whats-best.ai

Business Instant Messaging · head-to-head

Element vs Mattermost

Element

UK / wider Europe

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

Mattermost

Rest of world

Panel rating

Sovereignty: 1 of 4 dimensions proven

Full evaluation →

The written short answer is being updated after a re-evaluation. The scores below are current.

Read this comparison as one judge. Each weighs the same scores by what they care about.

The Security Officer

Assumes the archive will one day be read by someone it was not meant for. Wants end-to-end encryption that ordinary users survive, device verification, sessions an admin can revoke, and a plain statement of what the vendor cannot decrypt.

Element

This judge's pick

Mattermost

Criterion by criterion

Channels, threads & search

Element

Threads, reactions, attachments, polls and unlimited history are confirmed, and vendor-agnostic federation gives genuinely cross-organisation rooms — but the evidence is completely silent on search: no full-text search, no filters, no message-editing history, no pins. An archive you cannot evidence as findable after eighteen months is an archive I cannot trust as a record.

Mattermost

Channels, real threaded discussions, file previews and search up to three million posts are documented on the plan pages, the API exposes threads with collapsed-thread views, and a beta call can move a thread to another channel. By default every deployment retains all messages, edits and deletions included, so the history itself is uncapped. We found no public information on pinned and saved items, on end-user search filters by channel, person or date, or on channel archiving and renaming that preserves history.

Encryption & access control

Element

This is what the category should look like: the entire platform is end-to-end encrypted by default including calls, devices verify by QR code or emoji string via cross-signing, the cryptography is open (Matrix, AGPL-licensed server), and the vendor states plainly that end-to-end encrypted information is "never accessed by our teams or shared externally". The one thing the evidence never documents is an administrator revoking a user's sessions and devices — MDM and server deprovisioning appear, per-user session revocation does not.

Mattermost

Transport is TLS throughout, encryption at rest is infrastructure-level — LUKS, BitLocker, TDE, S3-managed keys — and granular roles, SSO, MFA and attribute-based channel access are all documented. The plain statement I prize is there, in an unwelcome direction: the deployment guide says encryption within the database is not offered, precisely so end-user search and compliance reporting can work, which tells me the server and whoever operates it reads everything. We found no public information on end-to-end encryption, device verification, or sessions an administrator can revoke.

Retention, discovery & co-determination

Element

Rules-based retention policies with a documented 7-day window before permanent deletion including media, in-room auditing for regulation, user-level data export, and an explicit statement that users are not profiled — the works council will like the last part. But there is no evidence of legal-hold or eDiscovery export capturing edits and deletions, the auditing is scoped to rooms rather than a full administrative audit trail, and presence control is unaddressed.

Mattermost

Legal hold, eDiscovery automation and exports in CSV, Actiance XML, Global Relay EML and Proofpoint formats are documented, carrying edits, deletions, file uploads and channel member history, with messages trackable by identifier across batches and query and download actions logged in an audit history. Retention is retain-everything by default with plan-dependent customisation, jobs report success with counts, and past history can be exported by timestamp from the command line. Two honest gaps: Playbooks and Boards content sits outside the compliance export, and we found no public information on per-channel retention granularity, a full administrative audit trail, or switching off activity analytics organisation-wide.

Deployment & data custody

Element

Custody is genuinely the customer's: AGPL-licensed server suite, official Helm charts for Kubernetes, install and support for air-gapped instances needing no internet, an open federated protocol, and a vendor that markets against lock-in rather than resisting exit. The single dent is that Element itself labels the community homeserver "not for use in production environments," nudging production self-hosting into the paid tier.

Mattermost

Custody is genuinely on the table: three deployment methods install the same server, high availability is self-managed, and an air-gap runbook with bill of materials and registry mirroring covers every edition from Team Edition upward, with FIPS-compliant, STIG-hardened images published. Export covers past history, files and member history into my own filestore, and Matrix protocol interoperability is named for federation. The door itself is the remaining question: we found no public information on the source licence terms behind the Team Edition or a documented migration path for bringing a legacy archive in.

Integrations & extensibility

Element

A handful of named widgets (NeoBoard, OpenProject, Jira) plus LDAP/SCIM provisioning and OIDC SSO get identity right, but the evidence says nothing about a documented REST API, webhooks, slash commands or any bot framework. If I cannot see the extension surface, I cannot audit what an integration is allowed to touch.

Mattermost

A documented REST API with bearer authentication and per-channel permission checks, incoming and outgoing webhooks on every plan, Slack-format compatibility, interactive Blocks with buttons and menus, interactive dialogs and administrator-enforced webhook channel locking make a real integration surface, and a Model Context Protocol connector is named at the Enterprise tier. The admin control over which channels a webhook may post to is exactly the kind of boundary I want to see. We found no public information on SCIM provisioning, event subscriptions with retries, documented rate limits, a sandbox, or an app directory with permissions a customer can audit.

European sovereignty

Element

The pipeline marks the formal attributes unknown, but the evidence's own privacy policy names a UK contracting entity (Element Creations Ltd, London, with US and EU subsidiaries), EU hosting on named AWS regions with customer choice, and a published subprocessor list — several of them US processors (Cloudflare, Twilio, Salesforce) with purposes named but no legal basis for the transfer. The self-hostable, air-gapped deployment is what keeps this defensible for a sovereignty-minded buyer; without it, the UK entity and US subprocessors would pull the score lower.

Mattermost

The contracting entity is Mattermost, Inc. of Palo Alto; we found no public information confirming EU data residency, and the captured security page names Azure and AWS as cloud options for US-headquartered providers without listing the subprocessors of the vendor-managed cloud. Transfers to the United States are disclosed with Data Privacy Framework certification, Standard Contractual Clauses and a TRUSTe referral path, and self-hosting with customer-controlled processing is the real mitigation — but even there, hosted push notifications can carry usernames, channel names and message preview snippets to the vendor unless the customer keeps that service off. For a European buyer this is a US chain with an escape hatch, not a sovereign one.

Pricing transparency

Element

The Community edition is free and public, but the tier anyone would run in production is "Priced per seat/month" with no number and a "Talk to an expert" button, and "price minimums" for additional servers are referenced without figures. No buyer can compute the annual invoice for the deployment that actually matters from these pages.

Mattermost

The captured pricing pages route every named plan to a human — Professional says "Contact Sales", Enterprise says "Get Pricing", Enterprise Advanced says "Request Quote" — and no per-user figure, billing period or VAT treatment appears anywhere. A free limited-use edition of Enterprise Advanced exists for technical evaluation, while compliance monitoring sits in the quote-only tiers. I cannot compute an annual invoice for any headcount from these pages.

Sovereignty, side by side

Dimension Element Mattermost
Legal entity Not determined Not determined
Ownership Not determined Not determined
Data residency Not determined Not determined
Subprocessors US CLOUD Act reach US CLOUD Act reach