Wire Logo

Wire

Swiss open-source secure messenger from Wire Swiss GmbH: always-on E2EE messaging, calls, and files (MLS), cloud or on-premises, for regulated teams and public sector.

E2EE + MLSOpen sourceOn-prem / self-hostSwiss HQEU cloud regionsISO 27001/27701 (claimed)

Shortlist Wire when you need always-on E2EE collaboration (MLS), Swiss legal entity, open-source clients/server, and a credible path from EU cloud to on-prem/federation. Skip when you need deep Microsoft 365/Slack app ecosystems or a pure non-AWS/US-SaaS subprocessor footprint—consider Nextcloud Talk or a Germany-hosted managed messenger such as ginlo Business instead.

Key capabilities

Messaging, conference calls, and in-app file shares are end-to-end encrypted by default—no toggle. Wire markets full-product MLS (IETF Messaging Layer Security) for scalable group key exchange, alongside Proteus/Double Ratchet heritage for pairwise messaging and SRTP/DTLS for calls. Suits orgs that reject optional encryption modes.

Invite outsiders into E2EE conversations via guest rooms in the browser without requiring a full account download, plus external team members with lifecycle controls (removal drops their history access). Practical for contractors, clients, and inter-org projects that must stay off consumer WhatsApp.

Run managed Wire Cloud or deploy on-premises/private cloud—including air-gapped networks—with optional federation between isolated Wire backends and admin control over which backends may interconnect. Aimed at governments and CNI that cannot accept pure SaaS only.

Enterprise tier adds SAML-based single sign-on, SCIM provisioning, and granular admin controls (for example enforce app lock, restrict self-deleting messages). Built for complex directories rather than only self-serve SMB signup.

Wire publishes client, server (wire-server, AGPL-3.0), and core-crypto components on GitHub for independent review. Multi-device accounts (up to 8 devices) with ID Shield certificate-based device verification reduce manual fingerprint workflows while keeping device trust visible.

Best fit when

  • Enterprises and public sector needing default E2EE for chat, calls, and files—not optional modes
  • Buyers evaluating MLS / post-quantum-ready group crypto roadmaps
  • Orgs that want open-source clients and server for independent review
  • Deployments that may start on EU cloud and later move to on-prem, air-gap, or federated backends
  • Teams that must collaborate with guests/contractors without forcing full seats or consumer WhatsApp
  • Swiss or EU procurement expecting a European legal entity and published DPA/subprocessor list

Poor fit when

  • Teams standardised on Teams/Slack primarily for apps, bots, and Office workflows rather than message confidentiality
  • Buyers requiring zero US-group cloud or US SaaS subprocessors (Wire Cloud uses AWS EMEA and several US-parent tools)
  • Use cases that depend on Wire Drive as if it were client-side E2EE messenger storage
  • Very small groups that only need a simple consumer messenger without admin, SSO, or on-prem

Consider instead when

  • When: You want a German managed business messenger with AD/LDAP cockpit and no self-host requirement

    Consider: ginlo Business

    Stronger Germany-hosting contract language; weaker open-source/on-prem story than Wire

  • When: Chat is secondary to self-hosted files, calendars, and groupware you already run

    Consider: Nextcloud (Talk / groupware)

    Broader collaboration suite; different crypto/admin model than Wire MLS messenger

  • When: You need the Microsoft 365 or Slack ecosystem more than E2EE-by-default

    Consider: Microsoft Teams or Slack

    Richer workplace integrations; weaker default E2EE and European sovereignty story

  • Independent security / crypto audit·Partial
  • ISO 27001·Vendor claimed
  • ISO 27701·Vendor claimed
  • SOC 2 / SOC 3·Not found
  • +5

Considerations & known limitations

  • MediumAWS EMEA + US-parent SaaS subprocessors

    Even with DE/IE regions and a Swiss controller, cloud tenants depend on AWS EMEA and several US-group tools for hosting, CRM, support, or payments. On-prem reduces hosting dependency but not necessarily all vendor-side SaaS.

  • MediumWire Drive is not client-side E2EE

    DPA distinguishes messenger E2EE from Drive encryption-at-rest with possible operator access. Misclassifying Drive as zero-knowledge chat storage creates compliance risk.

  • LowISO / Cyber Essentials need certificate proof

    Certifications are prominently claimed on marketing pages but should be validated with current certificates and scope statements before audit reliance.

  • LowMobile push via APNs/FCM

    Standard mobile delivery path involves Apple/Google push infrastructure for wake-ups; Wire states content is not shared. F-Droid build available to avoid FCM.

Open questions for due diligence

  • Can the vendor provide current ISO 27001/27701 and Cyber Essentials certificates with scope covering the proposed deployment?
  • For our data classification, which workloads stay on messenger E2EE versus Wire Drive?
  • What exact AWS regions/AZs and backup/DR locations apply to our cloud tenant?
  • Which enterprise features require on-prem versus cloud, and what federation limits apply across backends?
  • Are independent crypto/security assessment reports available under NDA, and how recent are they?

Questions Fréquemment Posées

Both. Wire Cloud is the managed service (servers described in Germany and Ireland on AWS EMEA per the DPA). Enterprise and government offerings support on-premises and private-cloud deployment, including air-gapped environments and optional backend federation. Confirm which features are cloud-only versus on-prem in a sales/architecture workshop—Wire notes some capabilities are on-prem exclusive.

No—treat them separately. Messenger conversation content is designed as client-side E2EE where Wire states it lacks decryption keys. The published Data Processing Addendum explicitly states Wire Drive content is not under that client-side E2EE model; Drive uses encryption at rest and Wire may access Drive content when needed to operate the service. Scope your data classification accordingly.

Security pages state Wire’s servers are in Germany and Ireland. DPA Annex 2 lists AWS EMEA SARL for hosting (EU), plus subprocessors such as Google Cloud EMEA (email), Zendesk (support), HubSpot/Salesforce (CRM/marketing), Stripe (payments—USA with SCCs), Box, ContractHero, Countly (Germany), and Wire Germany GmbH. Mobile push uses APNs/FCM without sharing message content, per Wire’s security FAQ.

Clients and related code are published under GPL-family licenses (overview repo GPL-3; server AGPL-3). Building a modified client that still talks to Wire’s production servers is subject to Wire’s Terms of Use restrictions (do not weaken security, change server interaction rules, etc.). Self-hosted backends you operate yourself are the path for full operational control.

Public materials include a GDPR Art. 28 DPA with TOMs and subprocessor table, Security and Privacy whitepapers, and marketing claims of ISO 27001, ISO 27701, and Cyber Essentials. Request current certificates, pen-test summaries, and any independent crypto reviews under NDA. Treat cert status as vendor-claimed until you see primary evidence.