Private Discuss Logo

Private Discuss

French secure collaboration suite from Limonest (Lyon area): E2EE video, webinars, messaging, co-editing, and admin controls for government and sensitive organisations, with SaaS or on-premise deployment.

EU-operated (France)E2EE (vendor claimed)France/EU hosting (claimed)On-premise optionUp to 1,000 video / 1M webinarsNot open source

Shortlist when you need a French-entity suite combining large secure video/webinars, E2EE messaging, co-editing, and strong admin controls with SaaS or on-premise options for government and sensitive business. Skip when you require open source, published independent crypto audits, or deep Microsoft 365/Slack ecosystem integration—consider Nextcloud Talk or ginlo Business instead.

Key capabilities

Vendor features and contact pages state secure HD audio/video conferences for up to 1,000 participants with screen sharing, virtual backgrounds, collaborative whiteboard, breakout rooms, live polls/voting, and in-meeting electronic signature—aimed at executive and sensitive operational meetings rather than consumer calls.

Webinar tooling includes organiser/presenter/participant roles, granular permissions (present, share, record, content access), interactive stage, moderated hand-raise, secure chat/reactions, and HD recording with encrypted storage and controlled access. Contact materials claim capacity up to 1 million participants for large virtual events.

Instant messaging covers 1:1 and group/channel chat with presence and mentions; secure file and media sharing (up to 20 GB per message via PiTransfer per marketing); cloud co-editing and a document library for sensitive document workflows. Security pages claim non-disableable E2EE, AES-256 for real-time calls, and RSA-2048 for file sharing.

Hosting options include fully managed cloud SaaS, on-premise/private servers behind the customer firewall, and use cases marketed for air-gapped or constrained networks. Privacy policy states encrypted message storage on servers hosted in France; GTS state EU hosting without transfer outside the EU for personal data in scope.

Administration covers local/regional admin roles, user and group management, time-based access, contact and file-sharing authorisations, activity monitoring, minimum client version enforcement, MFA, geographic access limits, custom retention, and remote revoke/wipe language for compromised devices—built for security teams governing a closed network.

Marketed AI features include deepfake/identity verification using camera, microphone, and device signals; real-time meeting translation; Private Translate for sensitive text/documents without content leaving customer infrastructure; and an AI companion for transcription, decisions, and post-meeting summaries—positioned for closed environments rather than public LLM APIs.

Best fit when

  • French or EU public-sector and regulated orgs wanting a French SAS counterparty for secure meetings and chat
  • Buyers who need large HD meetings (claimed up to 1,000) and webinar-scale events with role and recording control
  • Security teams that require admin kill-switch, MFA, geo restrictions, contact/sharing policies, and version enforcement
  • Deployments that must stay on-premise, behind a firewall, or in air-gapped environments rather than only multi-tenant SaaS
  • Organisations evaluating white-label sovereign collab with in-suite AI translation/deepfake features kept inside customer infrastructure

Poor fit when

  • Teams that require open-source clients/servers and community auditability
  • Buyers who need native Microsoft 365/Google Workspace depth (channels + full Office graph) as the primary collaboration hub
  • Procurement processes that block tools without published independent security audits or named ISO certificate packs
  • Small teams that only need lightweight chat without large video/webinar or heavy admin overhead

Consider instead when

  • When: You already run self-hosted files/groupware and want open-source Talk-style meetings under your keys

    Consider: Nextcloud (Talk)

    Broader OSS hub; different security and UX model than Private Discuss’s proprietary stack

  • When: You primarily need German-entity encrypted business messaging with AD/LDAP cockpit, not large webinars

    Consider: ginlo Business

    Narrower A/V scale; strong messenger admin story

  • When: You need everyday team chat with email bridging rather than government-scale secure video

    Consider: Fleep

    Estonian messenger positioning; different threat model and feature depth

  • Independent security / crypto audit·Not found
  • ISO 27001·Not found
  • SOC 2 / SOC 3·Not found
  • GDPR / EU data protection·Vendor claimed
  • +3

Considerations & known limitations

  • MediumNo public independent security audit

    Strong encryption and zero-knowledge claims are first-party only. Security-sensitive buyers should require audit reports, architecture review, and pilot verification before treating E2EE as proven.

  • MediumIncomplete public SaaS subprocessor inventory

    France/EU hosting is claimed, but backup, email, analytics, and mobile push processors are not fully listed publicly. Residual transfer and support-access risk for managed SaaS must be closed in the customer DPA.

  • LowRCS number inconsistency on public pages

    Legal notices and GTS use RCS 828 242 545; privacy policy cites 829 105 741. Confirm legal identity via official registry extract before contracting.

  • LowClosed proprietary platform

    Not open source; GTS emphasise vendor IP. Limits community audit and exit options compared with OSS collab stacks such as Nextcloud.

  • MediumAI features need separate diligence

    Deepfake detection, Private Translate, and AI companion expand the evaluation surface (model location, training data, false positives). Vendor claims on-prem/private processing for some features—verify architecture per deployment mode.

Open questions for due diligence

  • Will the vendor provide a current subprocessor list, DPA, and evidence pack (ISO/audit) for the chosen SaaS region?
  • What is the exact E2EE protocol suite, key custody model, and any server-side components that can access metadata or cleartext in admin/recording scenarios?
  • For on-premise/air-gapped installs: supported OS, HA, update path, and whether AI features run fully offline?
  • Which customer logos on the homepage reflect active production use vs historical/marketing relationships?
  • Which RCS registration number (828 242 545 vs 829 105 741) is authoritative, and is there a group structure beyond the SAS?

Preguntas Frecuentes

Yes according to the vendor. Hosting pages describe managed SaaS, on-premise/private servers, operation behind the customer firewall, and use cases for air-gapped or highly restricted networks. SaaS message storage is claimed in France/EU; on-prem keeps data under your governance policies. Confirm exact supported topologies, update path, and support SLAs in the commercial offer—public materials are capability-oriented rather than a full reference architecture.

Security pages claim automatic end-to-end encryption that cannot be disabled, AES-256 for real-time calls, RSA-2048 for file sharing, peer-to-peer treatment for some internal communications, JWT-protected sessions with limited TTL, and zero-knowledge framing so the vendor cannot decrypt communications. Privacy policy states messages are stored encrypted on servers in France and retention is set by the licensee administrator. No public independent crypto audit PDF was found—request protocol details and test evidence in procurement.

The administration suite is the control plane: multi-scope admin roles, user/group lifecycle, access windows, who may contact whom, file-sharing rules, activity monitoring, enforced minimum app versions, MFA, geographic restrictions, retention policies, and remote kill-switch/wipe style controls. This is aimed at security and IT teams running a closed collaborative network rather than self-serve consumer groups.

Privacy materials describe processing under a SaaS licence agreement with data-protection clauses when Private Discuss acts as processor, and publish dpo@private-discuss.com. GTS state EU hosting without transfer outside the EU. A downloadable standalone DPA, full subprocessor inventory, ISO 27001 certificate number, and independent audit report were not found on the public site during research—treat those as diligence items for the sales/legal pack.

Vendor materials claim HD conferences up to 1,000 participants and webinars up to 1 million participants, plus webinar-style role and recording controls. That is the product’s scale differentiator versus many secure messengers that only support small A/V calls. Validate real-world capacity, concurrent quality, and recording retention against your largest all-hands or public-event scenarios in a pilot.