Skip to main content Skip to footer
Spe­cial­ist solu­tion | com­pli­ance SUITE

Whis­tleblower soft­ware
from otris

An­onym­ous & con­fid­en­tial
Manage terms & es­cal­a­tions
Legally com­pli­ant doc­u­ment­a­tion
Request a demo
Request a demo
Skip ref­er­ence clients

Whis­tleblower soft­ware: secure re­port­ing, struc­tured pro­cessing, legally com­pli­ant doc­u­ment­a­tion

Our Whis­tleblower soft­ware sup­ports com­pan­ies, au­thor­it­ies and public in­sti­tu­tions in re­ceiv­ing reports se­curely, an­onym­ously and in a struc­tured manner, re­view­ing them in ac­cord­ance with legal re­quire­ments and pro­cessing them in a veri­fi­able manner. Work­flows, roles and terms ensure trans­par­ent pro­cesses. The audit-proof doc­u­ment­a­tion provides re­li­able evid­ence – for in­tern­al audits and to meet the re­quire­ments of the HinSchG (German Whis­tleblower Pro­tec­tion Act) and the EU Dir­ect­ive.

Receive an­onym­ous or non-an­onym­ous reports – with a secure feed­back channel.

Manage terms, re­spons­ib­il­it­ies and es­cal­a­tions – keep pro­cessing on sched­ule.

Audit se­cur­ity – com­plete history, logs and evid­ence.

Skip gallery

Fea­tures that set our Whis­tleblower soft­ware apart

otris is an es­tab­lished pro­vider of com­pli­ance soft­ware. Our solu­tions combine ease of use with high stand­ards of data pro­tec­tion and data se­cur­ity. Company-spe­cif­ic re­quire­ments can be mapped without much effort.

Safety

Our Whis­tleblower soft­ware is based on high se­cur­ity stand­ards: op­er­a­tion in ISO 27001-cer­ti­fied data centres in Germany, state-of-the-art en­cryp­tion and role-based access with logging. Regular se­cur­ity checks and pen­et­ra­tion tests com­ple­ment the pro­tec­tion concept.

Ad­apt­ab­il­ity

The solu­tion is ready for im­me­di­ate use and can be con­figured flex­ibly. Re­port­ing forms, work­flows and case man­age­ment can be adapted to your pro­cesses; in­ter­faces and SSO enable in­teg­ra­tion into ex­ist­ing systems. This allows you to map your gov­ernance without media dis­con­tinu­ity.

Dash­board & Reports

An in­teg­rated dash­board provides real-time per­form­ance in­dic­at­ors for control and com­pli­ance re­port­ing. Reports and graph­ic­al eval­u­ations (e.g. by topic, status, terms or or­gan­isa­tion­al units) create trans­par­ency and can be ex­por­ted as re­quired. The history remains audit­able and trace­able.

„The im­ple­ment­a­tion went really quickly and smoothly. Working with otris is straight­for­ward and easy.“

Michael Meyer-Schwick­er­ath
In-house counsel and com­pli­ance officer at KÖTTER Un­ternehmens­gruppe

Which edition of our whis­tleblower soft­ware suits your re­quire­ments?

All edi­tions meet the same high stand­ards of IT se­cur­ity and data pro­tec­tion. Which version is suit­able depends on factors such as company size, volume of reports and struc­ture. We would be happy to advise you per­son­ally.

STAND­ARD

Vor­fälle sicher dok­u­mentier­en und work­flowgestützt bearbeiten. Mehr­sprac­hige For­mu­lare. Melde­for­mu­lar flex­i­bel kon­fig­ur­i­erbar. Fristen- und Be­n­utzer­man­age­ment. 2-Faktor-Au­then­ti­fiz­ier­ung. Datens­chutzkon­form.

  • Case­m­an­age­ment und Melde­platt­form​
  • Schnell start­bereit​
  • Geringer in­tern­er IT-Aufwand
  • Keine hohen An­fangsin­vesti­tion­en

from
299 € / Monat (SaaS)

Die otris soft­ware AG wird alle hier bereit­ges­tell­ten In­form­a­tion­en aus­schließ­lich in Übere­in­stim­mung mit der Datens­chutzerklärung ver­wenden.

EN­TER­PRISE

Ex­ten­ded func­tion­al­ity for larger or­gan­isa­tions. Flex­ible cus­tom­isa­tion of editing pro­cesses, au­thor­isa­tion models and case files.

In ad­di­tion to STAND­ARD

  • Multi-client capable, con­trol­lable across the entire group
  • Con­fig­ur­a­tion of ex­ist­ing folders
  • Azure AD in­teg­ra­tion, in­clud­ing SSO
  • Mul­tiple re­port­ing plat­forms (URLs) pos­sible

from
499 € / Monat (SaaS)

Die otris soft­ware AG wird alle hier bereit­ges­tell­ten In­form­a­tion­en aus­schließ­lich in Übere­in­stim­mung mit der Datens­chutzerklärung ver­wenden.

EN­TER­PRISE plus

Maximum func­tion­al­ity for in­teg­ra­tion into busi­ness pro­cesses. Cus­tom­is­able in terms of re­quire­ments and in­ter­faces.

In ad­di­tion to EN­TER­PRISE

  • In­teg­ra­tion of cus­tom­er-spe­cif­ic in­ter­faces​
  • Con­fig­ur­a­tion of ad­di­tion­al work­flows​
  • Ad­di­tion of map types

on inquiry
/ Month

Die otris soft­ware AG wird alle hier bereit­ges­tell­ten In­form­a­tion­en aus­schließ­lich in Übere­in­stim­mung mit der Datens­chutzerklärung ver­wenden.

An­onym­ous com­mu­nic­a­tion and ef­fi­cient case hand­ling

What are the be­ne­fits of digital Whis­tleblower soft­ware?

Without in­tern­al and ex­tern­al reports, it is often dif­fi­cult to identi­fy prob­lems, and when they are iden­ti­fied, it is often too late. At the same time, po­ten­tial whis­tleblowers are re­luct­ant to report con­cerns for fear of re­pris­als. The otris Whis­tleblower soft­ware builds trust: it enables an­onym­ous com­mu­nic­a­tion via a secure re­port­ing channel, pro­tects the iden­tity of the whis­tleblower and ensures the con­fid­en­ti­al­ity of the report.

Tips help

Rule vi­ol­a­tions by in­di­vidu­al em­ploy­ees or ex­tern­al part­ners can have sig­ni­fic­ant legal and eco­nom­ic con­sequences. Early warn­ings – whether sub­mit­ted in­tern­ally or ex­tern­ally – support timely damage lim­it­a­tion, fa­cil­it­ate evid­ence gath­er­ing and promote pre­ven­tion. The Or­gan­isa­tion can learn from iden­ti­fied cases: pro­cesses, re­spons­ib­il­it­ies and con­trols are de­veloped in a tar­geted manner. Mo­tiv­at­ing in­tern­al re­port­ing is there­fore an im­port­ant com­pon­ent of an ef­fect­ive com­pli­ance strategy.

Strengthen mo­tiv­a­tion

Many whis­tleblowers fear damage to their repu­ta­tion or pro­fes­sion­al dis­ad­vant­ages. Secure, an­onym­ous re­port­ing chan­nels sig­ni­fic­antly reduce these hurdles. The otris Whis­tleblower soft­ware offers pseud­onym­ous dia­logue and gives whis­tleblowers the freedom to choose whether to reveal their iden­tity or remain an­onym­ous. Con­fid­en­ti­al­ity, role-based vis­ib­il­ity and doc­u­mented process steps in­crease trust – while also sup­port­ing the re­quire­ments of the HinSchG and EU Dir­ect­ive, in­clud­ing pro­tec­tion against re­pris­als within the frame­work of the re­spect­ive legal reg­u­la­tions.

„We are ex­tremely sat­is­fied with the support provided by otris soft­ware AG. Our contact persons are always avail­able, and change re­quests are im­ple­men­ted com­pet­ently and quickly.“

Dr. Monika Glogger
Lawyer (in-house counsel) and Com­pli­ance Officer GROB-Werke GmbH & Co. KG

Further ap­plic­a­tion scen­ari­os for your Whis­tleblower soft­ware

Use the system – beyond the scope of the HinSchG – for struc­tured com­plaint chan­nels in the supply chain, ad­min­is­tra­tion and in­terest groups.

Com­plaint man­age­ment in the supply chain (LkSG/CSDDD)

Se­curely record, assess and process in­form­a­tion on vi­ol­a­tions of com­pli­ance, sus­tain­ab­il­ity or quality re­quire­ments along the supply chain – with trans­par­ent doc­u­ment­a­tion.

  • Re­cord­ing: type of report, Sup­pli­er/loc­a­tion, product/batch, sever­ity, doc­u­ments
  • Work­flow: ab­stract/con­crete risk ana­lys­is, terms/es­cal­a­tions, re­spons­ib­il­it­ies, ef­fect­ive­ness mon­it­or­ing
  • Evid­ence: com­plete history, action status, eval­u­ations (trend, origin)

Au­thor­it­ies & min­is­tries – dif­fer­ent types of no­ti­fic­a­tions

Receive, assign and eval­u­ate reports in ac­cord­ance with legal re­quire­ments (in­tern­al/ex­tern­al) – mul­ti­lin­gual, with a pseud­onymised feed­back channel and in­teg­rated into ex­ist­ing pro­cesses.

  • Re­cord­ing: re­port­ing chan­nels, cat­egor­ies, re­spons­ib­il­it­ies by or­gan­isa­tion­al unit
  • Work­flow: stand­ard­ised review steps, dual control prin­ciple, follow-ups
  • Evid­ence: pro­to­cols, reports for boards/audits, export for stat­ist­ic­al offices

Com­plaints for in­terest groups

Receive con­cerns con­fid­en­tially, e.g. from rep­res­ent­at­ives for dis­abled persons, women’s/equal­ity of­ficers, and process them in a struc­tured manner – with a role-ap­pro­pri­ate view of sens­it­ive content.

  • Re­cord­ing: topic, af­fected group, event/loc­a­tion, evid­ence
  • Work­flow: secure dia­logue (an­onym­ous/pseud­onym­ous), terms, meas­ures, es­cal­a­tions
  • Evid­ence: doc­u­mented steps, de­cisions, reports for in­tern­al de­part­ments

Op­tim­ise your com­pli­ance with the otris Whis­tleblower soft­ware

In order to operate Whis­tleblower soft­ware in com­pli­ance with the law, con­fid­en­ti­al­ity must be main­tained and the iden­tity of the whis­tleblower must not be dis­closed. On a tech­nic­al level, the otris re­port­ing plat­form sup­ports pro­tec­tion through op­er­a­tion­ally sep­ar­ate cloud op­er­a­tion in Germany (otris systems) and en­cryp­ted com­mu­nic­a­tion.

Re­port­ing plat­form

The more trust­worthy the re­port­ing channel, the more likely whis­tleblowers are to share in­form­a­tion. The otris soft­ware AG re­port­ing plat­form trans­mits mes­sages to the re­cip­i­ent using high-level en­cryp­tion. An­onym­ity can be main­tained re­gard­less of whether the report is sub­mit­ted in­tern­ally or ex­tern­ally. An auto­mat­ic­ally gen­er­ated ID enables a pseud­onymised feed­back channel.

The re­port­ing plat­form is op­er­ated in the cloud in Germany by otris systems GmbH and provides tech­nic­al support for iden­tity pro­tec­tion. All content between whis­tleblowers and re­cip­i­ents is trans­mit­ted in en­cryp­ted form. In ad­di­tion to con­fid­en­ti­al­ity and se­cur­ity, the otris Whis­tleblower soft­ware (otris whis­tleblower) com­plies with legal re­quire­ments for data pro­tec­tion and data se­cur­ity.

The system also sup­ports use cases beyond the HinSchG, such as com­plaint man­age­ment in ac­cord­ance with LkSG/CSDDD re­quire­ments.

In ad­di­tion, the solu­tion sup­ports voice mes­sages and the struc­tured re­cord­ing of reports from other chan­nels (e.g. letter, tele­phone, email). All in­com­ing reports are as­signed to the case file, doc­u­mented and tracked with audit se­cur­ity.

Case man­age­ment

In ad­di­tion to the re­port­ing plat­form, the otris Whis­tleblower soft­ware in­cludes flex­ibly con­fig­ur­able case man­age­ment. Reports can be doc­u­mented, rated and con­sist­ently fol­lowed up in the system. In ac­cord­ance with EU Dir­ect­ive 2019/1937, the process provides for, among other things, con­firm­a­tion of receipt within 7 days and feed­back within 3 months. The system reminds you of dead­lines and sup­ports follow-ups. At the same time, you can record and eval­u­ate rel­ev­ant com­pli­ance KPIs (e.g. in ac­cord­ance with ISO 37301) in a struc­tured manner and verify them in reports.

Com­mu­nic­a­tion with whis­tleblowers takes place from case man­age­ment; mes­sages are trans­mit­ted to the re­port­ing plat­form and made avail­able there an­onym­ously via a secure feed­back channel. Case man­age­ment can be op­er­ated on-premises or in the cloud. For reasons of iden­tity pro­tec­tion, the re­port­ing plat­form remains de­signed as a sep­ar­ate cloud service (DE, otris systems GmbH).

With case man­age­ment, you can record and con­sol­id­ate com­pli­ance KPIs in ac­cord­ance with ISO 37301. This makes through­put times, feed­back rates and pro­cessing quality meas­ur­able and com­par­able. Dash­boards and reports support trend ana­lyses and man­age­ment reviews; thresholds can be used for KPI mon­it­or­ing and re­mind­ers/es­cal­a­tions.

„Un­com­plic­ated, secure and good value for money: we are com­pletely sat­is­fied with the otris whis­tleblower soft­ware.“

Andreas Tusch
Head of IT at the ARKIL Gruppe

FAQ | Whis­tleblower soft­ware

What is the purpose of the HinSchG – and who does it affect?

The Whis­tleblower Pro­tec­tion Act (HinSchG) trans­poses EU Dir­ect­ive 2019/1937 into German law. The aim is to uncover abuses more quickly and protect whis­tleblowers from re­pris­als.

Com­pan­ies with 50 or more em­ploy­ees are re­quired to set up in­tern­al re­port­ing offices. There are cor­res­pond­ing re­quire­ments for the public sector; details in local au­thor­it­ies are gov­erned by state law.
Re­port­ing offices must be de­signed in such a way that the con­fid­en­ti­al­ity of the iden­tity is main­tained.

How does the otris Whis­tleblower soft­ware support com­pli­ance with the HinSchG?

The system allows an­onym­ous or non-an­onym­ous reports and a secure return channel. It main­tains con­fid­en­ti­al­ity through tech­no­logy and Or­gan­isa­tion:

  • Op­er­a­tion of the re­port­ing plat­form sep­ar­ate from the re­cip­i­ent: Cloud in Germany, op­er­ated by otris systems.
  • No logging of per­son­al data on the re­port­ing plat­form (e.g. IP address) for an­onym­ous reports.
  • End-to-end en­cryp­tion of mes­sages/at­tach­ments in the re­port­ing channel; trans­port en­cryp­tion (TLS 1.3).
  • En­cryp­ted storage in re­port­ing plat­form and case man­age­ment.
  • Regular se­cur­ity checks/pen­et­ra­tion tests.
  • An­onym­ous mailbox for queries.
  • Ac­cess­ib­il­ity is ensured and checked on the basis of WCAG 2.1.

How does the system take the GDPR into account?

Per­son­al data (e.g. in non-an­onym­ous reports or third parties) is pro­tec­ted by trans­port and end-to-end en­cryp­tion.

  • Role and Au­thor­isa­tion concept limits access to au­thor­ised persons.
  • De­le­tion and re­ten­tion rules are con­fig­ur­able; rule-based de­le­tion routines support GDPR com­pli­ant pro­cessing.
  • Two-factor au­then­tic­a­tion can provide ad­di­tion­al se­cur­ity for access.
  • Whis­tleblowers receive in­form­a­tion on data pro­tec­tion (FAQs/notes on the re­port­ing plat­form).

What se­cur­ity stand­ards does the solu­tion meet?

  • ISO 27001-cer­ti­fied data centres in Germany (cloud op­er­a­tion by otris systems); op­tion­al on-premises for case man­age­ment.
  • Hybrid/asym­met­ric en­cryp­tion of report-related data on the re­port­ing plat­form, E2EE (end-to-end en­cryp­tion) in the re­port­ing channel.
  • TLS 1.3 for trans­port en­cryp­tion.
  • 2FA option, logging, regular se­cur­ity audits/pen tests (OWASP stand­ards as ref­er­ences).

How complex is the im­ple­ment­a­tion of the system?

The system is usually ready for use after a brief con­fig­ur­a­tion process. Tem­plates (data pro­tec­tion notices, FAQs, cat­egor­ies, system texts) are avail­able and can be cus­tom­ised. Work­flows, roles and forms can be ex­pan­ded step by step.

SaaS means low in­tern­al IT costs; on-premises is pos­sible (for case man­age­ment).

Does the HinSchG require soft­ware?

No. The law defines re­quire­ments (e.g. con­fid­en­ti­al­ity, Terms), but not the tech­no­logy. Al­tern­at­ives (om­bud­sper­son, email, hotline) are pos­sible in prin­ciple, but iden­tity/con­fid­en­ti­al­ity pro­tec­tion is often more dif­fi­cult to im­ple­ment in these cases.

Whis­tleblower soft­ware fa­cil­it­ates an­onym­ous com­mu­nic­a­tion, timely pro­cessing, audit se­cur­ity in terms of doc­u­ment­a­tion, and de­le­tion-com­pli­ant pro­cesses, among other things.

What are the terms for con­firm­a­tion of receipt and reply?

In ac­cord­ance with EU Dir­ect­ive 2019/1937:

  • Con­firm­a­tion of receipt: usually within 7 days.
  • Feed­back (e.g. status of review): usually within 3 months.
    The system sup­ports follow-ups, es­cal­a­tions and SLAs.

Can ex­tern­al persons (e.g. Sup­pli­ers) submit reports?

Yes. The system sup­ports in­tern­al and ex­tern­al reports – in mul­tiple lan­guages, in­clud­ing an­onym­ously. The channel can be con­trolled for each target group (public, Sup­pli­ers, Service Pro­viders).

How does the solu­tion fit into our IT in­fra­struc­ture?

Via in­ter­faces and SSO (e.g. Azure AD). Case man­age­ment on-premises or in the cloud (DE); sep­ar­ate re­port­ing plat­form in the cloud (DE, otris soft­ware AG) – to protect iden­tity.

Dis­cov­er otris’ Whis­tleblower soft­ware now

Would you like to receive reports se­curely, manage terms/es­cal­a­tions and provide audit-proof evid­ence of com­pli­ance KPIs (e.g. ac­cord­ing to ISO 37301)? With the otris Whis­tleblower soft­ware, you can process cases in a struc­tured manner – from receipt to veri­fic­a­tion.

Request a guided demo – we will show you typical pro­cesses and answer your ques­tions. Or book a con­sulta­tion ap­point­ment to discuss your re­quire­ments and find the right edition for you.

Get in touch

Per­son­al­ised online demo | No strings at­tached. Free of charge.

otris soft­ware AG will use all in­form­a­tion provided here ex­clus­ively in ac­cord­ance with the privacy policy.

Your contact

Back to navigation Back to content Back to navigation Back to content