CRM
ADITO xRM
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by ADITO Software GmbH · www.adito.de
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
ADITO xRM, a CRM from ADITO Software GmbH of Geisenhausen, Germany, was judged from a thin evidence base — a homepage and a privacy policy — and it shows. Sovereignty is the strongest criterion by a distance, at 3-4 against maxima of 2 or lower everywhere else: judges credit the German vendor and an on-premise option, and record Hetzner hosting in Germany under a signed Art. 28 DPA, retention-until-deletion and anonymized IPs, while flagging that this DPA governs adito.de, not the CRM, whose data residency, subprocessor exposure, ownership and entity jurisdiction the evidence lists as unknown. Everything else sits low: contact & data model 0-2, pipeline & forecasting 0-1, automation 0-1, integrations 0-1, with no captured fact describing stages, workflows, fields or APIs. Import, export & exit spreads 0-2, its higher scores resting solely on the on-premise option as an exit lever. No public price appears on any captured page, but pricing is not counted in these verdicts.
Speaks for it
- Sovereignty scores run 3-4, the only criterion above 2 anywhere in the table
- On-premise deployment is offered alongside cloud, the strongest residency control in the evidence
- The adito.de website is hosted by Hetzner Online GmbH in Germany under a signed Art. 28 DPA
- Data is retained only until deletion is requested, and IP addresses are anonymized
Held against it
- No contacts, companies, deals, custom fields or dedupe capability documented on any captured page (contact & data model 0-2)
- No stages, required fields, forecasts or reports evidenced (pipeline & forecasting 0-1)
- No triggers, sequences, routing or even email templates evidenced
- No API, webhooks, email/calendar sync or native connectors evidenced
- No import, export or migration tooling documented, and the only signed DPA covers the adito.de website rather than the CRM
Best for
- You need the database on your own servers — the on-premise option is the evidence's strongest control and the basis of the highest import, export & exit scores (2)
- Your procurement targets an EU-made, German vendor and can tolerate undocumented pipeline and integration depth
- You value GDPR posture signals — Germany-hosted website infrastructure, retention-until-deletion, anonymized IPs — while pursuing product-level paperwork in the sales cycle
Avoid if
- You need a documented API or connector ecosystem for your stack — ask the vendor: the public pages we read do not show it
- You must migrate data in or out — ask the vendor: the public pages we read do not show it
- Your finance team needs defensible forecasts — ask the vendor: the public pages we read do not show it
- You must verify product data residency and subprocessors before signing — the evidence marks both unknown and the only signed DPA covers the adito.de website, not the CRM
The scores
Contact & data model
Show reasoningHide reasoning
How this is scored
Depth and hygiene of the core records — contacts, companies, deals, custom fields, deduplication.
0 — A flat address book; no relations between people, companies and deals.
3 — The standard three objects exist but customization is cosmetic: few field types, no required fields, duplicates accumulate unchecked.
5 — Custom fields across objects, basic dedupe on create, activity history on the record; complex models still need workarounds.
8 — Rich field types with validation, merge and dedupe tooling, relationships beyond the standard model, permissioned field access.
10 — A genuinely modelable system: custom objects or equivalent, bulk hygiene tooling, field-level history — the data model bends to the business, not the reverse.
The Solo Seller
The only product claim in the whole registry is that it runs cloud or on-prem — not a word about contacts, companies, deals, custom fields, or dedupe. If the evidence can't show me a contact record, the data model doesn't exist as far as I'm concerned. 1
The Data Protection Officer
The registry is silent on every data-model fact — objects, field types, required fields, dedupe, merge, record history — and unevidenced capability is absent capability. A CRM is a database of other people's personal data before it is a sales tool, and this sheet shows me nothing about how that database is structured or kept clean. 1
The Sales Ops Lead
The captured pages evidence nothing about the data model — no contacts/companies/deals detail, no custom fields, no required fields, no dedupe anywhere in the registry. 1
The RevOps Integrator
The only product-level claim captured anywhere is a hosting tagline; the CRM category implies contacts exist, but nothing evidences companies, deals, custom fields, validation, or any dedupe tooling. Silence on the core data model is a data model I cannot build a stack on. 1
The Migrator
The captured pages say nothing about contacts, companies, deals, custom fields, dedupe or merge — an unevidenced data model is one I can't trust with a migration. Below the three-object anchor because even the standard objects aren't documented, only the 'CRM/xRM' label. 1
The Skeptic
Not one captured fact touches contacts, companies, deals, fields or dedupe — the registry is a homepage tagline and a privacy policy. I cannot even confirm the flat-address-book floor; the single point is courtesy of the 'xRM' in the product name and nothing else. 1
Pipeline & forecasting
Show reasoningHide reasoning
How this is scored
Whether the pipeline enforces a process and produces reporting a finance department accepts.
0 — A kanban of deals with amounts; nothing is enforced, nothing rolls up.
3 — Multiple pipelines and stage probabilities exist, but no required fields per stage and only canned reports.
5 — Stage requirements, win/loss capture and standard forecast views; custom reporting is limited or an add-on.
8 — Enforceable process (required fields, stage gates, routing), custom report builder, forecast by team and period with quota tracking.
10 — Forecasting a CFO signs: weighted and commit-based views, historical snapshots, attainment tracking, and reporting composable enough to answer questions the vendor never anticipated.
The Solo Seller
No pipelines, stage logic, win/loss capture, or forecast evidence anywhere — the evidence is silent on the entire criterion, and silence on pipeline means I'm not trusting my revenue reporting to it. 1
The Data Protection Officer
No pipeline, stage, required-field, forecast or report capability is evidenced on any captured page. There is nothing here to distinguish enforced process from a deal list, so the bottom anchor applies. 1
The Sales Ops Lead
This is my core test and it fails on silence: no stages, no stage gates, no required fields, no win/loss capture, no forecast view, no quota tracking — nothing a 40-seat forecast could stand on. All the evidence confirms is the CRM categorization on the homepage; a pipeline the CFO will accept is entirely unevidenced. 1
The RevOps Integrator
Not one captured page mentions stages, probabilities, required fields, forecasts, or a report builder — the homepage carries more words about hosting than about process. I can only credit the category label; nothing here shows finance would accept a number out of it. 1
The Migrator
Not one fact on stages, required fields, win/loss capture, forecasting or reporting; there is nothing here a finance department could sign off on, not even on paper. Scored at the bottom because the evidence is silent on the entire criterion. 1
The Skeptic
No stage model, no required fields, no forecast view, no report — the pipeline criterion has zero evidence to score, which lands at the floor. A CRM vendor that publishes nothing about its pipeline process gets no benefit of the doubt from me. 1
Automation & workflows
Show reasoningHide reasoning
How this is scored
Triggers, sequences and routing that remove manual work without a consultant.
0 — No automation beyond email templates.
3 — Simple if-this-then-that on records; no multi-step sequences, no branching.
5 — Multi-step workflows with delays and branching, email sequences, basic lead routing — capped by tier or count.
8 — Full workflow builder across objects with webhooks as steps, round-robin routing, sequence analytics.
10 — Automation as infrastructure: versioned workflows, error handling, per-step logs, and limits generous enough that the feature is not its own upsell.
The Solo Seller
No triggers, sequences, routing, or workflow builder evidenced on any captured page. I can't even confirm email templates, so there's nothing to score above the floor. 1
The Data Protection Officer
Not a single trigger, sequence, routing rule or workflow capability appears in the evidence. Automation is simply undocumented, and I do not score documentation that does not exist. 1
The Sales Ops Lead
Not even email templates, let alone triggers, multi-step sequences, branching or lead routing, appear in any captured fact. That is the bottom anchor: nothing in the evidence shows automation exists in this product. 1
The RevOps Integrator
No trigger, sequence, routing, or even email-template capability appears in the registry. The floor anchor is 'no automation beyond email templates' and the evidence won't even support the templates. 1
The Migrator
No trigger, sequence, routing or workflow capability appears anywhere in the evidence — by this sheet, nothing beyond the category label exists. Silence on automation limits is exactly how you end up on a tier that can't hold your workflows after you've moved in. 1
The Skeptic
Total silence on triggers, sequences and routing — not even email templates are evidenced anywhere in the captures. The 0 anchor is 'no automation beyond email templates,' and on paper we have less than that. 1
Integrations & API
Show reasoningHide reasoning
How this is scored
Two-way email/calendar sync, native connections, and an API that treats external systems as first-class.
0 — No API, no sync; data enters by CSV and leaves never.
3 — One-way email logging (BCC), a handful of Zapier triggers, a read-mostly API.
5 — Two-way email and calendar sync for the major providers, a documented REST API with sane limits, a modest native directory.
8 — Deep native integrations for the revenue stack, webhooks, OAuth apps, API parity with the UI for core objects.
10 — An ecosystem: public API covering everything the UI does, event streams, a marketplace, and sync so reliable the CRM can be the system of record without being the only system.
The Solo Seller
No API, no two-way email or calendar sync, no native directory — the registry shows zero integration evidence, so by the rules of this exercise the product has none I can rely on. 1
The Data Protection Officer
No API, no email or calendar sync, no native integration is evidenced anywhere in the registry. On this sheet the product has no documented connectivity in either direction. 1
The Sales Ops Lead
No API, no two-way email or calendar sync, no native connectors, no webhooks — the registry is completely silent on every integration path. If data gets in or out, the captured pages don't say how. 1
The RevOps Integrator
This is the criterion I exist to judge, and it's a blank: no API, no webhooks, no two-way email or calendar sync, no native connectors, no Zapier — nothing across the captured pages. An integration surface that is unevidenced is, for my purposes, a closed ecosystem. 1
The Migrator
No API documentation, no two-way email or calendar sync, no webhooks, no native directory is evidenced — the anchor-0 world where data enters by CSV and leaves never. I will not credit an API the vendor's own captured pages don't show. 1
The Skeptic
No API, no sync, no native directory, no webhooks appear in any captured page. Unevidenced means non-existent in this exercise, which is precisely the 'data enters by CSV and leaves never' condition. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where other people's personal data actually lives and under whose law — entity, hosting, subprocessors, DPA.
0 — US entity, US-default hosting, no public DPA or subprocessor list.
3 — A DPA exists and an EU region is available on request or on top tiers; subprocessor exposure to US CLOUD Act reach is broad and undocumented.
5 — EU hosting selectable at signup, published DPA and subprocessor list; core processing still touches US entities.
8 — EU entity or EU-default hosting with published subprocessors, consent-friendly fields, retention and deletion controls; residual US exposure named and narrow.
10 — European entity, EU-only processing including subprocessors, deletion that provably deletes — sovereignty a DPO can sign off without a caveat file.
The Solo Seller
On-premise availability is the strongest residency lever a small buyer gets, the vendor is German, and their site runs on Hetzner in Germany under an Art. 28 DPA. But that DPA covers adito.de's web servers, not my CRM data — no product DPA, no subprocessor list, no cloud residency statement, so I'd still be interrogating sales to run this compliantly. 1 2
The Data Protection Officer
The attribute block computes 0 on unknowns, but rubric level 0 is reserved for US-default posture: the evidence's own header names a German GmbH and the homepage publicly offers on-premise deployment — the strongest residency control a vendor can sell. The privacy policy shows real GDPR instincts — Hetzner Germany hosting under an Art. 28 AVV, retention until deletion is requested, anonymized IPs. But that AVV governs the adito.de website, not the CRM: product-level data residency, the product DPA and any subprocessor list are undocumented, which caps a cloud deployment below 5 while the on-premise option keeps it just above 3. 1 2
The Sales Ops Lead
German vendor per provenance, a genuine on-premise option, and adito.de hosted by Hetzner in Germany under an Art. 28 DPA, with retention-until-deletion and anonymized IPs — but that privacy policy governs the website, not the CRM: product data residency, subprocessors and a customer-facing DPA are all marked unknown. The on-premise lever is real; the documentation of cloud exposure is not, which pins this at the 'DPA exists, exposure undocumented' anchor. 1 2
The RevOps Integrator
German vendor with an on-premise option, retention-until-deletion and anonymized IPs, and a signed Art. 28 DPA with a Germany-based host — genuine GDPR posture. But that DPA covers the marketing website; the product's own data residency, subprocessor list, and legal entity are all undocumented, so a DPO still signs with a caveat file. 1 2
The Migrator
Real EU posture: German vendor, an on-premise option, Germany-hosted servers with a signed Art. 28 DPA, retention-until-deletion and anonymized IPs. But that DPA covers the website, not the product — nothing on where the CRM's cloud data resides, no product DPA, no subprocessor list — so it sits below the 5 anchor. 1 2
The Skeptic
German provenance and an on-premise option keep this off the floor, but the only signed DPA disclosed is with Hetzner for the marketing website — it governs adito.de, not your CRM data — while entity, residency and subprocessors are all 'unknown.' The privacy policy covers the brochure; the product's own processing chain is unpublished, so a DPO gets an on-premise promise and no paperwork. 1 2
Import, export & exit
Show reasoningHide reasoning
How this is scored
Getting in with history intact, and out with everything — the anti-lock-in criterion.
0 — Import is a support ticket; export is contacts-only CSV missing notes, activities and files.
3 — Self-serve CSV import with mapping; export covers main objects but drops activity history, attachments or relations.
5 — Guided migration from major competitors, full-object CSV export, API access sufficient to rebuild the database elsewhere with effort.
8 — Complete export (all objects, history, files) self-serve in open formats, import with dedupe and dry-run, no API metering that prices exit out of reach.
10 — Exit as a feature: documented full-fidelity export, migration tooling both directions, and contractual data-return terms — leaving is a weekend, which is exactly why you can stay.
The Solo Seller
Nothing on import, export, migration, or exit terms on any captured page. When a vendor shows me no way out, I assume leaving means a support ticket and a partial CSV at best. 1
The Data Protection Officer
No import, export, migration or API-access fact exists anywhere in the captured pages. As evidenced there is no documented way out of the system at all — for a database of contacts you merely steward, that is disqualifying. 1
The Sales Ops Lead
No import tooling, export, or API is evidenced anywhere; by the rules of this exercise those capabilities do not exist. One point above the floor only because the on-premise option puts the database on infrastructure the customer controls rather than behind a vendor's export gate. 1
The RevOps Integrator
The on-premise option is the one real anti-lock-in asset here: the database can live in the customer's own infrastructure. Beyond that, no import, export, migration, or API capability is evidenced, so exit tooling is a guess, not a feature. 1
The Migrator
Zero evidence of import with dedupe, dry-run, full-fidelity export or API-based exit; nothing a clean migration needs is documented anywhere. The one exit-friendly fact is the on-premise option — at least the database sits on your own servers when you leave, which is why this isn't a zero. 1
The Skeptic
No import, export, migration or API evidence of any kind in the evidence. Exit capability is scored as absent, which is the anchor-0 'import is a support ticket' world. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the real invoice — per seat, per month, at renewal — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — An entry price exists, but the tiers most buyers need are unpriced, or per-seat maths is obscured by bundles, minimums or mandatory onboarding fees.
5 — Most tiers carry real numbers with billing period and VAT treatment stated, but at least one commonly needed capability hides in an unpriced tier or usage-metered add-on.
8 — Every tier priced publicly including annual/monthly split; limits, seat minimums and overage rules stated; only genuine enterprise contracts are custom.
10 — Complete price computability: every tier, add-on, usage meter and renewal rule public, with a calculator or table that makes the invoice at 3 and 30 seats a two-minute exercise.
The Solo Seller
Not a single public price appears anywhere — no tiers, no per-seat math, no billing period, no VAT treatment. I pay with my own card, and an invoice I can't compute from public pages is an automatic no. 1
The Data Protection Officer
No tier, price, seat count, billing period or VAT treatment appears on any captured page. A buyer cannot compute any invoice, even roughly, so the bottom anchor applies. 1
The Sales Ops Lead
No price, tier, seat minimum, billing period or VAT treatment appears in any captured page — the homepage and privacy policy together make a 40-seat invoice uncomputable from public evidence. That is exactly the bottom anchor: every tier is a sales conversation. 1
The RevOps Integrator
No tier, seat price, billing period, or add-on figure appears on any captured page; per the floor anchor, if every number requires a sales conversation, the buyer cannot compute the invoice. German enterprise software culture is no excuse for a public price of zero. 1
The Migrator
No price appears on any captured page — no tiers, no per-seat maths, no VAT treatment, no renewal terms; public pricing is unevidenced, so by this sheet it doesn't exist. Kept just above 0 because silence is marginally less damning than a confirmed quote-only regime, but a buyer cannot compute any invoice from these pages. 1
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE ⚠ unverified | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 4 Report an error |
| Subprocessors | EU only ⚠ unverified | 2/2 pts | 4 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 11 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The imprint also lists a second group entity, ADITO Consulting GmbH und Co. KG, at the same address whose description text repeats the Software GmbH wording.
- Weak sourcing — Data residency. The claim sits in Trust Center marketing copy rather than a data processing agreement, and the same page also offers an on-premise appliance as an alternative hosting model.
- Weak sourcing — Subprocessors. No complete subprocessor list is published — only the hosting provider is named; the US providers in the privacy policy (AWS, Airbrake, Braze, Calendly, Cloudflare) process marketing-website data, not product data.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (adito.de, adito.de/datenschutz, adito.de/en/terms-and-conditions.html, adito.de/crm/sicherheit-compliance.html, adito.de/impressum.html). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 20 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 11 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 hosting fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (5)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.adito.de Checked 15 Sep 2026 Details →
- 2 Privacy policy www.adito.de Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
- 3 Terms of service www.adito.de Checked 21 Sep 2026 Details →
- 4 Security / trust page www.adito.de Checked 30 Sep 2026 Details →
- 5 Imprint www.adito.de Checked 30 Sep 2026 Details →