Online whistleblower system – compliant and available immediately.
The whistleblower system meets all legal requirements – with an external reporting platform and internal case management.
Legally compliant. Audit-proof. Efficient. Integrated. The first online whistleblower system.
Report whistleblower information easily and securely – online reporting system
The digital whistleblower system for modern organizations
The RiskFox whistleblower system combines a secure external reporting platform (accessible via the customer's website) with efficient internal case management – fully compliant with data protection regulations, anonymously usable, and audit-proof.
The software efficiently and cost-effectively (digitalization) replaces the work of expensive ombudsman offices (usually law firms) or internal non-anonymous reporting channels (compliance, legal).
The whistleblower system can be easily integrated into the RiskFox software platform with the following products upon request:
- Risk Management (ERM)
- Internal Control System (ICS)
- Compliance (COM)
- Environmental, Social & Governance (ESG)
- EU AI Act (AIA)
- Supply Chain Act (SCA)
- Whistle Bowing System (WBS)
- Critical Report. System (CIRS)
- Information Security Mgmt. System (ISMS/NIS2)
External Reporting Channel
The whistleblower system offers whistleblowers a secure, confidential channel, accessible at any time via the client website (including branding), to report misconduct anonymously or by name. A modern external reporting platform is web-based, GDPR-compliant, and enables secure and anonymous communication between whistleblowers and the company. It thus meets the legal requirements for independence, confidentiality, and technical security. Companies prefer external reporting systems to be informed about misconduct early on, before it becomes public.
Internal Case Management
Internal case management ensures that incoming external reports are processed confidentially within the company in a structured, transparent, and legally compliant manner. Responsible departments—such as Compliance or Legal—review the reports, document each step, and coordinate necessary actions. A professional case management system enables audit-proof case management, role and access control, and secure communication with whistleblowers. This ensures that every case is handled transparently, efficiently, and in accordance with the law.
Legal Processes & Deadlines
The Whistleblowing Directive and the Whistleblower Protection Act require adherence to clearly defined deadlines and procedures. Companies must acknowledge receipt of a report within seven days and provide substantial feedback on its status within three months. Furthermore, all steps must be documented, and reports must be retained for at least three years. Effective deadline management is therefore essential to comply with legal requirements and ensure the integrity of the whistleblower system.
Protection of the whistleblower
The protection of whistleblowers is the central aim of the Whistleblower Protection Act. Companies must ensure that whistleblowers do not suffer any disadvantages – such as dismissal, transfer, bullying, or other forms of reprisal. This includes technical measures such as anonymity and confidentiality, as well as organizational measures such as clear guidelines, training, and internal safeguards. An effective whistleblower system builds trust, lowers the barrier to reporting, and strengthens the compliance culture throughout the entire company.
Customer satisfaction (in %)
Customers (number)
Countries (number)
Technology leader (Ranking)
Advantages of RiskFox Online Software
RiskFox offers maximum legal certainty at minimal costs – without installations, without IT investments.
Your step towards digitalization and automation
- RiskFox Online Whistleblowing System -
Our RiskFox online software meets all regulatory requirements – fully, in a structured and audit-proof manner.
RiskFox's online whistleblower system is designed from the ground up according to the principle of "compliance by design." It supports companies in implementing the requirements of the EU Whistleblower Directive, the Salbanes-Oxley Act, and national whistleblower protection laws in a structured and legally compliant manner. Clearly defined reporting channels, audit-proof documentation, and data processing compliant with the General Data Protection Regulation (GDPR) ensure that reports are handled confidentially, transparently, and in accordance with the law.
All process steps – from initial confirmation of receipt and communication with whistleblowers to case processing – are documented in an audit-proof manner and logged in a traceable format. Standardized workflows and data protection-compliant processing in accordance with the General Data Protection Regulation (GDPR) ensure that reports are handled confidentially, legally, and within the required timeframe. This provides legal certainty, as companies can demonstrate that they operate a legally compliant reporting channel, process reports properly, and fulfill their organizational compliance obligations.
The following legal requirements are met by the RiskFox whistleblower system:
- Establishment of a secure reporting office (for 50 or more employees, confidentiality of identity).
- Protection of whistleblowers (prohibition of reprisals).
- Information for the whistleblower (acknowledgment of receipt after 7 days, action after a maximum of 3 months).
- Independent processing of the report (e.g., compliance).
- Documentation requirement (audit security, traceability).
- Procedural rules and compliance processes: clear internal processes.
Advantage: With the online RiskFox software, you are always audit-ready and fully meet your documentation obligations to auditors (internal/external) and regulatory authorities. Compared to manual tools like Excel, the RiskFox software allows you to map all regulatory requirements in a legally compliant, complete, and transparent manner.
Replace expensive ombudsman offices (law firms) with a structured and digitized workflow using RiskFox software.
Digitizing a whistleblower system not only increases efficiency but also significantly reduces ongoing costs. A web-based system like RiskFox replaces manual, lawyer-supervised ombudsman offices with an automated, audit-proof, and scalable workflow. This eliminates high external consulting costs while simultaneously increasing processing speed and conserving internal resources. The digital structure also ensures clear responsibilities, transparent processes, and complete documentation – all without the recurring fees of traditional ombudsman offices.
Ombudsman offices or compliance departments are often not legally compliant with the Whistleblower Protection Act (HinSchG) or the EU Whistleblower Directive, as they cannot guarantee or implement the documentation requirements (§11 HinSchG) or the feedback obligations (§11 HinSchG) towards whistleblowers in the case of anonymous reports (via email, contact form or telephone).
Specific cost advantages of using our web-based whistleblower system include:
- Automated processes for reporting and processing reports.
- Deadline and task management to ensure compliance with reporting obligations.
- Structured and documented process for handling measures.
- Secure storage of all evidence for audits, official inspections and internal audits.
Reduce external (ombudsman's office) and internal costs with RiskFox and save valuable resources.
RiskFox software reduces internal effort in implementing regulatory requirements by up to 70% through fully digitized, workflow-driven processes that cover all legal requirements. Instead of fragmented Excel spreadsheets, emails, and manual approvals, governance is centrally managed – legally compliant, time-saving, and scalable.
Specific cost advantages of using our web-based whistleblower system include:
- Elimination of external ombudsman office / law firm.
- Automated case acceptance and processing.
- Standardized, digitally managed workflows.
- Central, digital documentation.
- Faster processing times.
- Scalability without additional costs.
- Reduced training and onboarding costs.
Online availability - no complex IT installations and fast implementation.
RiskFox software integrates seamlessly into existing processes and role models, reflecting all company structures. The RiskFox online solution is scalable and suitable for companies of all sizes and industries. The RiskFox application can be flexibly adapted to your organizational and operational structures, thus supporting your company's holistic governance approach.
RiskFox software is a fully web-based solution that offers maximum legal certainty across numerous areas, without the need for expensive installations or IT investments. You have direct access to every single module via this website. The application is ready to use immediately and is continuously updated.
RiskFox meets the highest IT and data security standards, ensuring that all information is protected, stored in an audit-proof manner, and remains accessible at all times. At the same time, the solution is flexibly expandable: additional employees can be easily integrated, and even complex company structures are mapped precisely and individually.
Advantage: Unlike non-scalable tools such as Excel, RiskFox supports you regardless of your company size, from small businesses or SMEs to large international corporations.
Pricing Online-Software
Benefit from low operating costs, immediate readiness for use and state-of-the-art technology
No installations, no IT effort and scalable at any time.
Basic Version
€150 / month
- External Reporting Website
- Internal Case Management
- max. 5 Users
- Standard Master Data
- Standard Content & Questions
10% discount for annual payment (12 months)
Standard Version
€250 / month
- External Reporting Website
- Internal Case Management
- max. 10 Users
- Standard Master Data (configurable)
- Standard Content & Questions (configurable)
10% discount for annual payment (12 months)
Enterprise Version
€350 / month
- External Reporting Website
- Internal Case Management
- from 10 Users
- Customized Master Data
- Customized Content & Questions
10% discount for annual payment (12 months)
Testimonials
RiskFox's online software is recommended by users.
The RiskFox team has developed the most advanced whistleblower system currently available.
The RiskFox team consists of experienced experts with in-depth regulatory know-how. They work practically, with a sound legal and theoretical foundation, and were the first providers to offer an online whistleblower system on the market.
Team of Experts
Our interdisciplinary team consists of experienced senior consultants, specialized software developers, and industry experts with in-depth knowledge of regulated environments. Many of our colleagues are active as expert speakers, regularly sharing their knowledge through presentations, publications, and industry panels. We act as your experienced solution provider and sparring partner.
Experience
Our team brings extensive theoretical and practical experience from numerous successful projects. Intensive collaboration with clients from various industries has refined our solutions and made them highly practical. Our clients benefit from our in-depth expertise as well as our profound understanding of regulatory requirements.
Professionalism
We work with standardized processes that ensure efficient and high-quality project execution. At the same time, we rely on intelligent software solutions that combine innovation with practical applicability. Our methods and models are based on best practices, current research, and technological advancements.
Customer Focus
At the heart of everything we do is the tangible benefit for our customers. Our solutions are developed in close collaboration with subject matter experts and users – making them practical, easy to understand, and intuitive to use. We listen, think along with you, and develop with the goal of creating added value.
FAQ
Answers to the most important questions about our whistleblower system
Which companies need a whistleblower system?
A whistleblower system is legally required for many organizations and best practice in compliance, governance and risk management for all others.
Obligation according to the EU Whistleblowing Directive, Sarbanes-Oxley Act (SOX), Dodd-Frank Act and Whistleblower Protection Act (HinSchG):
- All companies with 50 or more employees
- All public bodies with a population of 10,000 or more
- All financial service providers – regardless of the number of employees
(Banks, insurance companies, asset managers, investment management companies, pension funds, fund providers, etc.)
Recommended for:
- Companies with increased compliance risk
- Companies with supply chain obligations (Swiss Supply Chain Act/ESG)
- Organizations with international locations
- Companies that want to minimize reputational risks
- Companies that want to identify internal problems early on
Short:Every company that takes compliance seriously benefits from a whistleblower system.
What are the advantages of the RiskFox online whistleblower system?
A modern online whistleblower system offers significant advantages over ombudsman offices, telephone hotlines or email mailboxes – both legally, organizationally and financially.
1. Cost Advantages Compared to Ombudsman Offices
Online systems are significantly cheaper than traditional ombudsmen, who often charge high annual flat fees or hourly rates. A digital
system incurs no additional costs per report, no consultation hours, and no external investigations. This significantly reduces ongoing compliance costs,
while simultaneously increasing the quality of case handling.
2. Simple and Fast Setup
An online whistleblower system is ready for immediate use without any IT installation. The RiskFox online system can be individually branded and configured. Companies
need neither a server nor a software rollout, and the solution can be activated in a very short time. Employees and external stakeholders access the system via a secure web address,
while the internal reporting office works via a browser-based dashboard. This reduces implementation effort and completely relieves the compliance and IT departments.
3. Audit-proof, auditable, and legally compliant
Digital systems automatically meet legal requirements:
- 7-day confirmation of receipt
- 3-month feedback
- Documentation and retention obligations
- GDPR compliance
- Access controls & role models
- Audit trail for every action
This makes internal and external audits easy, and companies can demonstrate their compliance at any time.
4. External Reporting Platform + Internal Case Management
An online system combines two legally required elements:
External Reporting Platform
- Accessible via the website
- Anonymous or non-anonymous
- Multilingual
- Available 24/7/365
- Encrypted communication
Internal Case Management
- Structured case management
- Secure communication with whistleblowers
- Role and rights management
- Documentation of all steps
- Deadline management
This ensures that the entire process – from reporting to action – is digitally, transparently and legally compliant.
5. Structured processes and clear workflows
An online system guides the reporting office through all steps of the legal process. Cases are automatically categorized, deadlines are monitored, and those responsible are
informed. This reduces errors, prevents missed deadlines, and ensures consistent, transparent processes throughout the entire company.
6. Anonymity and protection of the whistleblower
Digital systems enable genuine, technically secure anonymity – something that ombudsman offices or email inboxes cannot guarantee. Whistleblowers can communicate anonymously,
answer follow-up questions, and exchange documents without revealing their identity. This increases the motivation to report and strengthens the compliance culture.
What is the difference between "external reporting page" and "internal case management"?
RiskFox's whistleblower system includes both the "external reporting page" and the "internal case management":
1. External Reporting Page
The external reporting platform is the public, secure, and anonymous channel through which whistleblowers submit their reports. It is accessible to employees, suppliers,
customers, and other third parties and serves as a digital "door" to the whistleblower system. The platform must be accessible 24/7/365, GDPR-compliant, usable anonymously,
and technically protected. The external reporting platform is usually hosted on the company's website and can be accessed and submitted directly by the whistleblower.
The sole purpose of the external reporting platform is to receive reports and facilitate confidential communication with the whistleblower – without requiring them to disclose
their identity. The company typically provides a structured questionnaire to obtain the most detailed report possible and to derive internal analysis and investigations from it.
2. Internal Case Management
Internal case management is the non-public, internal workspace where authorized personnel (e.g., from Compliance, Legal, or HR) review, document, and process incoming reports.
Here, deadlines are monitored, actions are planned, internal investigations are conducted, and all steps are recorded in an audit-proof manner. Case management is therefore
the "engine" of the system: it ensures that every report is handled in a structured, traceable, and legally compliant way. Case management includes workflow and email functionalities
to integrate the right contacts and reviewers within the company.
How do I get access to the free demo version?
The demo version can be started directly via the "Request Demo" button. You will go through a simplified login process – the free demo version includes one user for a period of two weeks. Data and structures are already implemented, which can of course be individually configured in the production version. The demo version includes the "external reporting page" and the "internal case management".
How does the registration and ordering process work for the online version?
After clicking on “Buy Now”, select the desired modules and users, accept the terms and conditions and privacy policy, and complete the order via our secure checkout.
For paid packages, payment is processed via Stripe. Your account will be activated automatically, and you can log in and get started immediately.
How secure is my data in the RiskFox cloud?
RiskFox is hosted in the Oracle Cloud. The Oracle Cloud meets the highest IT and data security standards. Two-factor authentication is also available.
In addition, companies can individually control roles, permissions and access levels, so that only authorized people can view or edit content.
How does Risk Fox's pricing model work?
RiskFox offers a transparent, modular pricing model. You choose the modules you need and the number of users. Billing is done monthly via Stripe. No hidden costs, no installation fees, no long-term commitments.
Can I adapt RiskFox to the structure of my company?
Yes. The responsible user (e.g., power user, administrator) can individually configure and map organizational structures (locations, departments, subsidiaries, etc.) and responsibilities. Even complex corporate structures, matrix organizations, or group-wide governance models can be easily integrated. The unique feature of the RiskFox whistleblower system is that the power user or administrator can independently configure all questions (external reporting page) and evaluations (internal case management).
How quickly can I get started with RiskFox and how can I map individual structures?
You can start immediately after registration – no installation, no IT effort required. Our standard version includes pre-configured master data and content that, for example, the
administrator can modify and configure independently (-> Standard version).
Upon request, we can provide you with a customer-specific configuration (-> Enterprise Version) which you can edit, modify, or customize at any time.
What are the advantages of RiskFox and how does it differ from other software solutions?
RiskFox is the first fully online whistleblower system that is ready to use immediately, without installation, IT effort, or complex projects. While traditional Excel tools,
email systems, or the use of ombudsman offices (law firms) are often expensive, cumbersome, and technologically outdated, RiskFox relies on a modern, cloud-based architecture
that optimally combines speed, user-friendliness, and security.
Thanks to its consistently digital approach, the total costs are approximately 50–90% lower than alternative solutions such as ombudsman offices, email systems, or individual Excel
tools – while simultaneously offering greater flexibility and significantly faster implementation. Companies benefit from a system solution that seamlessly adapts to individual
structures, is infinitely scalable, and practically reflects regulatory requirements.
RiskFox is backed by a team with many years of experience in the regulatory environment, possessing both theoretical expertise and practical experience gained from projects with
banks, insurance companies, industry, and public institutions. This expertise is directly incorporated into the ongoing development of the system solution – technically sound,
technologically leading, and consistently aligned with real business needs.
Contact
Learn more about our RiskFox online software.
Contact us now - we look forward to hearing from you.







