Stackfield Logo

Stackfield

German all-in-one collaboration suite (chat, tasks/projects, video, docs) with optional client-side end-to-end encryption and Germany-hosted cloud or commercial on-premise.

EU-operated (DE)Optional client-side E2EGermany hosting (IONOS)ISO 27001 + BSI C5 (claimed)Commercial on-premiseChat + PM + video

Shortlist Stackfield when you need a German-operated all-in-one (chat + PM + meetings + docs) with optional client-side E2E rooms, Germany hosting, and a BSI C5 / ISO story for regulated teams. Skip when you need open-source DIY (prefer Nextcloud), Slack-scale app ecosystem depth, or pure secure messaging without project management (consider ginlo Business).

Key capabilities

Rooms and direct messages can add browser-side end-to-end encryption so Stackfield cannot read covered content at rest. Admins can force E2E, ban it, or let creators choose. Trade-offs include room-password recovery after login resets, limited lock-screen/email previews, and client-side search cost—plan org policy before migrating sensitive rooms.

List/Kanban/Gantt views, milestones, dependencies, automatic scheduling, critical path, custom fields, time tracking, reports, and project portfolios sit next to room chat and discussions. Suited to PMOs that refuse a separate tool silo; less deep than specialist ALM suites for software engineering pipelines.

Built-in audio/video/screen-sharing (plan-dependent) plus guest and external roles that only see assigned rooms. Useful for law firms, agencies, and public-sector projects with outside counsel or contractors without granting full org access.

Cloud tenants store data in German data centres; Stackfield names IONOS SE as infrastructure provider and claims no AWS/GCP/Azure product subprocessors. On-premise is a paid subscription (vendor-installed/updated, high minimum seat count) for air-gapped or policy-bound estates—test first in cloud; local PoC installs are not offered.

Higher tiers add enforced 2FA (including YubiKey options), IP allowlists, password policies, SSO, API provisioning, org-wide exports, and compliance-confirmation workflows. Organisation admins can conclude the GDPR DPA inside settings and download the signed PDF once per organisation.

Best fit when

  • German/EU orgs that want one tool for projects and communication instead of Slack + separate PM
  • Teams that need optional zero-knowledge rooms for highly sensitive matters (legal, M&A, HR, clinical ops)
  • Buyers requiring German legal entity, DPA in-product, and claimed ISO/BSI C5 for procurement questionnaires
  • Public sector, banking, insurance, and professional services evaluating cloud with an on-prem exit path
  • Orgs that will enforce 2FA/SSO/IP allowlists and guest-only access for externals

Poor fit when

  • Teams that need always-on E2E with full rich push previews and third-party calendar feeds without trade-offs
  • Engineering orgs standardised on Jira/GitHub-style ALM depth and automation
  • Buyers who require fully open-source, community-supported self-host without a commercial on-prem contract
  • Global enterprises whose primary requirement is the Slack/Teams integration marketplace
  • Very small teams needing only free-tier messaging with no seat-based SaaS commitment

Consider instead when

  • When: You need open-source self-host and full operational control of files/collab apps

    Consider: Nextcloud

    More DIY ops; broader app ecosystem; different PM depth.

  • When: You mainly need regulated secure messaging, not Gantt/portfolios

    Consider: ginlo Business

    Messaging-first German B2B chat; thinner project suite.

  • When: You already run Microsoft 365 and identity is non-negotiable

    Consider: Microsoft Teams (incumbent) or stay in M365 with EU data boundaries

    Teams wins on suite lock-in; loses on independent German vendor + optional client E2E story.

  • When: You want lighter EU team chat without full PM suite

    Consider: Fleep

    Chat-centric; different residency/subprocessor profile—verify separately.

  • Independent security / no-logs audit·Partial
  • ISO 27001·Vendor claimed
  • SOC 2 / SOC 3·Not found
  • BSI C5·Vendor claimed
  • +4

Considerations & known limitations

  • MediumE2E is optional and irreversible per room

    Without org policy, creators may leave sensitive rooms unencrypted. Encryption mode cannot be changed after creation; password recovery after login reset needs disciplined room-key handling.

  • MediumMobile push and optional US integrations

    Privacy policy documents Apple/Google push for mobile notifications and optional Giphy (US). Even with German content hosting, notification metadata and optional GIF traffic can touch US platforms—document in DPIA.

  • LowCertifications vendor-asserted

    ISO and BSI C5 are claimed with a downloadable certificate; treat as claimed until your auditor verifies scope, dates, and which systems are in-bounds.

  • LowOn-premise is commercial, not DIY open source

    Self-host means a paid on-prem product with vendor install/update and high seat minimums—not a free community edition. Budget implementation and support tickets accordingly.

  • MediumAI features require content decryption for processing

    Stackfield AI decrypts client-side content for the request path (then claims immediate deletion). External AI via customer keys is a separate transfer. Disable AI if zero-knowledge must never leave the client.

Open questions for due diligence

  • Will the vendor provide the current BSI C5 report, ISO certificate scope, and full subprocessor annex under NDA if not already in the DPA PDF?
  • Which fields remain outside E2E (metadata, search indexes, analytics) in your planned room configuration?
  • For mobile fleets: is APNs/FCM push acceptable, or must notifications be disabled/restricted?
  • On-premise: exact supported OS/hypervisor matrix, backup model, and upgrade cadence for your estate?
  • Is Stackfield AI (or customer external AI) allowed under your policy for rooms that contain special-category data?

Häufig gestellte Fragen

No. All traffic uses TLS in transit, but client-side E2E is an extra mode for rooms and direct messages. Organisation admins can require E2E for all new rooms, disable it, or let creators choose. Encryption type cannot be flipped on an existing room after creation—you must recreate and move content. Treat “we have E2E” marketing as a configuration outcome, not a universal default.

Choose cloud for faster rollout, vendor-operated Germany hosting (IONOS claimed), and lower ops load. Choose on-premise when policy requires servers under your control; it is a commercial subscription with vendor installation/updates, a high minimum user count, and no local trial—you evaluate features in the cloud first, then migrate. Confirm backup, identity, and network requirements with sales before budgeting.

Stackfield’s own AI add-on uses internally hosted open-source models on IONOS in Germany and claims no training on customer data and no third-country transfer for that path. For processing, content is decrypted on the client and sent with transport encryption, then discarded after the request—so E2E zero-knowledge does not hold during an AI action. Premium orgs can optionally wire external models (e.g. Anthropic, DeepL) with their own API keys, which is a separate transfer risk.

Public pages claim ISO 27001 / 27017 / 27018 and BSI C5, with a certificate download on the security page; re-verify dates and scope in your RFP. A DPA is available in-product for org admins. Subprocessors named in privacy/docs include IONOS, Inxmail, Myra, and optional Giphy; mobile push uses Apple/Google services. Ask for the current subprocessor annex, pen-test summary, and C5 report if your control framework requires them.

For many mid-market teams, yes on core surfaces: room chat, tasks with Kanban/Gantt, files, pages/whiteboards, and meetings live together. Expect a thinner integration marketplace than Slack and less developer-centric workflow depth than Jira. If your organisation’s value is in hundreds of chat apps or complex CI/CD issue tracking, keep a specialist tool and use Stackfield only where sovereignty + unified rooms matter more.