Trusty Whistleblowing
Whistleblowing Software Made Simple
Built by compliance experts with decades of practice, not just developers.
One secure channel for anonymous reports, two-way dialogue and case management, compliant with the EU Whistleblower Directive and US whistleblower rules.
Hosted in ISO 27001 certified data centres in the EU or the US, your choice.
Set up in minutes, from €49 per month.


Companies
Run their whistleblowing channel on Trusty, from 50-employee firms to listed groups.
Per month, flat
One price for the whole organisation. Unlimited employees, no per-seat fees.
Day free trial
All features included. Invoice or card. Live in minutes, no IT project.
Who is obliged
Who needs a whistleblowing channel
If one of these applies to you, a channel is mandatory. If none does, a voluntary channel still signals integrity to customers, tenders and auditors.
- EU companies with 50 or more employees, under Directive 2019/1937 (Art. 8(3)) and the national laws (HinSchG, Ley 2/2023, D.Lgs. 24/2023, loi Waserman, Lei 93/2021)
- Public bodies and municipalities, in most member states regardless of headcount
- Regulated sectors such as financial services and anti-money-laundering obliged entities, whatever the size
- US-listed companies and their subsidiaries: an anonymous channel for accounting and audit concerns under SOX Section 301
- Under 50 employees: voluntary, but increasingly expected by customers, tenders and ISO 37001 / 37002 audits
Built by Compliance Experts
What the law requires, and how Trusty covers it
Anonymous and confidential reporting
Required by law
Reporting channels must protect the identity of the reporter and of anyone named in the report, and accept reports in writing or orally (Directive (EU) 2019/1937, Art. 9(1)(a), Art. 9(2) and Art. 16).
Trusty does it:
- Public whistleblower portal and a secure inbox for further confidential communication.
- The reporter decides whether to stay anonymous.
Case handling by designated persons
Required by law
an impartial person or department must be designated to follow up on reports and keep in contact with the reporter (Art. 9(1)(c) and (d)).
Trusty does it:
- Manage access to cases with different user roles.
- Search for content across all cases from one spot.
- In-app features designed by compliance experts to categorise and evaluate reports.
Deadlines and retention
Required by law
acknowledge every report within seven days and give feedback within three months of the acknowledgment (Art. 9(1)(b) and (f)); keep a record of every report, for no longer than necessary (Art. 18(1)).
Trusty does it:
- Retention management and reminders.
- Case status, memo and dialogue box on every case.
Data protection and security
Required by law
channels must be operated securely so that non-authorized staff cannot access reports (Art. 9(1)(a)), and personal data must be processed under the GDPR (Art. 17).
Trusty does it:
- Hosted in a high-security data centre in Germany, certified to ISO 27001.
- Secure SSL encryption. Regular third-party penetration tests.
- You choose the hosting region: EU (Germany) by default, or US on request. With EU hosting your data never leaves the EU.
Local law and policy
Required by law
the 50-worker threshold and the internal channel duty come from the Directive (Art. 8(1) and 8(3)), but each member state transposed it into its own act (Art. 26), so the policy has to follow the local law.
Trusty does it:
- Whistleblowing policies in local languages, reviewed by partner law firms.
- Available for Germany, Italy, Spain, Poland, Czechia and Slovakia.
- The solution supports all languages.
Reporting and oversight
Required by law
diligent follow-up on every report, and clear, easily accessible information on how to report externally to the competent authority (Art. 9(1)(d) and (g)).
Trusty does it:
- Intuitive dashboards.
- Export statistics to an Excel file.
- Cybersecurity vulnerability reporting (NIS2) on the same platform, Advanced plan.
Stop worrying about compliance Start focusing on your business
Why 1,000+ companies chose Trusty
From 50-employee firms to international groups






















Live in minutes
Immediate deployment, no IT project. Set up your channel, invite your handlers and publish the link the same day.
One flat price
Unlimited employees, no per-seat fees. The price does not grow with your headcount.
A platform, not a point tool
Whistleblowing plus Compliance App Academy, QuickScreen360 and EUDR Passport: one compliance home, one login.
Whistleblowing software plans and pricing
One flat price, from €49 per month
One flat price per organisation. Unlimited employees, no per-seat fees. Every plan starts with a 7-day free trial and invoice is available on all plans. Prices exclude VAT.
LITE PLAN
€49
Month*
For small organizations that need one admin user, one reporting language, secure two-way dialogue, and basic case handling.
- 1 user / 1 language
- Dedicated unique reporting URL
- Secure reporting website
- Simple reporting form
- Unlimited reports & storage
- Whistleblower inbox access
- Secure two-way dialogue (anonymous or identified)
- Basic case management
- Secure access
- Tamper-proof documentation
Recommended
STANDARD PLAN
€69
Month*
For organizations that need automatic alerts when new reports arrive, a second admin user, and a second reporting language.
- EVERYTHING IN LITE, PLUS
- 2 users / 2 languages
- Structured, guided reporting forms
- Standard Case management: status, handling, follow-up
- Email notifications for new reports
- Two-factor authentication
- Online support. 48-hour response time
ADVANCED PLAN
€99
Month*
For organizations that need unlimited users, all languages, advanced workflows, reporting insights, and NIS2 cybersecurity vulnerability reporting.
- EVERYTHING IN STANDARD, PLUS
- Unlimited users. Role-based permissions
- All languages
- Custom branding & texts
- Configurable anonymity settings
- Supply-chain reporting
- Workflows and automated reminders
- Retention period management
- Insights, dashboards, statistics export
- Keyword search across all cases
- Online support. 24-hour response time
- NIS2 cybersecurity vulnerability reporting
Frequently Asked Questions
In the EU, every organisation with 50 or more employees must run an internal reporting channel under the Whistleblower Protection Directive 2019/1937 and its national laws. Public bodies and regulated sectors such as financial services are covered regardless of size. Below 50 employees the channel is voluntary, but customers, tenders and ISO 37001 / 37002 audits increasingly ask for it.
Yes. You decide whether your channel accepts anonymous reports, identified reports or both. An anonymous reporter files through your public whistleblower portal and then continues the conversation in a secure inbox, so your case handler can ask follow-up questions and confirm the outcome without ever learning who they are. Traffic is protected by SSL encryption and the platform is penetration tested by an external party.
Only the people you appoint. Reports land with the designated responder and access is controlled through user roles, so a case can stay with a single handler or be opened to a team. Advanced plans include unlimited users with role based permissions, which lets you keep anyone with a conflict of interest out of a case. The case file keeps the record of how each report was handled.
Minutes for the channel itself. You pick a plan, add your logo, colours and the languages you need, and your public reporting portal is live. The paperwork around it is what usually takes longer, so a whistleblowing policy is included with your subscription, with localised versions reviewed by partner law firms for the main EU markets.
Trusty starts at €49 per month for the whole organisation, flat, with unlimited employees. Standard is €69 and Advanced €99 per month. No set-up fees, no per-seat charges. Invoice is available on all plans.
Yes. Every plan starts with a 7-day free trial that includes all features. Pick a plan on the plans page and your channel is live in minutes.
Yes, and you choose where the data lives. The default is a high-security data centre in Germany, certified to the ISO 27001 standard and provided by Hetzner Online GmbH, so your data stays in the EU. Hosting in the United States is available as an option if you prefer your data there. Traffic is protected by SSL encryption and the platform is penetration tested regularly by an external party. Trusty AG is a Swiss company, so Switzerland is our domicile, not a hosting location.
US-listed companies and their subsidiaries must give employees an anonymous, confidential way to raise accounting and audit concerns (Sarbanes-Oxley Act, Section 301), and several states have their own whistleblower protection acts. Trusty provides the anonymous channel, the confidential two-way dialogue and the case documentation these rules expect, on the same platform as the EU channel.
Yes. The EU NIS2 Directive (2022/2555) requires organisations to have structured processes for receiving and managing cybersecurity vulnerability disclosures. Trusty runs a dedicated Cybersecurity Vulnerability Reporting channel alongside your whistleblowing channel on the same platform. The whistleblowing channel handles misconduct reports under the EU Whistleblower Directive, and the vulnerability channel handles responsible disclosure from researchers, partners and internal teams. Both give you confidential intake, traceable case workflows and the audit trail regulators expect. Available on the Advanced plan.
Trusty Policy App includes a standard whistleblowing policy in English plus localised versions reviewed by partner law firms for Germany, Italy, Spain, Poland, Czechia and Slovakia. Each policy covers who it applies to, what can be reported, how to report, how reports are processed, protection against retaliation, and how long reports are retained. They are prepared in line with the EU Whistleblower Protection Directive and the ISO 37002 standard on whistleblower management systems.
Whistleblowing & Compliance Insights
Latest news, updates and insights on whistleblowing regulations from Trusty Compliance experts.
Whistleblower Hotline Requirements by US State
Whistleblower hotline requirements depend on what kind of company you are. Publicly traded companies must have one: Sarbanes-Oxley Section 301 requires audit committees to maintain…
What is a Whistleblower?
A whistleblower is a person who reports unlawful acts or irregular conduct inside an organization, either through the company's internal whistleblowing channel or externally to…
Law 2/2023: Protection of Whistleblowers
Spain's Law 2/2023 on the protection of persons who report regulatory infringements and the fight against corruption obliges companies to run an internal reporting system…