Tixeo
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign This listing EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Montpellier-based French secure video conferencing (founded 2003), ANSSI CSPN-certified, hosted on SecNumCloud-qualified infrastructure, defense + government grade.
Tixeo is an EU-owned service hosted in France, with no identified CLOUD Act exposure. It is listed under Video conferencing.
Assessment notes
Tixeo is a Montpellier-based French video-collaboration vendor founded in 2003 and is the only video conferencing technology in Europe that holds both ANSSI CSPN certification (since 2017, renewed three times) and an ANSSI qualification (renewed for TixeoServer), with TixeoPrivateCloud additionally running on SecNumCloud-qualified hosting (3DS Outscale holds that qualification; Tixeo itself does not), the highest French sovereignty bar. End-to-end encrypted multipoint audio/video/data, NIS 2 + DORA + GDPR compliant, 100% software design and development inside Europe with proprietary technology not subject to foreign legislation, and 30% of Europe's top-100 defence companies (per Sipri 2023) on the customer list: EU-owned, EU-hosted (FR), no CLOUD Act exposure, ANSSI CSPN certified in its own right with TixeoPrivateCloud hosted on SecNumCloud-qualified infrastructure, and the strongest sovereignty positioning in the video-conferencing category.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned This listing EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 0 none disclosed
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: Yes
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: No
-
Third-party certification: Yes
Jump to
About Tixeo
Tixeo is a Montpellier-headquartered French secure-video-collaboration vendor, founded in 2003, and is structurally the most-credentialed sovereign video-conferencing listing in this directory. The product portfolio is three-tier: TixeoCloud (managed SaaS), TixeoServer (customer-self-hosted on-premise), and TixeoPrivateCloud (sovereign cloud hosting on the SecNumCloud-qualified operator 3DS Outscale). All three modes share the same proprietary end-to-end encrypted multipoint audio/video/data architecture: true E2EE regardless of the number of participants, with encryption-by-default across messaging, file transfer, and collaboration modes.
The sovereignty positioning is built on two French government credentials, one held by Tixeo itself and one by its sovereign-cloud host. First, ANSSI CSPN (Certification de Sécurité de Premier Niveau) awarded by the French Cybersecurity Agency in 2017 and renewed three times since. Tixeo is the only video-conferencing technology in Europe to hold both this CSPN certification and an ANSSI qualification, the latter renewed for TixeoServer. Other vendors in this category now list a CSPN of their own, so it is the pairing rather than the CSPN alone that remains unique to Tixeo. Second, TixeoPrivateCloud runs on SecNumCloud-qualified hosting: the qualification is held by the operator 3DS Outscale, not by Tixeo's own legal entity, and it carries the legal-protection-from-extraterritorial-laws guarantees that ANSSI builds into the SecNumCloud framework (specifically engineered against US CLOUD Act and FISA Section 702 reach). Compliance posture additionally covers NIS 2 (the EU cybersecurity directive), DORA (financial-services operational resilience), and full GDPR alignment. Software design and development are entirely inside Europe. Tixeo's own messaging is unambiguous: "our proprietary technology is not subject to foreign legislation".
Customer base reflects the sovereignty positioning: 30% of Europe's top-100 defence companies (per the Stockholm International Peace Research Institute 2023 ranking) use Tixeo for secure collaboration, alongside customers from finance, public administration, industry, and energy. Pricing is enterprise / sales-engaged. Tixeo does not publish a self-serve consumer tier. Best fit: defence and aerospace primes (Airbus-class organisations), French and EU public-sector procurement (where CSPN + SecNumCloud are usually mandatory bid criteria), regulated financial services subject to DORA, healthcare systems requiring NIS 2 compliance, and any mid-market or enterprise buyer for whom CLOUD-Act-clean E2EE video is non-negotiable.
Sub-processor map · none disclosed
Frameworks & certifications
Held by the provider that operates the hosting, not by Tixeo itself.
Capability matrix
Table 1Capabilities of Tixeo
Integration & access
Compliance & governance
Pricing & tiers
Public documents
-
n/aData Processing Addendum (DPA)— not assessed
-
OpenSub-processors listwww.tixeo.com/en…
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
SwitzerlandEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
France · €10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
€10/mo |