Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Filen

VERIFIED
File sharing · Germany
Founded 2021 · filen.io ↗

German zero-knowledge E2E cloud (Filen Cloud Dienste UG, Recklinghausen, 2021), Tier IV ISO 27001 DCs, no US data, open source apps.

Why this score?

Filen Cloud Dienste UG (Recklinghausen, Germany; founded mid-2021 by Jan Lenczyk, Jan Kulartz, and Phil Hedrich) runs an explicit ''next-generation zero-knowledge end-to-end encrypted cloud'' from Tier IV ISO 27001-certified German data centres with no data stored in the United States, AES-256 client-side encryption, open-source applications on GitHub, and a founder-led cap table with no external venture capital — rated 3/5: an otherwise strong German-sovereignty profile, but Filen does not publish a publicly accessible DPA; the /privacy page lists third-party sub-processors (Stripe IE, PayPal US, Cloudflare US, Sentry US) but contains no DPA document, and no standalone DPA URL exists on the public site; under EU Vetted''s rubric a DPA that small EU buyers cannot self-serve caps the score at 3/5.

SCORE
3.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
0 none disclosed
JUMP TO
OVERVIEW

About Filen

Filen is a German-headquartered zero-knowledge end-to-end encrypted cloud-storage product operated by **Filen Cloud Dienste UG (haftungsbeschränkt)**, founded in mid-2021 in **Recklinghausen, Germany** by Jan Lenczyk (CEO + CTO), Jan Kulartz (COO + CMO), and Phil Hedrich (CDO + Customer Care). The product is structurally similar to Mega and Internxt — every file is encrypted on the user's device with AES-256 before it leaves the client, the encryption keys never reach Filen's servers, and the company mathematically cannot read uploaded content — and ships as Filen Drive, Filen Notes, Filen Chats, Filen Sync, and a network-drive client across Windows, macOS, Linux, iOS, Android, and the web. The applications are open source on GitHub for independent audit. For an EU-sovereignty audit Filen is among the cleanest listings in the file-sharing category. **All servers are located in Germany** in **Tier IV ISO 27001-certified high-security data centres** across multiple regions for disaster-recovery redundancy. The vendor states explicitly that **no data is stored in the United States** — an unusually strong commitment for a product at this price point. German data-protection law (Bundesdatenschutzgesetz) applies on top of GDPR, and the UG legal structure is a German limited-liability format. The ownership chain is clean: founder-led with no VC/PE investors on record. Customer keys, file content, file names, and metadata are all encrypted client-side — zero-knowledge end-to-end. Among the directory's 5/5 file-sharing entries (Proton Drive, Tresorit, Internxt, Filen, Cryptee), Filen wins on price-to-performance for users who want German jurisdiction specifically. Pricing is the most aggressive in the directory's encrypted-cloud category: free tier available with limited storage; **Pro I starts at €1.99/month for 200 GiB**; Pro II / III / IV scale up with more storage and higher upload caps; unlimited bandwidth, uploads, client-side encryption, syncing, and file sharing across all paid tiers. No lifetime plans (vendor explicitly opts out). Best fit: privacy-conscious individuals and small teams who want German jurisdiction, zero-knowledge encryption by default, open-source apps, and aggressive pricing — particularly relevant for journalists, NGOs, and SMBs in DACH.
SUB-PROCESSORS

Sub-processor map · none disclosed

Source ↗
Vendor discloses zero sub-processors. All data processing happens in-house.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-18).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option No
PRICING

Pricing & tiers

FREEMIUM
from €2/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    filen.io/privacy…
    Open ↗
  • Terms of Service
    filen.io/terms…
    Open ↗
ALTERNATIVES

Alternatives in this category