Skip to content
Independently verified · Quarterly re-audit
EU VETTED
Curated collection

Docs & wikis without US sub-processors

European documentation and wiki tools verified to run with no US sub-processors, compared on ownership, hosting region, CLOUD Act exposure and sub-processor chain.

In short

The documentation and wiki tools listed here operate with no US sub-processors in the data path: an EU/EEA/Switzerland operator with no US parent and no US-incorporated processor. Knowledge bases concentrate a company's most sensitive internal text, so the search, AI-assist and attachment-storage sub-processors matter as much as the hosting region; each listing records the full chain.

EU Vetted Editorial
Verified June 2026 How we verify

Some links on this site are affiliate links. We may earn a commission at no extra cost to you. Editorial signals and rankings are never influenced by affiliate relationships.

Why it matters

At a glance

Key facts per option, checked against each vendor's own documents.

  • Anytype

    hosted in Germany, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.

    Best for: Local-first notes and knowledge tool for privacy-conscious knowledge workers and researchers wanting a Notion or Obsidian alternative with offline, end-to-end-encrypted sync.

  • BookStack

    hosted in United Kingdom, encrypted at rest, no CLOUD Act exposure, from €0/mo.

    Best for: Self-hosted wiki for IT teams building internal knowledge bases who want an MIT-licensed Confluence alternative with no vendor counterparty.

  • CryptPad

    hosted in France, zero-knowledge end-to-end encryption, no CLOUD Act exposure, free tier available.

    Best for: Collaboration suite for privacy-maximalist teams, journalists, and EU public-sector buyers who need a full office suite the vendor cannot read.

  • HumHub

    hosted in Germany, encrypted at rest, no CLOUD Act exposure, free tier available.

    Best for: Self-hosted intranet and social network for EU corporates, public-sector, and educational organisations wanting an AGPLv3 platform.

  • Joplin

    hosted in France, encrypted at rest, no CLOUD Act exposure, from €3/mo.

    Best for: Note-taking app for privacy-conscious individuals, journalists, and freelancers wanting a self-hostable Obsidian or Evernote alternative with EU data residency.

  • Wiki.js

    hosted in Canada, encrypted at rest, no CLOUD Act exposure, from €0/mo.

    Best for: Self-hosted wiki for developer and engineering teams building internal documentation on a Node.js stack with Git-versioned content.

How to choose
FAQ

Frequently asked questions

Why are sub-processors especially sensitive for a knowledge base?
A wiki concentrates internal documentation: strategy, incidents, credentials in prose, customer notes. The search index, any AI-assist feature and attachment storage all process that text, so a US-incorporated processor in one of those layers exposes the most sensitive corpus you hold. We record each one separately.
What counts as 'no US sub-processors' here?
An EU/EEA/Swiss operating company, no US parent, and no US-incorporated sub-processor in the data path. That is the directory's 'CLOUD Act exposure: none' bar, verified against public sub-processor lists and ownership records.
Do these tools offer AI features without US processors?
It varies. AI-assist often routes through a US-incorporated model provider, which would re-introduce exposure even on an EU-hosted tool. Where a listing offers AI, check the profile for whether the model layer is EU-operated or can be disabled.
Is self-hosting required to avoid US sub-processors?
No. Several EU-operated hosted wikis clear the bar without self-hosting. Self-hosting is one route to control the chain, but the hosted options here are verified on the same criteria. Pick based on your operational capacity, not the assumption that hosted means exposed.
How often is this re-verified?
Quarterly, with a last-verified date on each listing; AI and search layers change often, so the chain is re-checked each audit.
Methodology

How we verified every listing here.

For each product we read the public DPA, sub-processors document, hosting region declaration, certifications, and corporate ownership records. Each is timestamped. Signals are editorial, re-verified quarterly. We never accept self-attestation.

Read methodology →