whats-best.ai

Business Instant Messaging

Flock

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Flock · flock.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Flock is a business instant messaging product judged from one captured vendor page, and the verdict tracks the evidence. Integrations are the clear strength, scored 4 with no spread: the FlockOS platform with Browse Apps and Build Apps, an app store, offered API documentation, and a CRM integration that notifies on qualified leads. Core messaging scored a flat 2 — channels, real-time file sharing, and shared notes and to-dos are shown — while we found no public information on threading, search or history limits. Every custody-oriented criterion sits low: encryption and access, governance and discovery, deployment control and sovereignty each scored 0-1, with no public information on encryption mechanisms, retention, export, audit logs, self-hosting, hosting location or subprocessors; no sovereignty attributes are on record, and the only contracting entity named is Titan Solution Ltd SEZC. The one-point spreads reflect strictness, not fact disputes — the security officer alone put encryption and access at 0 — and the flagged split check lists none. Pricing appears only as a 30-day free trial.

Report an error

Speaks for it

  • Integrations scored 4 with no spread, on the FlockOS platform with Browse Apps and Build Apps, an app store, offered API documentation, and CRM lead notifications
  • Channels, real-time file sharing, and shared notes, to-dos and reminders are evidenced
  • Apps are listed for Windows PC, Mac, Linux and Chrome, with built-in video and voice calling and screen sharing from any device
  • A 30-day free trial, personalized onboarding in 10 days, and 24/7 dedicated customer support are published

Report an error

Held against it

  • We found no public information on encryption mechanisms, key handling, SSO or guest scoping, with encryption and access scored 0-1
  • We found no public information on retention policies, export in a documented format, legal hold or audit logs, with governance and discovery scored 0-1
  • We found no public information on self-hosting, a private-cloud or dedicated-instance option, or a documented exit export, with deployment control scored 0-1
  • No sovereignty attributes are on record, with hosting location and subprocessors unstated and Titan Solution Ltd SEZC the only contracting entity named
  • We found no public information on threading, mentions, search across history or any history limit, with messaging core scoring a flat 2

Report an error

Best for

  • You want a channel-based messenger you can extend in-house, with an app store, offered API documentation and a build-your-own-apps path on FlockOS
  • Your sales team wants notifications in chat when a new lead gets qualified via a CRM connection
  • You need clients on Windows PC, Mac, Linux and Chrome with built-in video and voice calling across all devices
  • You want to start with the 30-day free trial and personalized onboarding in 10 days

Report an error

Avoid if

  • You must show a regulator or works council documented retention, export and audit-log controls before rollout — governance and discovery scored 0-1 and we found no public information to inspect
  • You need EU custody or a subprocessor chain you can vet — ask the vendor: the public pages we read do not show it
  • You need self-hosting or a documented exit path that takes the archive with you — deployment control scored 0-1
  • You need documented encryption and access mechanisms for a security review — encryption and access scored 0-1

Report an error

The scores

Channels, threads & search

Show reasoning
How this is scored

The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.

0 — Flat group chats with no threads; search covers recent messages only, and history is capped.

3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.

5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.

8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.

10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.

Report an error

The Team Lead

Channels and real-time file sharing are shown, which is a start, but that is where the evidence stops. I found no public information on threading, mentions, search across history, or any history limit, so nothing here evidences the readable threads or the find-last-spring's-decision search my team actually lives in. 1

Report an error

The Security Officer

Channels and real-time file sharing are the only conversation mechanics actually evidenced; we found no public information on threading, mentions, reactions, or whether search exists at all, let alone whether it can find a decision made eighteen months ago. For an archive meant to be a knowledge base, silence on search and history limits is decisive. 1

Report an error

The Works Council Advocate

Channels and real-time file sharing are the only pieces of the daily surface the captured page evidences; we found no public information on threads, mentions, reactions, or search of any kind, let alone whether search can find a decision made eighteen months ago. For an archive that must stay a working record, that silence is decisive. 1

Report an error

The Compliance Counsel

The captured page confirms channels and real-time file sharing, and that is where the evidence ends: I found no public information on threading, search coverage, history limits, message editing, or export of a conversation a human could read. Channels alone are not enough to call this a surface where an eighteen-month-old decision can be found and produced. 1

Report an error

The Platform Engineer

Channels are the organising model and real-time file sharing plus shared notes and to-dos are shown, but I found no public information on threading, search across the whole history, or any history limit. A channel-and-attachments surface with the archive capabilities wholly unevidenced is a thin daily tool. 1

Report an error

The Skeptic

Channels and secure real-time file sharing are the only conversation mechanics the captured page names, and we found no public information on threading, mentions, search, or any message-history limit — so I cannot credit even the basic-search level, let alone filters or a working archive. Scored between the lowest levels: channels are real, everything that makes a chat usable over eighteen months is unevidenced. 1

Report an error

Encryption & access control

Show reasoning
How this is scored

What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.

0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.

3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.

5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.

8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.

10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.

Report an error

The Team Lead

The only security evidence is a marketing phrase about "best-in-class admin features" for data security and privacy. Judged on documented mechanism, I found no public information on transport or at-rest encryption, key handling, per-channel roles, SSO, or guest scoping. 1

Report an error

The Security Officer

The captured page promises "best-in-class admin features" and "secure" file sharing, but we found no public information on the encryption mechanism, key custody, device verification, sessions an administrator can revoke, or any statement of what the vendor can and cannot decrypt. Judged on documented mechanism, as this must be, the page offers only adjectives. 1

Report an error

The Works Council Advocate

The page promises best-in-class admin features and secure file sharing, but we found no public information on what is actually encrypted, who holds the keys, how guests are scoped, or how sessions can be revoked. A promise of safety is not a documented mechanism, and none is shown. 1

Report an error

The Compliance Counsel

The only statements are marketing-level — best-in-class admin features and secure file sharing — and I found no public information on encryption in transit or at rest, key handling, per-channel roles, guest scoping, SSO, or what the vendor can read. An undocumented mechanism is a risk I cannot underwrite in a written opinion. 1

Report an error

The Platform Engineer

Security appears only as marketing language — best-in-class admin features and secure file sharing — and we found no public information on encryption at rest or in transit, SSO, guest scoping, or what the vendor can read. Judged on documented mechanism, there is nothing here to inspect. 1

Report an error

The Skeptic

The only security language is marketing — 'best-in-class admin features' and the word 'secure' on file sharing — and we found no public information on transport or at-rest encryption, key handling, per-channel roles, SSO, or guest access. An undifferentiated claim of safety is worth almost nothing against descriptions that name mechanisms. 1

Report an error

Retention, discovery & co-determination

Show reasoning
How this is scored

The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.

0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.

3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.

5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.

8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.

10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.

Report an error

The Team Lead

The archive as a legal object is invisible on the captured pages: I found no public information on retention policies, admin export, audit logs, legal hold, or any control over activity analytics. A works council would have nothing to review, and the vague admin-features claim cannot stand in for any of it. 1

Report an error

The Security Officer

We found no public information on retention policies, export in a documented format, an audit log, or any control over presence and analytics; the only governance signal is a generic promise of admin features for data security and privacy. An archive whose retention and export story is unpublished cannot be handed to a works council or a subpoena on equal terms. 1

Report an error

The Works Council Advocate

We found no public information on retention policy, export for discovery, an audit log, or any presence and activity analytics and whether they can be switched off. None of the machinery a works agreement must be able to inspect is on show, so this sits at the floor by the published standard for absence. 1

Report an error

The Compliance Counsel

Nothing on the record speaks to the archive as a legal object: I found no public information on retention policies, per-channel or global, legal hold, export in a documented format, an audit log of administrative actions, or any ability to switch off presence and activity analytics. An unevidenced archive is scored as an absent one, because on the day a subpoena arrives I will be the one explaining it. 1

Report an error

The Platform Engineer

We found no public information on retention policies, export for discovery, audit logging, or any admin control over presence and activity analytics; the only adjacent claim is admin features for data security and privacy, which names no mechanism. An archive that cannot be evidenced is not yet a legal object. 1

Report an error

The Skeptic

We found no public information on retention configuration, admin export in any format, an audit log, or whether presence and activity analytics can be disabled. The single generic claim about admin features for data security evidences none of the archive-as-legal-object capabilities this buyer needs. 1

Report an error

Deployment & data custody

Show reasoning
How this is scored

Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.

0 — Cloud-only, proprietary, with export limited to a partial archive.

3 — Cloud-only, but with a documented full export in an open-ish format.

5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.

8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.

10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.

Report an error

The Team Lead

Clients for Windows PC, Mac, Linux and Chrome are listed, but those are apps, not custody of the archive. I found no public information on self-hosting, a private-cloud option, an open-source server, or a documented export, so an exit path is not evidenced. 1

Report an error

The Security Officer

The listed platforms are desktop and browser clients, not deployment choices: we found no public information on self-hosting, a dedicated or private instance, an open-source core, or a documented exit with full export. On this evidence the customer has no documented way to hold their own archive. 1

Report an error

The Works Council Advocate

Desktop clients are listed, but we found no public information on self-hosting, a private-cloud option, open source, or an exit that takes the whole archive with it. Custody of the record is the vendor's on everything shown, and that is where the evidence leaves it. 1

Report an error

The Compliance Counsel

I found no public information on self-hosting, a private-cloud or dedicated-instance option, open-source code, federation, or a documented full export including files and metadata. With no exit path described anywhere in the capture, custody of the archive rests entirely with the vendor on terms the buyer cannot see. 1

Report an error

The Platform Engineer

The captured page lists apps for Windows, Mac, Linux and Chrome — clients, not servers — and we found no public information on self-hosting, open source, federation, or a documented export path. Whether an exit from this service is supported in any way is simply unanswered. 1

Report an error

The Skeptic

The page presents a cloud product with desktop and browser apps, and we found no public information on self-hosting, a private-cloud or dedicated-instance option, open-source code, or any documented export path. Custody alternatives and an exit story are entirely unevidenced. 1

Report an error

Integrations & extensibility

Show reasoning
How this is scored

Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.

0 — No API, no webhooks, no bots.

3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.

5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.

8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.

10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.

Report an error

The Team Lead

There is a genuine platform signal here: API documentation is offered, an app store connects daily-use apps, FlockOS lets customers browse and build apps, and a CRM integration pushes qualified-lead notifications into chat. I found no public information on webhooks, slash commands, bot accounts, SCIM provisioning, rate limits or a sandbox, which keeps it a mid-level offering rather than a full app framework. 1

Report an error

The Security Officer

An app store, a build-your-own-apps platform with published API documentation, and a CRM integration with lead notifications are genuinely evidenced, which lifts this above a static list of native connectors. We found no public information on webhooks, SSO, a bot account model or documented rate limits, so it stays short of a fully documented developer platform. 1

Report an error

The Works Council Advocate

This is the one area with substance: an app store, a build-your-own-apps platform on FlockOS, offered API documentation, and a CRM integration that notifies on qualified leads. We found no public information on webhooks, bot accounts, SSO, or documented rate limits, which keeps it between the basic and the full platform marks. 1

Report an error

The Compliance Counsel

The page evidences a documented API, an app store for daily-use applications, a build-your-own-apps platform, and a CRM notification integration — more than a bare webhook list. I found no public information on webhooks, slash commands, a bot account model, SSO or provisioning, documented rate limits, or app permissions a customer could audit, which keeps it short of a fully documented API baseline. 1

Report an error

The Platform Engineer

This is the strongest showing on the page: API documentation is offered, an app store connects daily-use apps, CRM lead notifications are demonstrated, and the FlockOS platform supports both browsing and building apps. We found no public information on webhooks, bot permissions, rate limits, SCIM provisioning or a sandbox — the line between an app directory and a real platform. 1

Report an error

The Skeptic

A genuine developer surface is on display — the FlockOS platform with an app store, a Build Apps path, offered API documentation, and CRM lead notifications — which goes beyond a handful of native integrations. But we found no public information on webhooks, bot accounts, slash commands, SSO, or documented rate limits and sandboxing, which keeps it short of the fuller platform descriptions. 1

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.

Report an error

The Team Lead

The only legal entity named is Titan Solution Ltd SEZC, and no sovereignty attributes are on record; I found no public information on hosting location, EU residency for messages or metadata, or any subprocessor. For a buyer weighing European custody, nothing on the captured pages evidences it. 1

Report an error

The Security Officer

The captured page names Titan Solution Ltd SEZC as the contracting entity with nothing on it indicating a European footing, and the sovereignty attributes on record are empty: we found no public information on hosting location, subprocessors, or certification. Where the archive and its metadata are processed is entirely unpublished. 1

Report an error

The Works Council Advocate

The sovereignty pipeline has nothing on record: we found no public information on where the archive and its metadata are hosted, which subprocessors touch them, or any residency commitment. The only contracting entity named is Titan Solution Ltd SEZC, and no EU hosting, certification or safeguard appears in the capture. 1

Report an error

The Compliance Counsel

No sovereignty attributes are on record: hosting location, data-residency commitments, and the subprocessor chain are all unstated, and the only published contracting entity is Titan Solution Ltd SEZC — I found no public information on any European entity, residency option, or safeguard for non-EU processing. An unnamed chain is an unmanaged chain, and I cannot map it to a regulator's questionnaire. 1

Report an error

The Platform Engineer

The contracting entity is Titan Solution Ltd SEZC and no sovereignty attributes are on record — hosting is unstated and no subprocessors are named. We found no public information placing the archive, its metadata, or any certification inside the EU. 1

Report an error

The Skeptic

The contracting entity is Titan Solution Ltd SEZC, outside the EU; hosting location is unstated and we found no public information on subprocessors, data residency, or any European processing at all. The sovereignty record is empty in both directions — nothing European evidenced, nothing named that a buyer could vet. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.

5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.

8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.

10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.

Report an error

The Team Lead

The only pricing fact captured is a 30-day free trial. I found no public information on per-user prices, tier boundaries, billing period, VAT treatment, or where retention and compliance capabilities begin, so an annual invoice for a given headcount cannot be derived from public pages. 1

Report an error

The Security Officer

A 30-day free trial is the only pricing-adjacent statement captured; we found no public information on per-user prices, tier boundaries for history or compliance features, billing period, or VAT treatment. A buyer cannot compute any part of the annual invoice from what is published. 1

Report an error

The Works Council Advocate

A 30-day free trial is the only pricing fact published; we found no public information on per-user prices, tiers, billing period, or where retention and admin controls would sit. No annual invoice can be worked out from the captured pages for any headcount. 1

Report an error

The Compliance Counsel

The only pricing fact in the capture is a 30-day free trial; I found no public information on per-user prices, tier boundaries, billing period, VAT treatment, or where retention control, SSO, or compliance export would begin. A buyer cannot compute any invoice for any headcount from this page. 1

Report an error

The Platform Engineer

The only public pricing fact is a 30-day free trial; we found no public information on per-user prices, tier boundaries, billing period, or where retention and compliance features begin. No annual invoice is computable from this page. 1

Report an error

The Skeptic

Only a 30-day free trial and 24/7 dedicated support are public, and we found no public per-user price, tier structure, billing period, or VAT treatment anywhere in the captured material. A buyer cannot compute any part of an annual invoice from what has been published, and where SSO or retention features might begin is equally unstated. 1

Report an error

European sovereignty — proven facts

0 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (5)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page flock.com Checked 29 Sep 2026 Details →
  2. 2 Channels, threads & search — found from sitemap www.flock.com Checked 1 Oct 2026 Details →
  3. 3 Encryption & access control — found from sitemap www.flock.com Checked 1 Oct 2026 Details →
  4. 4 Encryption & access control — found from sitemap www.flock.com Checked 1 Oct 2026 Details →
  5. 5 Integrations & extensibility — found from sitemap www.flock.com Checked 1 Oct 2026 Details →