Whistleblower application ranking

Edition III, 2024

How best to meet the requirements for whistleblower protection? This question has been asked by our customers for a long time. Therefore, in 2022 we have already tested the applications available on the Polish market and published the results in the form of a ranking.

Maciej Kaczmarski

Maciej Kaczmarski - CEO ODO 24

Whistleblower application ranking – assumptions

We are pleased to present the results of the third edition of the TOP 10 ranking of applications for whistleblowers that support proper implementation of whistleblower protection. For the study we invited the authors of all applications available on 1 September 2024. The ranking primarily promotes safe platforms for whistleblowers to report legal violations. We have created a tool to explore applications that we can recommend with full confidence.

The order in the ranking was determined based on points earned for key criteria. In the case of an equal number of points, the order was determined by the total score for useful (facilitating) criteria. Due to the large number of criteria, for greater presentation clarity we divided the set of more than 100 criteria into additional subcategories.

Office with people standing in flames - drawing

Top 10 signalling apps

The points for each criterion are assigned certain colours, according to the following scale:

  • the highest assessment
  • high rating
  • average estimate
  • not fulfilled criterion
Application
Sygna App logo
e-SDS logo
Whistleblower Software logo
Whiblo logo
Amodit logo
WeMoral logo
Whistelink logo
Sygnalista 365 logo
Sygnanet logo
Statlook logo
Base points

152

review

150

review

145

review

143

review

143

review

137

review

137

review

137

review

134

review

131*

review
Free trial of the applicationTESTTESTTESTTESTTESTTESTTESTTESTTESTTEST
Availability of signalling applications
Availability of the required information
Response deadline reminders
Ability to send feedback
Support for multiple entities including corporate groups
Connecting scans, transcripts, recordings
Register of notifications
Deletion of data after retention period expires
Fulfilment of individuals' rights under the GDPR
Data minimization
Data processing agreement between the Client and the Provider
Data are not transferred outside the EEA
Provider supports DPIA execution
Assurance of anonymity
Handling of reports by authorized persons
No linking of IP address to the content of the report
Possibility to anonymize a copy of the document
Vulnerability management and protection against malicious software
Security of applications and files
Encryption / secure communication channel
Access controls
Authentication
Registration of events
Intuitive interface, self-configuration
Facilitation of breach report management
Automatic logging of operation history
Provider is responsible for personnel and subcontractors
Provider is responsible for hacking attacks
Provider is responsible for failures of its infrastructure
All subcontractors explicitly identified
Possibility to object to a change of subcontractor
Subcontractors are vetted by the Provider
Comprehensive interface and efficient notification mechanism (max. 3 pts)

3 points

1 points

3 points

2 points

1 points

2 points

2 points

1 points

1 points

2 points

Easy-to-use breach reporting panel (max. 2 pts)

2 points

2 points

2 points

1 points

2 points

2 points

2 points

2 points

2 points

2 points

As you can see in the table above, the TOP 10 of the rankings were: applications that meet the vast majority of the required criteria, To the highest or highest degree. an individual's personal view, as subjectively assessed by an expert The difference is presented in the traditional scoring form.

*Optional criterion — some applications (2024) The Statlook Signalist app was created on-premise. Such a solution is preferred by a certain group of customers who do not authorise the processing of alerts from whistleblowers outside their territory; The criteria for the SaaS model are supported, but their The manufacturer's instructions are not fulfilled because the manufacturer's instructions are not fulfilled. the on-premise system, the ability to implement them is on the customer's side.

Facilities

65

66

60

59

55

64

62

57

54

57

Availability of the required information
Handling reports by authorised persons
Vulnerability management and protection against malicious software
ISO 27001 certification
Encryption / secure communication channel
Authentication
Intuitive interface, self-configuration
The application does not require integration with company systems
Accessibility features for persons with disabilities
Facilities for managing breach reports
Dedicated mobile app (Android / iOS / Huawei)
Online chat (within the application, with a live operator)
Application personalisation according to company needs
Automation of notifications of notifications
Permission management for handling reports
Multilingual interface
Liability insurance
Limit of liability
Meets UKNF requirements for cloud solutions
Additional features supporting follow-up actions
ODO 24 reviewreviewreviewreviewreviewreviewreviewreviewreviewreviewreview
Free trial of the applicationTESTTESTTESTTESTTESTTESTTESTTESTTESTTEST

For the second edition we invited ranking of applications for whistleblowers. The number of companies that have submitted their applications and agreed to be evaluated. We would like to point out that not all of the platforms listed below participated in the ranking. Alertador, BluSezam, CS-Sygnalista, Demaskator, E-nform, e-Signaller, Fraud Control, Gwizdek, EQS Integrity Line, e-SDS, e-Sygnalista, Ethicontrol, EY VCO, Genprox, GoWhistle, HeroApp, Hintbox, Just Report, Linia Etyki, Notibox, Panel Sygnalisty, Qualitime, Safelink, Sygnali, Sygnalista, I'm not sure if I'm going to be able to do that.SygnalistaOnline.eu, SygnalistaOnline.pl, Sygnalista+, Sygnaliści,Sygnalist@ka, Sygnalista Online, Sygnalista.com, Sygnalista.net, Sygnaliści.app, Sygnalisci.org, Sygnalix, Sygnalizuj.net, Sygnalizuje.com, Syon, Sygnanet, WeMoral, Whistboard, Whistleblower, WhistleblowerProductive 24, Whistlesystem.Whistlelink, Whistlesystem. We invite more companies!

Who created the ranking – meet the team of experts

Leszek Kępa

Leszek Kępa

IT security expert

Paweł Radecki

Paweł Radecki

Compliance expert

Karolina Langer

Karolina Langer

Data protection specialist

What parameters have we considered?

We have developed a set of 9 categories and 100 specific criteria based ona zero-one method, which made it possible to conduct a rigorous study. We divided these criteria into required (key) and useful (facilitating) criteria and assigned points from 1 to 3 according to weight. Only two criteria (comprehensive interface, effective notification mechanism notifications and an easy-to-use breach reporting panel) were subject to individual assessment by ODO 24 experts, based on research conducted in stage I. For the remaining criteria, we relied on the explicit statements of the application authors.

In order to objectively verify certain criteria, we have reservedthe possibility to request additional documents. Verification of these documents we carried out in the final stage. We requested evidence for:

  • Reporting of breaches of internal regulations or standards ethical standards.
  • Penetration tests before/after deployment.
  • Automatically scan the vulnerability of applications and infrastructure.
  • ISO 27001 certificate.
  • Slowing down attacks by brute force.
  • Secure the files generated and downloaded from the application with a password.

We've verified these documents in the final stages.

Position in the ranking determined by the number of points for the requirementsbasic, and in the case of an equal number of points the sum of points perUseful criteria and ease of use.It was £152.00 and £75.00 respectively.

9 categories and 100 criteria

  • Compliance with the provisions of the Law on the Protection of Signalers from the Day 14 June 2024 (15 criteria).
  • Compliance with the General Data Protection Regulation (GDPR) (8 criteria).
  • Protection of the identity of the whistleblower and the third party mentioned in the report (4 criteria).
  • Data security (criteria 30)
  • Ease of use (5 criteria).
  • Functionality (26 criteria)
  • Responsibility (5 criteria)
  • Subcontractors (4 criteria).
  • Additional functions (three criteria).

See more

How did we conduct the study?

Whistleblower applications were reviewed by our experts in the field of personal data protection law, whistleblower protection and IT security in three stages. In the first stage, the review consisted of testing and analysing individual applications, both from the whistleblower reporting a breach and from administrators (coordinators, case managers, compliance officers, etc.) managing reports and the application itself. We were also interested in how follow-up actions after receiving a report are organised.

In the second stage, we asked application authors to complete a confidential detailed form containing 100 criteria subject to evaluation. In the next stage, to objectively verify certain responses, we asked for relevant documents confirming that a given criterion was met.

Please note that our whistleblower application ranking serves only as an auxiliary function when choosing an application. ODO 24 does not accept liability for business decisions made solely on the basis of an analysis of the results of our ranking.

Before you deploy a whistleblower application, update your security procedures. The law requires it.

See the offer

Katarzyna Szczypińska
Man in a tie steering currencies – illustration

How to choose a whistleblower application on your own?

  • Step 1. Review the TOP 10 application ranking in table form. Select two or three applications.
  • Step 2. Read the descriptions of applications selected by you that we published below.
  • Step 3. Based on the ranking and descriptions, select with a wider team.
  • Step 4. Choose the application that you think performed best during testing.
  • To fully realise the potential of a whistleblower application, ensure proper implementation of a whistleblower protection system.

Applications for whistleblowers ODA reviews 24

SygnaApp

SygnaApp moved significantly into the lead and was the only participant from the previous edition of the ranking to retain a podium position. This shows the vendor's established position in the market. SygnaApp is a fully compliant, user-friendly and intuitive tool for receiving and handling whistleblower reports, with high cybersecurity standards, which also supports internal investigations. Thanks to extensive configuration options, it can be quickly tailored to the needs of any organisation – in both the private and public sectors. The application supports internal and external reporting processes. SygnaApp is used by companies of various sizes and organisational complexity (including capital groups) as well as public bodies and authorities, including central government institutions.

Strengths:

  • a comprehensive reporting form for infringements,
  • a personalized, friendly and readable administrator panel,
  • the system suggests further steps during the examination of the application,
  • automatically generating message templates,
  • the possibility of adding notifications from other channels.

Weaknesses:

  • we see no major issues; perhaps more language versions could be added (there are currently 5).

Distinction:

  • easy configuration of the reporting form to suit the company's needs.
Odo24

How correctly and in accordance with Regulation (EU) No 1303/2013 can signal protection be implemented?

With the processing of personal data of whistleblowers and persons whose reporting It's very risky, so it's very important to prepare Implementation of the protection of whistleblowers in accordance with the requirements of the GDPR Personal data of persons reporting as: And the individuals concerned by the notification.

  • Analysis of organisational needs
  • Package of model documents
  • Individual consultations on the implementation
  • The Commission shall adopt delegated acts in accordance with Article 21 of Regulation (EU) No 182/2011 and shall adopt delegated acts in accordance with Article 21 thereof.
  • Support in the selection of signalling applications
  • Training of the breach team
  • Employee training (e-learning)
e-SDS

e-SDS is an advanced tool for reporting breaches securely, designed by Codefellow sp. z o.o. in close cooperation with Data Protection Advisory Group sp. z o.o. By combining modern technology with deep expertise in personal data protection, the application ensures maximum information security. The platform operates on a SaaS model but also offers installation on the client's local servers. The implemented security mechanisms meet the highest industry standards, guaranteeing reliability and protection of transmitted data.

Strengths:

  • anonymisation of data, deletion and modification of user data,
  • encryption of the annexes to the notifications,
  • Compatibility with different devices (computer, tablet, smartphone),
  • real-time alerts for new notifications and important changes,
  • the automation of the notification management process.

Weaknesses:

  • the breach reporting form could offer more options.

Distinction:

  • A simple, easy-to-read application that can be easily customized for your business.
Whistleblower Software

Whistleblower Software is one of the leading tools for handling whistleblower reports, recognised worldwide. The platform is the highest-rated solution in this category on G2, a renowned business software review portal. It is currently used by over 5 million employees in 7,000 organisations operating in more than 80 countries. Thanks to its broad reach and flexibility, Whistleblower Software helps companies and institutions meet legal requirements for whistleblower protection across many international markets.

Strengths:

  • Multi-language support,
  • a fully configurable reporting page,
  • support for multiple reporting channels,
  • unlimited number of users,
  • secure transfer of files (removal of metadata),
  • encrypted end-to-end communication.

Weaknesses:

  • somewhat overly monotonous graphics.

Distinction:

  • handling of voice reports (voice distortion).
Whiblo

Whiblo is a service that enables confidential written reporting of suspected illegal or unethical activities within an organisation. It allows an anonymous, encrypted dialogue between the whistleblower and the organisation after a report is submitted. The solution also supports report management through assignment to coordinators, status tracking, document storage, a report register and report generation. The application is compliant with regulations and ensures data security. It is a user-friendly system for any organisation.

Strengths:

  • the possibility to configure the infringement notification form,
  • the ISO information security certificate,
  • Two-Factor Authentication (SMS)/aplikacja mobilna),
  • the anonymisation of the data of the alert holder during the examination of the report of the infringement,
  • tailoring the application to the needs of the company.

Weaknesses:

  • the reporting infringement must enter and remember its own password to verify the status of the report.

Distinction:

  • a simple, legible breach reporting form and an administrator panel.
Amodit

AMODIT is a comprehensive whistleblower protection system combining security, flexibility and regulatory compliance. Fast deployment, full whistleblower anonymity and advanced report management features make it an ideal solution for companies of any size. A dedicated panel, process automation and system personalisation provide full control over reports. With AMODIT, organisations can effectively protect whistleblowers while streamlining internal processes and minimising the risk of retaliation.

Strengths:

  • different options for reporting, rules setting and integration with other systems,
  • the ability to activate telephone notifications,
  • the possibility of adapting the reporting process to the specific characteristics of the company.

Weaknesses:

  • somewhat sparse graphics.

Distinction:

  • rapid platform implementation.
WeMoral

WeMoral offers an exceptionally simple, uncomplicated, intuitive and easy-to-use tool for reporting breaches. The company offers one-day service deployment. Reports preceded by basic information for the whistleblower are anonymous by default, but a name field can be added and marked as personal data in the system. Two-way communication between the whistleblower and the administrator is encrypted. The administrator panel requires an additional password after login to read report content.

Strengths:

  • 25 language versions,
  • a comprehensive notification form,
  • the granting of different levels of powers,
  • decrypting the contents of the notification after entering the password,
  • the anonymisation of the signal data during follow-up actions,
  • the ability to visually configure the form.

Weaknesses:

  • lack of extensive support for follow-up actions.

Distinction:

  • a simple, easy-to-use application after quick deployment.
Sygnalista 365

Sygnalista365 is an advanced SaaS (Software as a Service) platform designed for secure and anonymous reporting of irregularities in organisations. The application helps companies build a culture of ethics and responsibility while ensuring full protection of whistleblower identity. Sygnalista365 is a comprehensive irregularity reporting solution combining security, anonymity and ease of use. With flexible pricing plans and technical support, Sygnalista365 is a reliable partner in report management and building trust within the company.

Strengths:

  • rapid deployment of the platform,
  • adapting the platform to the specific needs of the company (personalization),
  • live chat.

Weaknesses:

  • rather sparse graphics.

Distinction:

  • ready-made documentation as an option.
Sygnanet

Sygnanet is an encrypted system for receiving and processing whistleblower reports. Ready to set up in 5 minutes, it is simple, secure, helps fulfil obligations and protects the employer and those investigating reports. Data is transmitted to the server already encrypted and made available to the recipient on their device in that form. Together with the system, Sygnanet clients receive: an internal procedure template, deployment for report recipients, employee training and a deployment platform with educational materials for report recipients and employees.

Strengths:

  • a personalised notification form according to the company's preferences,
  • ready response templates for the signal declaration,
  • granting different levels of rights to handle applications,
  • the anonymisation of the signal data during follow-up operations.

Weaknesses:

  • simple captcha to verify when reporting a breach, poor graphics.

Distinction:

  • an extensive deployment and educational platform.
Statlook

Statlook is a simple, intuitive and secure tool for reporting and handling irregularities in an organisation. It allows employees to report workplace misconduct confidentially or anonymously. The system enables secure two-way communication between the whistleblower (including anonymous) and the person handling the report. The application can be an integral module of Statlook software, a standalone tool alongside that system, or used entirely independently. Statlook is software, not a SaaS service, ensuring compliance with Polish and European law.

Strengths:

  • compliance with ISO 37002 for the management of whistleblower notifications,
  • a multilingual interface,
  • a form adapted to mobile devices,
  • the possibility of submitting reports via the TOR network,
  • tailoring the application to the needs of the company.

Weaknesses:

  • we see no major issues; perhaps overly minimalist graphics.

Distinction:

  • a simple, clear and efficiently operating application.

What are the application requirements for signalling?

Rysynek - people chasing a man with the word GDPR on his shirt
  • The www application should provide an adequate level of protection for whistleblowers
  • The application should primarily provide identity protection
  • The platform should also allow the signal to access complex

How can we assist you today?

Please contact us and we will find a solution.
Form decoration

Use the form

Select service

The data controller will be ODO 24 sp. z o.o. with its registered office in Warsaw at ul. Kamionkowska 45. Your data will be processed for the purpose of preparing, sending and archiving the cooperation offer. More information can be found in the Privacy Policy

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.
Ranking of the best whistleblower apps TOP 10 | ODO 24