exist (Essentials, Professional, WhistleB) and the closest thing to a price is 'a fast, affordable way'. An obligated company cannot compute any invoice from public pages — rubric level 0. 2
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in US ⚠ unverified | 0/3 pts | 16 Report an error |
|---|---|---|---|
| Ownership | Not determined ⚠ unverified | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 23 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Ownership, Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Legal entity. The address appears on a third-party service provider list rather than an imprint, and no commercial register entry is given.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 82 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 28 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 19 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (16)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.navex.com Checked 16 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
- 2 Whistleblowing solutions overview www.navex.com Checked 16 Sep 2026 +1 earlier capture: 23 Aug 2026 Details →
- 3 EthicsPoint product page www.navex.com Checked 16 Sep 2026 +1 earlier capture: 23 Aug 2026 Details →
- 4 WhistleB (EU product) page www.navex.com Checked 16 Sep 2026 Details →
- 5 Privacy statement www.navex.com Checked 16 Sep 2026 +1 earlier capture: 23 Aug 2026 Details →
- 6 Terms of service www.navex.com Checked 30 Sep 2026 Details →
- 7 Reporting channels & reporter experience — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 8 Reporting channels & reporter experience — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 9 Case management & deadline discipline — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 10 Case management & deadline discipline — found from sitemap support.navex.com Checked 1 Oct 2026 Details →
- 11 Legal compliance alignment — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 12 Legal compliance alignment — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 13 Security & anonymity assurance — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 14 Security & anonymity assurance — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 15 Group & multi-entity capability — found from sitemap www.navex.com Checked 1 Oct 2026 Details →
- 16 Group & multi-entity capability — found from sitemap www.navex.com Checked 1 Oct 2026 Details →