CryptPad
VERIFIEDParis-based E2E-encrypted open-source collaboration suite (CryptPad by XWiki SAS), NLnet/NGI-EU-funded; zero-knowledge architecture.
Why this score?
CryptPad is the end-to-end encrypted open-source collaboration suite developed by XWiki SAS (Paris, France; making open-source software since 2004). Funded by NLnet PET, NGI TRUST, NGI DAPSI, NGI Zero Commons Fund (European Commission's Next Generation Internet programme) plus CryptPad.fr subscribers and Open Collective donations — making this one of the most clearly EU-publicly-funded sovereign-tech projects in the directory. Zero-knowledge encryption means even XWiki cannot read customer documents; full source on GitHub; self-hostable on EU infrastructure. Rated 4/5: French SAS, EU public funding lineage, E2E architecture, no US-VC, no US legal entity — but the DPA is not publicly accessible; it is reachable only inside a customer account for paid Organisation-Plan holders; the rubric reserves 5/5 for a publicly accessible DPA.
- SCORE
- 4.0/5
- CLOUD ACT
- CLOUD ACT EXPOSURE
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- OWNERSHIP
- OWNERSHIP
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
US-owned US-headquartered, or has a US parent company.
-
Other Swiss, UK or another non-EU jurisdiction.
-
- SUB-PROCS
- — not disclosed
JUMP TO
About CryptPad
Sub-processor map · not disclosed
Frameworks & certifications · none listed
Capability matrix
Pricing & tiers
Public documents
-
missingData Processing Addendum (DPA)— missing
-
missingSub-processors list— missing
Alternatives in this category
UK solo-dev MIT-licensed self-hosted wiki + documentation platform (Dan Brown, 2015); no SaaS, no vendor counterparty risk.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Munich-based AGPLv3 open-source enterprise social network + intranet (HumHub GmbH & Co. KG, 2015), 4,500+ organisations, self-hostable on EU infra.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
AGPLv3 open-source Node.js wiki by Nicolas Giard (Canada, 2016); 100M+ downloads; multiple DB backends; 40+ languages; self-host only.
- EU / adequacy operator
- EU / adequacy hosting
- No US CLOUD Act exposure
- Third-party certification
- Open-source clients
- Public DPA
- Sub-processors disclosed
How exposed customer data is to US authorities under the CLOUD Act.
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.