Twenty
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked This listing Operated by a US-incorporated entity, directly subject to US jurisdiction.
Twenty.com PBC (Delaware public benefit corporation, San Francisco notice address), contracting party and DPA processor for the managed cloud; French operating subsidiary Twenty SAS (SIREN 914 989 041, Paris)
Paris-built open-source CRM (AGPL-3.0) from Twenty SAS; the managed cloud is contracted with US parent Twenty.com PBC, also the DPA processor, and runs on AWS Frankfurt.
Twenty is operated by a US-incorporated entity and remains directly subject to the CLOUD Act. It is listed under CRM.
Assessment notes
Twenty is built in Paris by Twenty SAS (SIREN 914 989 041, registered 24 June 2022, 18 rue Soleillet, 75020 Paris), the French entity that employs the product team and holds the software IP. The managed cloud, however, is contracted with Twenty.com PBC, a Delaware public benefit corporation, under Delaware law, and since a DPA revision merged on 12 August 2026 (pull request #24026 in the public repository) the PBC is also the processor and, under the Standard Contractual Clauses, the data importer for EU-hosted workspaces. The generated DPA states that Twenty PBC is the processor and Twenty SAS the EU affiliate for every hosting region, and that EU hosting does not by itself exclude a transfer where data is made available to Twenty PBC. With a US-incorporated company as the contracting processor, CLOUD Act exposure is recorded as direct; ownership stays EU HQ, US-funded, because the team, the IP and the operating company are French while control sits with the US parent. All customer records sit on AWS eu-central-1 (Frankfurt), and the always-engaged sub-processor set adds ClickHouse (US-incorporated, processing in Germany), Cloudflare (edge, worldwide) and Sentry (processing in the United States). An EU office under a US parent that is itself the processor is the 2/5 row of the rubric. In its favour: EU data residency by default, an unusually granular public sub-processor register on the trust centre, SOC 2 Type 2, a self-serve DPA that any workspace admin can generate and sign in-app (there is no public DPA URL), and an AGPL-3.0 codebase that lets a buyer leave the US contract entirely by self-hosting, which is scored separately and comes out clean.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent This listing European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
Other A non-EU jurisdiction. Swiss/EEA-owned vendors count as European here; the UK and others do not.
-
- Sub-processors
- 9 · 8 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Not assessed
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: Yes
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct This listing The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Twenty
Twenty is an open-source CRM built by a Paris product team and positioned as the open alternative to Salesforce. The code lives at github.com/twentyhq/twenty under AGPL-3.0 (with a small set of files marked @license Enterprise under a separate Twenty.com Commercial License, and the SDK packages under MIT) and has passed 54,000 GitHub stars. Founders Félix Malfait, Charles Bochet and Thomas des Francs went through Y Combinator S23 and raised a 5 million USD seed round in November 2024 led by Runa Capital, with angels from HubSpot, Front, Cal.com, Sentry and Photoroom. Functionally it is a developer-shaped CRM rather than a sales-suite: unlimited custom objects, fields and views, table / kanban / calendar views, workflows and AI agents, two-way email and calendar sync, REST and GraphQL APIs, webhooks and an MCP server.
The corporate structure is the thing a European buyer has to read carefully. Twenty SAS (SIREN 914 989 041, registered 24 June 2022 in the 20th arrondissement of Paris) employs the product team and holds the software IP, but the managed service is contracted with Twenty.com PBC, a Delaware public benefit corporation with a San Francisco notice address, under Delaware law, and the privacy policy states plainly that Twenty is based in the United States. Since a DPA revision merged in August 2026, the PBC is also the processor and, under the Standard Contractual Clauses, the data importer for EU-hosted workspaces: the DPA generated in each workspace names Twenty PBC as processor and Twenty SAS as EU affiliate for every hosting region, keeps Delaware as the governing law, and notes that EU hosting does not by itself exclude a transfer where data is made available to Twenty PBC. An EU operating company under a US parent that is itself the contracting processor is why ownership is recorded as EU-headquartered with US funding and why CLOUD Act exposure is Direct. Data residency itself is clean: every customer record, backup and log sits on AWS eu-central-1 in Frankfurt, Germany, with audit logs in ClickHouse (also processed in Germany), Cloudflare in front for CDN and WAF, Sentry for error monitoring in the United States, and optional AI features routed to Anthropic, OpenAI or Mistral only when a workspace turns them on. Residency does not change the legal reach, though: the processor and the hyperscaler holding the data at rest are both US companies. The trust centre at trust.twenty.com publishes SOC 2 Type 2 and GDPR status plus a per-vendor sub-processor register with processing locations, but the underlying policy documents are behind a request-access wall, and the DPA has no public URL: a workspace admin generates and signs it in-app under Settings > DPA.
Pricing is USD-denominated with no EUR list price: Pro at $9 per user per month, Organization at 19 USD per user per month for row-level permissions, SAML/OIDC SSO, custom domain and audit logs, and Enterprise from 50,000 USD per year for single-tenant isolation, IP allow-listing and SCIM. There is no free hosted tier, only a 30-day trial without a card. The product UI ships 33 locale catalogues including French, German, Spanish, Italian, Dutch, Polish and the Nordic languages. Best fit: technical teams that want a customisable CRM they can fork, extend and eventually take with them. Buyers whose procurement rules exclude a US parent or a US-owned hyperscaler should either self-host Twenty on Hetzner, OVHcloud or Scaleway, which removes the US contract and AWS entirely, or look at centralstationCRM (DE) or combit CRM (DE) elsewhere in this category, since weclapp and Teamleader both run customer data on Amazon Web Services.
Sub-processor map · 9
-
Amazon Web Services USGermany
Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged.
-
Anthropic USUnited States
Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place.
-
ClickHouse USGermany
Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged.
-
Cloudflare USUnited States
CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged.
-
Google Cloud Platform USGermany
Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features.
-
OpenAI USUnited States
Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place.
-
Sentry USUnited States
Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged.
-
Stripe USUnited States
Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10.
-
Mistral AI EUFrance
Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data.
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services | Germany | Primary hosting: compute, managed databases, object storage and encrypted backups. Holds all customer CRM data at rest in eu-central-1 (Frankfurt). Always engaged. | US |
| Anthropic | United States | Optional AI features (drafting, summarisation, enrichment). Engaged only when a workspace enables AI and runs an action; no training on customer data; SCCs in place. | US |
| ClickHouse | Germany | Analytical database storing audit logs and powering in-product analytics and reporting; may contain customer personal data. Processed in Germany, always engaged. | US |
| Cloudflare | United States | CDN, DNS and web application firewall. Processes request/response content and connection metadata in transit only across the worldwide edge network, no long-term retention. Always engaged. | US |
| Google Cloud Platform | Germany | Google Maps look-ups and Google single sign-on only. Processed in Germany, engaged only for workspaces that use those features. | US |
| OpenAI | United States | Optional AI features, depending on the model configured for the workspace. Processed in the United States and the EU; no training on customer data; SCCs in place. | US |
| Sentry | United States | Application error and performance monitoring; stack traces and request context, scrubbed but may incidentally contain customer data. Processed in the United States, always engaged. | US |
| Stripe | United States | Payment processing for the managed cloud subscription. Named in the privacy policy only; absent from the trust-centre register and from subprocessors.json as of 2026-08-10. | US |
| Mistral AI | France | Optional AI features, depending on the model configured for the workspace. EU provider with EU hosting, so no transfer outside the EEA; no training on customer data. | EU |
Source: the vendor’s published sub-processor list, read 2 Oct 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Twenty
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
Germany · €24/moEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
GermanyEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Not assessed Sub-processors: Yes Open source: No -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
€24/mo |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Not assessed
Sub-processors: Yes
Open source: No
|
— |