Business Instant Messaging
Mattermost
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Mattermost, Inc. · mattermost.com
Compare with Slack → Compare with Element → Compare with Rocket.Chat → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Mattermost is a business instant messaging platform from Mattermost, Inc. aimed at defense, intelligence, security and critical infrastructure. Its strongest area is deployment & data custody: on-premises, private cloud and air-gapped deployment are named, Kubernetes at Enterprise scales to 50,000 concurrent users and Enterprise Advanced to 200,000, and the privacy policy states that with self-hosted products the customer controls processing of end-user data. Channels, threads & search sits at 6, encryption & access control at 5-6 (no end-to-end encryption or documented key handling), and retention, discovery & co-determination at 6-7, where Enterprise lists legal hold, compliance export and eDiscovery automation but no admin audit log is evidenced. The lowest counted scores are integrations (4-5; no documented REST API, webhooks or SCIM) and sovereignty, the genuine split at 1-4: three judges score 4 because self-hosting and air-gapped operation remove the vendor from the data path, while two score 2 and the skeptic 1, citing the US contracting entity, transfers to the USA, unnamed subprocessors, and optional hosted push notifications that can ship usernames, full names, channel names and message preview snippets off-premises. Pricing is quote-only and not counted.
Speaks for it
- Deploys on-premises, in private cloud and air-gapped, with air-gapped deployment an Enterprise Advanced capability that scales to 200,000 concurrent users
- With self-hosted products the customer controls the processing of end-user data, and telemetry collection can be opted out
- Enterprise tier lists data retention policy, legal hold, compliance export and eDiscovery automation
- Strong access model — SSO and MFA from Professional, granular per-channel RBAC with AD/LDAP sync, ABAC and zero-trust channel access at Advanced — on top of TLS and encryption-at-rest
- Shared channels and federation via Matrix protocol interoperability for cross-organisation rooms
Held against it
- No end-to-end encryption, device verification or documented key handling appears anywhere in the evidence
- Developer surface unevidenced: no documented REST API, webhooks, slash commands, SCIM, rate limits or sandbox
- Vendor-side sovereignty gaps: US contracting entity, unstated data residency, transfers to the USA under the DPF, subprocessors referenced only as document titles, and an optional Hosted Push Notification Service that can carry usernames, full names, channel names and message preview snippets off-premises
- No admin audit log is evidenced ('advanced logging' is not an audit trail), and nothing says compliance exports capture edits and deletions
- No public pricing: Professional is Contact Sales, Enterprise is Get Pricing, Enterprise Advanced is Request Quote
Best for
- You need collaboration that runs on-premises, in a private cloud or air-gapped inside your own perimeter, with your organisation controlling processing of end-user data
- You operate in defense, intelligence, security or critical infrastructure and need data retention policy, legal hold, compliance export and eDiscovery automation from the Enterprise tier
- Your access-control needs are deep — granular RBAC, AD/LDAP sync, ABAC and zero-trust channel access — and vendor-held keys with TLS and encryption-at-rest meet your bar
- You need cross-organisation collaboration through shared channels and Matrix protocol federation
Avoid if
- You need end-to-end encryption, device verification or documented key handling — ask the vendor: the public pages we read do not show it
- You build against a documented developer surface (REST API, webhooks, SCIM, sandbox) — the evidence evidences none
- You depend on the cloud path under strict sovereignty constraints — transfers to the USA, subprocessors referenced only as document titles, and an optional push service that can carry message preview snippets off-premises
- You need an evidenced admin audit trail, or assurance that exports capture message edits and deletions
The scores
Channels, threads & search
Show reasoningHide reasoning
How this is scored
The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.
0 — Flat group chats with no threads; search covers recent messages only, and history is capped.
3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.
5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.
8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.
10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.
The Team Lead
Channels, real threaded discussions and link and file previews are on the plan page, and the API docs show threads you can pull and move between channels — the move is marked beta, but it's the tidying-without-losing-history capability I ask for. Search is described as core search up to three million posts on Professional and enterprise search above that. I found no public information on end-user search filters by person or date, pinned or saved items, or how guest-channel boundaries are drawn, which keeps it off the upper band. 2 5 6 13
The Security Officer
Channels, real threaded discussions, file previews and search up to three million posts are documented on the plan pages, the API exposes threads with collapsed-thread views, and a beta call can move a thread to another channel. By default every deployment retains all messages, edits and deletions included, so the history itself is uncapped. We found no public information on pinned and saved items, on end-user search filters by channel, person or date, or on channel archiving and renaming that preserves history. 2 5 6 10
The Works Council Advocate
Channels and threads are real enough to have their own API endpoints and even a beta operation to move a thread to another channel, with guest accounts, file previews, and, on the Enterprise plan, shared channels and Matrix-protocol federation; edits and deletions are retained in the record by default, and search is documented at a three-million-post scale on Professional and beyond that on Enterprise. We found no public information on pinned or saved items, search filters by channel, person or date, or channel archiving and merging. 2 5 6 9 10
The Compliance Counsel
Channel-based collaboration, threaded discussions, link and file previews, guest accounts and search up to three million posts are documented, and the thread structure is exposed through the API with permissions and pagination detail. Compliance exports flag edits and deletions per message, which tells me the history beneath the surface stays intact. We found no public information on pinned and saved items, on end-user search filters by channel, person or date, or on channel lifecycle such as archive and rename without losing history. 2 6 9
The Platform Engineer
Channel-based collaboration, real threaded discussions with a documented thread API and per-endpoint permissions, file sharing with link and file previews, and search documented up to 3 million posts — and the default retains every message including edits and deletes, so no history cap bites. I found no public information on pinned or saved items or search filtered by channel, person and date, and moving a thread to another channel is flagged as beta subject to change, so I stop just above the solid baseline. 2 5 6 10
The Skeptic
Channels, real threads and a documented thread API are evidenced, and at least the search cap is printed rather than hidden: core search up to three million posts on Professional, enterprise search beyond three million on Enterprise. I found no public information on pinned or saved items, mentions and reactions, or search filters by channel, person and date, and the thread-move endpoint is flagged as beta. Default behaviour retains every message including edits and deletes plus all files, so the history itself appears uncapped. 2 5 6 10
Encryption & access control
Show reasoningHide reasoning
How this is scored
What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.
0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.
3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.
5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.
8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.
10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.
The Team Lead
Transport and at-rest encryption are documented down to the mechanics — TLS with named ciphers, disk-level encryption via LUKS, BitLocker or TDE, S3-managed keys — and access control runs from granular role-based permissions and AD/LDAP sync up to attribute-based zero-trust channel access. The deployment guide states plainly that it does not encrypt within the database so that search and compliance reporting keep working, which is the honest statement I want from a vendor. We found no public information on end-to-end encryption, device verification or admin-revocable sessions, so it sits mid-band. 2 7 8
The Security Officer
Transport is TLS throughout, encryption at rest is infrastructure-level — LUKS, BitLocker, TDE, S3-managed keys — and granular roles, SSO, MFA and attribute-based channel access are all documented. The plain statement I prize is there, in an unwelcome direction: the deployment guide says encryption within the database is not offered, precisely so end-user search and compliance reporting can work, which tells me the server and whoever operates it reads everything. We found no public information on end-to-end encryption, device verification, or sessions an administrator can revoke. 2 4 7 8
The Works Council Advocate
Transport and at-rest mechanisms are documented concretely — TLS with AES-256 and 2048-bit RSA, disk-level encryption on infrastructure the customer runs, S3 with S3-managed keys, and cluster traffic encrypted with AES-256 — and the deployment guide says plainly that the database is not encrypted at the application layer so that search and compliance reporting keep working, which is the kind of honesty I want more of. Granular role-based access, AD/LDAP sync, SSO, guest accounts and zero-trust channel access are evidenced; we found no public information on end-to-end encryption of message content, device verification, or sessions an administrator can revoke. 2 4 7 8
The Compliance Counsel
TLS with named ciphers, encryption-at-rest through customer-side disk and database methods, granular role-based access controls, SSO with SAML assertion encryption and attribute-based zero-trust channel access at the top tier are all documented. The vendor states plainly that the database itself holds no encryption so that search and compliance reporting work — candour I value, though it confirms the server sees plaintext. We found no public information on end-to-end encryption, device verification, or session management an administrator can revoke. 2 7 8
The Platform Engineer
Transport TLS with named ciphers, at-rest encryption via disk or storage-level methods within your own infrastructure, granular role-based access with AD/LDAP sync, SSO and MFA are all documented, and the pages state plainly that the database itself is unencrypted so search and compliance reporting work — plus exactly what the optional hosted push service sees. I found no public information on end-to-end encryption, device verification, or admin-revocable session management, which is what separates the operator-reads-everything mode from the top anchors. 2 4 7
The Skeptic
The sentence I hunt for exists here: the database holds messages unencrypted specifically so search and compliance reporting of history work, which means TLS in transit and disk-level encryption at rest — no end-to-end encryption claim appears on the captured pages. Single sign-on and multifactor authentication sit on Professional, granular role-based and attribute-based controls on Enterprise, so the tier map is visible. I found no public information on device verification or session management an administrator can revoke. 2 7 8
Retention, discovery & co-determination
Show reasoningHide reasoning
How this is scored
The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.
0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.
3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.
5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.
8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.
10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.
The Team Lead
The compliance export machinery is genuinely deep — CSV, Actiance XML, Global Relay EML and Proofpoint formats, daily scheduled jobs, filters by date, user and keyword, and messages tracked by identifier as they are edited or deleted across export batches — with legal hold and eDiscovery automation named on the Enterprise plans. Default retention keeps all messages including edits and deletes, with customisable retention depending on plan. Playbooks and Boards are excluded from compliance export, and we found no public information on a full administrative audit trail or an organisation-wide switch for activity analytics. 2 4 9 10
The Security Officer
Legal hold, eDiscovery automation and exports in CSV, Actiance XML, Global Relay EML and Proofpoint formats are documented, carrying edits, deletions, file uploads and channel member history, with messages trackable by identifier across batches and query and download actions logged in an audit history. Retention is retain-everything by default with plan-dependent customisation, jobs report success with counts, and past history can be exported by timestamp from the command line. Two honest gaps: Playbooks and Boards content sits outside the compliance export, and we found no public information on per-channel retention granularity, a full administrative audit trail, or switching off activity analytics organisation-wide. 2 4 9 10
The Works Council Advocate
Compliance export runs in formats a lawyer already uses — Global Relay EML, Actiance XML, Proofpoint — tracking each message by ID through edits and deletions, with job status visible and every query and download action logged in an audit history explicitly to prevent unauthorised queries; that last part is the co-determination instinct done right. Data Retention Policy and Legal Hold are named at the Enterprise tier and self-hosted telemetry can be opted out; but the default retains everything including deletions rather than deleting, and we found no public information on presence a person can control or on activity analytics and whether they can be switched off organisation-wide. 2 4 9 10
The Compliance Counsel
The compliance export is the real thing: CSV, Actiance XML, Global Relay EML and Proofpoint formats, edits and deletions flagged per message, message tracking across export batches, channel member history, past-history export from a timestamp, and query and download actions logged in an audit history. Legal hold and eDiscovery automation are named on the Enterprise plan, and the default is to retain everything including edits and deletes. Two reservations hold this back: Playbooks and Boards content is documented as excluded from compliance export, so decisions that migrate there escape the subpoena, and we found no public information on per-channel retention granularity or organisation-wide switching of activity analytics. 2 4 9 10
The Platform Engineer
Legal hold and eDiscovery automation are named plan features, and the compliance export documentation is the real thing: CSV, Actiance XML, Global Relay EML and Proofpoint formats, edit and deletion tracking by message identifier across export batches, configurable daily jobs with visible job status, and an audit history of every compliance query and download. I found no public information on organisation-wide switching of activity analytics or user-controlled presence, and Playbooks and Boards sit outside the compliance export — the captured pages stop me short of the works-agreement grade. 2 4 9 10
The Skeptic
The discovery machinery is unusually concrete: compliance exports in CSV, Actiance XML, Global Relay EML and Proofpoint formats, edits and deletions tracked by message ID, channel member history included, past history exportable by command line, and every query and download logged in an audit history — with Playbooks and Boards explicitly excluded, which I respect being told. Legal hold and data retention policy appear as feature names on Enterprise without documented mechanism, and the audit trail I can see covers compliance queries rather than all administrative actions. I found no public information on activity analytics being switchable off organisation-wide. 2 4 9 10
Deployment & data custody
Show reasoningHide reasoning
How this is scored
Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.
0 — Cloud-only, proprietary, with export limited to a partial archive.
3 — Cloud-only, but with a documented full export in an open-ish format.
5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.
8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.
10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.
The Team Lead
This is where they are strongest: the same server installs via Kubernetes, Linux or containers, a documented air-gap runbook with registry mirroring covers every edition down to Team Edition, and FIPS-compliant, STIG-hardened images are published. The privacy policy says the self-hosting customer controls the processing of end-user data, telemetry is opt-out, and Matrix-protocol federation is named on the Enterprise plan. I held back from the top only because the captured pages show compliance-format exports rather than a documented full workspace export and import for migration. 2 3 4 11 12
The Security Officer
Custody is genuinely on the table: three deployment methods install the same server, high availability is self-managed, and an air-gap runbook with bill of materials and registry mirroring covers every edition from Team Edition upward, with FIPS-compliant, STIG-hardened images published. Export covers past history, files and member history into my own filestore, and Matrix protocol interoperability is named for federation. The door itself is the remaining question: we found no public information on the source licence terms behind the Team Edition or a documented migration path for bringing a legacy archive in. 2 9 11 12 13
The Works Council Advocate
Custody really can be the customer's: the same server installs via Kubernetes, Linux or containers, an air-gapped runbook with a bill of materials and registry mirroring is published, FIPS-compliant STIG-hardened images exist, and the customer stands up the database, file storage and TLS themselves — with Matrix-protocol federation and Slack-compatible webhooks giving paths in and past message history exportable via a command-line tool. The compliance export excludes Playbooks and Boards data, and we found no public information on a complete single-format export of an entire workspace. 2 9 11 12
The Compliance Counsel
Custody can be entirely the customer's: the same server installs via Kubernetes, Linux or containers, high availability is self-managed, FIPS-compliant STIG-hardened images are published, and the air-gap documentation includes a runbook, bill of materials and registry mirroring. The privacy policy states that with self-hosted products the customer controls the processing of end user data, and federation via Matrix protocol interoperability is named on the Enterprise plan. We found no public information on a documented migration path in and out, and the source availability of the server is not confirmed on the captured pages. 2 4 11 12
The Platform Engineer
This is a supported deployment, not a hobby build: Kubernetes, Linux and container paths install the same server, high availability is available self-managed, a FIPS-compliant STIG-hardened image of every container is published, and the air-gap runbook goes down to a bill of materials and private registry mirroring. Federation via Matrix protocol interoperability and a command-line past-history export with a from-timestamp option put custody genuinely with the customer; I found no public information on migration-in tooling or deeper federation detail. 1 2 9 11 12
The Skeptic
Self-hosting is documented as a first-class path: Kubernetes, Linux and container methods install the same server, an air-gapped runbook with registry mirroring is published, FIPS-compliant STIG-hardened images exist, and the privacy policy states the customer controls processing of end-user data on self-hosted products. Federation via Matrix protocol interoperability is listed at Enterprise tier. The captured pages do not state a licence or source-availability model for the server, so I score the deployment paths rather than assume an open-source core. 2 4 11 12
Integrations & extensibility
Show reasoningHide reasoning
How this is scored
Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.
0 — No API, no webhooks, no bots.
3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.
5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.
8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.
10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.
The Team Lead
There's a documented REST API with bearer auth and per-endpoint permissions, incoming and outgoing webhooks on every plan including the free Entry level, Slack webhook format compatibility for migration, interactive dialogs and Blocks for structured posts, and administrators can enforce webhook channel locking. GitLab notifications land through the standard webhook path, which is the busy-Tuesday test. We found no public information on slash commands, SCIM provisioning, documented rate limits or a sandbox, so it stops short of a full platform story. 2 6 13 14
The Security Officer
A documented REST API with bearer authentication and per-channel permission checks, incoming and outgoing webhooks on every plan, Slack-format compatibility, interactive Blocks with buttons and menus, interactive dialogs and administrator-enforced webhook channel locking make a real integration surface, and a Model Context Protocol connector is named at the Enterprise tier. The admin control over which channels a webhook may post to is exactly the kind of boundary I want to see. We found no public information on SCIM provisioning, event subscriptions with retries, documented rate limits, a sandbox, or an app directory with permissions a customer can audit. 2 6 13 14
The Works Council Advocate
A versioned REST API documented endpoint by endpoint with its permission requirements, incoming and outgoing webhooks available on every plan including the entry edition, Slack-compatible webhook payloads, interactive dialogs and Mattermost Blocks, plus admin-enforced channel locking for webhooks — a control I am glad to see. We found no public information on an app directory, SCIM provisioning, documented rate limits, or an event-subscription model with retries. 2 5 6 13 14
The Compliance Counsel
A documented REST API with bearer authentication and per-endpoint permission detail, incoming and outgoing webhooks with Slack-format compatibility, interactive components via blocks and dialogs, and SSO with AD/LDAP sync are all evidenced. Administrators can enforce channel locking on webhooks and enable webhook debugging, and posts from plugins and bots appear in the compliance record, so automations stay capturable. We found no public information on SCIM provisioning, documented rate limits, event subscriptions with retries, or an app directory. 2 6 13 14
The Platform Engineer
A versioned REST API with bearer authentication and permission requirements documented per endpoint, incoming and outgoing webhooks that are Slack-compatible for migration, interactive blocks and dialogs for structured interaction, and admin-enforced channel locking on webhooks — real permission controls where the pages speak. I found no public information on SCIM provisioning, documented rate limits, event subscriptions with retries, a sandbox, or a plugin framework whose permissions a customer can audit, which is what my upgrade path depends on. 2 6 13 14
The Skeptic
A versioned REST API with bearer authentication, incoming and outgoing webhooks with Slack-compatible payloads, interactive dialogs and structured interactive blocks, plus single sign-on — a solid middle of this scale. I found no public information on slash commands, SCIM provisioning, documented rate limits, an app directory or a sandbox. Bot posts are acknowledged in compliance export contents, but no bot account model is documented on the captured pages. 2 6 13 14
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.
The Team Lead
The contracting entity is Mattermost, Inc. in California, transfers to the United States are disclosed in the privacy policy, and the captured pages give no official subprocessor list for the vendor-managed cloud — Azure and AWS appear only as customer-chosen hosting. What rescues a European deployment is custody: self-hosting with a telemetry opt-out and customer control of end-user data, plus fully documented air-gap operation. We found no public information on EU data residency being offered, so this stays near the bottom for anyone buying the vendor's cloud. 3 4 12
The Security Officer
The contracting entity is Mattermost, Inc. of Palo Alto; we found no public information confirming EU data residency, and the captured security page names Azure and AWS as cloud options for US-headquartered providers without listing the subprocessors of the vendor-managed cloud. Transfers to the United States are disclosed with Data Privacy Framework certification, Standard Contractual Clauses and a TRUSTe referral path, and self-hosting with customer-controlled processing is the real mitigation — but even there, hosted push notifications can carry usernames, channel names and message preview snippets to the vendor unless the customer keeps that service off. For a European buyer this is a US chain with an escape hatch, not a sovereign one. 3 4 11 12
The Works Council Advocate
The captured pages show a United States vendor relying on the EU–U.S. Data Privacy Framework and Standard Contractual Clauses, personal information transferred to the United States, Google Analytics on the sites, Azure and AWS named as cloud hosting for US-headquartered providers, and no published list of the subprocessors behind the vendor-managed cloud. The documented air-gapped, self-hosted path with telemetry opt-out is what removes the question in practice for a European deployment, but the contracting entity sits outside the EU and we found no public information on EU hosting or an EU entity. 3 4 12
The Compliance Counsel
The contracting entity is Mattermost, Inc., a US company relying on the Data Privacy Framework and Standard Contractual Clauses, with transfers to the United States named, a US-based premier support tier on offer, and Google Analytics on the vendor's sites; we found no public information on EU data residency, an EU contracting entity, or a published subprocessor list for the vendor-managed cloud. The self-hosted and air-gapped options put the archive itself in the customer's hands, which is the only reason this clears the floor. Hosted push notifications and self-hosted telemetry are opt-out, so the European buyer must configure rather than assume. 2 3 4 12
The Platform Engineer
The contracting entity is Mattermost, Inc., the privacy framework is built around US transfer mechanisms with US-based premier support on offer, and I found no public information on EU data residency or a published subprocessor list for the vendor-managed offering. What saves it for me is the self-hosted path, documented as customer-controlled processing, with air-gap operation and telemetry that can be opted out — run it that way and the question mostly disappears, but that is my work, not the vendor's chain. 2 4 12
The Skeptic
The contracting entity is Mattermost, Inc. in the United States, transfers to the USA are disclosed, and reliance is on the EU-U.S. Data Privacy Framework and Standard Contractual Clauses; the captured pages give no hosting location and no published subprocessor list for the vendor-managed cloud, while Azure and AWS appear as cloud options for US-headquartered providers. What lifts this off the floor is documented self-hosting where the customer controls the data and telemetry can be opted out — custody can move to the customer, but the vendor chain remains American and its footprint remains unstated. 2 3 4
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.
5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.
8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.
10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.
The Team Lead
Every named plan — Professional, Enterprise, Enterprise Advanced — routes through "Contact Sales", "Get Pricing" or "Request Quote", and no per-user figure appears anywhere in the captured pages. A free limited-use Enterprise Advanced edition exists for evaluation and FAQs cover how licences are sold and seat overage, but the compliance and eDiscovery capabilities a buyer needs sit in the sales-conversation tiers. I cannot compute an annual invoice for my headcount from anything published here. 2 10 11
The Security Officer
The captured pricing pages route every named plan to a human — Professional says "Contact Sales", Enterprise says "Get Pricing", Enterprise Advanced says "Request Quote" — and no per-user figure, billing period or VAT treatment appears anywhere. A free limited-use edition of Enterprise Advanced exists for technical evaluation, while compliance monitoring sits in the quote-only tiers. I cannot compute an annual invoice for any headcount from these pages. 2 10 12
The Works Council Advocate
The captured pricing page routes every named plan to a sales conversation — Professional to "Contact Sales", Enterprise to "Get Pricing", Enterprise Advanced to "Request Quote" — and we found no public per-user price for any tier anywhere in the captures. A limited-use free edition of Enterprise Advanced is offered for technical evaluation, but no buyer can compute an annual invoice from these pages. 2
The Compliance Counsel
Every plan routes to Contact Sales, Get Pricing or Request Quote, and we found no public per-user price, billing period, VAT treatment or minimum term; only a free limited-use evaluation edition is public. The compliance monitoring and export features a regulated buyer needs sit on the Enterprise and Enterprise Advanced tiers, both unpriced. A buyer cannot compute an annual invoice for any headcount from these pages. 2 10
The Platform Engineer
Every plan ends in a sales conversation — Professional says Contact Sales, Enterprise says Get Pricing, Enterprise Advanced says Request Quote — and I found no public information on any per-user price, so an annual invoice cannot be computed from the pricing page. Credit for a free evaluation edition and unusually clear feature-to-plan boundaries, but the money is entirely opaque. 2
The Skeptic
Every tier routes to sales — Professional says Contact Sales, Enterprise says Get Pricing, Enterprise Advanced says Request Quote — and no per-user figure appears anywhere on the captured pricing pages. Credit for labelled tier boundaries: single sign-on at Professional, compliance export and retention policy from Enterprise, Professional support capped at 250 users, plus a free limited-use evaluation edition. No annual invoice is computable from the public pages, whatever the headcount. 2
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined | — | uncited Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Subprocessors. Azure and AWS are named as customer-selected cloud hosting options for US-headquartered providers; page does not list the official subprocessors for the vendor-managed cloud offering.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 12 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 legal fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
Sources (14)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage mattermost.com Checked 15 Sep 2026 Details →
- 2 Pricing mattermost.com Checked 15 Sep 2026 Details →
- 3 Security page mattermost.com Checked 15 Sep 2026 Details →
- 4 Privacy policy mattermost.com Checked 15 Sep 2026 Details →
- 5 Channels, threads & search — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 6 Channels, threads & search — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 7 Encryption & access control — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 8 Encryption & access control — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 9 Retention, discovery & co-determination — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 10 Retention, discovery & co-determination — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 11 Deployment & data custody — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 12 Deployment & data custody — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 13 Integrations & extensibility — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
- 14 Integrations & extensibility — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →