Nextcloud
Germany· Cloud Computing
Confronta Nextcloud e Stackfield su capacità, giurisdizione, garanzie e idoneità per acquirenti europei.
Germany· Cloud Computing
Germany· Groupware
Needs review
Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).
Le righe evidenziate differiscono tra i due prodotti.
| Caratteristica | ||
|---|---|---|
| Paese di origine | ||
| Categoria | Cloud Computing | Groupware |
| Open source | Sì | No |
| Self-hosted | Sì | Sì |
| Sede | Non indicato | Germany |
| Soggetto giuridico | Non indicato | Stackfield GmbH, Maximiliansplatz 17, 80333 München, Germany |
| Capogruppo / controllo USA | Non indicato | Nessuna capogruppo USA nota |
| Esposizione CLOUD Act (indicativa) | Non indicato | Medio |
| Hosting / residenza | Non indicato | Product data claimed stored in Germany; infrastructure provider IONOS SE (DE). Vendor states no AWS/GCP/Azure product subcontractors. Named EU processors: Inxmail (email, DE), Myra Security (edge protection, DE). Mobile push uses Apple APNs and Google push services (US platforms). Optional admin-enabled Giphy (US). Marketing site uses Google/Bing ads (not workspace content path). Optional customer-keyed external AI leaves Stackfield’s IONOS-hosted model path. |
| Riassunto | Open-source, self-hosted content collaboration Hub from Nextcloud GmbH (Germany): Files, Talk, Groupware, Office, local AI Assistant, and Flow—an on-prem alternative to Microsoft 365-style suites. | German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise. |
| Tag |
| A colpo d'occhio | ||
|---|---|---|
| HQ | Non indicato | Munich, Germany |
| Legal entity | Non indicato | Stackfield GmbH (HRB 199536) |
| Founded | Non indicato | 2012 (vendor claim) |
| Hosting | Non indicato | Germany; IONOS SE (vendor-named) |
| Deployment | Non indicato | SaaS cloud + commercial on-premise |
| Open source | Non indicato | No |
| Commercial model | Non indicato | Seat-based plans; trial; AI/Office add-ons |
| Key capabilities | ||
|---|---|---|
| EU-operated (DE) | Non indicato | Sì |
| Optional client-side E2E | Non indicato | Sì |
| Germany hosting (IONOS) | Non indicato | Sì |
| ISO 27001 + BSI C5 (claimed) | Non indicato | Sì |
| Commercial on-premise | Non indicato | Sì |
| Chat + PM + video | Non indicato | Sì |
Sincronizzazione e condivisione file sicura
Sincronizzazione crittografata tra dispositivi, con link pubblici, permessi e scadenza. Vantaggi: accesso remoto sicuro, nessuna perdita di dati — ideale per team con file sensibili.
Collaborazione in tempo reale e Office
Integrazione Collabora/OnlyOffice per editing documenti live. Talk abilita chat e videoconferenze. Produttività come Google Workspace, ma self-hosted per la privacy.
Groupware e suite di produttività
Calendario, contatti, mail e attività in un'app. Flow automatizza i flussi di lavoro; Assistant usa IA locale per traduzioni e riepiloghi. Centralizza gli strumenti, riducendo la proliferazione di app.
Optional client-side E2E rooms (AES-256 + RSA-2048)
Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.
Tasks, Gantt, portfolios, and workflows in the same rooms as chat
List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.
Video conferences, screen share, and guest/external roles
Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.
Germany cloud (IONOS) plus commercial on-premise
Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.
Enterprise access controls and in-product DPA
Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.
| Assurance & compliance | ||
|---|---|---|
| Independent security / no-logs audit | Non indicato | Partial Vendor claims regular penetration tests and APPVISORY Trusted App for mobile; no public independent no-logs or full security audit report found. |
| ISO 27001 | Non indicato | Vendor claimed Vendor states ISO 27001 (plus 27017/27018) with certificate download on security page; not independently registry-verified in this draft. |
| SOC 2 / SOC 3 | Non indicato | Not found No SOC 2/3 claim found on primary security pages reviewed. |
| BSI C5 | Non indicato | Vendor claimed Vendor claims BSI C5 attestation on homepage and security page; obtain current report in procurement. |
| GDPR / EU data protection | Non indicato | Vendor claimed EU controller Stackfield GmbH; Germany hosting claims; in-product DPA; public privacy policy with processor list fragments. |
| US CLOUD Act exposure (indicative) | Non indicato | Partial EU entity, no known US parent, core hosting claimed via IONOS DE without AWS/GCP/Azure. Residual paths: Apple/Google mobile push; optional Giphy; optional customer external AI. Assessment only—not legal advice. |
| Data processing agreement (B2B) | Non indicato | Vendor claimed Organisation admins can conclude DPA inside Organisation Settings and download signed PDF; one DPA per organisation. |
| EU AI Act | Non indicato | Not applicable Optional text-assist AI add-on; not an AI-centric product. Revisit if agents expand into high-risk use cases. |
| Considerations & known limitations | ||
|---|---|---|
| E2E is optional and irreversible per room | Non indicato | Medium Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling. |
| Mobile push and optional US integrations | Non indicato | Medium Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA. |
| Certifications vendor-asserted | Non indicato | Low ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds. |
| On-premise is commercial, not DIY open source | Non indicato | Low Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly. |
| AI features require content decryption for processing | Non indicato | Medium Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client. |
Non indicato
Non indicato
When: You need open-source self-host and full operational control of files/collab apps
Consider: Nextcloud
More DIY ops; broader app ecosystem; different PM depth.
When: You mainly need regulated secure messaging, not Gantt/portfolios
Consider: ginlo Business
Messaging-first German B2B chat; thinner project suite.
When: You already run Microsoft 365 and identity is non-negotiable
Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries
Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.
When: You want lighter EU team chat without full PM suite
Consider: Fleep
Chat-centric; different residency/subprocessor profile—verify separately.
Non indicato