whats-best.ai

Business Instant Messaging · head-to-head

Element vs Mattermost

Element

UK / wider Europe

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

Mattermost

Rest of world

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Platform Engineer

Would rather run it than rent it, and wants to know whether that is a supported deployment or a hobby build. Cares about open protocols, federation, a plugin system with real permissions, and an upgrade path that does not orphan the customisations.

Element

Mattermost

This judge's pick

Criterion by criterion

Channels, threads & search

Element

Threads, reactions, polls, voice messages, attachments and unlimited history are all evidenced, and federation gives genuine cross-organisation rooms with boundaries. But the evidence says nothing about search anywhere — no full-text, no filters, no edit history, no pins — and silence on the one thing that turns an archive into a knowledge base caps it at the anchor that doesn't depend on it.

Mattermost

Channel-based collaboration, real threaded discussions with a documented thread API and per-endpoint permissions, file sharing with link and file previews, and search documented up to 3 million posts — and the default retains every message including edits and deletes, so no history cap bites. I found no public information on pinned or saved items or search filtered by channel, person and date, and moving a thread to another channel is flagged as beta subject to change, so I stop just above the solid baseline.

Encryption & access control

Element

E2EE is the default across the whole platform with the non-encrypted option named as an explicit configuration, device verification via QR code or emoji is exactly the cross-signing UX ordinary users survive, and the vendor states plainly that end-to-end encrypted data is never accessed by their teams. One point held back because admin-revocable session management and documented key handling don't appear on these pages.

Mattermost

Transport TLS with named ciphers, at-rest encryption via disk or storage-level methods within your own infrastructure, granular role-based access with AD/LDAP sync, SSO and MFA are all documented, and the pages state plainly that the database itself is unencrypted so search and compliance reporting work — plus exactly what the optional hosted push service sees. I found no public information on end-to-end encryption, device verification, or admin-revocable session management, which is what separates the operator-reads-everything mode from the top anchors.

Retention, discovery & co-determination

Element

Rules-based retention for messages and media with a documented 7-day deletion window, no user profiling, and opt-in Matomo analytics hosted in London — the works-council questions have answers. But the 'auditing' fact is an in-room record of discussion, not an administrative audit trail, there's no legal hold or eDiscovery export, and the export format is unspecified.

Mattermost

Legal hold and eDiscovery automation are named plan features, and the compliance export documentation is the real thing: CSV, Actiance XML, Global Relay EML and Proofpoint formats, edit and deletion tracking by message identifier across export batches, configurable daily jobs with visible job status, and an audit history of every compliance query and download. I found no public information on organisation-wide switching of activity analytics or user-controlled presence, and Playbooks and Boards sit outside the compliance export — the captured pages stop me short of the works-agreement grade.

Deployment & data custody

Element

This is the one I'd actually run: an AGPL server distribution, official helm charts with GitOps, air-gapped install with vendor support, and an LTS every 6 months with security backports — a supported deployment, not a hobby build. Federation runs on a vendor-neutral open standard governed by the Matrix.org Foundation, the customer owns their homeserver's data, and exit means moving to any Matrix server. Custody is genuinely the customer's.

Mattermost

This is a supported deployment, not a hobby build: Kubernetes, Linux and container paths install the same server, high availability is available self-managed, a FIPS-compliant STIG-hardened image of every container is published, and the air-gap runbook goes down to a bill of materials and private registry mirroring. Federation via Matrix protocol interoperability and a command-line past-history export with a from-timestamp option put custody genuinely with the customer; I found no public information on migration-in tooling or deeper federation detail.

Integrations & extensibility

Element

The identity side is solid — OIDC SSO, LDAP, SCIM provisioning and MDM — and widgets like NeoBoard, OpenProject and Jira exist. But the evidence evidences no REST API, no webhooks, no bot framework, no rate limits and no app directory; none of the developer surface I'd build against is on the page, so I can't credit it.

Mattermost

A versioned REST API with bearer authentication and permission requirements documented per endpoint, incoming and outgoing webhooks that are Slack-compatible for migration, interactive blocks and dialogs for structured interaction, and admin-enforced channel locking on webhooks — real permission controls where the pages speak. I found no public information on SCIM provisioning, documented rate limits, event subscriptions with retries, a sandbox, or a plugin framework whose permissions a customer can audit, which is what my upgrade path depends on.

European sovereignty

Element

The pipeline logged unknowns, but the vendor's own policy names a UK controller (Element Creations Ltd), AWS hosting in Amsterdam/Stockholm with customer region choice, and a published subprocessor list that includes US processors — Cloudflare, Twilio, Salesforce, Hubspot. EU-region content hosting with a named chain sits mid-scale; the self-hosted, air-gapped edition removes most of the question for a buyer like me, but the contracting entity is still not EU.

Mattermost

The contracting entity is Mattermost, Inc., the privacy framework is built around US transfer mechanisms with US-based premier support on offer, and I found no public information on EU data residency or a published subprocessor list for the vendor-managed offering. What saves it for me is the self-hosted path, documented as customer-controlled processing, with air-gap operation and telemetry that can be opted out — run it that way and the question mostly disappears, but that is my work, not the vendor's chain.

Pricing transparency

Element

The Community edition is publicly free under AGPL, which is more than nothing. But the paid tier is 'Priced per seat/month' with no figure and a 'Talk to an expert' button, and the per-server price minimums that govern real deployments are unstated — no buyer can compute an invoice for any headcount from this page.

Mattermost

Every plan ends in a sales conversation — Professional says Contact Sales, Enterprise says Get Pricing, Enterprise Advanced says Request Quote — and I found no public information on any per-user price, so an annual invoice cannot be computed from the pricing page. Credit for a free evaluation edition and unusually clear feature-to-plan boundaries, but the money is entirely opaque.

Sovereignty, side by side

Dimension Element Mattermost
Legal entity Not determined Not determined
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors US CLOUD Act reach US CLOUD Act reach