Stackfield
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Munich collaboration suite (Stackfield GmbH, 2012) with per-room end-to-end encryption; ISO 27001 + BSI C5, German data centres, on-premise edition.
Stackfield is an EU-owned service hosted in Germany, with no identified CLOUD Act exposure. It is listed under Project management.
Assessment notes
Stackfield GmbH (Munich, Maximiliansplatz 17; HRB 199536; founded 2012, led by CEO Cristian Mudure and COO Christopher Diesing; 10,000+ customer companies) combines team chat, tasks, projects, files, whiteboards and audio/video calls in one workspace. Content in rooms created as end-to-end encrypted (a per-room choice at creation, or an organisation-wide default) is encrypted with AES-256 and RSA-2048 in the browser, so Stackfield cannot read it; 1:1 calls are end-to-end encrypted, group conferences are transport-encrypted via Stackfield's own server. ISO/IEC 27001, 27017, 27018 and BSI C5 for Stackfield GmbH; customer data stored in German data centres. The public sub-processor list names four German companies (IONOS Cloud for hosting, Myra Security for DDoS protection, united-domains and Inxmail for email), none US-owned; the DPA is concluded inside the customer account, and the BSI C5 attestation exempts the listing from the DPA-accessibility criterion. EU-owned, no CLOUD Act exposure. An on-premise edition (installed by Stackfield on the customer's servers) is sold as a subscription for 100+ users.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 4 · 0 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Stackfield
Stackfield is a Munich-based team-collaboration platform operated by Stackfield GmbH (Maximiliansplatz 17, 80333 Munich; HRB 199536 Local Court Munich; VAT DE283871998; managing director Cristian Mudure). Founded in 2012 and led by CEO Cristian Mudure and COO Christopher Diesing, the company serves 10,000+ companies with one workspace that combines team chat, tasks and projects (list, Kanban, Gantt, milestones, time tracking, portfolios), files, whiteboards, audio/video calls with screen sharing, and email forwarding. Stackfield positions itself against Slack, Microsoft Teams, Asana, monday.com and ClickUp.
The security model is the reason buyers shortlist it. Content in rooms created as end-to-end encrypted (messages, tasks, files and file contents, pages, discussions, whiteboards, events) is encrypted with AES-256 and RSA-2048 in the browser before it reaches Stackfield's servers, so Stackfield cannot read it. Encryption is chosen per room when the room is created, or set as the default by the organisation admin, and cannot be switched on later for an existing room. Calls follow a separate rule: 1:1 calls are end-to-end encrypted, while group conferences run transport-encrypted (WebRTC with DTLS/SRTP) through Stackfield's own server, with no recordings or transcripts stored. Using the optional AI add-on on encrypted content means the browser decrypts it and sends it, transport-encrypted, to open-source models Stackfield runs on IONOS in Germany. Stackfield GmbH holds ISO/IEC 27001, 27017 and 27018 and a BSI C5 attestation; customer data is stored in German data centres. The public sub-processor list names four German companies (IONOS Cloud for hosting, Myra Security for DDoS protection, united-domains and Inxmail for email), none US-owned.
Pricing in EUR, per user and month on annual billing: Starter €9 (up to 10 users and 3 rooms), Business €14, Premium €18 (adds audio/video conferences up to 30 participants, browser join for guests without an account, whiteboards, unlimited externals), Enterprise €28 (SSO, API provisioning, unlimited organisations). There is no free plan; the 14-day trial unlocks Premium. Add-ons: AI €3.90, Office editing €2.40, Public Sector (EVB-IT cloud contract) €2.40, and a §203 StGB confidentiality agreement for professional secrecy holders €3.90. An on-premise edition runs on the customer's own servers: subscription from €28 per user and month on annual billing for at least 100 users, installed and updated by Stackfield. Best fit: German and DACH organisations that need a Slack or Teams replacement with encrypted project rooms, BSI C5 / ISO 27001 evidence for procurement, and the option to move on-premise later.
Sub-processor map · 4
-
Inxmail GmbH EUGermany
Internet-based solution for sending and receiving email.
-
IONOS Cloud GmbH EUGermany
Compute capacity in a cloud provider's data centre: hosting of the Stackfield platform and customer data (until 30 June 2026 contracted as IONOS SE). Also hosts the open-source models behind the AI add-on.
-
Myra Security GmbH EUGermany
Internet-based protection of the IT infrastructure (DDoS mitigation and web application firewall in front of stackfield.com).
-
united-domains GmbH EUGermany
Internet-based solution for sending and receiving email.
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Inxmail GmbH | Germany | Internet-based solution for sending and receiving email. | EU |
| IONOS Cloud GmbH | Germany | Compute capacity in a cloud provider's data centre: hosting of the Stackfield platform and customer data (until 30 June 2026 contracted as IONOS SE). Also hosts the open-source models behind the AI add-on. | EU |
| Myra Security GmbH | Germany | Internet-based protection of the IT infrastructure (DDoS mitigation and web application firewall in front of stackfield.com). | EU |
| united-domains GmbH | Germany | Internet-based solution for sending and receiving email. | EU |
Source: the vendor’s published sub-processor list, read 2 Oct 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Stackfield
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
Netherlands · $10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
-
Germany · €19.99/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: No Open source: No -
-
Germany · €99/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
$10/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: No
Open source: No
|
€19.99/mo |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: Yes
Open source: No
|
€99/mo |