Whistleblowing Portals
preeco | hinweisgeberschutz
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by preeco GmbH & Co. KG · www.preeco.de
Compare with EQS Integrity Line → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
preeco | hinweisgeberschutz, a German-hosted whistleblowing portal, is judged strongest at reporter intake: reporting channels & reporter experience scores 8-9, a one-point split over the self-assessed 'weitgehend kompatibel' WCAG 2.1 AA conformance and the one-line no-access-logs statement — the 8-point rationales treat both as capping, the 9-point ones weigh anonymous two-way dialog via Melde-ID and password, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG and up to 26 languages higher. Case management & deadline discipline holds at 7 on automatic 7-day/3-month clocks and a tamper-evident activity log, with no conflict-of-interest handling for implicated case handlers in the evidence. The weakest counted criterion is security & anonymity assurance at 4: preeco holds no own ISO 27001 (only the Hetzner datacenters are certified) and no pentest or disclosure policy appears. Legal compliance alignment lands at 5 with a single 6 — HinSchG is built into the product, but no second transposition or named counsel is evidenced. One-point spreads remain on group & multi-entity capability and sovereignty, turning on implied group reporting and the default-off OpenAI path; flagged splits flag none above threshold. Pricing is a separate individual offer (0-2, uncounted).
Speaks for it
- Fully anonymous intake with two-way dialog via Melde-ID and password, QR-code entry, and in-browser voice messages under § 16 Abs. 3 HinSchG
- Automatic 7-day/3-month statutory deadline monitoring per organisation with due dates shown in the case list
- Immutable reporter messages plus an admin-only, tamper-evident activity log recording old and new values, actor and timestamp
- Per-Mandant architecture with strict data separation, whitelabel branding, and new Mandanten created in under 3 minutes
- Hosting of Cloud and Private Cloud exclusively at ISO 27001-certified Hetzner datacenters in Nürnberg/Falkenstein with a public Art. 28 DPA naming Hetzner (DE) and UpCloud (FI)
Held against it
- No own ISO 27001 for the vendor — only the Hetzner datacenters are certified — with no pentest attestation or security disclosure policy in the evidence
- No conflict-of-interest mechanism to exclude implicated case handlers is evidenced anywhere
- Compliance evidence covers HinSchG only — no second national transposition, no per-country rule sets, no named counsel or documented legal review
- Accessibility is self-assessed ('weitgehend kompatibel' with WCAG 2.1 AA / EN 301 549 V3.2.1) rather than audited
- Ownership is undocumented in the evidence, and the optional AI path can send report content to OpenAI (US) if switched on
Best for
- You are a German-obligated organisation (from 50 Mitarbeitende) that wants HinSchG duties — 7-day acknowledgment, 3-month feedback, § 16 Abs. 3 voice intake — as product features rather than policy text
- You are an external DPO, consultant or ombudsperson managing many clients and need strict per-Mandant data separation behind one login
- You need reporters to stay fully anonymous while still holding a two-way dialog, including voice intake without a phone connection
- You require German-law contracting with Hetzner hosting in Nürnberg/Falkenstein and a published Art. 28 DPA with downloadable TOMs
Avoid if
- You operate across multiple jurisdictions and need per-country legal rule sets or transpositions beyond HinSchG — ask the vendor: the public pages we read do not show it
- You must satisfy a hostile security or procurement audit — ask the vendor: the public pages we read do not show it
- You need built-in conflict-of-interest lockout of implicated case handlers before external investigators can rely on the case file
- You require audited accessibility conformance rather than a self-assessed 'weitgehend kompatibel' declaration
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
The frightened reporter is actually served here: fully anonymous submission with two-way dialog via a protected Melde-ID/password area that works even for anonymous reports, in-browser voice messages grounded in § 16 Abs. 3 HinSchG without a phone connection, and QR-code entry, with up to 26 languages plus AI translation reviewed by the team. Accessibility is self-assessed WCAG 2.1 AA / EN 301 549 ('weitgehend kompatibel') rather than audited, and the no-access-logs promise is a single line — good, but not the documented anonymity engineering of the top anchor. 2 14 11 13
The Reporter's Advocate
This is intake built for the scared one: fully anonymous reporting with a protected two-way dialog (Melde-ID plus password) that explicitly works even when the report is anonymous, voice messages recorded in the browser under §16 Abs. 3 HinSchG with no phone call to trace, QR entry, 26 languages, no app install, and a stated 'no logs that allow inferences about whistleblowers'. Held below the top only because accessibility is self-assessed ('weitgehend kompatibel', not audited) and there is no telephone hotline at all for the reporter with a dumbphone. 2 14 13 11
The SME Operator
Fully anonymous form with genuine two-way dialog via Melde-ID and password even for anonymous reports, browser voice messages on a § 16 Abs. 3 HinSchG basis without any phone service, QR entry, 26 languages, WCAG 2.1 AA (self-assessed), no install, and an explicit 'keine Zugriffs-Logs' promise keeping identity out of the channel. Only a real hotline and independently audited accessibility are missing, so just under the 10 anchor. 2 14 11 13
The Group Counsel
Intake is genuinely engineered for the frightened reporter: fully anonymous reporting with a protected two-way dialog via Melde-ID and password even for anonymous reports, QR entry, in-browser voice messages under § 16 Abs. 3 HinSchG without a voice service provider, up to 26 languages, no install, and an explicit 'Keine Zugriffs-Logs, die Rückschlüsse auf Hinweisgebende ermöglichen'. Only the self-assessed 'weitgehend kompatibel' WCAG 2.1 AA/EN 301 549 conformance and the absence of any phone hotline keep this off the top anchor. 11 13 14 2
The Security Auditor
Web form with fully anonymous mode, QR-code entry, in-browser voice messages per §16 Abs. 3 HinSchG that work even anonymously, and two-way dialog via a protected area with Melde-ID and password — the anonymous dialog is first-class, not bolted on. 26 languages with optional DeepL translation and no install required round it out. Held below the top anchor because accessibility is only a self-assessed 'weitgehend kompatibel' with WCAG 2.1 AA and the 'no logs enabling conclusions about whistleblowers' claim is a one-line marketing statement, not documented engineering of how identity stays out of the channel. 2 14 11 1
The Skeptic
Anonymous web form, QR entry, in-browser voice messages per § 16 Abs. 3 HinSchG, secured two-way dialog via Melde-ID/password that works even fully anonymously, 26 languages, no install, and an explicit no-access-logs statement — that is rubric level 8 nearly line by line. It stays below 9 because WCAG 2.1 AA is only a self-assessment hedged as 'weitgehend kompatibel', not verified. 14 2 11 13
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The statutory clocks are the product's, not mine: automatic 7-day/3-month monitoring with automatic Fristsetzung per organization, due dates shown in the case list, and reminders; reporter messages and system entries cannot be edited or deleted, and the admin-only activity log records every change with old/new value, timestamp and actor — documentation that would survive a regulator. Deletion is scheduled per case after closure, but there is not one word on conflict-of-interest handling or excluding implicated case handlers, which is why it stops short of the top anchors. 2 7 14 1
The Reporter's Advocate
The statutory clocks are real product behaviour — 7-day and 3-month deadlines set automatically per organisation, reminders, a due-date column — with three separated roles and a genuinely tamper-evident record (immutable reporter messages, immutable activity log with old/new values, actor and timestamp). What keeps it under the 8 anchor: no conflict-of-interest mechanism to exclude an implicated case handler is evidenced anywhere, and management reporting is a filterable XLSX export rather than caseload oversight. 2 7 14
The SME Operator
The statutory clocks run themselves — automatic 7-day/3-month deadline setting per organization with reminders — and the three-role model confines Sachbearbeiter:innen to assigned cases, with immutable reporter messages and an immutable activity log for audit-proof history. No evidence of conflict-of-interest exclusion for implicated handlers, and management reporting is an XLSX export rather than built-in reporting, which holds it under the 8 anchor. 2 7 14
The Group Counsel
Automatic statutory clocks (7-day acknowledgment / 3-month feedback, configurable per organization, auto-set deadlines shown in the case list), three-role separation where Sachbearbeiter see only assigned cases, immutable reporter messages plus an immutable old/new-value activity log, and per-case deletion scheduling — nearly the 8-anchor. But the evidence is silent on conflict-of-interest handling that locks out implicated case handlers, which I need before an external investigator can rely on the case file. 14 2 7
The Security Auditor
Automated statutory clocks per organization (7-day/3-month) with reminders, immutable reporter messages, a tamper-evident activity log recording old and new values with actor and timestamp, and configurable GDPR deletion scheduling after case closure are all evidenced. rubric level 8's conflict-of-interest handling — excluding implicated case handlers — appears nowhere in the evidence, and management reporting is XLSX exports plus a dashboard, so 7. 2 7 14
The Skeptic
Automated statutory clocks (7-day/3-month) per organisation with visible deadlines, immutable messages and an admin-only, tamper-evident activity log with configurable retention, three-tier role separation and per-case deletion scheduling clear the 5-anchor comfortably. But there is not one word on conflict-of-interest handling — excluding an implicated case handler is a HinSchG basic, and deadline reminders are implied rather than evidenced, so it cannot reach 8. 2 7 14 8
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
The HinSchG is implemented as features, not marketing: automated deadline management, automatic acknowledgment 'gemäß HinSchG', a voice channel citing § 16 Abs. 3 HinSchG specifically, and configurable post-case deletion. But that is exactly one national law — no reference to Directive 2019/1937, no second transposition, no named counsel or documented legal review — so the single-law anchor is where it lands. 14 2 7
The Reporter's Advocate
One national law, implemented properly rather than invoked: HinSchG clocks as features, automatic acknowledgment, an applicability-area checklist export, voice intake citing §16 Abs. 3 by paragraph. But the evidence shows Germany only — EU Directive 2019/1937 is never named, no second transposition, no named counsel or documented legal review — so 'at least one national law, with guidance for the rest' is met, and the rest is simply absent. 14 2 7
The SME Operator
HinSchG is implemented as product, not marketing: automatic Eingangsbestätigung 'gemäß HinSchG', the 7-day/3-month clocks, § 16 Abs. 3 voice intake, an Anwendungsbereich-Checkliste export and 'HinSchG-konform entwickelt und betrieben'. That exceeds the single-law rubric level 5 in depth, but there is nothing on other national transpositions, named counsel or documented legal review, so it cannot approach 8. 14 2 7 1
The Group Counsel
The duties of one national law are real product features — automatic acknowledgment 'gemäß HinSchG', 7-day/3-month clocks, § 16 Abs. 3 voice intake, GDPR-conform deletion after case closure — which is the 5-anchor exactly. But only HinSchG is evidenced: no second national transposition, no per-country rule sets, no named counsel or documented legal review maintaining templates; for my dozen countries this is one jurisdiction's tool. 14 2 7
The Security Auditor
HinSchG duties are implemented as product features: automatic deadline setting tied to the three-month rule, automatic acknowledgment, and voice intake citing §16(3) — one national law done properly, which is the anchor-5 definition. No mention of EU Directive 2019/1937 or any other national transposition, no named counsel, no documented legal review, and updates when the law moves is only asserted for other modules (NIS2/DORA). 14 7 2
The Skeptic
The HinSchG duties are real product features, not brochure text: automatic 7-day/3-month clocks, § 16 Abs. 3 voice intake, automatic acknowledgment, per-case deletion — that is exactly rubric level 5 for one national law. No evidence of any second transposition, no per-country rule sets, no named counsel or documented legal review behind the 1,200+ templates; 'HinSchG-konform entwickelt und betrieben' is an unaudited vendor assertion and the update promise ('DSGVO-Updates werden zeitnah umgesetzt') has no lawyer's name on it. 14 2 1 7
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
Two of the three mid-anchor elements are there: ISO 27001 (Hetzner data centers, Germany) and an explicit statement that no logs allow inferences about reporters, plus enforceable team-wide TOTP 2FA. But preeco itself admits it holds no ISO 27001 certification, encryption is TLS plus AES-at-rest for essential data — not end-to-end, with no architecture documentation — and there is no pentest attestation and no disclosure policy; I could not answer a hostile auditor with this file. 14 2 9
The Reporter's Advocate
The anonymity line I care about is explicit — 'keine Zugriffs-Logs, die Rückschlüsse auf Hinweisgebende ermöglichen' — but the engineering evidence around it is thin: TLS plus AES on reporter correspondence is asserted, ISO 27001 covers only the Hetzner datacenters, and preeco itself states it holds no certification. No pentest, no end-to-end architecture, no disclosure policy, and nobody answers 'how would you unmask a reporter?' beyond that one no-logs sentence. 14 2 9 1
The SME Operator
The vendor admits it plainly: 'preeco GmbH aktuell keine eigene ISO 27001 Zertifizierung' — only the Hetzner datacenters are certified — and the evidence shows no pentest report, no security contact or disclosure policy, and AES only on 'essentielle Daten' rather than end-to-end encryption. The explicit no-access-logs statement, enforceable TOTP-2FA and AES-256 backups earn it above rubric level 3, but nothing here is audited for the product itself. 14 2 9
The Group Counsel
SSL/TLS in transit and AES for essential data at rest, team-enforceable TOTP with brute-force protection, AES-256 off-site backups, and the no-access-log statement are real, but preeco itself holds no ISO 27001 (only the Hetzner data centers do), there is no pentest attestation, no end-to-end encryption claim, and no security contact or disclosure policy. A hostile auditor would walk away unconvinced. 9 14 2
The Security Auditor
The vendor states it holds no own ISO 27001 — the certificate covers only the Hetzner datacenters — and no penetration test is published anywhere in the registry; encryption is SSL/TLS plus AES on 'essential' database fields, meaning the operator can read report content, and no end-to-end architecture is documented. Credit for the explicit 'no logs that enable conclusions about whistleblowers' statement, team-enforceable TOTP 2FA with brute-force protection, and an AI path that by default never transmits reporter identity and deletes content in 7 days — enough to lift it just above unaudited adjectives. 14 9 2
The Skeptic
Credit where due: they admit plainly 'Aktuell keine eigene ISO 27001 Zertifizierung' — only the Hetzner datacenters are certified — and the no-logs pledge ('Keine Logs, die Rückschlüsse auf Hinweisgebende ermöglichen') is specific, with 2FA and AES-256 backups on top. But that is where it ends: no vendor ISMS, no penetration test ever mentioned, no security contact or disclosure policy, TLS+AES-at-rest instead of any end-to-end claim — and an optional OpenAI integration that would ship report content to a US model, off by default or not. That is a 3-anchor lifted one notch by honesty, not an 8. 14 2 9 1
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
This is a real Mandant architecture, not N instances in a trenchcoat: per-entity settings, users and strict data separation with one-click central switching, per-organization deadlines, notifications and languages, ombudsperson and Sachbearbeiter roles scoped per organization with assignment-only visibility, whitelabel branding and own domain from Private Cloud, and a claim of hundreds of Mandanten managed centrally with new ones in under three minutes. What is missing for the top is per-country legal rule assignment per entity and a true consolidated group-level statistics view. 12 2 1 7
The Reporter's Advocate
Mandanten are first-class architecture, not an account switcher: per-entity organisations with own settings, handlers and whitelabel branding (own domain from Private Cloud), ombudsperson access scoped to their organisations, per-tenant languages and module flags, central administration of 'hunderte Mandanten' created in under three minutes. Missing from the 10 anchor: no per-country legal rule assignment per entity and no documented group-level reporting that respects entity boundaries. 12 1 2 14
The SME Operator
Mandanten are real architecture: strict data separation, per-entity settings, users and modules, whitelabel logo and colors (own domain from Private Cloud up), and an ombudsperson role scoped to their organizations; new Mandanten in under three minutes suits my afternoon-deployment instinct. Group-level consolidated reporting that respects entity boundaries and delegated administration are simply not evidenced, so it sits between the 5 and 8 anchors. 12 2 14 1
The Group Counsel
This is the architecture I look for: per-Mandant channels with strictly separated users, settings and languages ('Jeder Mandant erhält eigene Einstellungen, Dokumente und Nutzer'), central administration with one-click switching, new entities in under three minutes, whitelabel per organization, and external ombudspersonen managing hundreds of Mandanten through one login. It misses the 10-anchor because per-country legal rule assignment per entity does not exist (HinSchG only), own domains start only at Private Cloud, and consolidated group reporting that respects entity boundaries is only implied by central admin and XLSX statistics. 12 14 2 1
The Security Auditor
Per-tenant channels with strict data separation and own users, per-organization branding with own domain from Private Cloud, central administration with one-click tenant switching, a dedicated ombudsperson role, and documentation that external DPOs and ombudspersons manage hundreds of Mandanten centrally. Missing only the anchor-10 items: per-country legal rule assignment per entity, and white-label/own domain is withheld below the Private Cloud tier. 12 2 1 14
The Skeptic
Genuine multi-tenancy is documented: per-entity channels with strict data separation, per-tenant languages, modules and whitelabel branding, ombudsperson and per-report role scoping, hundreds of Mandanten manageable from one login in under 3 minutes. Missing for an 8-to-10: group-level consolidated reporting that respects entity boundaries is only implied by XLSX exports, delegated per-entity administration is not spelled out, and there is no per-country legal rule assignment whatsoever. 12 1 2 14
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The default chain is jurisdictionally clean: German GmbH in Ulm under German law, hosting exclusively in named Hetzner data centers in Nürnberg/Falkenstein, storage location Germany, no third-country transfer, and a published AVV listing only EU subprocessors (Hetzner DE, UpCloud FI) with downloadable TOMs. On-premises exists but is restricted to the public sector and Enterprise segment, and the optional AI endpoints can point at OpenAI — opt-in and default-off, but it means the clean chain is a configuration choice, not an architecture guarantee. 9 10 14 5
The Reporter's Advocate
A German GmbH under German law (HRB 737082, venue Ulm), hosting exclusively at Hetzner Nürnberg/Falkenstein with 'keine Übermittlung in Dritländer', a published DPA, downloadable TOMs and a subprocessor list with objection rights — Hetzner (DE), UpCloud (FI, monitoring only). Two honest deductions from 10: the optional DeepL translation of report content has no documented jurisdiction in the evidence, and the AGB itself never states where the cloud data lives — the EU-only promise lives in the privacy policy. 9 14 10 4
The SME Operator
German GmbH with Ulm register entry, hosting exclusively in named Hetzner datacenters in Nuremberg/Falkenstein with 'Speicherort Deutschland' for cloud and private cloud, no third-country transfer, plus a public DPA with downloadable TOMs and a 2-week subprocessor notice naming only EU processors (Hetzner, UpCloud for internal monitoring). It misses 10 because ownership is undocumented and the opt-in AI path can send report content to OpenAI if switched on. 3 9 10 14 4
The Group Counsel
German entity (preeco GmbH, Ulm, HRB 737082), German law and venue Ulm, exclusive Hetzner hosting in Nürnberg/Falkenstein for Cloud and Private Cloud with 'keine Übermittlung in Dritländer', a public DPA naming its EU subprocessors (Hetzner, UpCloud-for-monitoring) with a two-week objection right, downloadable TOMs, and an on-premises option. The 10-anchor slips because ownership is undocumented and the optional, default-off AI path can push report content to US-based OpenAI if a tenant opts in. 3 5 9 10 14
The Security Auditor
German GmbH in Ulm under German law with venue Ulm, hosting exclusively at named Hetzner datacenters in Nuremberg/Falkenstein with offsite backup in Falkenstein, and a public Art. 28 DPA naming subprocessors Hetzner (DE) and UpCloud (FI, monitoring only) plus downloadable TOMs. Ownership is undocumented, the AGB only vaguely reference 'von preeco genutzte Rechenzentren' while the Germany-only statements live in the product spec and privacy policy, and optional US AI endpoints (off by default) are the one content-touching wrinkle — 8, not 10. 3 9 10 14 4
The Skeptic
German GmbH in Ulm with HRB number, German law and venue, Hetzner-only hosting in named German datacenters (Nürnberg/Falkenstein), a public DPA with TOMs, audit rights and EU subprocessors (Hetzner, UpCloud-Finland), plus an on-premises option — most of rubric level 8 is evidenced. Two things hold it back: an opt-in OpenAI (US) integration touches report content and appears nowhere in the published subprocessor list, and ownership/jurisdiction are flagged unknown in the evidence — a GmbH & Co. KG versus GmbH naming discrepancy I do not reward. 3 9 10 14 2
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — there is not one public number in the entire sheet, so no obligated company can compute anything; the pricing factors (Mandanten, headcount, hosting variant) tell me the axes of the invoice but never the amounts. The published contract mechanics — no setup fees, no cancellation period, VAT excluded, monthly or annual billing — are the only thing keeping this off an absolute zero. 14 5
The Reporter's Advocate
Not one public price appears anywhere in the evidence; the Leistungsbeschreibung itself says the licensing and pricing model is created as a separate individual offer from named factors (mandanten, headcount, hosting variant, licence model). Every invoice is a sales conversation, so an obligated company can compute nothing from public pages — the 0 anchor, verbatim. 14 5
The SME Operator
No public prices at all — the license and price model is a separate, individual offer — so my two-minute invoice exercise is impossible and every quote is a sales call. I credit the unusually clean terms: no setup fees, no cancellation periods, VAT treatment and billing period stated, free trial and free onboarding, but rubric level 3 requires at least an entry price and there isn't one. 14 5 2
The Group Counsel
The license and price model 'wird als separates, individuelles Angebot erstellt' — the factors (number of Mandanten, employees, hosting variant) and terms (no setup fees, no cancellation period, net prices, 30-day trial) are published, but not one euro figure is. A 60-employee company or my 5-entity group cannot compute anything from public pages; this is a sales conversation in writing. 5 14
The Security Auditor
'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — no public price for any tier, so an obligated company cannot compute anything; this is the anchor-0 situation of every tier being a sales conversation. The pricing dimensions (organizations, employee count, hosting variant, license model), no-setup-fee claim, billing periods and VAT treatment are at least disclosed, which is the only thing lifting it above zero. 14 5
The Skeptic
The spec states outright: 'Das Lizenzierungs- und Preismodell wird als separates, individuelles Angebot erstellt' — pricing factors are named (entities, employees, hosting variant, license model) but no tier, band or amount is public anywhere in the evidence. Premium support has a FAQ question about its cost with no captured answer; the contract mechanics are clean (no setup fees, VAT excluded, 30-day price-increase notice) but an obligated company cannot compute a single euro from public pages. 14 5 6
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 23 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors, Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 127 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 40 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 37 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 32 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 32 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 12 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (23)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 15 Sep 2026, 11 Sep 2026, 24 Aug 2026 Details →
- 2 Product page www.preeco.de Checked 5 Oct 2026 +4 earlier captures: 16 Sep 2026, 11 Sep 2026, 24 Aug 2026, 23 Aug 2026 Details →
- 3 Imprint www.preeco.de Checked 5 Oct 2026 Details →
- 4 Privacy policy www.preeco.de Checked 5 Oct 2026 Details →
- 5 Terms www.preeco.de Checked 5 Oct 2026 Details →
- 6 Product documentation library www.preeco.de Checked 5 Oct 2026 +2 earlier captures: 15 Sep 2026, 24 Aug 2026 Details →
- 7 Deadline automation doc www.preeco.de Checked 5 Oct 2026 +3 earlier captures: 11 Sep 2026, 24 Aug 2026, 24 Aug 2026 Details →
- 8 Notification routing doc www.preeco.de Checked 5 Oct 2026 +2 earlier captures: 24 Aug 2026, 24 Aug 2026 Details →
- 9 Hosting variants page www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 16 Sep 2026 Details →
- 10 Published DPA (AVV) for cloud customers www.preeco.de Checked 5 Oct 2026 Details →
- 11 Accessibility statement www.preeco.de Checked 5 Oct 2026 Details →
- 12 Multi-entity use case page www.preeco.de Checked 5 Oct 2026 Details →
- 13 Multilingualism use case page www.preeco.de Checked 5 Oct 2026 Details →
- 14 Full product specification (Leistungsbeschreibung) www.preeco.de Checked 5 Oct 2026 +1 earlier capture: 16 Sep 2026 Details →
- 15 Reporting channels & reporter experience — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 16 Reporting channels & reporter experience — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 17 Case management & deadline discipline — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 18 Case management & deadline discipline — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 19 Legal compliance alignment — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 20 Security & anonymity assurance — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 21 Security & anonymity assurance — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 22 Group & multi-entity capability — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →
- 23 Group & multi-entity capability — found from sitemap www.preeco.de Checked 5 Oct 2026 Details →