ginlo Business vs Stackfield

Comparez ginlo Business et Stackfield sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Microsoft Teams, Slack

Logo: ginlo Business

ginlo Business

Germany· Groupware

Needs review

Shortlist when you need a German-entity, Germany-hosted encrypted business messenger with Management Cockpit (AD/LDAP, policies, remote wipe) and free external reach via ginlo Private. Skip when you require open source, self-hosting, or published independent crypto audits—consider Wire or Nextcloud Talk instead.

EU-operated (Germany)End-to-end encryption (claimed)Germany hosting (claimed)AD/LDAP admin cockpitManaged SaaSNot open source
Logo: Stackfield

Stackfield

Germany· Groupware

Needs review

Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).

EU-operated (DE)Optional client-side E2EGermany hosting (IONOS)ISO 27001 + BSI C5 (claimed)Commercial on-premiseChat + PM + video
ginlo Business vs Stackfield: Aperçu
CaractéristiqueLogo: ginlo Businessginlo BusinessLogo: StackfieldStackfield
Pays d'origineGermanyGermany
CatégorieGroupwareGroupware
Open sourceNonNon
Auto-hébergéNonOui
SiègeGermanyGermany
Entité légaleginlo.net Gesellschaft für Datenkommunikationsdienste mbH (ginlo.net GmbH), Rupert-Mayer-Str. 44, 81379 MunichStackfield GmbH, Maximiliansplatz 17, 80333 München, Germany
Maison mère / contrôle USAucune maison mère US connueAucune maison mère US connue
Exposition CLOUD Act (indicative)MoyenMoyen
Hébergement / résidenceVendor GTC require server and storage in a German computer centre certified to ISO 27001 based on BSI IT-Grundschutz; privacy notice states processors such as German data-centre operators, internet/line providers, and payment providers, and asserts no third-country processing by ginlo. Host operator names are not published. Mobile push uses platform channels (e.g. Apple Push Notification, Google Cloud Messaging) per GTC.Product data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path.
Résumé

German-hosted secure business messenger from Munich-based ginlo.net GmbH: E2EE chat, files, and A/V calls with Management Cockpit admin for AD/LDAP, policies, and external ginlo Private contacts.

German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise.

Tags
En un coup d'œil: ginlo Business vs Stackfield
En un coup d'œilLogo: ginlo Businessginlo BusinessLogo: StackfieldStackfield
HQMunich, GermanyMunich, Germany
Legal entityginlo.net GmbH (HRB 254209)Stackfield GmbH (HRB 199536)
DeploymentManaged SaaS (not self-hosted)SaaS cloud + commercial on-premise
Hosting (vendor claim)Germany computer centre; no ginlo-initiated third-country transferNon indiqué
AdminOptional Management Cockpit (AD/LDAP/CSV, policies, MDM hooks)Non indiqué
Commercial modelSeat licences; optional trial (see vendor for current terms)Seat-based plans; trial; AI/Office add-ons
FoundedNon indiqué2012 (vendor claim)
HostingNon indiquéGermany; IONOS SE (vendor-named)
Open sourceNon indiquéNo
Key capabilities: ginlo Business vs Stackfield
Key capabilitiesLogo: ginlo Businessginlo BusinessLogo: StackfieldStackfield
EU-operated (Germany)OuiOui
End-to-end encryption (claimed)OuiNon indiqué
Germany hosting (claimed)OuiOui
AD/LDAP admin cockpitOuiNon indiqué
Managed SaaSOuiNon indiqué
Not open sourceOuiNon indiqué
Optional client-side E2ENon indiquéOui
ISO 27001 + BSI C5 (claimed)Non indiquéOui
Commercial on-premiseNon indiquéOui
Chat + PM + videoNon indiquéOui

ginlo Business

  • Full encryption design for chat and files

    Vendor GTC describe a full-encryption architecture: no unencrypted messages stored on ginlo servers, decryption keys only on authorised messenger clients, and encryption in transit plus on devices and intermediate server storage. Practical for regulated orgs replacing email for sensitive threads—confirm cipher suite details in procurement docs.

  • Management Cockpit with AD/LDAP and MDM hooks

    Central admin for licences, CSV/AD/LDAP user import, department keywords, password and attachment policies, corporate design, groups, and info channels. Leaver accounts can be blocked and communications deleted quickly when devices are lost—built for IT ops without requiring a messaging platform engineer.

  • Business to ginlo Private external bridge

    Employees on paid Business seats can message external contacts on free ginlo Private without charging those outsiders. Suits practices, schools, and authorities that need secure outbound reach beyond the licensed tenant.

  • Multi-device sync, channels, and A/V conferences

    Use up to ten devices per account with server-side sync while messages remain available; announcement/content channels for org-wide updates; audio/video conferences with screen sharing; self-deleting and scheduled messages plus QR identity checks and ginlo ID without exposing a phone number.

  • Germany-hosted managed service

    Contracting party is ginlo.net GmbH in Munich; GTC require the server and storage in a German computer centre certified to ISO 27001 based on BSI IT-Grundschutz, with no ginlo-initiated third-country transfer. Managed SaaS only—no public self-host option.

Stackfield

  • Optional client-side E2E rooms (AES-256 + RSA-2048)

    Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.

  • Tasks, Gantt, portfolios, and workflows in the same rooms as chat

    List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.

  • Video conferences, screen share, and guest/external roles

    Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.

  • Germany cloud (IONOS) plus commercial on-premise

    Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.

  • Enterprise access controls and in-product DPA

    Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.

Assurance & compliance: ginlo Business vs Stackfield
Assurance & complianceLogo: ginlo Businessginlo BusinessLogo: StackfieldStackfield
Independent security / no-logs audit
Not found

Marketing mentions regular security audits; no public independent audit report located on vendor site.

Partial

Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found.

ISO 27001
Vendor claimed

Claimed for the hosting computer centre based on IT-Grundschutz (BSI); no public certificate number/PDF found.

Vendor claimed

Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft.

SOC 2 / SOC 3
Not found
Not found

No SOC 2/3 claim found on primary security pages reviewed.

GDPR / EU data protection
Vendor claimed

EU/German entity; public privacy notice under GDPR; supervisory authority BayLDA referenced.

Vendor claimed

EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments.

US CLOUD Act exposure (indicative)
Partial

German entity, no known US parent, Germany hosting claimed; residual exposure via APNs/FCM push paths and unnamed processors. Not legal advice.

Partial

EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice.

Data processing agreement (B2B)
Not found

Privacy policy published; standalone B2B DPA download not found on public site—confirm in procurement.

Vendor claimed

Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation.

EU AI Act
Not applicable

Secure messaging product; not AI-centric.

Not applicable

Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases.

BSI IT-Grundschutz (hosting)
Vendor claimed

ISO 27001 based on IT-Grundschutz claimed for data centre in marketing and GTC.

Non indiqué
BSI C5Non indiqué
Vendor claimed

Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement.

Considerations & known limitations: ginlo Business vs Stackfield
Considerations & known limitationsLogo: ginlo Businessginlo BusinessLogo: StackfieldStackfield
Limited public audit and cert artefacts
Medium

ISO 27001/IT-Grundschutz and regular audits are vendor-asserted; no public audit PDF or cert registry entry found. Procurement should request evidence under NDA.

Non indiqué
Closed managed SaaS only
Medium

No self-host or open-source server path. Exit and independent verification depend on vendor cooperation and export tooling.

Non indiqué
Mobile push via Apple/Google
Low

GTC reference Apple Push Notification and Google Cloud Messaging for new-message signals. Content is claimed E2EE, but delivery metadata still touches US platform infrastructure.

Non indiqué
Processors described by category only
Medium

Privacy policy lists German data centres, line providers, and payment providers without naming operators. Harder to complete CLOUD Act / transfer diligence from public sources alone.

Non indiqué
External parties must use ginlo
Low

The Private bridge helps, but contacts still need ginlo Private installed—unlike email or WhatsApp ubiquity.

Non indiqué
E2E is optional and irreversible per roomNon indiqué
Medium

Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling.

Mobile push and optional US integrationsNon indiqué
Medium

Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA.

Certifications vendor-assertedNon indiqué
Low

ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds.

On-premise is commercial, not DIY open sourceNon indiqué
Low

Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly.

AI features require content decryption for processingNon indiqué
Medium

Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client.

Adéquation

ginlo Business

Best fit when

  • German or EU orgs that want a Munich legal entity and stated Germany-only server placement for business chat
  • Practices, schools, authorities, and SMEs needing admin control (licences, AD/LDAP import, leaver wipe) without running a messaging stack
  • Teams replacing informal WhatsApp/email for sensitive internal and external conversations when counterparts will install ginlo Private
  • Rollouts that need multi-device sync, channels, and A/V calls in one encrypted messenger rather than a full collaboration suite

Poor fit when

  • Buyers that mandate open-source clients/servers or on-premises deployment under their own infrastructure
  • Enterprises requiring published independent security audits and named public subprocessor lists before shortlisting
  • Teams needing deep Slack/Teams-style workspace integrations, bots, and app ecosystems
  • Organisations whose external audience will not install a second messenger app

Consider instead when

  • When: You need open-source components, MLS roadmap, or private-cloud/on-prem options

    Consider: Wire (Swiss secure collaboration)

    Wire is commonly shortlisted for enterprise secure messaging with more deployment flexibility than pure SaaS messengers.

  • When: You already run a self-hosted collaboration hub and want chat inside that stack

    Consider: Nextcloud Talk (Germany)

    Pairs with Nextcloud Files/Groupware; different product shape than a standalone dual Business/Private messenger.

  • When: You need mass consumer reach more than organisational sovereignty

    Consider: WhatsApp Business or Microsoft Teams

    Higher network effects; weaker EU-sovereignty and admin story for sensitive regulated chat.

Stackfield

Best fit when

  • German/EU orgs that want one tool for projects and communication instead of Slack + separate PM
  • Teams that need optional zero-knowledge rooms for highly sensitive matters (legal, M&A, HR, clinical ops)
  • Buyers requiring German legal entity, DPA in-product, and claimed ISO/BSI C5 for procurement questionnaires
  • Public sector, banking, insurance, and professional services evaluating cloud with an on-prem exit path
  • Orgs that will enforce 2FA/SSO/IP allowlists and guest-only access for externals

Poor fit when

  • Teams that need always-on E2E with full rich push previews and third-party calendar feeds without trade-offs
  • Engineering orgs standardised on Jira/GitHub-style ALM depth and automation
  • Buyers who require fully open-source, community-supported self-host without a commercial on-prem contract
  • Global enterprises whose primary requirement is the Slack/Teams integration marketplace
  • Very small teams needing only free-tier messaging with no seat-based SaaS commitment

Consider instead when

  • When: You need open-source self-host and full operational control of files/collab apps

    Consider: Nextcloud

    More DIY ops; broader app ecosystem; different PM depth.

  • When: You mainly need regulated secure messaging, not Gantt/portfolios

    Consider: ginlo Business

    Messaging-first German B2B chat; thinner project suite.

  • When: You already run Microsoft 365 and identity is non-negotiable

    Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries

    Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.

  • When: You want lighter EU team chat without full PM suite

    Consider: Fleep

    Chat-centric; different residency/subprocessor profile—verify separately.

Open questions for due diligence

ginlo Business

  • Will the vendor sign a B2B DPA and provide a current named subprocessor list including data-centre operator(s)?
  • Can procurement obtain ISO 27001 certificate details and latest independent security assessment under NDA?
  • Which exact encryption protocols/algorithms are used for messaging and calls today (beyond BSI recommendations)?
  • What export, eDiscovery, and legal-hold options exist within the 90-day server retention model?

Stackfield

  • Will the vendor provide the current BSI C5 report, ISO certificate scope, and full subprocessor annex under NDA if not already in the DPA PDF?
  • Which fields remain outside E2E (metadata, search indexes, analytics) in your planned room configuration?
  • For mobile fleets: is APNs/FCM push acceptable, or must notifications be disabled/restricted?
  • On-premise: exact supported OS/hypervisor matrix, backup model, and upgrade cadence for your estate?
  • Is Stackfield AI (or customer external AI) allowed under your policy for rooms that contain special-category data?