whats-best.ai

Business Instant Messaging

Mattermost

Rest of world Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Mattermost, Inc. · mattermost.com

Compare with Slack → Compare with Element → Compare with Rocket.Chat → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The Compliance Counsel

Weighted verdict

Will one day have to produce this archive, edits and deletions included, to a regulator or a court. Wants legal hold, an export a lawyer can work from, retention per channel, and an audit trail that survives the admin who made the change.

Same scores as the panel view — this lens weights them the way this judge cares.

Scored by The Compliance Counsel

Channels, threads & search

How this is scored

The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.

0 — Flat group chats with no threads; search covers recent messages only, and history is capped.

3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.

5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.

8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.

10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.

Report an error

The Compliance Counsel

Channel-based collaboration, threaded discussions, link and file previews, guest accounts and search up to three million posts are documented, and the thread structure is exposed through the API with permissions and pagination detail. Compliance exports flag edits and deletions per message, which tells me the history beneath the surface stays intact. We found no public information on pinned and saved items, on end-user search filters by channel, person or date, or on channel lifecycle such as archive and rename without losing history. 2 6 9

Report an error

Encryption & access control

How this is scored

What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.

0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.

3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.

5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.

8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.

10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.

Report an error

The Compliance Counsel

TLS with named ciphers, encryption-at-rest through customer-side disk and database methods, granular role-based access controls, SSO with SAML assertion encryption and attribute-based zero-trust channel access at the top tier are all documented. The vendor states plainly that the database itself holds no encryption so that search and compliance reporting work — candour I value, though it confirms the server sees plaintext. We found no public information on end-to-end encryption, device verification, or session management an administrator can revoke. 2 7 8

Report an error

Retention, discovery & co-determination

How this is scored

The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.

0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.

3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.

5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.

8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.

10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.

Report an error

The Compliance Counsel

The compliance export is the real thing: CSV, Actiance XML, Global Relay EML and Proofpoint formats, edits and deletions flagged per message, message tracking across export batches, channel member history, past-history export from a timestamp, and query and download actions logged in an audit history. Legal hold and eDiscovery automation are named on the Enterprise plan, and the default is to retain everything including edits and deletes. Two reservations hold this back: Playbooks and Boards content is documented as excluded from compliance export, so decisions that migrate there escape the subpoena, and we found no public information on per-channel retention granularity or organisation-wide switching of activity analytics. 2 4 9 10

Report an error

Deployment & data custody

How this is scored

Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.

0 — Cloud-only, proprietary, with export limited to a partial archive.

3 — Cloud-only, but with a documented full export in an open-ish format.

5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.

8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.

10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.

Report an error

The Compliance Counsel

Custody can be entirely the customer's: the same server installs via Kubernetes, Linux or containers, high availability is self-managed, FIPS-compliant STIG-hardened images are published, and the air-gap documentation includes a runbook, bill of materials and registry mirroring. The privacy policy states that with self-hosted products the customer controls the processing of end user data, and federation via Matrix protocol interoperability is named on the Enterprise plan. We found no public information on a documented migration path in and out, and the source availability of the server is not confirmed on the captured pages. 2 4 11 12

Report an error

Integrations & extensibility

How this is scored

Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.

0 — No API, no webhooks, no bots.

3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.

5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.

8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.

10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.

Report an error

The Compliance Counsel

A documented REST API with bearer authentication and per-endpoint permission detail, incoming and outgoing webhooks with Slack-format compatibility, interactive components via blocks and dialogs, and SSO with AD/LDAP sync are all evidenced. Administrators can enforce channel locking on webhooks and enable webhook debugging, and posts from plugins and bots appear in the compliance record, so automations stay capturable. We found no public information on SCIM provisioning, documented rate limits, event subscriptions with retries, or an app directory. 2 6 13 14

Report an error

European sovereignty

How this is scored

Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.

Report an error

The Compliance Counsel

The contracting entity is Mattermost, Inc., a US company relying on the Data Privacy Framework and Standard Contractual Clauses, with transfers to the United States named, a US-based premier support tier on offer, and Google Analytics on the vendor's sites; we found no public information on EU data residency, an EU contracting entity, or a published subprocessor list for the vendor-managed cloud. The self-hosted and air-gapped options put the archive itself in the customer's hands, which is the only reason this clears the floor. Hosted push notifications and self-hosted telemetry are opt-out, so the European buyer must configure rather than assume. 2 3 4 12

Report an error

Pricing transparency not rated — the vendor publishes no price

How this is scored

Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.

5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.

8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.

10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.

Report an error

The Compliance Counsel

Every plan routes to Contact Sales, Get Pricing or Request Quote, and we found no public per-user price, billing period, VAT treatment or minimum term; only a free limited-use evaluation edition is public. The compliance monitoring and export features a regulated buyer needs sit on the Enterprise and Enterprise Advanced tiers, both unpriced. A buyer cannot compute an annual invoice for any headcount from these pages. 2 10

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined — uncited Report an error
Subprocessors US CLOUD Act reach ⚠ unverified 0/2 pts 3 Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (14)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor homepage mattermost.com Checked 15 Sep 2026 Details →
  2. 2 Pricing mattermost.com Checked 15 Sep 2026 Details →
  3. 3 Security page mattermost.com Checked 15 Sep 2026 Details →
  4. 4 Privacy policy mattermost.com Checked 15 Sep 2026 Details →
  5. 5 Channels, threads & search — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  6. 6 Channels, threads & search — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  7. 7 Encryption & access control — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  8. 8 Encryption & access control — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  9. 9 Retention, discovery & co-determination — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  10. 10 Retention, discovery & co-determination — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  11. 11 Deployment & data custody — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  12. 12 Deployment & data custody — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  13. 13 Integrations & extensibility — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →
  14. 14 Integrations & extensibility — found from sitemap docs.mattermost.com Checked 1 Oct 2026 Details →