Nextcloud
Germany· Cloud Computing
Vergleichen Sie Nextcloud und Stackfield nach Funktionen, Rechtsraum, Nachweisen und Einsatzpassung.
Germany· Cloud Computing
Germany· Groupware
Needs review
Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).
Hervorgehobene Zeilen unterscheiden sich zwischen den Produkten.
| Merkmal | ||
|---|---|---|
| Herkunftsland | ||
| Kategorie | Cloud Computing | Groupware |
| Open Source | Ja | Nein |
| Self-Hosted | Ja | Ja |
| Hauptsitz | Nicht angegeben | Germany |
| Rechtsträger | Nicht angegeben | Stackfield GmbH, Maximiliansplatz 17, 80333 München, Germany |
| US-Mutter / Kontrolle | Nicht angegeben | Keine bekannte US-Mutter |
| CLOUD-Act-Exposition (indikativ) | Nicht angegeben | Mittel |
| Hosting / Residenz | Nicht angegeben | Product data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path. |
| Zusammenfassung | Open-source, self-hosted content collaboration Hub from Nextcloud GmbH (Germany): Files, Talk, Groupware, Office, local AI Assistant, and Flow—an on-prem alternative to Microsoft 365-style suites. | German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise. |
| Tags |
| Auf einen Blick | ||
|---|---|---|
| HQ | Nicht angegeben | Munich, Germany |
| Legal entity | Nicht angegeben | Stackfield GmbH (HRB 199536) |
| Founded | Nicht angegeben | 2012 (vendor claim) |
| Hosting | Nicht angegeben | Germany; IONOS SE (vendor-named) |
| Deployment | Nicht angegeben | SaaS cloud + commercial on-premise |
| Open source | Nicht angegeben | No |
| Commercial model | Nicht angegeben | Seat-based plans; trial; AI/Office add-ons |
| Key capabilities | ||
|---|---|---|
| EU-operated (DE) | Nicht angegeben | Ja |
| Optional client-side E2E | Nicht angegeben | Ja |
| Germany hosting (IONOS) | Nicht angegeben | Ja |
| ISO 27001 + BSI C5 (claimed) | Nicht angegeben | Ja |
| Commercial on-premise | Nicht angegeben | Ja |
| Chat + PM + video | Nicht angegeben | Ja |
Sichere Dateisynchronisation und Freigabe
Ende-zu-Ende-verschlüsselte Synchronisation über Geräte hinweg mit öffentlichen Links, Berechtigungen und Ablaufdaten. Vorteile: Sicherer Remote-Zugriff ohne Datenlecks – ideal für Teams mit sensiblen Dateien.
Echtzeit-Kollaboration und Office
Integration von Collabora und OnlyOffice für Live-Dokumentenbearbeitung. Talk ermöglicht Chat und Videokonferenzen. Produktivität wie Google Workspace, aber self-hosted für Privatsphäre.
Groupware und Produktivitätssuite
Kalender, Kontakte, Mail und Aufgaben in einer App. Flow automatisiert Workflows; Assistant nutzt lokale KI für Übersetzungen und Zusammenfassungen. Zentralisiert Tools und reduziert App-Fragmentierung.
Optional client-side E2E rooms (AES-256 + RSA-2048)
Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.
Tasks, Gantt, portfolios, and workflows in the same rooms as chat
List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.
Video conferences, screen share, and guest/external roles
Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.
Germany cloud (IONOS) plus commercial on-premise
Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.
Enterprise access controls and in-product DPA
Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.
| Assurance & compliance | ||
|---|---|---|
| Independent security / no-logs audit | Nicht angegeben | Partial Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found. |
| ISO 27001 | Nicht angegeben | Vendor claimed Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft. |
| SOC 2 / SOC 3 | Nicht angegeben | Not found No SOC 2/3 claim found on primary security pages reviewed. |
| BSI C5 | Nicht angegeben | Vendor claimed Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement. |
| GDPR / EU data protection | Nicht angegeben | Vendor claimed EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments. |
| US CLOUD Act exposure (indicative) | Nicht angegeben | Partial EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice. |
| Data processing agreement (B2B) | Nicht angegeben | Vendor claimed Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation. |
| EU AI Act | Nicht angegeben | Not applicable Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases. |
| Considerations & known limitations | ||
|---|---|---|
| E2E is optional and irreversible per room | Nicht angegeben | Medium Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling. |
| Mobile push and optional US integrations | Nicht angegeben | Medium Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA. |
| Certifications vendor-asserted | Nicht angegeben | Low ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds. |
| On-premise is commercial, not DIY open source | Nicht angegeben | Low Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly. |
| AI features require content decryption for processing | Nicht angegeben | Medium Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client. |
Nicht angegeben
Nicht angegeben
When: You need open-source self-host and full operational control of files/collab apps
Consider: Nextcloud
More DIY ops; broader app ecosystem; different PM depth.
When: You mainly need regulated secure messaging, not Gantt/portfolios
Consider: ginlo Business
Messaging-first German B2B chat; thinner project suite.
When: You already run Microsoft 365 and identity is non-negotiable
Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries
Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.
When: You want lighter EU team chat without full PM suite
Consider: Fleep
Chat-centric; different residency/subprocessor profile—verify separately.
Nicht angegeben