Private Discuss vs Stackfield

Compare Private Discuss and Stackfield on capabilities, jurisdiction, assurance, and fit for European buyers.

Both listed as alternatives to: Microsoft Teams, Slack

Logo: Private Discuss

Private Discuss

France· Groupware

Needs review

Shortlist when you need a French-entity suite combining large secure video/webinars, E2EE messaging, co-editing, and strong admin controls with SaaS or on-premise options for government and sensitive business. Skip when you require open source, published independent crypto audits, or deep Microsoft 365/Slack ecosystem integration—consider Nextcloud Talk or ginlo Business instead.

EU-operated (France)E2EE (vendor claimed)France/EU hosting (claimed)On-premise optionUp to 1,000 video / 1M webinarsNot open source
Logo: Stackfield

Stackfield

Germany· Groupware

Needs review

Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).

EU-operated (DE)Optional client-side E2EGermany hosting (IONOS)ISO 27001 + BSI C5 (claimed)Commercial on-premiseChat + PM + video
Private Discuss vs Stackfield: Snapshot
FeatureLogo: Private DiscussPrivate DiscussLogo: StackfieldStackfield
Country of originFranceGermany
CategoryGroupwareGroupware
Open sourceNoNo
Self-hostedYesYes
HeadquartersFranceGermany
Legal entityPRIVATE DISCUSS SAS, 304 Route Nationale 6, 69760 Limonest; RCS Lyon 828 242 545; VAT FR91 828 242 545 (legal notices / GTS). Privacy policy also cites RCS 829 105 741—confirm live registry extract.Stackfield GmbH, Maximiliansplatz 17, 80333 München, Germany
US parent / controlNo known US parentNo known US parent
CLOUD Act exposure (indicative)LowMedium
Hosting / residencyProduct privacy/GTS: encrypted message stores hosted in France; personal data hosted in the EU without transfer outside the EU. Public website storage: OVH SAS, Roubaix, France. SaaS vs on-premise changes who operates the stack. No complete public SaaS subprocessor inventory (backup, email, analytics, mobile push) found.Product data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path.
Summary

French secure collaboration suite from Limonest (Lyon area): E2EE video, webinars, messaging, co-editing, and admin controls for government and sensitive organisations, with SaaS or on-premise deployment.

German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise.

Tags
At a glance: Private Discuss vs Stackfield
At a glanceLogo: Private DiscussPrivate DiscussLogo: StackfieldStackfield
HQLimonest (Lyon area), FranceMunich, Germany
Legal entityPRIVATE DISCUSS SAS (RCS Lyon 828 242 545)Stackfield GmbH (HRB 199536)
DeploymentSaaS, on-premise / private cloud, air-gapped (claimed)SaaS cloud + commercial on-premise
Hosting (claimed)France/EU for product data; public site on OVH RoubaixNot listed
Open sourceNo (proprietary)No
Commercial modelPlans with host-based billing; free and paid tiers referenced; demo/sales for enterpriseSeat-based plans; trial; AI/Office add-ons
FoundedNot listed2012 (vendor claim)
HostingNot listedGermany; IONOS SE (vendor-named)
Key capabilities: Private Discuss vs Stackfield
Key capabilitiesLogo: Private DiscussPrivate DiscussLogo: StackfieldStackfield
EU-operated (France)YesYes
E2EE (vendor claimed)YesNot listed
France/EU hosting (claimed)YesNot listed
On-premise optionYesYes
Up to 1,000 video / 1M webinarsYesNot listed
Not open sourceYesNot listed
Optional client-side E2ENot listedYes
Germany hosting (IONOS)Not listedYes
ISO 27001 + BSI C5 (claimed)Not listedYes
Chat + PM + videoNot listedYes

Private Discuss

  • HD video meetings up to 1,000 participants

    Vendor features and contact pages state secure HD audio/video conferences for up to 1,000 participants with screen sharing, virtual backgrounds, collaborative whiteboard, breakout rooms, live polls/voting, and in-meeting electronic signature—aimed at executive and sensitive operational meetings rather than consumer calls.

  • Large-scale webinars with role and recording control

    Webinar tooling includes organiser/presenter/participant roles, granular permissions (present, share, record, content access), interactive stage, moderated hand-raise, secure chat/reactions, and HD recording with encrypted storage and controlled access. Contact materials claim capacity up to 1 million participants for large virtual events.

  • E2EE messaging, files, and co-editing in one suite

    Instant messaging covers 1:1 and group/channel chat with presence and mentions; secure file and media sharing (up to 20 GB per message via PiTransfer per marketing); cloud co-editing and a document library for sensitive document workflows. Security pages claim non-disableable E2EE, AES-256 for real-time calls, and RSA-2048 for file sharing.

  • Sovereign deployment: SaaS, on-prem, or air-gapped

    Hosting options include fully managed cloud SaaS, on-premise/private servers behind the customer firewall, and use cases marketed for air-gapped or constrained networks. Privacy policy states encrypted message storage on servers hosted in France; GTS state EU hosting without transfer outside the EU for personal data in scope.

  • Admin suite, kill switch, and policy controls

    Administration covers local/regional admin roles, user and group management, time-based access, contact and file-sharing authorisations, activity monitoring, minimum client version enforcement, MFA, geographic access limits, custom retention, and remote revoke/wipe language for compromised devices—built for security teams governing a closed network.

  • In-house AI tools for identity and translation

    Marketed AI features include deepfake/identity verification using camera, microphone, and device signals; real-time meeting translation; Private Translate for sensitive text/documents without content leaving customer infrastructure; and an AI companion for transcription, decisions, and post-meeting summaries—positioned for closed environments rather than public LLM APIs.

Stackfield

  • Optional client-side E2E rooms (AES-256 + RSA-2048)

    Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.

  • Tasks, Gantt, portfolios, and workflows in the same rooms as chat

    List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.

  • Video conferences, screen share, and guest/external roles

    Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.

  • Germany cloud (IONOS) plus commercial on-premise

    Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.

  • Enterprise access controls and in-product DPA

    Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.

Assurance & compliance: Private Discuss vs Stackfield
Assurance & complianceLogo: Private DiscussPrivate DiscussLogo: StackfieldStackfield
Independent security / crypto audit
Not found

No public independent audit PDF or third-party crypto review located on official site.

Partial

Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found.

ISO 27001
Not found

Hosting marketing mentions ISO-certified infrastructure generically; no certificate number or cert PDF found on public pages.

Vendor claimed

Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft.

SOC 2 / SOC 3
Not found

Not found on security, legal, or privacy pages.

Not found

No SOC 2/3 claim found on primary security pages reviewed.

GDPR / EU data protection
Vendor claimed

French controller/processor framing, CNIL notification language, DPO contact, EU hosting/no extra-EU transfer statements in GTS/privacy. Not legal advice.

Vendor claimed

EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments.

US CLOUD Act exposure (indicative)
Partial

French SAS, no known US parent, France/EU hosting claims and OVH for website. No public full subprocessor list for SaaS; marketing 'CLOUD Act free' language applies mainly to customer-controlled/on-prem narratives. Assessment only—not legal advice.

Partial

EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice.

Data processing agreement (B2B)
Partial

Privacy policy references SaaS licence agreement with data-protection clauses when acting as processor; standalone public DPA download not found.

Vendor claimed

Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation.

EU AI Act
Unknown

Product markets deepfake detection, translation, and AI companion features; no public AI Act classification or conformity materials found.

Not applicable

Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases.

BSI C5Not listed
Vendor claimed

Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement.

Considerations & known limitations: Private Discuss vs Stackfield
Considerations & known limitationsLogo: Private DiscussPrivate DiscussLogo: StackfieldStackfield
No public independent security audit
Medium

Strong encryption and zero-knowledge claims are first-party only. Security-sensitive buyers should require audit reports, architecture review, and pilot verification before treating E2EE as proven.

Not listed
Incomplete public SaaS subprocessor inventory
Medium

France/EU hosting is claimed, but backup, email, analytics, and mobile push processors are not fully listed publicly. Residual transfer and support-access risk for managed SaaS must be closed in the customer DPA.

Not listed
RCS number inconsistency on public pages
Low

Legal notices and GTS use RCS 828 242 545; privacy policy cites 829 105 741. Confirm legal identity via official registry extract before contracting.

Not listed
Closed proprietary platform
Low

Not open source; GTS emphasise vendor IP. Limits community audit and exit options compared with OSS collab stacks such as Nextcloud.

Not listed
AI features need separate diligence
Medium

Deepfake detection, Private Translate, and AI companion expand the evaluation surface (model location, training data, false positives). Vendor claims on-prem/private processing for some features—verify architecture per deployment mode.

Not listed
E2E is optional and irreversible per roomNot listed
Medium

Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling.

Mobile push and optional US integrationsNot listed
Medium

Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA.

Certifications vendor-assertedNot listed
Low

ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds.

On-premise is commercial, not DIY open sourceNot listed
Low

Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly.

AI features require content decryption for processingNot listed
Medium

Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client.

Fit

Private Discuss

Best fit when

  • French or EU public-sector and regulated orgs wanting a French SAS counterparty for secure meetings and chat
  • Buyers who need large HD meetings (claimed up to 1,000) and webinar-scale events with role and recording control
  • Security teams that require admin kill-switch, MFA, geo restrictions, contact/sharing policies, and version enforcement
  • Deployments that must stay on-premise, behind a firewall, or in air-gapped environments rather than only multi-tenant SaaS
  • Organisations evaluating white-label sovereign collab with in-suite AI translation/deepfake features kept inside customer infrastructure

Poor fit when

  • Teams that require open-source clients/servers and community auditability
  • Buyers who need native Microsoft 365/Google Workspace depth (channels + full Office graph) as the primary collaboration hub
  • Procurement processes that block tools without published independent security audits or named ISO certificate packs
  • Small teams that only need lightweight chat without large video/webinar or heavy admin overhead

Consider instead when

  • When: You already run self-hosted files/groupware and want open-source Talk-style meetings under your keys

    Consider: Nextcloud (Talk)

    Broader OSS hub; different security and UX model than Private Discuss’s proprietary stack

  • When: You primarily need German-entity encrypted business messaging with AD/LDAP cockpit, not large webinars

    Consider: ginlo Business

    Narrower A/V scale; strong messenger admin story

  • When: You need everyday team chat with email bridging rather than government-scale secure video

    Consider: Fleep

    Estonian messenger positioning; different threat model and feature depth

Stackfield

Best fit when

  • German/EU orgs that want one tool for projects and communication instead of Slack + separate PM
  • Teams that need optional zero-knowledge rooms for highly sensitive matters (legal, M&A, HR, clinical ops)
  • Buyers requiring German legal entity, DPA in-product, and claimed ISO/BSI C5 for procurement questionnaires
  • Public sector, banking, insurance, and professional services evaluating cloud with an on-prem exit path
  • Orgs that will enforce 2FA/SSO/IP allowlists and guest-only access for externals

Poor fit when

  • Teams that need always-on E2E with full rich push previews and third-party calendar feeds without trade-offs
  • Engineering orgs standardised on Jira/GitHub-style ALM depth and automation
  • Buyers who require fully open-source, community-supported self-host without a commercial on-prem contract
  • Global enterprises whose primary requirement is the Slack/Teams integration marketplace
  • Very small teams needing only free-tier messaging with no seat-based SaaS commitment

Consider instead when

  • When: You need open-source self-host and full operational control of files/collab apps

    Consider: Nextcloud

    More DIY ops; broader app ecosystem; different PM depth.

  • When: You mainly need regulated secure messaging, not Gantt/portfolios

    Consider: ginlo Business

    Messaging-first German B2B chat; thinner project suite.

  • When: You already run Microsoft 365 and identity is non-negotiable

    Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries

    Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.

  • When: You want lighter EU team chat without full PM suite

    Consider: Fleep

    Chat-centric; different residency/subprocessor profile—verify separately.

Open questions for due diligence

Private Discuss

  • Will the vendor provide a current subprocessor list, DPA, and evidence pack (ISO/audit) for the chosen SaaS region?
  • What is the exact E2EE protocol suite, key custody model, and any server-side components that can access metadata or cleartext in admin/recording scenarios?
  • For on-premise/air-gapped installs: supported OS, HA, update path, and whether AI features run fully offline?
  • Which customer logos on the homepage reflect active production use vs historical/marketing relationships?
  • Which RCS registration number (828 242 545 vs 829 105 741) is authoritative, and is there a group structure beyond the SAS?

Stackfield

  • Will the vendor provide the current BSI C5 report, ISO certificate scope, and full subprocessor annex under NDA if not already in the DPA PDF?
  • Which fields remain outside E2E (metadata, search indexes, analytics) in your planned room configuration?
  • For mobile fleets: is APNs/FCM push acceptable, or must notifications be disabled/restricted?
  • On-premise: exact supported OS/hypervisor matrix, backup model, and upgrade cadence for your estate?
  • Is Stackfield AI (or customer external AI) allowed under your policy for rooms that contain special-category data?