Threema
Synthèse de la propriété et de l’exposition au CLOUD Act.
-
Souverain UE Cette fiche Détenu et exploité dans l’UE/EEE/Suisse, sans exposition au CLOUD Act identifiée.
-
Basé UE Exploité dans l’UE, avec au plus une exposition américaine mineure ou transitoire.
-
Hébergé UE Hébergement UE disponible, mais une maison mère américaine ou un sous-traitant hyperscaler crée une exposition matérielle.
-
Lié aux US Exploité par une entité constituée aux États-Unis, directement soumise à la juridiction américaine.
Swiss E2EE messenger (Pfäffikon SZ, founded 2012), own servers in ISO 27001-certified Swiss data centres, no phone number required; consumer + enterprise (Threema Work) + on-prem.
Threema est un service sous contrôle européen hébergé en Suisse, sans exposition identifiée au CLOUD Act. Référencé dans la catégorie Visioconférence.
Notes d’évaluation
Threema GmbH (Pfäffikon SZ, Switzerland, CHE-221.440.104) runs its own hardware in two physically separated, redundant data centres in the Zurich area and processes personal data for all essential functions exclusively on those Swiss servers, publishes a DPA and a named sub-processor annex without a login, ships open-source clients with reproducible builds, and is Swiss-incorporated with EU adequacy: no CLOUD Act exposure for EU or Swiss data subjects. Correction at the 2026-08 re-verify: the ISO 27001 certificate belongs to Threema's colocation partner, not to Threema GmbH — the vendor's own wording is that it "runs its own servers in data centers of an ISO 27001-certified collocation partner" — so certifications is now empty rather than claiming a certification Threema does not itself hold. The sub-processor annex names only four parties: two Swiss SMS providers, Leaseweb Netherlands BV operating the Selective Forwarding Units that route end-to-end encrypted group calls, and Twilio Inc. (USA) restricted to phone-number verification for data subjects outside Switzerland, the EU and the EEA.
Constats
- CLOUD Act
- Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
-
- Actionnariat
- Propriété
Où se situe le contrôle ultime de la société exploitante.
-
Propriété UE Établie et contrôlée dans l'UE ; pas de participation américaine notable.
-
Européen Cette fiche Propriété suisse/EEE, sans participation américaine notable, considérée comme européenne.
-
Siège UE, financement US Siège dans l'UE mais contrôlée par des capitaux américains (VC/PE).
-
Filiale UE, maison mère US Société d'exploitation européenne détenue par une société mère américaine.
-
Propriété US La société exploitante a elle-même son siège aux États-Unis.
-
- Sous-traitants
- 4 · 1 US
Signaux vérifiés
-
Hébergement UE / adéquation: Oui
-
Opérateur UE / adéquation: Oui
-
Aucune exposition au CLOUD Act: Oui
-
DPA public: Oui
-
Sous-traitants divulgués: Oui
-
Clients open source: Oui
-
Certification tierce: Non
Aller à
À propos de Threema
Threema is a Swiss end-to-end encrypted messaging application developed and operated by Threema GmbH (Pfäffikon SZ, Switzerland, Commercial Register: CHE-221.440.104), founded in December 2012 by three Swiss developers as a privacy-first alternative to WhatsApp, launching on Apple's App Store the same month the app was conceived. The legal entity was formally registered as Threema GmbH in spring 2014 to support professional expansion. Key milestones: post-Snowden traction in 2013, Threema Work (business edition) launched 2016, surpassed 10 million users in early 2021 following WhatsApp's controversial terms-of-service update, and a new CEO appointed in 2024.
The product portfolio is three-tier. Threema Private (consumer): one-off purchase app for iOS + Android + desktop, no phone number or email required for sign-up; fully anonymous use possible. Threema Work (business): managed admin console, MDM integration, enforced encryption policies, SSO via SAML/OIDC, priced at €3/user/month (Core) or €5/user/month (Professional); 30-day free trial for up to 30 users. Threema OnPrem (self-hosted): the full Threema Work stack deployable on customer infrastructure, for buyers who require complete data sovereignty inside their own security perimeter. All three tiers share the same cryptographic core: end-to-end encrypted messages, voice calls, video calls, group chats, file transfers, and polls using the NaCl/libsodium cryptography library; encryption by default with no plaintext fallback.
Compliance posture is among the strongest in the messenger category. Threema runs its own hardware in two physically separated, redundant data centres in the Zurich area, operated by an ISO 27001-certified colocation partner; the vendor's own wording places that certificate with the partner rather than with Threema GmbH. Data processing for all essential functions runs on those Swiss servers (confirmed in the publicly available DPA), with one documented exception: end-to-end encrypted group calls are routed through Selective Forwarding Units operated by Leaseweb Netherlands BV in the Netherlands, an intra-EEA flow in which the forwarder only ever handles ciphertext. Switzerland holds an EU adequacy decision (Art. 45 GDPR), SCC-free for EU↔CH transfers. The DPA (threema.com/en/dpa) is publicly accessible without login and references standard contractual safeguards for any third-party functions. The company explicitly positions Threema as compliant with NIS 2, DORA, and CER EU directives. Ownership: Threema was acquired by Comitis Capital GmbH (a German investment firm focused on purpose-driven companies) from Afinum Management GmbH in early 2026, still EU-controlled, no US capital. Open-source: a Google-free Android version (Threema Libre) ships via F-Droid with reproducible builds for independent verification; the app source code is publicly auditable. Best fit: privacy-conscious individuals replacing WhatsApp or Signal with a Swiss-hosted option; German and EU enterprises needing an auditable E2EE messaging platform under their own IT control; regulated sectors subject to NIS 2 / DORA that need a compliant internal comms layer.
Carte des sous-traitants · 4
-
Twilio Inc. USÉtats-Unis
Telephone number verification for data subjects outside Switzerland/EU/EEA only
-
F24 Schweiz AG EUSuisse
Telephone number verification SMS
-
Leaseweb Netherlands BV EUPays-Bas
Selective Forwarding Units routing end-to-end encrypted group calls
-
Swissphone Wireless AG EUSuisse
Telephone number verification SMS
| Prestataire | Pays | Finalité | Propriétaire |
|---|---|---|---|
| Twilio Inc. | États-Unis | Telephone number verification for data subjects outside Switzerland/EU/EEA only | US |
| F24 Schweiz AG | Suisse | Telephone number verification SMS | EU |
| Leaseweb Netherlands BV | Pays-Bas | Selective Forwarding Units routing end-to-end encrypted group calls | EU |
| Swissphone Wireless AG | Suisse | Telephone number verification SMS | EU |
Source : liste publiée des sous-traitants de l’éditeur, lue le 26 août 2026.
Référentiels & certifications · aucune répertoriée
Matrice de fonctionnalités
Tableau 2Fonctionnalités de Threema
Intégration & accès
Conformité & gouvernance
Tarifs & paliers
Documents publics
Alternatives dans cette catégorie
-
Royaume-UniHébergé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Cette fiche Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Oui -
-
SuisseSouverain UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Cette fiche Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Oui Sous-traitants: Oui Open source: Non -
-
France · 10 €/moisBasé UEExposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
Aucune Opérateur UE, sans société mère ni sous-traitant américain notable.
-
Mineure Cette fiche Un sous-traitant américain transitoire (CDN, cartes) ; les données au repos restent dans l'UE.
-
Significative Société mère américaine, ou un sous-traitant central est un hyperscaler américain.
-
Directe L'opérateur lui-même est établi aux États-Unis.
DPA public: Non Sous-traitants: Non Open source: Oui -
| Produit | Souveraineté | CLOUD Act | Signaux | À partir de |
|---|---|---|---|---|
|
|
Hébergé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Oui
|
— |
|
|
Souverain UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Oui
Sous-traitants: Oui
Open source: Non
|
— |
|
|
Basé UE | Exposition au CLOUD Act
Le degré d'exposition des données clients aux autorités américaines au titre du CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
DPA public: Non
Sous-traitants: Non
Open source: Oui
|
10 €/mois |