Wire
A single roll-up of ownership and CLOUD Act exposure.
-
EU-Sovereign EU/EEA/Switzerland-owned and -operated, with no identified CLOUD Act exposure.
-
EU-Based EU-operated, with at most minor or transient US exposure.
-
EU-Hosted This listing EU hosting available, but a US parent or hyperscaler sub-processor creates material exposure.
-
US-Linked Operated by a US-incorporated entity, directly subject to US jurisdiction.
Swiss-headquartered enterprise messaging + video (Wire Swiss GmbH, Zug + Berlin), MLS E2EE, BSI VS-NfD Zulassung for Wire Bund, 90%+ European institutional ownership.
Wire offers EU hosting in Germany, but a US parent or sub-processor leaves material CLOUD Act exposure. It is listed under Video conferencing.
Assessment notes
Wire Swiss GmbH (HQ Zug, Switzerland, with main development centre in Berlin) was founded Fall 2012 by Jonathan Christensen, Alan Duric, and Priidu Zilmer (Skype/Microsoft alumni; backed by Skype co-founder Janus Friis); Wire Group Holdings GmbH is majority-owned by European institutional investors, who collectively hold over 90% of the company, with the advisory board including Rolf Schumann of Schwarz Gruppe (Lidl / STACKIT parent), Diana Meyel of Cipio Partners, Janus Friis, and CEO Benjamin Schilz. End-to-end MLS encryption by default with zero-knowledge architecture, hosted inside the EU (Germany and Ireland), granted a BSI VS-NfD Zulassung on 27 April 2026, valid to the end of 2028 and scoped to the Wire Bund offering deployed inside the institution's own infrastructure rather than to Wire Cloud, Wire for SMB or Wire for Enterprise, NIS 2 compliant, customer list includes the German Bundesamt für Sicherheit in der Informationstechnik (BSI) plus US Air Force, 1,800+ total. EU-hosted with 90%+ European institutional ownership, but material CLOUD Act exposure on the business-operations path: core hosting runs on AWS (US hyperscaler) and US-incorporated sub-processors handle CRM and support (Hubspot, Salesforce, Zendesk). MLS end-to-end encryption keeps message content private even from those processors, but customer metadata and CRM records sit with US-jurisdiction vendors, so the messaging is sovereign while the surrounding operations are not. Public DPA with disclosed sub-processors, ISO/IEC 27001 and ISO/IEC 27701 certification for Wire Swiss GmbH and its German parent holding entity, and a BSI VS-NfD approval covering the Wire Bund deployment scenario.
Findings
- CLOUD Act
- CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
-
- Ownership
- Ownership
Where ultimate control over the operating company sits.
-
EU-owned EU-incorporated and EU-controlled; no significant US ownership.
-
European This listing Swiss/EEA-owned, with no significant US ownership; treated as European.
-
EU HQ, US-funded EU-headquartered but US venture- or PE-controlled.
-
EU subsidiary, US parent European operating company owned by a US parent company.
-
US-owned The operating company itself is US-headquartered.
-
- Sub-processors
- 10 · 7 US
Verified signals
-
EU / adequacy hosting: Yes
-
EU / adequacy operator: Yes
-
No US CLOUD Act exposure: No
-
Public DPA: Yes
-
Sub-processors disclosed: Yes
-
Open-source clients: Yes
-
Third-party certification: Yes
Exposure depends on how you run this product.
Vendor-operated: the sub-processors below apply.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Deploy on your own EU infrastructure and you control hosting and every sub-processor.
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Jump to
About Wire
Wire is a secure enterprise messaging, calls, and collaboration platform operated by Wire Swiss GmbH, headquartered in Zug, Switzerland, with its main development centre in Berlin, Germany. The company was founded in Fall 2012 by Jonathan Christensen, Alan Duric, and Priidu Zilmer (engineers who had previously worked at Skype and Microsoft) and is backed by Skype co-founder Janus Friis. The current CEO since January 2024 is Benjamin Schilz; the advisory board includes Schilz, Diana Meyel (Cipio Partners), Janus Friis, and notably Rolf Schumann of Schwarz Gruppe (the German private retail giant that also operates STACKIT), a direct tie between the Wire / Schwarz sovereign-tech ecosystems. The product surface covers instant messaging, voice + video calls, file sharing (Wire Drive), document collaboration, and an enterprise admin console.
For procurement-grade EU buyers Wire's ownership architecture is unusually clean: Wire Group Holdings GmbH is majority-owned by European institutional investors who collectively hold more than 90% of the company: no US PE or US VC majority anywhere in the cap table. The Zug Switzerland legal entity benefits from CH's EU adequacy decision (Art. 45 GDPR) for SCC-free EU-CH transfers, and customer data is hosted inside the EU. Security architecture is built on MLS (Messaging Layer Security), the IETF-standardised end-to-end encryption protocol, with zero-knowledge keys so Wire itself cannot read customer messages. Wire holds a BSI VS-NfD Zulassung granted on 27 April 2026 and valid to the end of 2028 (VS-NfD is the German "Verschlusssache: Nur für den Dienstgebrauch" classification for restricted government information), and is NIS 2 compliant. The scope matters when quoting it: Wire states the approval is tied to a specific product version and a defined deployment scenario, and covers the Wire Bund offering run inside the institution's own infrastructure, not Wire Cloud, Wire for SMB or Wire for Enterprise. Wire Swiss GmbH and its German parent holding entity are additionally ISO/IEC 27001 and ISO/IEC 27701 certified, with UK Cyber Essentials alongside.
Customer base reflects the security posture: the German Federal Office for Information Security (BSI) is a public reference, alongside the US Air Force and 1,800+ total organisations covering governments, public authorities, law enforcement, and regulated industries. Wire offers an on-premise deployment option for customers needing fully-controlled infrastructure, plus a managed Wire Cloud. Pricing is freemium at the entry point and sales-engaged above it: Wire for Free covers up to 5 people, Wire for SMB is €7.45 per person per month on annual billing for up to 100 people, and Wire for Enterprise and Wire for Partners are quote-based. Best fit: governments and defence ministries (especially DACH, where the VS-NfD approval is the procurement key), regulated financial services, law-enforcement agencies, and any organisation that wants MLS-based E2EE messaging from a vendor structurally independent of US capital.
Sub-processor map · 10
-
Amazon Web Services EMEA SARL USLuxembourg
Hosting
-
Box, Inc. USUnited Kingdom
Signature management
-
Google Cloud EMEA Limited USIreland
Email provider
-
Hubspot Inc. USUnited States
Website hosting, marketing, CRM
-
Salesforce, Inc. USUnited States
CRM services
-
Stripe Payments Europe, Limited USIreland
Payment services (with USA transfer via SCCs)
-
Zendesk, Inc. USUnited States
Customer support
-
ContractHero GmbH EUGermany
Contract management
-
Countly Ltd. non-USUnited Kingdom
Product analytics
-
Wire Germany GmbH EUGermany
Development of services
| Vendor | Country | Purpose | Owner |
|---|---|---|---|
| Amazon Web Services EMEA SARL | Luxembourg | Hosting | US |
| Box, Inc. | United Kingdom | Signature management | US |
| Google Cloud EMEA Limited | Ireland | Email provider | US |
| Hubspot Inc. | United States | Website hosting, marketing, CRM | US |
| Salesforce, Inc. | United States | CRM services | US |
| Stripe Payments Europe, Limited | Ireland | Payment services (with USA transfer via SCCs) | US |
| Zendesk, Inc. | United States | Customer support | US |
| ContractHero GmbH | Germany | Contract management | EU |
| Countly Ltd. | United Kingdom | Product analytics | non-US |
| Wire Germany GmbH | Germany | Development of services | EU |
Source: the vendor’s published sub-processor list, read 26 Aug 2026.
Frameworks & certifications
Capability matrix
Table 2Capabilities of Wire
Integration & access
Compliance & governance
Pricing & tiers
Public documents
Alternatives in this category
-
United KingdomEU-HostedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material This listing US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: Yes -
-
SwitzerlandEU-SovereignCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None This listing EU operator, no US parent, no US sub-processors of note.
-
Minor A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: Yes Sub-processors: Yes Open source: No -
-
France · €10/moEU-BasedCLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
-
None EU operator, no US parent, no US sub-processors of note.
-
Minor This listing A transient US sub-processor (CDN, maps); data at rest stays in the EU.
-
Material US parent, or a core sub-processor is a US-owned hyperscaler.
-
Direct The operator itself is US-incorporated.
Public DPA: No Sub-processors: No Open source: Yes -
| Product | Sovereignty | CLOUD Act | Signals | From |
|---|---|---|---|---|
|
|
EU-Hosted | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: Yes
|
— |
|
|
EU-Sovereign | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: Yes
Sub-processors: Yes
Open source: No
|
— |
|
|
EU-Based | CLOUD Act exposure
How exposed customer data is to US authorities under the CLOUD Act (Clarifying Lawful Overseas Use of Data Act).
|
Public DPA: No
Sub-processors: No
Open source: Yes
|
€10/mo |