Skip to content
Independently verified · Quarterly re-audit
EU VETTED

Twenty

VERIFIED

Twenty SAS (SIREN 914 989 041, Paris, France), subsidiary of Twenty.com PBC (public benefit corporation, Delaware / San Francisco, USA)

CRM · France
Founded 2022 · twenty.com ↗

Paris-built open-source CRM (AGPL-3.0) from Twenty SAS, but the managed cloud is sold by a Delaware PBC and runs on AWS Frankfurt.

In short

Twenty, in the CRM category, offers EU hosting with Germany as its hosting location, but a US parent or sub-processor leaves material CLOUD Act exposure.

Assessment notes

Twenty is built in Paris by Twenty SAS (SIREN 914 989 041, registered 24 June 2022, 18 rue Soleillet, 75020 Paris), the French entity that employs the product team and holds the software IP, and EU workspaces are processed under a French-law DPA naming Twenty.com SAS as processor. But the managed cloud is sold under the terms of Twenty.com PBC, a Delaware public benefit corporation, governed by Delaware law, and the company's own privacy policy states that Twenty is based in the United States; that is a US parent, so eu_owned is off the table. All customer records sit on AWS eu-central-1 (Frankfurt), which keeps the data physically in the EU but under a US-owned hyperscaler, and the always-engaged sub-processor set adds ClickHouse (US-incorporated, processing in Germany), Cloudflare (edge, worldwide) and Sentry (processing in the United States). US parent plus AWS at rest is exactly the pattern the rubric calls material CLOUD Act exposure, and the score does not go above 3 for that reason. Positives that keep it at 3 rather than 2: EU-only data residency for the default region, an unusually granular public sub-processor register on the trust centre, SOC 2 Type 2, a self-serve DPA that any workspace admin can generate and sign in-app (which by itself caps the score at 4 under the DPA-accessibility rule since there is no public DPA URL), and an AGPL-3.0 codebase that lets a buyer leave the US contract entirely by self-hosting.

CLOUD ACT
OWNERSHIP
SUB-PROCS
9 · 8 US
CLOUD Act by deployment

Exposure depends on how you run this product.

Hosted SaaS (default)

Vendor-operated: the sub-processors below apply.

Self-hosted (open-source)

Deploy on your own EU infrastructure and you control hosting and every sub-processor.

Verified signals
Jurisdiction
  • EU / adequacy hosting
  • EU / adequacy operator
  • No US CLOUD Act exposure
Transparency
  • Public DPA
  • Sub-processors disclosed
  • Open-source clients
  • Third-party certification
JUMP TO
OVERVIEW

About Twenty

Twenty is an open-source CRM built by a Paris product team and positioned as the open alternative to Salesforce. The code lives at github.com/twentyhq/twenty under AGPL-3.0 (with a small set of files marked @license Enterprise under a separate Twenty.com Commercial License, and the SDK packages under MIT) and has passed 54,000 GitHub stars. Founders Félix Malfait, Charles Bochet and Thomas des Francs went through Y Combinator S23 and raised a 5 million USD seed round in November 2024 led by Runa Capital, with angels from HubSpot, Front, Cal.com, Sentry and Photoroom. Functionally it is a developer-shaped CRM rather than a sales-suite: unlimited custom objects, fields and views, table / kanban / calendar views, workflows and AI agents, two-way email and calendar sync, REST and GraphQL APIs, webhooks and an MCP server.

The corporate structure is the thing a European buyer has to read carefully. Twenty SAS (SIREN 914 989 041, registered 24 June 2022 in the 20th arrondissement of Paris) employs the product team and holds the software IP, and the DPA configuration published in the source repository names Twenty.com SAS, 9 rue des Colonnes, 75002 Paris as the processor for the EU region under French law, with no SCC annex needed because nothing leaves the EEA by default. The commercial terms of the managed service, however, are those of Twenty.com PBC, a Delaware public benefit corporation with a San Francisco notice address, governed by Delaware law, and the privacy policy states plainly that Twenty is based in the United States. That is a US parent over a French subsidiary, which is why ownership is recorded as EU-headquartered with US funding rather than EU-owned, and why CLOUD Act exposure is Material. Data residency itself is clean: every customer record, backup and log sits on AWS eu-central-1 in Frankfurt, Germany, with audit logs in ClickHouse (also processed in Germany), Cloudflare in front for CDN and WAF, Sentry for error monitoring in the United States, and optional AI features routed to Anthropic, OpenAI or Mistral only when a workspace turns them on. AWS is the determining fact: it is a US-owned hyperscaler holding the data at rest, so an EU region does not remove the exposure. The trust centre at trust.twenty.com publishes SOC 2 Type 2 and GDPR status plus a per-vendor sub-processor register with processing locations, but the underlying policy documents are behind a request-access wall, and the DPA has no public URL: a workspace admin generates and signs it in-app under Settings > DPA, which under our DPA-accessibility rule caps the score at 4 before the CLOUD Act deduction.

Pricing is USD-denominated with no EUR list price: Pro at 9 USD per user per month (€8 equivalent), Organization at 19 USD per user per month for row-level permissions, SAML/OIDC SSO, custom domain and audit logs, and Enterprise from 50,000 USD per year for single-tenant isolation, IP allow-listing and SCIM. There is no free hosted tier, only a 30-day trial without a card. The product UI ships 33 locale catalogues including French, German, Spanish, Italian, Dutch, Polish and the Nordic languages. Best fit: technical teams that want a customisable CRM they can fork, extend and eventually take with them. Buyers whose procurement rules exclude a US parent or a US-owned hyperscaler should either self-host Twenty on Hetzner, OVHcloud or Scaleway, which removes the US contract and AWS entirely, or look at centralstationCRM (DE), weclapp (DE) or Teamleader (BE) elsewhere in this category.

SUB-PROCESSORS

Sub-processor map · 9

Source ↗
  • Amazon Web Services US
    Germany

    Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged.

  • Anthropic US
    United States

    Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place.

  • ClickHouse US
    Germany

    Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged.

  • Cloudflare US
    United States

    CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged.

  • Google Cloud Platform US
    Germany

    Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features.

  • OpenAI US
    United States

    Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place.

  • Sentry US
    United States

    Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged.

  • Stripe US
    United States

    Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10.

  • Mistral AI EU
    France

    Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data.

8 of 9 sub-processors are US-incorporated. CLOUD Act exposure applies.
CERTIFICATIONS

Frameworks & certifications

SOC 2
ACTIVE
Informational · US framework
FEATURES

Capability matrix

Sales pipeline Yes
Email sync Yes
Workflow automation Yes
Lead capture No
Email campaigns No
Quotes / invoicing No
Telephony No
Mobile app No
Free tier No
INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) Yes
COMPLIANCE & GOVERNANCE
Audit log Yes
Self-host / on-prem option Yes
PRICING

Pricing & tiers

PAID
from €8/mo
View pricing page ↗
PUBLIC DOCUMENTS

Public documents

DPA provided on request. The vendor provides its Data Processing Addendum to customers on request (by email or inside the account portal) rather than publishing it at a public URL, so it is not counted as a public DPA (see How we assess).
  • Data Processing Addendum (DPA)
    — on request
    on request
  • Sub-processors list
    trust.twenty.com
    Open ↗
  • Terms of Service
    twenty.com/legal…
    Open ↗
ALTERNATIVES

Alternatives in this category

Capsule CRM
United Kingdom · Founded 2009
EU-HOSTED

Manchester-based UK CRM (Zestia Ltd) with a free tier, public DPA, and AWS hosting; post-Brexit jurisdiction.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
MATERIAL
centralstationCRM
Germany · Founded 2010
EU-SOVEREIGN

Cologne-based German SMB CRM (42he GmbH), all-German hosting on Hetzner + Core-Backbone + Telekom, free tier for 3 users.

Public DPA Sub-processors Open source
FROM
€24/mo
CLOUD ACT
NONE
combit CRM
Germany · Founded 1989
EU-SOVEREIGN

Konstanz-based German CRM (combit Software, since 1989), founder-owned, on-prem + cloud, German Mittelstand vendor.

Public DPA Sub-processors Open source
FROM
CLOUD ACT
NONE