Kolab Now vs Private Discuss

Compare Kolab Now and Private Discuss on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Google Workspace

Logo: Kolab Now

Kolab Now

Switzerland· Groupware

Needs review

Shortlist when you want Swiss-operated, FOSS-based classical groupware (mail, CalDAV/CardDAV, ActiveSync, files, Collabora) on operator-owned Bern infrastructure. Skip when you need default zero-access E2EE mail, public ISO/SOC evidence, or mature video — consider Proton Mail/Tuta for E2EE mail or Google Workspace/Microsoft 365 for enterprise suite depth.

Swiss-operatedFOSS Kolab stackFull groupware suiteIMAP / CalDAV / ActiveSyncHosted in Bern (claimed)Optional PGP
Logo: Private Discuss

Private Discuss

France· Groupware

Needs review

Shortlist when you need a French-entity suite combining large secure video/webinars, E2EE messaging, co-editing, and strong admin controls with SaaS or on-premise options for government and sensitive business. Skip when you require open source, published independent crypto audits, or deep Microsoft 365/Slack ecosystem integration—consider Nextcloud Talk or ginlo Business instead.

EU-operated (France)E2EE (vendor claimed)France/EU hosting (claimed)On-premise optionUp to 1,000 video / 1M webinarsNot open source
Kolab Now vs Private Discuss: Snapshot
FeatureLogo: Kolab NowKolab NowLogo: Private DiscussPrivate Discuss
Country of originSwitzerlandFrance
CategoryGroupwareGroupware
Open sourceYesNo
Self-hostedNoYes
HeadquartersSwitzerlandFrance
Legal entityApheleia IT AG (trade register CH-036.3.053.227-3; VAT CHE-149.254.861)PRIVATE DISCUSS SAS, 304 Route Nationale 6, 69760 Limonest; RCS Lyon 828 242 545; VAT FR91 828 242 545 (legal notices / GTS). Privacy policy also cites RCS 829 105 741—confirm live registry extract.
Governing lawSwiss law (see Terms of Service for contract details)Not listed
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)MediumLow
Hosting / residencyPrimary mailbox/groupware hosting claimed on operator-controlled infrastructure in Bern, Switzerland (IBM OpenPOWER hypervisors, hardware-encrypted IBM storage, RHEL). No AWS/GCP/Azure hosting advertised for customer mail. Billing wallet supports PayPal, credit card, and EUR bank transfer — US-linked payment processors for payment data. Full subprocessor/backup register not published on pages reviewed.Product privacy/GTS: encrypted message stores hosted in France; personal data hosted in the EU without transfer outside the EU. Public website storage: OVH SAS, Roubaix, France. SaaS vs on-premise changes who operates the stack. No complete public SaaS subprocessor inventory (backup, email, analytics, mobile push) found.
Summary

Swiss-hosted FOSS Kolab groupware from Apheleia IT AG: email, calendars, contacts, files and optional Collabora collab on operator infrastructure in Bern.

French secure collaboration suite from Limonest (Lyon area): E2EE video, webinars, messaging, co-editing, and admin controls for government and sensitive organisations, with SaaS or on-premise deployment.

Tags
At a glance: Kolab Now vs Private Discuss
At a glanceLogo: Kolab NowKolab NowLogo: Private DiscussPrivate Discuss
HQ / operatorApheleia IT AG, Bern, SwitzerlandNot listed
Product since2013 (Swiss-operated hosted Kolab)Not listed
HostingOperator rack in Bern; IBM OpenPOWER + encrypted storage (vendor FAQ)Not listed
StackKolab FOSS; RHEL; open mail/groupware protocolsNot listed
Self-host this SKUNo (managed); Kolab suite is self-hostable separatelyNot listed
Commercial modelPaid modular subscriptions via prepaid wallet; trial monthPlans with host-based billing; free and paid tiers referenced; demo/sales for enterprise
HQNot listedLimonest (Lyon area), France
Legal entityNot listedPRIVATE DISCUSS SAS (RCS Lyon 828 242 545)
DeploymentNot listedSaaS, on-premise / private cloud, air-gapped (claimed)
Hosting (claimed)Not listedFrance/EU for product data; public site on OVH Roubaix
Open sourceNot listedNo (proprietary)
Key capabilities: Kolab Now vs Private Discuss
Key capabilitiesLogo: Kolab NowKolab NowLogo: Private DiscussPrivate Discuss
Swiss-operatedYesNot listed
FOSS Kolab stackYesNot listed
Full groupware suiteYesNot listed
IMAP / CalDAV / ActiveSyncYesNot listed
Hosted in Bern (claimed)YesNot listed
Optional PGPYesNot listed
EU-operated (France)Not listedYes
E2EE (vendor claimed)Not listedYes
France/EU hosting (claimed)Not listedYes
On-premise optionNot listedYes
Up to 1,000 video / 1M webinarsNot listedYes
Not open sourceNot listedYes

Kolab Now

  • FOSS Kolab groupware with open clients

    Hosted Kolab stack: IMAP/SMTP mail, CalDAV/CardDAV calendars and contacts, tasks, notes, and WebDAV files. ActiveSync is available for mobile/Outlook-style sync on full groupware subscriptions. Teams keep standard desktop and mobile clients instead of a proprietary-only app.

  • Private domains, multi-user cockpit, shared folders

    Primary account owners verify custom domains (DNS guides in the KB), add users under one wallet, and share mail folders, calendars, notes, and files inside the domain. Fits small businesses and families that need branded addresses and shared inboxes without Google Workspace.

  • Swiss own-rack hosting with PFS and header hygiene

    Operator FAQ places production systems in a Bern rack on IBM OpenPOWER with hardware-encrypted storage, RHEL, and segmented firewalls. TLS is described as end-to-end inside the platform with Perfect Forward Secrecy; outbound mail strips client IP and MUA identity from headers.

  • Sieve filters, DKIM, modular spam controls

    Server-side Sieve rules (folder, redirect, vacation, discard) run in the web client. Outbound DKIM is supported with CNAME delegation for private domains. Spam tagging is available; aggressive auto-junk is deliberately left to customer Sieve policy rather than opaque provider filtering.

  • Collabora Online files plus optional PGP and Kolab Meet

    Domain users can collaboratively edit documents/presentations via Collabora Online on shared files. Webmail can import PGP keys for optional message encryption (vendor warns keys on server are weaker than offline E2EE). Kolab Meet adds personal video rooms on groupware plans but remains public beta.

  • TOTP 2FA with an important client trade-off

    Time-based one-time passwords (e.g. Aegis) can be required for accounts. When 2FA is enabled for a user, vendor docs state non-web clients (IMAP, POP, ActiveSync, CalDAV/CardDAV, WebDAV) are blocked — evaluate this before mandating 2FA on mobile-heavy fleets.

Private Discuss

  • HD video meetings up to 1,000 participants

    Vendor features and contact pages state secure HD audio/video conferences for up to 1,000 participants with screen sharing, virtual backgrounds, collaborative whiteboard, breakout rooms, live polls/voting, and in-meeting electronic signature—aimed at executive and sensitive operational meetings rather than consumer calls.

  • Large-scale webinars with role and recording control

    Webinar tooling includes organiser/presenter/participant roles, granular permissions (present, share, record, content access), interactive stage, moderated hand-raise, secure chat/reactions, and HD recording with encrypted storage and controlled access. Contact materials claim capacity up to 1 million participants for large virtual events.

  • E2EE messaging, files, and co-editing in one suite

    Instant messaging covers 1:1 and group/channel chat with presence and mentions; secure file and media sharing (up to 20 GB per message via PiTransfer per marketing); cloud co-editing and a document library for sensitive document workflows. Security pages claim non-disableable E2EE, AES-256 for real-time calls, and RSA-2048 for file sharing.

  • Sovereign deployment: SaaS, on-prem, or air-gapped

    Hosting options include fully managed cloud SaaS, on-premise/private servers behind the customer firewall, and use cases marketed for air-gapped or constrained networks. Privacy policy states encrypted message storage on servers hosted in France; GTS state EU hosting without transfer outside the EU for personal data in scope.

  • Admin suite, kill switch, and policy controls

    Administration covers local/regional admin roles, user and group management, time-based access, contact and file-sharing authorisations, activity monitoring, minimum client version enforcement, MFA, geographic access limits, custom retention, and remote revoke/wipe language for compromised devices—built for security teams governing a closed network.

  • In-house AI tools for identity and translation

    Marketed AI features include deepfake/identity verification using camera, microphone, and device signals; real-time meeting translation; Private Translate for sensitive text/documents without content leaving customer infrastructure; and an AI companion for transcription, decisions, and post-meeting summaries—positioned for closed environments rather than public LLM APIs.

Assurance & compliance: Kolab Now vs Private Discuss
Assurance & complianceLogo: Kolab NowKolab NowLogo: Private DiscussPrivate Discuss
Independent security / no-logs audit
Not found

Vendor describes no content analytics and limited operational logs (up to six months). No public third-party no-logs or security audit PDF located.

Not found

No public independent audit PDF or third-party crypto review located on official site.

ISO 27001
Not found

No public ISO 27001 certificate found on primary site/KB materials reviewed.

Not found

Hosting marketing mentions ISO-certified infrastructure generically; no certificate number or cert PDF found on public pages.

SOC 2 / SOC 3
Not found

No public SOC 2/3 report found.

Not found

Not found on security, legal, or privacy pages.

GDPR / EU data protection
Vendor claimed

Swiss operator; KB GDPR article asserts customer data ownership, no ad analytics, export/delete paths, and Swiss warrant process for third-party access. Confirm DPA/ToS for EU controllers.

Vendor claimed

French controller/processor framing, CNIL notification language, DPO contact, EU hosting/no extra-EU transfer statements in GTS/privacy. Not legal advice.

US CLOUD Act exposure (indicative)
Partial

Swiss entity / no known US parent; mail claimed on Bern own-infra (not hyperscaler). Partial residual exposure via PayPal/card payment processors and unpublished full subprocessor list. Not legal advice.

Partial

French SAS, no known US parent, France/EU hosting claims and OVH for website. No public full subprocessor list for SaaS; marketing 'CLOUD Act free' language applies mainly to customer-controlled/on-prem narratives. Assessment only—not legal advice.

Data processing agreement (B2B)
Not found

No public standalone DPA download located on marketing/KB pages in this pass; may exist in ToS or on request — confirm before B2B processing.

Partial

Privacy policy references SaaS licence agreement with data-protection clauses when acting as processor; standalone public DPA download not found.

EU AI Act
Not applicable

Groupware/email product; not an AI system offering.

Unknown

Product markets deepfake detection, translation, and AI companion features; no public AI Act classification or conformity materials found.

Considerations & known limitations: Kolab Now vs Private Discuss
Considerations & known limitationsLogo: Kolab NowKolab NowLogo: Private DiscussPrivate Discuss
Mail not zero-access by default
Medium

Unlike Proton/Tuta defaults, ordinary stored mail is provider-accessible for protocol delivery unless users apply PGP or another client E2EE scheme. Material for threat models that assume provider compromise or compelled access to plaintext.

Not listed
2FA blocks non-web clients
Medium

Documented behaviour: enabling TOTP 2FA confines the user to the web client and blocks IMAP/ActiveSync/CalDAV and related protocols. Breaks many mobile/Outlook deployments if applied naively.

Not listed
Limited public compliance pack
Medium

No public ISO/SOC certs, independent audit, or subprocessor register found. Procurement must rely on vendor FAQs, ToS, and direct questions — slower security review than certified EU SaaS peers.

Not listed
US-linked payment processors
Low

Wallet top-ups via PayPal and credit cards introduce US-group payment processors for billing data even when mailboxes stay in Switzerland. Scope is payment metadata, not IMAP content, but still relevant to transfer inventories.

Not listed
Kolab Meet still beta
Low

Voice/video rooms are labelled public beta; vendor notes support may be limited. Do not treat as a Zoom/Teams replacement for critical meetings.

Not listed
No public independent security auditNot listed
Medium

Strong encryption and zero-knowledge claims are first-party only. Security-sensitive buyers should require audit reports, architecture review, and pilot verification before treating E2EE as proven.

Incomplete public SaaS subprocessor inventoryNot listed
Medium

France/EU hosting is claimed, but backup, email, analytics, and mobile push processors are not fully listed publicly. Residual transfer and support-access risk for managed SaaS must be closed in the customer DPA.

RCS number inconsistency on public pagesNot listed
Low

Legal notices and GTS use RCS 828 242 545; privacy policy cites 829 105 741. Confirm legal identity via official registry extract before contracting.

Closed proprietary platformNot listed
Low

Not open source; GTS emphasise vendor IP. Limits community audit and exit options compared with OSS collab stacks such as Nextcloud.

AI features need separate diligenceNot listed
Medium

Deepfake detection, Private Translate, and AI companion expand the evaluation surface (model location, training data, false positives). Vendor claims on-prem/private processing for some features—verify architecture per deployment mode.

Fit

Kolab Now

Best fit when

  • Small teams and professional practices that need shared mailboxes, calendars, and private domains under Swiss jurisdiction
  • Buyers who prioritise open standards (IMAP, CalDAV/CardDAV, ActiveSync, WebDAV) and FOSS components over proprietary lock-in
  • Organisations that will accept provider-accessible mail at rest and apply PGP/S/MIME themselves for sensitive threads
  • Users leaving Google Workspace who want groupware depth without US Big Tech mail custody
  • Account owners comfortable with prepaid wallet billing and modular per-user subscriptions

Poor fit when

  • Requirements for default end-to-end encrypted mail with zero provider access (prefer Proton Mail or Tuta)
  • Enterprises that need public ISO 27001/SOC 2 packs, signed DPAs, and a published subprocessor list on day one
  • Fleets that must combine TOTP 2FA with IMAP/ActiveSync clients on the same user (documented mutual exclusion)
  • Orgs treating video conferencing as a core, production-grade service (Kolab Meet is still beta)
  • Buyers seeking a permanent free tier or consumer-grade onboarding polish comparable to Gmail

Consider instead when

  • When: You need default zero-access / E2EE email more than ActiveSync groupware

    Consider: Proton Mail or Tuta

    Stronger default cryptography story; thinner classical groupware/ActiveSync depth than Kolab Now.

  • When: You want privacy-focused German email without full suite complexity

    Consider: Posteo

    Leaner privacy mail; not a Collabora + shared-domain groupware suite.

  • When: You need Google/Microsoft-class admin scale, apps marketplace, and compliance certifications

    Consider: Google Workspace or Microsoft 365

    Far larger ecosystems; US-centric custody and CLOUD Act profile differ sharply.

  • When: You want full self-host control of the same FOSS stack

    Consider: Self-hosted Kolab (kolab.org) or Nextcloud plus a mail stack

    More operational burden; Apheleia also sells Kolab professional services.

Private Discuss

Best fit when

  • French or EU public-sector and regulated orgs wanting a French SAS counterparty for secure meetings and chat
  • Buyers who need large HD meetings (claimed up to 1,000) and webinar-scale events with role and recording control
  • Security teams that require admin kill-switch, MFA, geo restrictions, contact/sharing policies, and version enforcement
  • Deployments that must stay on-premise, behind a firewall, or in air-gapped environments rather than only multi-tenant SaaS
  • Organisations evaluating white-label sovereign collab with in-suite AI translation/deepfake features kept inside customer infrastructure

Poor fit when

  • Teams that require open-source clients/servers and community auditability
  • Buyers who need native Microsoft 365/Google Workspace depth (channels + full Office graph) as the primary collaboration hub
  • Procurement processes that block tools without published independent security audits or named ISO certificate packs
  • Small teams that only need lightweight chat without large video/webinar or heavy admin overhead

Consider instead when

  • When: You already run self-hosted files/groupware and want open-source Talk-style meetings under your keys

    Consider: Nextcloud (Talk)

    Broader OSS hub; different security and UX model than Private Discuss’s proprietary stack

  • When: You primarily need German-entity encrypted business messaging with AD/LDAP cockpit, not large webinars

    Consider: ginlo Business

    Narrower A/V scale; strong messenger admin story

  • When: You need everyday team chat with email bridging rather than government-scale secure video

    Consider: Fleep

    Estonian messenger positioning; different threat model and feature depth

Open questions for due diligence

Kolab Now

  • Will Apheleia sign a GDPR Art. 28 DPA and provide a current subprocessor list (including backups, monitoring, and payment processors) under NDA if needed?
  • What is the current imprint address and governing ToS URL for contract annexes (product footer vs apheleia-it.ch addresses differ)?
  • Is there any ISO 27001, SOC 2, or independent penetration-test summary available to customers on request?
  • How are backups and disaster recovery stored (same Bern facility only, or additional sites/providers)?
  • For regulated workloads: what is the practical process and historical volume of Swiss lawful-access requests affecting customer content?

Private Discuss

  • Will the vendor provide a current subprocessor list, DPA, and evidence pack (ISO/audit) for the chosen SaaS region?
  • What is the exact E2EE protocol suite, key custody model, and any server-side components that can access metadata or cleartext in admin/recording scenarios?
  • For on-premise/air-gapped installs: supported OS, HA, update path, and whether AI features run fully offline?
  • Which customer logos on the homepage reflect active production use vs historical/marketing relationships?
  • Which RCS registration number (828 242 545 vs 829 105 741) is authoritative, and is there a group structure beyond the SAS?