
ginlo Business
German-hosted secure business messenger from Munich-based ginlo.net GmbH: E2EE chat, files, and A/V calls with Management Cockpit admin for AD/LDAP, policies, and external ginlo Private contacts.
Shortlist when you need a German-entity, Germany-hosted encrypted business messenger with Management Cockpit (AD/LDAP, policies, remote wipe) and free external reach via ginlo Private. Skip when you require open source, self-hosting, or published independent crypto audits—consider Wire or Nextcloud Talk instead.
Key capabilities
Vendor GTC describe a full-encryption architecture: no unencrypted messages stored on ginlo servers, decryption keys only on authorised messenger clients, and encryption in transit plus on devices and intermediate server storage. Practical for regulated orgs replacing email for sensitive threads—confirm cipher suite details in procurement docs.
Central admin for licences, CSV/AD/LDAP user import, department keywords, password and attachment policies, corporate design, groups, and info channels. Leaver accounts can be blocked and communications deleted quickly when devices are lost—built for IT ops without requiring a messaging platform engineer.
Employees on paid Business seats can message external contacts on free ginlo Private without charging those outsiders. Suits practices, schools, and authorities that need secure outbound reach beyond the licensed tenant.
Use up to ten devices per account with server-side sync while messages remain available; announcement/content channels for org-wide updates; audio/video conferences with screen sharing; self-deleting and scheduled messages plus QR identity checks and ginlo ID without exposing a phone number.
Contracting party is ginlo.net GmbH in Munich; GTC require the server and storage in a German computer centre certified to ISO 27001 based on BSI IT-Grundschutz, with no ginlo-initiated third-country transfer. Managed SaaS only—no public self-host option.
Best fit when
- German or EU orgs that want a Munich legal entity and stated Germany-only server placement for business chat
- Practices, schools, authorities, and SMEs needing admin control (licences, AD/LDAP import, leaver wipe) without running a messaging stack
- Teams replacing informal WhatsApp/email for sensitive internal and external conversations when counterparts will install ginlo Private
- Rollouts that need multi-device sync, channels, and A/V calls in one encrypted messenger rather than a full collaboration suite
Poor fit when
- Buyers that mandate open-source clients/servers or on-premises deployment under their own infrastructure
- Enterprises requiring published independent security audits and named public subprocessor lists before shortlisting
- Teams needing deep Slack/Teams-style workspace integrations, bots, and app ecosystems
- Organisations whose external audience will not install a second messenger app
Consider instead when
When: You need open-source components, MLS roadmap, or private-cloud/on-prem options
Consider: Wire (Swiss secure collaboration)
Wire is commonly shortlisted for enterprise secure messaging with more deployment flexibility than pure SaaS messengers.
When: You already run a self-hosted collaboration hub and want chat inside that stack
Consider: Nextcloud Talk (Germany)
Pairs with Nextcloud Files/Groupware; different product shape than a standalone dual Business/Private messenger.
When: You need mass consumer reach more than organisational sovereignty
Consider: WhatsApp Business or Microsoft Teams
Higher network effects; weaker EU-sovereignty and admin story for sensitive regulated chat.
- Independent security / no-logs audit·Not found
- ISO 27001·Vendor claimed
- SOC 2 / SOC 3·Not found
- GDPR / EU data protection·Vendor claimed
- +4
Considerations & known limitations
- MediumLimited public audit and cert artefacts
ISO 27001/IT-Grundschutz and regular audits are vendor-asserted; no public audit PDF or cert registry entry found. Procurement should request evidence under NDA.
- MediumClosed managed SaaS only
No self-host or open-source server path. Exit and independent verification depend on vendor cooperation and export tooling.
- LowMobile push via Apple/Google
GTC reference Apple Push Notification and Google Cloud Messaging for new-message signals. Content is claimed E2EE, but delivery metadata still touches US platform infrastructure.
- MediumProcessors described by category only
Privacy policy lists German data centres, line providers, and payment providers without naming operators. Harder to complete CLOUD Act / transfer diligence from public sources alone.
- LowExternal parties must use ginlo
The Private bridge helps, but contacts still need ginlo Private installed—unlike email or WhatsApp ubiquity.
Open questions for due diligence
- Will the vendor sign a B2B DPA and provide a current named subprocessor list including data-centre operator(s)?
- Can procurement obtain ISO 27001 certificate details and latest independent security assessment under NDA?
- Which exact encryption protocols/algorithms are used for messaging and calls today (beyond BSI recommendations)?
- What export, eDiscovery, and legal-hold options exist within the 90-day server retention model?
Veelgestelde Vragen
No. It is a managed multi-platform service on ginlo.net GmbH servers. Apps are distributed via platform stores and a web messenger; the GTC grant a non-exclusive licence to use the messenger with the ginlo server only. Buyers needing open-source clients/servers or on-prem control should evaluate peers such as Wire or Nextcloud Talk instead.
According to the privacy notice and GTC, Business messages are stored encrypted on servers in Germany and deleted from the server 90 days after send (30 days for the consumer product). Devices keep encrypted local copies for multi-device sync during that window; users can also set self-deleting messages. Confirm retention and export needs against your records policies.
Optional Management Cockpit is the admin plane: import users via CSV, LDAP, or Active Directory; set security and compliance policies; manage licences and devices; create groups and info channels; and align app appearance with corporate design. Solo users can run without the cockpit; multi-team rollouts typically start with a trial of cockpit licences.
Yes within the product model: Business users can communicate with ginlo Private users so clients, patients, parents, or suppliers need not buy seats. Identity can use ginlo ID/QR rather than only phone numbers. Evaluate whether your external audience will install ginlo Private versus staying on WhatsApp or email.
Marketing and GTC claim German data centres certified to ISO 27001 based on IT-Grundschutz and regular security audits, plus algorithms aligned with BSI recommendations. No public audit report or certificate number was found on the official site during research—request evidence under NDA and treat independent audit status as a diligence item.