The six-judge panel splits rather than settles. Wire is ahead on encryption and access, 9.5 to 8.5, 6 judges lean Wire, 0 ties; on deployment control, 7.7 to 7.3, 3 lean Wire, 1 Threema Work, 2 tie; and on sovereignty, 5.2 to 5.0, 4 lean Wire, 2 Threema Work. Threema Work holds the higher governance and discovery mean, 2.5 to 2.3, with 1 lean and 5 ties. Messaging core (2.2 each), integrations (4.0 each) and pricing transparency (5.2 each) are even. Weighted totals also split: security officer 6.2 vs 5.2, works council 5.4 vs 5.0, compliance counsel 4.6 vs 4.5 and skeptic 5.0 vs 4.6 favor Wire; messaging team lead 4.3 vs 4.1 and platform engineer 5.8 vs 5.6 favor Threema Work. Both list a Swiss legal entity, unknown ownership and EU-only residency; subprocessor exposure differs: EU-only for Threema Work, US Cloud Act for Wire.
Choose Threema Work if
Your platform engineering team leads the evaluation: its weighted total is 5.8 for Threema Work against 5.6 for Wire.
Your messaging team lead signs off: the weighted total is 4.3 for Threema Work against 4.1 for Wire.
You need air-gapped, self-hosted operation with white-labeling: the deployment control verdict for Threema Work evidences self-hosting, air-gapped operation and white-labeling on its OnPrem tier, and 1 judge leans Threema Work on that criterion.
Your procurement requires subprocessor exposure within the EU: Threema Work's sovereignty attribute is EU-only for subprocessor exposure, while Wire's is US Cloud Act.
Choose Wire (Messaging) if
You need end-to-end encryption as the default for text, voice, video and files: Wire's encryption and access mean is 9.5 against 8.5, with 6 judges leaning Wire and 0 ties.
Your security officer makes the call: the weighted total is 6.2 for Wire against 5.2 for Threema Work.
Your works council weighs in: its weighted total is 5.4 against 5.0, and the governance verdict credits deletion-on-delivery plus consent-based, self-hosted analytics.
You want servers in Germany and Ireland with a published subprocessor list: 4 judges lean Wire on sovereignty, 5.2 against 5.0.
Your compliance counsel and the skeptic judge both review the buy: their weighted totals favor Wire at 4.6 vs 4.5 and 5.0 vs 4.6.
Read this comparison as one judge. Each weighs the same scores by what they care about.
The Security Officer
Assumes the archive will one day be read by someone it was not meant for. Wants end-to-end encryption that ordinary users survive, device verification, sessions an admin can revoke, and a plain statement of what the vendor cannot decrypt.
Threema Work
Wire (Messaging)
This judge's pick
Criterion by criterion
Channels, threads & search
Threema Work
Group chats, polls, reactions, file sharing and edit/delete are evidenced, but the evidence says nothing about threads, channels, search, or exporting a conversation in human-readable form. For a product whose whole pitch is that the server cannot read anything, that silence matters: I have no evidence a decision made eighteen months ago can be found or extracted by the organisation that made it.
Wire (Messaging)
Group chats up to 500–2000 participants, file sharing, self-deleting messages and audio/video messages are evidenced, but the evidence is completely silent on channels, threading, mentions and — damningly for an archive — search. A product that cannot show me search cannot find a decision made eighteen months ago, and silence here is the answer.
Encryption & access control
Threema Work
This is the product's spine: end-to-end encryption as the default mode with a zero-knowledge statement in plain words — "not even Threema has access" — plus perfect forward secrecy, open source and independent audits, which is exactly the vendor-cannot-decrypt statement I demand. It stays below the top because the evidence evidences no device or key verification, no admin-revocable sessions, and no documented key handling; MDM and central management are named but never as session revocation.
Wire (Messaging)
This is the rare product that writes down what I demand in writing: end-to-end encryption of text, voice, video and files, open MLS cryptography auditable on GitHub, certificate-based ID Shield plus manual device verification, and the plain statement 'Wire does not have access to encryption keys and does not use backdoors.' It misses 10 only because no evidence shows an admin revoking sessions or devices, and the 'cannot decrypt' statement is asserted rather than itemised.
Retention, discovery & co-determination
Threema Work
Every retention statement in the evidence concerns Threema's own website forms and logs; for the customer's message archive there is no retention policy, no export format, no audit log and no legal hold anywhere. The off-hours policy is the single control a works council would recognise, and it does not make an archive governable.
Wire (Messaging)
Messages are deleted from servers immediately upon delivery, which keeps the archive out of strangers' hands but also means there is no customer-side retention policy, no discovery export, and no admin audit log anywhere in this sheet — a subpoena lands on scattered devices, not a manageable store. The one mercy is that the only analytics (Countly) is consent-based, self-hosted and EU-based, so a works council has little to switch off.
Deployment & data custody
Threema Work
A genuine self-hosted OnPrem edition with air-gapped operation and white-labelling of all apps is evidenced, which puts real custody within the customer's reach. But no export or migration path in or out is documented anywhere in the evidence, and "Open Source" is unscoped — client apps or server, it does not say.
Wire (Messaging)
Custody can genuinely be the customer's: 'comprehensive on-premises deployment support', federation, multi-tenancy and data sovereignty are offered, and the source code is 100% open on GitHub. What holds it at 8 is pure silence on export and migration — nothing in the evidence documents how a customer walks out with their history, and an exit I can't evidence is an exit the vendor controls.
Integrations & extensibility
Threema Work
An integration API, an admin API for automated administration, a broadcast API with bots, and gateway credits are evidenced, plus AAD sync at an unstated additional charge. No webhooks, slash commands, SSO, documented rate limits or sandbox appear anywhere, so this is a thin but real API surface rather than a framework.
Wire (Messaging)
The admin console can deploy third-party bots, a GitHub integration is listed, and SSO/SCIM are evidenced — slightly more than bare webhooks. But there is no documented REST API, no webhooks, no slash commands, no rate limits and no app framework in the evidence, so I cannot credit extensibility a buyer could actually build on.
European sovereignty
Threema Work
Hosting is named and certified — Threema's own servers in two ISO 27001 colocation data centers in Zurich — but the contracting entity is Swiss, not EU, and the pipeline found no published subprocessor list beyond Livestorm for webinar registration. The OnPrem option would remove the question entirely, but on the cloud product this is a third-country arrangement dressed with an Art. 27 GDPR representative in Bonn.
Wire (Messaging)
Servers in Germany and Ireland, a published subprocessor list with locations and transfer safeguards, and ISO 27001/27701 certification are close to the 8 anchor — but the contracting entity is Wire Swiss GmbH in Zug, with Wire Germany GmbH a mere Article 27 representative, and Stripe processes payments in the USA. A Swiss entity with GDPR exposure and a transparent chain earns a solid middle score, not a high one.
Pricing transparency
Threema Work
Core at EUR 3/user/month with annual payment stated and Professional at EUR 5 are public. But the OnPrem tier — the one carrying the sovereignty and air-gap — is priced only as "CUSTOM", AAD sync is an unpriced "additional charge", and VAT treatment is nowhere stated, so the invoice for the deployment a security buyer actually wants is not computable from public pages.
Wire (Messaging)
€7.45 per person/month (€8.94 monthly) with SSO, SCIM and guest roles included is genuinely computable up to 100 people — better than the usual trick of hiding SSO in an unpriced tier. But data sovereignty, federation, ID-Shield and on-premises sit in a custom-priced Enterprise tier, and VAT treatment, terms and storage limits are unstated, so the invoice a regulated buyer actually needs remains a sales conversation.
Sovereignty, side by side
Dimension
Threema Work
Wire (Messaging)
Legal entity
Not determined
Incorporated in CH
Ownership
Not determined
Not determined
Data residency
Not determined
EU only
Subprocessors
Not determined
US CLOUD Act reach
Facts, side by side
Only facts both products carry under the same definition — anything else would not be a fair row.
Compliance · Supervisory authority
Federal Data Protection and Information Commissioner (FDPIC) · Switzerland1