Whistleblowing Portals
Red Flag Reporting
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Red Flag Reporting LLC · redflagreporting.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Red Flag Reporting LLC, whose services are "available for purchase by organizations only," markets hotline intake across ethics, compliance, safety, fraud and whistleblower lines plus a product described as "an easier, more powerful, more secure hotline + incident case management solution." Reporting channels is the bench's strongest criterion, with scores clustered at 2; security assurance sits at 0, the tagline's "more secure" being the only security content captured. Compliance alignment, sovereignty, multi-entity scale and pricing transparency each span 0 to 1, and case management spans 1 to 2; the flagged splits flag none of these spreads, so the bench shows no material split — the pattern across the judges is capability named but not evidenced. We found no public information on anonymous filing, statutory deadline tracking, EU Directive 2019/1937 mapping, hosting location, a data processing agreement or a subprocessor list. Persona-weighted totals range from 0.4 to 1.3.
Speaks for it
- Markets hotline intake across ethics, compliance, safety, fraud and whistleblower lines, where reporting channels scores cluster at 2.
- Names incident case management as part of the offering, with case management scores spanning 1 to 2.
- Publishes a 3-step implementation framework ending in 'launch with ease.'
Held against it
- Security assurance scores cluster at 0, the tagline's 'more secure' being the only security content captured.
- We found no public information mapping any feature to EU Directive 2019/1937 or a national transposition, and compliance alignment spans 0 to 1.
- No sovereignty attributes are on record — we found no public information on hosting location, a data processing agreement or a subprocessor list.
- We found no public information on anonymous filing, two-way follow-up, language coverage or accessibility for reporters.
- We found no public information on per-entity channels or a consolidated group view, and multi-entity scale spans 0 to 1.
Best for
- You want a hotline and incident case management offering to shortlist for a sales conversation, since the named capability set is the core of the public record.
- You value a quick start — the published launch path is three steps, from answering questions to 'launch with ease.'
- You are an organization (sales are to organizations only) seeking an intake channel spanning ethics, compliance, safety, fraud and whistleblower lines.
Avoid if
- You must show documented security assurance — certificates, penetration tests, encryption or metadata handling — before a single report is filed.
- You answer to EU Directive 2019/1937 or a national transposition and need acknowledgment and feedback clocks and retention handled in-product.
- You operate a corporate group that needs per-entity channels or a consolidated group view.
The scores
Reporting channels & reporter experience
Show reasoningHide reasoning
How this is scored
The intake side: how a reporter actually submits — web form, anonymous dialog, phone/voice, languages, accessibility — and whether anonymity survives first contact.
0 — A web form that is an email in disguise: no anonymous route, no way to reach the reporter afterwards.
3 — An anonymous form exists but the dialogue ends there — no secured mailbox for follow-up questions, few languages, desktop-only.
5 — Anonymous two-way dialog via a protected mailbox, a usable set of languages, mobile-friendly; voice or phone intake missing or an add-on.
8 — Multiple channels (web, voice message or hotline, QR entry points), broad language coverage with translation support, accessibility considered, and the anonymous dialog is first-class rather than bolted on.
10 — Intake engineered around the frightened reporter: every channel anonymous-capable, dozens of languages, WCAG-conscious, no app install or account required, and the vendor documents how the reporter's identity is kept out of the channel itself.
The Compliance Officer
The captured page names ethics, compliance, safety, fraud and whistleblower 'hotline services', so voice intake is a marketed channel, but I found no public information on an anonymous reporting route, a protected mailbox for follow-up questions, language coverage or accessibility. I cannot send a frightened employee into a channel whose anonymity promise is undocumented. 1
The Reporter's Advocate
The whole pitch is hotline — ethics, compliance, safety, fraud and whistleblower hotlines — so phone-style intake appears to be the core product, and a phone channel is what a night-shift worker can actually use. Beyond that word, we found no public information on two-way anonymous dialog, languages beyond English, mobile or accessibility handling, or how the reporter's identity is kept out of the channel. I cannot certify a frightened reporter safe on a marketing noun. 1
The SME Operator
The captured page markets a hotline and whistleblower intake service alongside incident case management, which is more than a bare form. Beyond that we found no public information on anonymous two-way dialog, a secured follow-up mailbox, languages, or mobile access, so the reporter's actual experience stays unevidenced — and I need the frightened employee's route documented, not just advertised. 1
The Group Counsel
The captured pages name ethics, compliance, safety, fraud and whistleblower hotline services, so voice-style intake is at least claimed alongside a case management product. We found no public information on anonymous two-way dialog, a protected follow-up mailbox, language coverage or accessibility — the things a reporter in each of a dozen countries needs before I trust the channel. 1
The Security Auditor
Intake is marketed as hotline services across ethics, compliance, safety, fraud and whistleblower lines, so a phone-style channel exists in name. We found no public information on whether reports can be filed anonymously, on any two-way protected mailbox for follow-up questions, on language coverage, or on accessibility. For whistleblowing intake, an anonymity story that is not documented does not count. 1
The Skeptic
The captured page sells 'hotline' five ways — ethics, compliance, safety, fraud, whistleblower — but I found no public information on an anonymous web form, a secured two-way mailbox, languages, accessibility, or how a reporter's identity survives the channel. Naming channels is not evidencing them, so this sits just above bare-minimum on the strength of repeated voice-intake claims alone. 1
Case management & deadline discipline
Show reasoningHide reasoning
How this is scored
The case worker's side: triage, statutory deadlines (7-day acknowledgment, 3-month feedback), role separation, audit-proof documentation.
0 — Reports land in an inbox; deadlines, roles and history live in a spreadsheet next door.
3 — A case list with status fields, but deadlines are manual, permissions are all-or-nothing, and the record of who did what is thin.
5 — Deadline tracking with reminders for the statutory clocks, case notes and attachments, basic role separation between case handlers; reporting on the caseload is limited.
8 — Automated statutory clocks, conflict-of-interest handling (excluding implicated case handlers), complete tamper-evident case history, retention and deletion rules applied per case, and management reporting.
10 — A case system an external investigator can rely on: enforced workflows, full audit trail, legally aware retention/deletion automation, evidence handling, and statistics that survive a regulator's questions.
The Compliance Officer
The vendor promises 'an easier, more powerful, more secure hotline + incident case management solution' — a product category, not a capability list. I found no public information on automated acknowledgment or feedback deadlines, role separation between case handlers, tamper-evident history or per-case retention rules; if the statutory clocks remain my problem, this is not a case system I can defend to a regulator. 1
The Reporter's Advocate
"Incident case management" is named as part of the offering and nothing more is said about it. We found no public information on deadline tracking for the 7-day acknowledgment or 3-month feedback clocks, role separation, tamper-evident case history, or retention and deletion. A case worker evaluating this page learns that a feature exists, not what it does. 1
The SME Operator
Incident case management is confirmed as part of the offering, and the three-step implementation framework suggests a launch I could plausibly manage in an afternoon. We found no public information on statutory deadline clocks, role separation, audit-proof case history, or retention rules, so I cannot tell whether the case handler's duties would actually be handled by the product or left to me in a spreadsheet. 1
The Group Counsel
The vendor markets "an easier, more powerful, more secure hotline + incident case management solution", which names the capability but shows none of its workings. We found no public information on statutory deadline clocks, role separation, conflict-of-interest handling, tamper-evident history or retention rules — the questions a works council or regulator would ask first. 1
The Security Auditor
Case management is asserted as part of the offering — a hotline plus incident case management solution — with no functional detail on the public pages. We found no public information on statutory deadline tracking, role separation, tamper-evident case history, or retention and deletion per case. A named module with nothing evidenced earns almost nothing. 1
The Skeptic
'An easier, more powerful, more secure hotline + incident case management solution' is the entire case-management record — a product category name, not a demonstrated capability. I found no public information on statutory deadline clocks, role separation, tamper-evident history, retention rules, or caseload reporting. 1
Legal compliance alignment
Show reasoningHide reasoning
How this is scored
How specifically the product implements EU Directive 2019/1937 and national transpositions (HinSchG et al.) — not whether the marketing mentions them.
0 — Generic feedback software wearing a whistleblowing label; no reference to the legal obligations it claims to satisfy.
3 — The directive is invoked in marketing but the mapping is vague; deadline rules, documentation duties and retention periods are the customer's problem.
5 — The statutory duties are implemented as product features — acknowledgment and feedback clocks, documentation, deletion after the retention period — for at least one national law, with guidance for the rest.
8 — Multiple national transpositions supported with their differing details, legal templates and process guidance maintained by named counsel or documented review, and updates when the law moves.
10 — The product is a legal instrument: per-country rule sets kept current, documented legal review, guidance for edge cases (group-wide channels, external ombudsman setups), and the vendor shows its homework in public.
The Compliance Officer
Beyond the marketing label 'compliance hotline', I found no public reference to EU Directive 2019/1937 or any national transposition, and no deadline, documentation or retention feature is named anywhere on the captured page. For my 7-day and 3-month clocks that mapping is worth almost nothing. 1
The Reporter's Advocate
"Compliance" appears as a hotline flavor next to fraud and safety, but we found no public information connecting the product to EU Directive 2019/1937 or any national transposition such as the German HinSchG. No acknowledgment clock, documentation duty or retention rule is named anywhere; the legal vocabulary is marketing, not implementation. 1
The SME Operator
The page sells an ethics, compliance, safety and fraud hotline framing, but we found no public information tying any of it to the EU Whistleblower Directive or a national transposition — no acknowledgment clock, no feedback deadline, no retention or documentation duty. For a company obligated by law, generic compliance marketing is nearly the same as no legal alignment at all. 1
The Group Counsel
The pages market compliance and whistleblower hotline services without naming a single legal obligation — no EU Directive 2019/1937, no national transposition, nothing on acknowledgment or feedback deadlines or documentation duties. We found no public information on any statutory mapping, so I must treat this as a general feedback tool wearing a whistleblowing label. 1
The Security Auditor
The captured marketing names compliance hotline services but references no legal regime at all — no EU Directive 2019/1937, no national transposition, no acknowledgment or feedback deadlines. We found no public information mapping any product feature to a statutory duty. Vocabulary is not legal implementation. 1
The Skeptic
The captured page invokes 'whistleblower' and 'compliance' purely as marketing labels and names no legal obligation — no directive, no national transposition, no acknowledgment or feedback deadlines. That is exactly the generic software wearing a whistleblowing label pattern. 1
Security & anonymity assurance
Show reasoningHide reasoning
How this is scored
Whether the confidentiality promise is engineered and evidenced: encryption, metadata handling, penetration tests, certifications.
0 — Security is a paragraph of adjectives; no certificates, no test reports, no statement on metadata.
3 — TLS and encryption at rest asserted, but nothing audited: no ISO 27001 or equivalent, no published pentest, silence on IP and metadata logging.
5 — A current ISO 27001 (or equivalent) certificate for vendor or hosting, end-to-end encryption of report content claimed with some technical detail, an explicit no-IP-logging statement.
8 — Certified ISMS covering the product, regular third-party penetration tests attested, documented end-to-end encryption architecture, metadata minimization explained, security contact and disclosure policy published.
10 — Assurance a hostile auditor accepts: current certificates with visible scope, recurring pentest summaries public, cryptographic architecture documented, anonymity analysed against the operator itself — the vendor can answer "how would you unmask a reporter?" with "we cannot, and here is why".
The Compliance Officer
Security appears in the capture as a single adjective — 'more secure' — with no certificate, no penetration test, no encryption or metadata statement behind it. That is precisely the adjectives-only state: a regulator's first security question would find no answer on this page. 1
The Reporter's Advocate
Security on the captured page reduces to the adjective "secure" in a single sentence, with no certificate, no penetration test, no encryption architecture and no statement on IP or metadata logging. A whistleblower product's only promise to a frightened reporter is confidentiality, and here that promise is entirely unevidenced — I can give it nothing. 1
The SME Operator
The only security content on record is the word 'secure' in the product tagline — a paragraph of adjectives and nothing else. We found no public information on certifications, penetration tests, encryption architecture, or metadata and IP logging, and for the most sensitive data my company will ever hold, that is precisely the assurance gap that would stop me signing. 1
The Group Counsel
Security appears exactly once, as an adjective in the product tagline ("more secure"), with nothing behind it. We found no public information on certificates, penetration tests, encryption architecture, or IP and metadata handling — for the most sensitive data a company holds, adjectives are not assurance. 1
The Security Auditor
The entirety of the security posture on the public pages is the adjective 'more secure.' We found no public information on certifications with visible scope, penetration tests, encryption architecture, IP or metadata logging, or a security contact and disclosure policy. An unevidenced confidentiality promise is worth zero in my line of work. 1
The Skeptic
The sum of security evidence is the adjective 'secure' in a tagline: no certificate, no penetration test, no word on encryption architecture, IP logging, or metadata. A paragraph of adjectives is not assurance, and here it is barely a sentence. 1
Group & multi-entity capability
Show reasoningHide reasoning
How this is scored
Whether one contract can serve a corporate group: separate channels per legal entity, central oversight, ombudsman access, white-labeling.
0 — One company, one channel; a group buys and administers N separate instances.
3 — Multiple channels under one account, but no separation of case access per entity and no consolidated view.
5 — Per-entity channels with separated case handlers and a group-level overview; branding per entity is basic; external counsel access possible.
8 — Real multi-tenant group structure: per-entity channels, languages and branding, delegated administration, external ombudsman roles, group reporting that respects entity boundaries.
10 — Group compliance as architecture: hundreds of entities manageable centrally, per-country legal rule assignment per entity, white-label reporting pages, and access separation strong enough to satisfy each subsidiary's works council.
The Compliance Officer
I found no public information on per-entity channels, separated case-handler access, delegated administration, ombudsman roles or a group-level overview. The one organizational fact — services are sold to organizations only — is a purchase condition, not evidence of a group architecture under a single contract. 1
The Reporter's Advocate
Organizations are the stated customer and implementation is a three-step launch, and that is all the structure on record. We found no public information on channels separated per legal entity, a consolidated group view, external ombudsman roles, or per-entity branding — a corporate group cannot see itself in this material. 1
The SME Operator
We found no public information on separate channels per legal entity, delegated administration, ombudsman or external counsel access, or a consolidated group view. With nothing evidencing group capability, I have to treat this as a single-organization service a group would have to buy piecemeal. 1
The Group Counsel
The only organizational statement on record is that services are sold to organizations only, not to individuals — which says who may buy, nothing about serving a corporate group. We found no public information on per-entity channels, access separation, delegated administration, ombudsman roles or group-level reporting, so a 25-subsidiary rollout would be an unverified bet. 1
The Security Auditor
We found no public information on separate channels per legal entity, delegated administration, group-level reporting, or ombudsman access. The only structural fact is that the service is sold to organizations rather than individuals; whether one contract can serve a corporate group cannot be determined from the public pages. 1
The Skeptic
I found no public information on per-entity channels, separated case access per subsidiary, consolidated group oversight, external ombudsman roles, or per-entity branding. The only adjacent fact — that sales are 'available for purchase by organizations only' — says who may buy, nothing about serving a group under one contract. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where reports about people actually live and under whose law — entity, hosting, subprocessors, DPA. In this category the data is by definition the most sensitive a company holds.
0 — Non-EU entity, non-EU-default hosting, no public DPA or subprocessor list — for whistleblowing data.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad or undocumented.
5 — EU hosting is the default, DPA and subprocessor list published; the vendor or a critical subprocessor is still within non-European jurisdictional reach.
8 — EU entity, EU hosting with named data centers, published subprocessor list free of content-touching non-EU processors, DPA and TOMs public.
10 — Jurisdictionally clean end to end: European ownership, EU-only hosting and subprocessors for report content and metadata, on-premises or sovereign-cloud options, and the whole chain documented publicly.
The Compliance Officer
The record holds no sovereignty attributes at all: no hosting region, no DPA, no subprocessor list, and the only entity marker is an LLC designation. For the most sensitive data a company holds, I found no public information on where reports would live or under whose law. 1
The Reporter's Advocate
No sovereignty attributes are on record at all: we found no public information on hosting location for report content, a published data processing agreement, subprocessors, or any European option. For the most sensitive data a company holds, the public record here is silent from end to end. 1
The SME Operator
The vendor has no sovereignty attributes on record — we found no public information on the operating entity's jurisdiction, hosting location, data processing agreement, or subprocessor list. For whistleblowing data this is the worst documented position a European buyer could face, and nothing here would survive my legal review. 1
The Group Counsel
The captured pages record no sovereignty attributes at all: we found no public information on the vendor's jurisdiction, hosting location, data processing agreement, technical measures or subprocessor list. For whistleblowing data about named people, an undocumented chain is the floor of unacceptability regardless of what a sales conversation might later reveal. 1
The Security Auditor
No sovereignty attributes are on record: we found no public information on the hosting location for report content, the jurisdiction of the vendor or its data centers, a data processing agreement, or any subprocessor list. For the most sensitive data a company holds, a completely undocumented chain is as close to the floor of the scale as I will write. 1
The Skeptic
The vendor is an LLC and no sovereignty attributes are on record: no EU hosting claim, no named data centers, no DPA, no subprocessor list — for the most sensitive data a company holds. Where the reports live and whose law reaches them is entirely undocumented on the captured page. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether an obligated company can compute the real invoice — per entity, per employee band, per year — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most obligated companies need are unpriced, or the maths is obscured by employee bands, per-report fees or mandatory setup charges.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability — extra entities, extra languages, phone intake — hides in an unpriced add-on.
8 — Every tier priced publicly with employee-band boundaries, entity rules and setup fees stated; only genuine corporate-group contracts are custom.
10 — Complete price computability: every tier, band, add-on and renewal rule public, so the invoice for a 60-employee company and a 5-entity group is a two-minute exercise.
The Compliance Officer
The only pricing-adjacent statement on the captured page is that services are available for purchase by organizations only; I found no public prices, tiers, employee bands or billing terms of any kind. An obligated company cannot compute even a first-year estimate from this page. 1
The Reporter's Advocate
No price of any kind appears — no tiers, no employee bands, no numbers. The only pricing-adjacent fact published is that the service is available for purchase by organizations only; an obligated company can compute nothing from that. 1
The SME Operator
The only pricing-related statement on record is that services are available for purchase by organizations only, not individual people — the word 'affordable' carries no number. No public tiers, employee bands, setup fees, or billing terms appear anywhere captured, so I could not begin to compute what a year would cost my sixty employees before the year-end review. 1
The Group Counsel
The only pricing-related statement is that services are available for purchase by organizations only and are not sold to individual people; no tier, employee band, setup fee or billing period appears anywhere. An obligated company cannot compute even a rough invoice from public pages, so every price is a sales conversation. 1
The Security Auditor
The only pricing-related facts are that services are sold to organizations only and that the product is described as 'affordable' — an adjective, not a price. We found no public information on tiers, employee bands, setup fees, billing periods, or VAT treatment. An obligated company cannot compute an invoice from these pages. 1
The Skeptic
The only public statement about price is who may buy — 'available for purchase by organizations only' — and no tier, number, employee band, billing period, or setup fee appears anywhere. Every real invoice begins with a sales conversation, which is precisely the zero-price-transparency situation. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | US by default ⚠ unverified | 0/3 pts | 2 Report an error |
| Subprocessors | Not determined | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 22 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Data residency. The page never names a hosting region or server location; the US reading is inferred from the Data Privacy Framework statement that EU/UK/Swiss personal information is transferred to the United States, not from an explicit hosting or storage declaration.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We could not confirm any compliance information on the vendor’s own pages as captured, so this page shows none rather than a statement we cannot stand behind. Know more? Tell us
- 4 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 hosting fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 support fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (7)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page redflagreporting.com Checked 22 Sep 2026 Details →
- 2 Privacy policy — found from the homepage www.redflagreporting.com Checked 30 Sep 2026 Details →
- 3 Reporting channels & reporter experience — found from sitemap www.redflagreporting.com Checked 1 Oct 2026 Details →
- 4 Reporting channels & reporter experience — found from sitemap www.redflagreporting.com Checked 1 Oct 2026 Details →
- 5 Case management & deadline discipline — found from sitemap www.redflagreporting.com Checked 1 Oct 2026 Details →
- 6 Case management & deadline discipline — found from sitemap www.redflagreporting.com Checked 1 Oct 2026 Details →
- 7 Legal compliance alignment — found from sitemap www.redflagreporting.com Checked 1 Oct 2026 Details →