Skip to content
Independently verified · Quarterly re-audit
EU VETTED

CryptPad

VERIFIED
Docs & wikis · France
Founded 2014 · cryptpad.org ↗

Paris-based E2E-encrypted open-source collaboration suite (CryptPad by XWiki SAS), NLnet/NGI-EU-funded; zero-knowledge architecture.

Why this score?

CryptPad is the end-to-end encrypted open-source collaboration suite developed by XWiki SAS (Paris, France; making open-source software since 2004). Funded by NLnet PET, NGI TRUST, NGI DAPSI, NGI Zero Commons Fund (European Commission's Next Generation Internet programme) plus CryptPad.fr subscribers and Open Collective donations — making this one of the most clearly EU-publicly-funded sovereign-tech projects in the directory. Zero-knowledge encryption means even XWiki cannot read customer documents; full source on GitHub; self-hostable on EU infrastructure. Rated 4/5: French SAS, EU public funding lineage, E2E architecture, no US-VC, no US legal entity — but the DPA is not publicly accessible; it is reachable only inside a customer account for paid Organisation-Plan holders; the rubric reserves 5/5 for a publicly accessible DPA.

SCORE
4.0/5
CLOUD ACT
OWNERSHIP
SUB-PROCS
not disclosed
JUMP TO
OVERVIEW

About CryptPad

CryptPad is the canonical end-to-end-encrypted open-source collaboration suite, actively developed by a team at **XWiki SAS** — a Paris-based French company that has been building open-source software since 2004. The platform delivers a Google Docs / Notion / Microsoft Office Online alternative built around zero-knowledge encryption: documents are encrypted on the user's device before any data leaves it, and XWiki itself has no ability to read customer documents. The product surface covers rich text, code, slides, forms, kanban, calendar, polls, whiteboard, sheet, and team drives — a complete office-suite-grade feature set running entirely E2E. Funding architecture is the structurally interesting story. **CryptPad is funded by NLnet PET, NGI TRUST, NGI DAPSI, and the NGI Zero Commons Fund** — the European Commission's Next Generation Internet (NGI) programme that channels EU public-research money into European-sovereign open-source infrastructure. Additional funding comes from **CryptPad.fr subscribers and Open Collective donations**. This combination — **EU public funding + community subscriptions** — gives CryptPad a structurally different cap table from any US-VC-funded competitor: no exit pressure, no dilution risk, no acquisition rumours, and explicit alignment with the European Commission's sovereign-tech agenda. Pricing for CryptPad.fr (the managed cloud) is freemium with paid storage tiers; the entire codebase is open source on GitHub (cryptpad/cryptpad) and self-hostable for organisations wanting full control. Best fit: privacy-maximalist EU teams, journalists and activists, EU public-sector and education buyers (where NLnet / NGI funding lineage is itself a procurement signal), and any organisation that wants a full office suite where the vendor structurally cannot read the documents.
SUB-PROCESSORS

Sub-processor map · not disclosed

Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
CERTIFICATIONS

Frameworks & certifications · none listed

We checked the vendor's website and standard certification body registries. No active certifications found at the time of last audit (2026-05-18).
FEATURES

Capability matrix

INTEGRATION & ACCESS
REST API Yes
SSO (SAML / OIDC) No
COMPLIANCE & GOVERNANCE
Audit log No
Self-host / on-prem option Yes
PRICING

Pricing & tiers

FREEMIUM
Custom pricing

Contact vendor for tier or volume pricing.

View pricing page ↗
PUBLIC DOCUMENTS

Public documents

Vendor does not publish a public DPA. Without a publicly accessible Data Processing Addendum, small EU customers cannot self-serve the processor agreement — this caps the compliance score (see How we score).
Vendor does not publish a sub-processors list. Schrems II compliance and CLOUD Act exposure cannot be independently verified without it.
  • Data Processing Addendum (DPA)
    — missing
    missing
  • Sub-processors list
    — missing
    missing
ALTERNATIVES

Alternatives in this category