Stackfield
Zusammenfassung aus Eigentümerschaft und CLOUD-Act-Risiko.
-
EU-souverän Dieser Eintrag In EU-/EWR-/Schweizer Eigentum und betrieben, ohne erkennbares CLOUD-Act-Risiko.
-
EU-ansässig EU-betrieben, mit höchstens geringfügigem oder vorübergehendem US-Bezug.
-
EU-gehostet EU-Hosting verfügbar, aber ein US-Mutterkonzern oder Hyperscaler-Unterauftragsverarbeiter erzeugt ein materielles Risiko.
-
US-verbunden Von einem US-Unternehmen betrieben, direkt der US-Jurisdiktion unterworfen.
Munich collaboration suite (Stackfield GmbH, 2012) with per-room end-to-end encryption; ISO 27001 + BSI C5, German data centres, on-premise edition.
Stackfield ist ein EU-eigener Dienst mit Hosting in Deutschland und ohne erkennbares CLOUD-Act-Risiko. Gelistet unter Projektmanagement.
Bewertungsnotizen
Stackfield GmbH (Munich, Maximiliansplatz 17; HRB 199536; founded 2012, led by CEO Cristian Mudure and COO Christopher Diesing; 10,000+ customer companies) combines team chat, tasks, projects, files, whiteboards and audio/video calls in one workspace. Content in rooms created as end-to-end encrypted (a per-room choice at creation, or an organisation-wide default) is encrypted with AES-256 and RSA-2048 in the browser, so Stackfield cannot read it; 1:1 calls are end-to-end encrypted, group conferences are transport-encrypted via Stackfield's own server. ISO/IEC 27001, 27017, 27018 and BSI C5 for Stackfield GmbH; customer data stored in German data centres. The public sub-processor list names four German companies (IONOS Cloud for hosting, Myra Security for DDoS protection, united-domains and Inxmail for email), none US-owned; the DPA is concluded inside the customer account, and the BSI C5 attestation exempts the listing from the DPA-accessibility criterion. EU-owned, no CLOUD Act exposure. An on-premise edition (installed by Stackfield on the customer's servers) is sold as a subscription for 100+ users.
Befund
- CLOUD Act
- CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines Dieser Eintrag EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
-
- Eigentümer
- Eigentümerschaft
Wo die letztliche Kontrolle über das Betreiberunternehmen liegt.
-
EU-Eigentum Dieser Eintrag In der EU ansässig und EU-kontrolliert; keine nennenswerte US-Beteiligung.
-
EU-Sitz, US-finanziert EU-Hauptsitz, aber von US-Risikokapital oder -Private-Equity kontrolliert.
-
EU-Tochter, US-Mutter Europäische Betriebsgesellschaft im Eigentum einer US-Muttergesellschaft.
-
US-Eigentum Das Betreiberunternehmen selbst hat seinen Hauptsitz in den USA.
-
Sonstige Eine Nicht-EU-Jurisdiktion. Schweizer/EWR-Eigentum gilt hier als europäisch; UK und andere nicht.
-
- Unterauftragsverarbeiter
- 4 · 0 US
Geprüfte Signale
-
EU-/Angemessenheits-Hosting: Ja
-
EU-/Angemessenheits-Betreiber: Ja
-
Keine US-CLOUD-Act-Exposition: Ja
-
Öffentlicher AVV: Nicht bewertet
-
Unterauftragsverarbeiter offengelegt: Ja
-
Open-Source-Clients: Nein
-
Zertifizierung durch Dritte: Ja
Springen zu
Über Stackfield
Stackfield is a Munich-based team-collaboration platform operated by Stackfield GmbH (Maximiliansplatz 17, 80333 Munich; HRB 199536 Local Court Munich; VAT DE283871998; managing director Cristian Mudure). Founded in 2012 and led by CEO Cristian Mudure and COO Christopher Diesing, the company serves 10,000+ companies with one workspace that combines team chat, tasks and projects (list, Kanban, Gantt, milestones, time tracking, portfolios), files, whiteboards, audio/video calls with screen sharing, and email forwarding. Stackfield positions itself against Slack, Microsoft Teams, Asana, monday.com and ClickUp.
The security model is the reason buyers shortlist it. Content in rooms created as end-to-end encrypted (messages, tasks, files and file contents, pages, discussions, whiteboards, events) is encrypted with AES-256 and RSA-2048 in the browser before it reaches Stackfield's servers, so Stackfield cannot read it. Encryption is chosen per room when the room is created, or set as the default by the organisation admin, and cannot be switched on later for an existing room. Calls follow a separate rule: 1:1 calls are end-to-end encrypted, while group conferences run transport-encrypted (WebRTC with DTLS/SRTP) through Stackfield's own server, with no recordings or transcripts stored. Using the optional AI add-on on encrypted content means the browser decrypts it and sends it, transport-encrypted, to open-source models Stackfield runs on IONOS in Germany. Stackfield GmbH holds ISO/IEC 27001, 27017 and 27018 and a BSI C5 attestation; customer data is stored in German data centres. The public sub-processor list names four German companies (IONOS Cloud for hosting, Myra Security for DDoS protection, united-domains and Inxmail for email), none US-owned.
Pricing in EUR, per user and month on annual billing: Starter €9 (up to 10 users and 3 rooms), Business €14, Premium €18 (adds audio/video conferences up to 30 participants, browser join for guests without an account, whiteboards, unlimited externals), Enterprise €28 (SSO, API provisioning, unlimited organisations). There is no free plan; the 14-day trial unlocks Premium. Add-ons: AI €3.90, Office editing €2.40, Public Sector (EVB-IT cloud contract) €2.40, and a §203 StGB confidentiality agreement for professional secrecy holders €3.90. An on-premise edition runs on the customer's own servers: subscription from €28 per user and month on annual billing for at least 100 users, installed and updated by Stackfield. Best fit: German and DACH organisations that need a Slack or Teams replacement with encrypted project rooms, BSI C5 / ISO 27001 evidence for procurement, and the option to move on-premise later.
Unterauftragsverarbeiter-Karte · 4
-
Inxmail GmbH EUDeutschland
Internet-based solution for sending and receiving email.
-
IONOS Cloud GmbH EUDeutschland
Compute capacity in a cloud provider's data centre: hosting of the Stackfield platform and customer data (until 30 June 2026 contracted as IONOS SE). Also hosts the open-source models behind the AI add-on.
-
Myra Security GmbH EUDeutschland
Internet-based protection of the IT infrastructure (DDoS mitigation and web application firewall in front of stackfield.com).
-
united-domains GmbH EUDeutschland
Internet-based solution for sending and receiving email.
| Anbieter | Land | Zweck | Eigentümer |
|---|---|---|---|
| Inxmail GmbH | Deutschland | Internet-based solution for sending and receiving email. | EU |
| IONOS Cloud GmbH | Deutschland | Compute capacity in a cloud provider's data centre: hosting of the Stackfield platform and customer data (until 30 June 2026 contracted as IONOS SE). Also hosts the open-source models behind the AI add-on. | EU |
| Myra Security GmbH | Deutschland | Internet-based protection of the IT infrastructure (DDoS mitigation and web application firewall in front of stackfield.com). | EU |
| united-domains GmbH | Deutschland | Internet-based solution for sending and receiving email. | EU |
Quelle: veröffentlichte Unterauftragsverarbeiter-Liste des Anbieters, gelesen am 2 Okt 2026.
Rahmenwerke & Zertifizierungen
Funktionsmatrix
Tabelle 2Funktionen von Stackfield
Integration & Zugriff
Compliance & Governance
Preise & Tarife
Öffentliche Dokumente
Alternativen in dieser Kategorie
-
Niederlande · 10 $/Mt.EU-ansässigCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Dieser Eintrag Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Nein Subprozessoren: Nein Open Source: Ja -
-
Deutschland · 19.99 €/Mt.EU-souveränCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines Dieser Eintrag EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Nicht bewertet Subprozessoren: Nein Open Source: Nein -
-
Deutschland · 99 €/Mt.EU-ansässigCLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
-
Keines EU-Betreiber, kein US-Mutterkonzern, keine relevanten US-Unterauftragsverarbeiter.
-
Gering Dieser Eintrag Ein vorübergehender US-Unterauftragsverarbeiter (CDN, Karten); ruhende Daten bleiben in der EU.
-
Erheblich US-Mutterkonzern oder ein zentraler Unterauftragsverarbeiter ist ein US-Hyperscaler.
-
Direkt Der Betreiber selbst ist US-ansässig.
Öffentl. AVV: Nein Subprozessoren: Ja Open Source: Nein -
| Produkt | Souveränität | CLOUD Act | Signale | Ab |
|---|---|---|---|---|
|
|
EU-ansässig | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Nein
Subprozessoren: Nein
Open Source: Ja
|
10 $/Mt. |
|
|
EU-souverän | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Nicht bewertet
Subprozessoren: Nein
Open Source: Nein
|
19.99 €/Mt. |
|
|
EU-ansässig | CLOUD-Act-Risiko
Wie stark Kundendaten US-Behörden nach dem CLOUD Act (Clarifying Lawful Overseas Use of Data Act) ausgesetzt sind.
|
Öffentl. AVV: Nein
Subprozessoren: Ja
Open Source: Nein
|
99 €/Mt. |