Stackfield vs Wire

Comparez Stackfield et Wire sur les capacités, la juridiction, les garanties et l'adéquation pour les acheteurs européens.

Tous deux listés comme alternatives à: Microsoft Teams, Slack

Logo: Stackfield

Stackfield

Germany· Groupware

Needs review

Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).

EU-operated (DE)Optional client-side E2EGermany hosting (IONOS)ISO 27001 + BSI C5 (claimed)Commercial on-premiseChat + PM + video
Logo: Wire

Wire

Switzerland· Groupware

Needs review

Shortlist Wire when you need always-on E2EE collaboration (MLS), Swiss legal entity, open-source clients/server, and a credible path from EU cloud to on-prem/federation. Skip when you need deep Microsoft 365/Slack app ecosystems or a pure non-AWS/US-SaaS subprocessor footprint—consider Nextcloud Talk or a Germany-hosted managed messenger such as ginlo Business instead.

E2EE + MLSOpen sourceOn-prem / self-hostSwiss HQEU cloud regionsISO 27001/27701 (claimed)
Stackfield vs Wire: Aperçu
CaractéristiqueLogo: StackfieldStackfieldLogo: WireWire
Pays d'origineGermanySwitzerland
CatégorieGroupwareGroupware
Open sourceNonOui
Auto-hébergéOuiOui
SiègeGermanySwitzerland
Entité légaleStackfield GmbH, Maximiliansplatz 17, 80333 München, GermanyWire Swiss GmbH (CHE 432.881.146), Untermüli 9, CH-6300 Zug; EU rep Wire Germany GmbH, Berlin
Droit applicableNon indiquéSwiss law (business ToU for non-US use); jurisdiction Zurich
Maison mère / contrôle USAucune maison mère US connueAucune maison mère US connue
Exposition CLOUD Act (indicative)MoyenMoyen
Hébergement / résidenceProduct data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path.Cloud: servers in Germany and Ireland per security pages; DPA lists Amazon Web Services EMEA SARL for hosting (EU). Other subprocessors include Google Cloud EMEA (email), Zendesk, HubSpot, Salesforce (Germany processing location stated), Stripe (USA/SCCs), Box, ContractHero, Countly (Germany), Wire Germany GmbH. On-prem customers host in their own environment.
Résumé

German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise.

Swiss open-source secure messenger from Wire Swiss GmbH: always-on E2EE messaging, calls, and files (MLS), cloud or on-premises, for regulated teams and public sector.

Tags
En un coup d'œil: Stackfield vs Wire
En un coup d'œilLogo: StackfieldStackfieldLogo: WireWire
HQMunich, GermanyZug, Switzerland (Wire Swiss GmbH)
Legal entityStackfield GmbH (HRB 199536)Non indiqué
Founded2012 (vendor claim)Non indiqué
HostingGermany; IONOS SE (vendor-named)Non indiqué
DeploymentSaaS cloud + commercial on-premiseEU cloud and/or on-prem / private cloud
Open sourceNoYes (clients GPL-3; server AGPL-3)
Commercial modelSeat-based plans; trial; AI/Office add-onsNon indiqué
EU representativeNon indiquéWire Germany GmbH, Berlin
ProductNon indiquéE2EE messenger + calls + files; optional Drive
Hosting (cloud)Non indiquéDE/IE regions; AWS EMEA (per DPA)
Key capabilities: Stackfield vs Wire
Key capabilitiesLogo: StackfieldStackfieldLogo: WireWire
EU-operated (DE)OuiNon indiqué
Optional client-side E2EOuiNon indiqué
Germany hosting (IONOS)OuiNon indiqué
ISO 27001 + BSI C5 (claimed)OuiNon indiqué
Commercial on-premiseOuiNon indiqué
Chat + PM + videoOuiNon indiqué
E2EE + MLSNon indiquéOui
Open sourceNon indiquéOui
On-prem / self-hostNon indiquéOui
Swiss HQNon indiquéOui
EU cloud regionsNon indiquéOui
ISO 27001/27701 (claimed)Non indiquéOui

Stackfield

  • Optional client-side E2E rooms (AES-256 + RSA-2048)

    Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.

  • Tasks, Gantt, portfolios, and workflows in the same rooms as chat

    List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.

  • Video conferences, screen share, and guest/external roles

    Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.

  • Germany cloud (IONOS) plus commercial on-premise

    Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.

  • Enterprise access controls and in-product DPA

    Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.

Wire

  • Always-on MLS / E2EE for chat, calls, and files

    Messaging, conference calls, and in-app file shares are end-to-end encrypted by default—no toggle. Wire markets full-product MLS (IETF Messaging Layer Security) for scalable group key exchange, alongside Proteus/Double Ratchet heritage for pairwise messaging and SRTP/DTLS for calls. Suits orgs that reject optional encryption modes.

  • Guest rooms and external collaboration

    Invite outsiders into E2EE conversations via guest rooms in the browser without requiring a full account download, plus external team members with lifecycle controls (removal drops their history access). Practical for contractors, clients, and inter-org projects that must stay off consumer WhatsApp.

  • Cloud, on-premises, air-gap, and federation

    Run managed Wire Cloud or deploy on-premises/private cloud—including air-gapped networks—with optional federation between isolated Wire backends and admin control over which backends may interconnect. Aimed at governments and CNI that cannot accept pure SaaS only.

  • Enterprise identity: SSO, SCIM, and admin policy

    Enterprise tier adds SAML-based single sign-on, SCIM provisioning, and granular admin controls (for example enforce app lock, restrict self-deleting messages). Built for complex directories rather than only self-serve SMB signup.

  • Open-source clients, server, and crypto

    Wire publishes client, server (wire-server, AGPL-3.0), and core-crypto components on GitHub for independent review. Multi-device accounts (up to 8 devices) with ID Shield certificate-based device verification reduce manual fingerprint workflows while keeping device trust visible.

Assurance & compliance: Stackfield vs Wire
Assurance & complianceLogo: StackfieldStackfieldLogo: WireWire
Independent security / no-logs audit
Partial

Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found.

Partial

Vendor publishes Security/Privacy whitepapers and states external pen tests and ISO audits in TOMs; public third-party audit PDFs (e.g. historic Kudelski/X41 claims in secondary sources) were not re-verified as current primary evidence during this draft.

ISO 27001
Vendor claimed

Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft.

Vendor claimed

Asserted on Wire security marketing page; request certificate in procurement.

SOC 2 / SOC 3
Not found

No SOC 2/3 claim found on primary security pages reviewed.

Not found

No public SOC 2/3 claim located on security/legal pages during research.

BSI C5
Vendor claimed

Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement.

Non indiqué
GDPR / EU data protection
Vendor claimed

EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments.

Vendor claimed

Swiss FADP controller; GDPR for EU/EEA individuals; EU Art. 27 representative Wire Germany GmbH; public privacy policy and DPA.

US CLOUD Act exposure (indicative)
Partial

EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice.

Partial

Swiss entity / no known US parent, but AWS EMEA hosting and US-parent SaaS subprocessors (Stripe, HubSpot, Salesforce, Zendesk corporate groups; APNs/FCM push). Not legal advice.

Data processing agreement (B2B)
Vendor claimed

Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation.

Vendor claimed

Public Art. 28 GDPR Processing Agreement with TOMs and Annex 2 subprocessor list (updated March 12, 2025 on page).

EU AI Act
Not applicable

Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases.

Not applicable

Secure messaging/collaboration product; not marketed as an AI system core offering.

ISO 27701Non indiqué
Vendor claimed

Asserted alongside ISO 27001 on security page; not independently verified here.

Cyber Essentials (UK)Non indiqué
Vendor claimed

Asserted on security page as UK government-backed baseline certification.

Considerations & known limitations: Stackfield vs Wire
Considerations & known limitationsLogo: StackfieldStackfieldLogo: WireWire
E2E is optional and irreversible per room
Medium

Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling.

Non indiqué
Mobile push and optional US integrations
Medium

Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA.

Non indiqué
Certifications vendor-asserted
Low

ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds.

Non indiqué
On-premise is commercial, not DIY open source
Low

Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly.

Non indiqué
AI features require content decryption for processing
Medium

Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client.

Non indiqué
AWS EMEA + US-parent SaaS subprocessorsNon indiqué
Medium

Even with DE/IE regions and a Swiss controller, cloud tenants depend on AWS EMEA and several US-group tools for hosting, CRM, support, or payments. On-prem reduces hosting dependency but not necessarily all vendor-side SaaS.

Wire Drive is not client-side E2EENon indiqué
Medium

DPA distinguishes messenger E2EE from Drive encryption-at-rest with possible operator access. Misclassifying Drive as zero-knowledge chat storage creates compliance risk.

ISO / Cyber Essentials need certificate proofNon indiqué
Low

Certifications are prominently claimed on marketing pages but should be validated with current certificates and scope statements before audit reliance.

Mobile push via APNs/FCMNon indiqué
Low

Standard mobile delivery path involves Apple/Google push infrastructure for wake-ups; Wire states content is not shared. F-Droid build available to avoid FCM.

Adéquation

Stackfield

Best fit when

  • German/EU orgs that want one tool for projects and communication instead of Slack + separate PM
  • Teams that need optional zero-knowledge rooms for highly sensitive matters (legal, M&A, HR, clinical ops)
  • Buyers requiring German legal entity, DPA in-product, and claimed ISO/BSI C5 for procurement questionnaires
  • Public sector, banking, insurance, and professional services evaluating cloud with an on-prem exit path
  • Orgs that will enforce 2FA/SSO/IP allowlists and guest-only access for externals

Poor fit when

  • Teams that need always-on E2E with full rich push previews and third-party calendar feeds without trade-offs
  • Engineering orgs standardised on Jira/GitHub-style ALM depth and automation
  • Buyers who require fully open-source, community-supported self-host without a commercial on-prem contract
  • Global enterprises whose primary requirement is the Slack/Teams integration marketplace
  • Very small teams needing only free-tier messaging with no seat-based SaaS commitment

Consider instead when

  • When: You need open-source self-host and full operational control of files/collab apps

    Consider: Nextcloud

    More DIY ops; broader app ecosystem; different PM depth.

  • When: You mainly need regulated secure messaging, not Gantt/portfolios

    Consider: ginlo Business

    Messaging-first German B2B chat; thinner project suite.

  • When: You already run Microsoft 365 and identity is non-negotiable

    Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries

    Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.

  • When: You want lighter EU team chat without full PM suite

    Consider: Fleep

    Chat-centric; different residency/subprocessor profile—verify separately.

Wire

Best fit when

  • Enterprises and public sector needing default E2EE for chat, calls, and files—not optional modes
  • Buyers evaluating MLS / post-quantum-ready group crypto roadmaps
  • Orgs that want open-source clients and server for independent review
  • Deployments that may start on EU cloud and later move to on-prem, air-gap, or federated backends
  • Teams that must collaborate with guests/contractors without forcing full seats or consumer WhatsApp
  • Swiss or EU procurement expecting a European legal entity and published DPA/subprocessor list

Poor fit when

  • Teams standardised on Teams/Slack primarily for apps, bots, and Office workflows rather than message confidentiality
  • Buyers requiring zero US-group cloud or US SaaS subprocessors (Wire Cloud uses AWS EMEA and several US-parent tools)
  • Use cases that depend on Wire Drive as if it were client-side E2EE messenger storage
  • Very small groups that only need a simple consumer messenger without admin, SSO, or on-prem

Consider instead when

  • When: You want a German managed business messenger with AD/LDAP cockpit and no self-host requirement

    Consider: ginlo Business

    Stronger Germany-hosting contract language; weaker open-source/on-prem story than Wire

  • When: Chat is secondary to self-hosted files, calendars, and groupware you already run

    Consider: Nextcloud (Talk / groupware)

    Broader collaboration suite; different crypto/admin model than Wire MLS messenger

  • When: You need the Microsoft 365 or Slack ecosystem more than E2EE-by-default

    Consider: Microsoft Teams or Slack

    Richer workplace integrations; weaker default E2EE and European sovereignty story

Open questions for due diligence

Stackfield

  • Will the vendor provide the current BSI C5 report, ISO certificate scope, and full subprocessor annex under NDA if not already in the DPA PDF?
  • Which fields remain outside E2E (metadata, search indexes, analytics) in your planned room configuration?
  • For mobile fleets: is APNs/FCM push acceptable, or must notifications be disabled/restricted?
  • On-premise: exact supported OS/hypervisor matrix, backup model, and upgrade cadence for your estate?
  • Is Stackfield AI (or customer external AI) allowed under your policy for rooms that contain special-category data?

Wire

  • Can the vendor provide current ISO 27001/27701 and Cyber Essentials certificates with scope covering the proposed deployment?
  • For our data classification, which workloads stay on messenger E2EE versus Wire Drive?
  • What exact AWS regions/AZs and backup/DR locations apply to our cloud tenant?
  • Which enterprise features require on-prem versus cloud, and what federation limits apply across backends?
  • Are independent crypto/security assessment reports available under NDA, and how recent are they?