whats-best.ai

Business Instant Messaging

Pumble

Provenance unknown Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: not determined

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by CAKE.com · pumble.com

Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

The panel's verdict

Pumble is a business instant messaging product from CAKE.com Inc. It is strongest on messaging core, where scores cluster at 4-6: channels, threads, one-on-one and group messages, file sharing, and unlimited message history with search that finds "any message, whenever it happened" are all stated plainly. Integrations follow at 3-4, resting on a stated API and MCP plus named integrations with Clockify, Plaky and Google Drive, though we found no public documentation of webhooks, rate limits or a bot account model. The compliance side is weakest: encryption and access sits at 1-2 with guest access the only access detail on record, and governance and discovery, deployment control and sovereignty each sit at 0-1, where we found no public information on retention policies, audit logs, self-hosting, hosting location, certification or subprocessors. The bench shows no genuine split; the widest spread is messaging core at 4-6. In passing on pricing: the Free Forever tier is specified with unlimited users, channels and message history, while Pro, Business and Enterprise are named without public figures.

Report an error

Speaks for it

  • Channels, threads, one-on-one and group messages, and file sharing are all stated features.
  • Unlimited message history is paired with unlimited search that finds "any message, whenever it happened".
  • An API and MCP are named as available, with integrations including Clockify, Plaky and Google Drive.
  • Voice calls, video conferencing, meeting links and screen sharing are confirmed.
  • Guest access is described as limited access for external people.

Report an error

Held against it

  • We found no public information on transport or at-rest encryption, key handling, single sign-on, or what the vendor can read.
  • We found no public information on retention policies, admin export formats, audit logs or legal hold.
  • We found no public information on self-hosting, dedicated instances or a documented export path.
  • We found no public information on hosting location, certification or subprocessors; the contracting entity appears as CAKE.com Inc. with no jurisdiction stated.
  • The API and MCP claims rest on labels, with no public documentation of webhooks, bot accounts or rate limits.

Report an error

Best for

  • You need everyday team chat with channels, threads, file sharing and unlimited searchable history.
  • Your team spans Mac, Windows, Linux, Android, iOS and web clients.
  • You want to wire chat into Google Drive or the vendor's own Clockify and Plaky through the stated API and MCP.
  • You run calls from chat, with voice, video, screen sharing and meeting links confirmed.

Report an error

Avoid if

  • You need retention policies, audit logs and export formats evidenced for a regulator or works council.
  • You need self-hosting or a documented exit path for your archive.
  • You need encryption, single sign-on and role-based access documented before rollout.
  • You need hosting location and subprocessor details for a European procurement.

Report an error

The scores

Channels, threads & search

Show reasoning
How this is scored

The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.

0 — Flat group chats with no threads; search covers recent messages only, and history is capped.

3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.

5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.

8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.

10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.

Report an error

The Team Lead

Channels organised by topic, real threads, direct and group messages, and file sharing are all confirmed, and the vendor states unlimited search that finds any message whenever it happened alongside unlimited message history — that is the daily surface my team needs. We found no public information on mentions and reactions, message editing history, pinned items, or search filters by channel, person and date. 1

Report an error

The Security Officer

Channels, real threads, direct and group messaging, and file sharing are all stated, and unlimited message history with search that finds any message, whenever it happened, removes any history cap. Mentions, reactions, message edit history, search filters, and channel lifecycle are things I found no public information on, which keeps this short of the working-knowledge-base standard. 1

Report an error

The Works Council Advocate

Channels, real threads, file sharing and guest access are all stated, and search is advertised as unlimited over an unlimited message history — an archive that keeps an eighteen-month-old decision findable is the part I care about. We found no public information on mentions and reactions, channel privacy models, message editing history, pinned items, or search filters by channel, person and date. That places it just under the middle of the scale. 1

Report an error

The Compliance Counsel

Channels, real threads, file sharing, and unlimited search across unlimited message history are stated plainly, which covers the working archive I need day to day. I found no public information on message edit history, pinned items, search filters by channel or date, channel lifecycle, or export of a conversation in human-readable form, so this stays mid-grade. 1

Report an error

The Platform Engineer

Channels, threads, one-to-one and group messages, and file sharing are all evidenced, and unlimited search over unlimited message history is the right shape for finding an eighteen-month-old decision. I found no public information on mentions, reactions, message editing history, search filters, or exporting a conversation, so it stays just below the middle of the scale. 1

Report an error

The Skeptic

Channels, threads, file sharing and one-on-one and group messages are each named features, and the page promises unlimited message history with search that finds "any message, whenever it happened" — the sentence I look for, though "unlimited" is stated with no exclusions or tier conditions attached. I found no public information on mentions, reactions, channel privacy types, message editing history or search filters, which holds this below the middle band. 1

Report an error

Encryption & access control

Show reasoning
How this is scored

What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.

0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.

3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.

5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.

8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.

10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.

Report an error

The Team Lead

The only access-control fact on record is guest accounts described as limited access for external people. We found no public information on encryption mechanism, SSO, configurable roles per channel, session management, or any statement of what the vendor can read, and in this category that silence speaks. 1

Report an error

The Security Officer

On what I weigh first — what is encrypted and against whom — I found no public information: no statement on transport or at-rest encryption, no key handling, and no plain statement of what the vendor can or cannot read. Guest access is described as limited for external people, and that is the only access-control detail captured. I found no public information on per-channel roles, SSO, device verification, or sessions an admin can revoke. 1

Report an error

The Works Council Advocate

The only access statement on the captured page is guest access described as limited access for external people. We found no public information on transport or at-rest encryption, key handling, configurable roles, SSO, session revocation, or what the vendor itself can read — and that silence is the first thing a works council reads. 1

Report an error

The Compliance Counsel

The only access fact on the page is guest access described as limited access to external people; I found no public information on encryption at rest, transport encryption, per-channel roles, SSO, guest scoping within channels, or a statement of what the vendor can read. Judged on documented mechanism, an undocumented access and encryption model starts near the floor. 1

Report an error

The Platform Engineer

Guests are at least described as limited access for external people, which hints at scoped visibility. Beyond that I found no public information on encryption of any kind, SSO, per-channel roles, session management, or what the vendor can read — judged on documented mechanism, almost no mechanism is documented. 1

Report an error

The Skeptic

Guests are described as limited access for external people, and that is the only access-scoping statement the page makes. I found no public information on encryption of any kind — transport, at rest, or end-to-end — on single sign-on, per-channel roles, or on what the vendor can read, so guests aside, everything this criterion judges rests on silence. 1

Report an error

Retention, discovery & co-determination

Show reasoning
How this is scored

The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.

0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.

3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.

5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.

8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.

10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.

Report an error

The Team Lead

Nothing on the captured page touches retention policies, admin export, audit logs, eDiscovery, or analytics a works council would ask about; we found no public information on any of these. Unlimited message history is stated, but that is a promise to keep messages, not a policy for governing them. 1

Report an error

The Security Officer

For the archive as a legal object I found no public information on retention policies, admin export in a documented format, audit logs, or whether presence and activity analytics exist and can be switched off. Unlimited message history is a user-facing feature, not a retention regime. 1

Report an error

The Works Council Advocate

We found no public information on retention policy configuration, admin export in a documented format, an audit log, or whether call recording and any presence or activity analytics can be switched off organisation-wide — recording appears as a feature with no published governance around it. A chat log is a record of who spoke to whom at what hour, and on this evidence nothing about that record is inspectable or negotiable. 1

Report an error

The Compliance Counsel

This is the criterion I litigate, and I found no public information on retention policies, admin export formats, audit logging, legal hold, or any control over presence and activity analytics. Unlimited message history is retention by never deleting, not a policy I can hand to a regulator or a works council. 1

Report an error

The Platform Engineer

The only archive-related fact on record is unlimited message history; I found no public information on retention policies, export in a documented format, audit logging, or whether presence and activity analytics can be switched off. On the captured pages there is nothing here to bring to a works council. 1

Report an error

The Skeptic

The only archive-related fact is unlimited message history on the free plan; I found no public information on retention policies, admin export formats, audit logs, or whether presence and activity analytics can be switched off — precisely the questions a works council asks first. An Enterprise tier is named with nothing attached to it. 1

Report an error

Deployment & data custody

Show reasoning
How this is scored

Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.

0 — Cloud-only, proprietary, with export limited to a partial archive.

3 — Cloud-only, but with a documented full export in an open-ish format.

5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.

8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.

10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.

Report an error

The Team Lead

The product is presented as a cloud service with apps for six platforms and nothing more; we found no public information on self-hosting, open source, federation, or a documented export and migration path. On everything the page shows, custody of the archive stays with the vendor. 1

Report an error

The Security Officer

Mac, Windows, Linux, Android, iOS and Web are clients, not custody. I found no public information on self-hosting, a dedicated private instance, source availability, federation, or a documented exit export, so nothing captured speaks to a customer holding their own archive. 1

Report an error

The Works Council Advocate

The captured page presents a hosted service with clients for Mac, Windows, Linux, Android, iOS and web, and we found no public information on self-hosting, a private-cloud or dedicated-instance option, open source, federation, or a documented export path. On this evidence the customer's own hold on their archive, and any exit from the vendor, is undocumented. 1

Report an error

The Compliance Counsel

I found no public information on self-hosting, a private-cloud or dedicated-instance option, open source, federation, or a documented export including files and metadata. With none of that evidenced, custody of the archive rests entirely with the vendor and an exit path is unevidenced. 1

Report an error

The Platform Engineer

The platform list covers client apps on six operating systems, which tells me nothing about who holds the server or the archive. I found no public information on self-hosting, source availability, federation, full export, or a migration path, so as far as the captured pages go this reads as a cloud-only proprietary product. 1

Report an error

The Skeptic

The platform list — Mac, Windows, Linux, Android, iOS, Web — describes client apps, not server custody. I found no public information on self-hosting, private-cloud or dedicated instances, open-source licensing, or export of the archive, so the captured evidence supports nothing toward the customer holding their own archive. 1

Report an error

Integrations & extensibility

Show reasoning
How this is scored

Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.

0 — No API, no webhooks, no bots.

3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.

5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.

8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.

10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.

Report an error

The Team Lead

An API and MCP support are confirmed as available and three integrations are named — Clockify, Plaky and Google Drive — but nothing documents webhooks, slash commands, a bot account model, rate limits or SSO. A confirmed-but-undocumented API flag is exactly the feature-list item that does not survive a busy Tuesday. 1

Report an error

The Security Officer

An API is confirmed available and MCP is offered, with named integrations including Google Drive, Clockify and Plaky. I found no public information on webhooks, a bot account model, SSO, documented rate limits, or a sandbox, so the question of a buildable platform stays open. 1

Report an error

The Works Council Advocate

An API and an MCP interface are listed, with named integrations including Google Drive alongside Clockify and Plaky, which belong to the vendor's own suite. We found no public information on webhooks, slash commands, a bot account model, SCIM provisioning, documented rate limits or a sandbox, so what a customer can build rests on API access whose documentation we have not seen. 1

Report an error

The Compliance Counsel

An API and MCP are stated as available, with named integrations for Clockify, Plaky and Google Drive. I found no public information on webhooks, slash commands, a bot account model, SCIM provisioning, SSO, or documented rate limits, which keeps this just above the basic tier. 1

Report an error

The Platform Engineer

An API and MCP support are claimed, with named integrations for Clockify, Plaky and Google Drive — two of which are the vendor's own suite. I found no public information on webhooks, a bot account model, SCIM provisioning, documented rate limits, or a permission model a customer could audit, which caps it well short of a platform. 1

Report an error

The Skeptic

A handful of native integrations are named — Clockify, Plaky, Google Drive — and the page carries a bare "API" and "MCP" label, which is an integration surface by name. I found no public information on webhooks, bot accounts, slash commands, single sign-on, rate limits or a sandbox, so the API claim rests on a two-word label rather than documented behaviour. 1

Report an error

European sovereignty panel opinion

Show reasoning
How this is scored

Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.

0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.

3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.

8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.

Report an error

The Team Lead

No sovereignty attributes are on record: the only contracting entity named is CAKE.com Inc., and we found no public information on hosting location, subprocessors, or any EU-specific arrangements. For a European buyer, the capture offers nothing to hold onto. 1

Report an error

The Security Officer

The sovereignty record is empty: the contracting entity is CAKE.com Inc., and I found no public information on where hosting or metadata sit, or which subprocessors touch the archive. No element of an EU chain — hosting, entity attributes, certification, subprocessor list — is evidenced. 1

Report an error

The Works Council Advocate

The sovereignty record holds no attributes for this vendor: hosting location unstated, subprocessors unnamed, and the contracting entity is CAKE.com Inc., a name that carries no European indicators on the captured page. An unknown jurisdiction for the archive and its metadata is the worst position a works council can plan around; the published contracting entity alone lifts this slightly. 1

Report an error

The Compliance Counsel

The only fact on record is the contracting entity, CAKE.com Inc.; I found no public information on hosting location, subprocessors, EU data residency, certification, or any non-EU processing and its legal basis. For this buyer, an archive whose entire custody chain is unevidenced scores at the floor. 1

Report an error

The Platform Engineer

The sovereignty record is empty: no hosting location, no subprocessor list, no certification, and the contracting entity is CAKE.com Inc. with no jurisdiction shown. I found no public information evidencing EU residency anywhere in the chain, so it scores at the bottom of the range. 1

Report an error

The Skeptic

No sovereignty attributes are on record: I found no public information on hosting location, data residency, certification or any named subprocessor, and the contracting entity appears only as CAKE.com Inc. with no jurisdiction stated. Nothing in the captured evidence speaks to European custody of the archive or its metadata. 1

Report an error

Pricing transparency not rated — the vendor publishes no price

Show reasoning
How this is scored

Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.

5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.

8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.

10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.

Report an error

The Team Lead

The Free Forever tier is publicly described with unlimited users, unlimited channels and unlimited message history, but the Pro, Business and Enterprise plans are named without figures — no per-user price, billing period, VAT treatment or feature boundaries anywhere on record. An annual invoice for a given headcount cannot be computed from these pages. 1

Report an error

The Security Officer

The plan ladder is public — Free, Pro, Business, Enterprise — and the free tier is unusually clear: unlimited users, unlimited channels and unlimited message history at no cost. I found no public information on per-user prices for the paid tiers or on where SSO, retention and compliance capabilities begin, so a buyer cannot compute an annual invoice from the captured pages. 1

Report an error

The Works Council Advocate

The free tier is published plainly — unlimited users, unlimited channels, unlimited message history — and four plan names appear: Free, Pro, Business, Enterprise. We found no public prices for any paid tier in the captured page, so an annual invoice for a given headcount cannot be computed from public information, and the tier where compliance capabilities begin is unstated. 1

Report an error

The Compliance Counsel

The Free plan is fully specified — unlimited users, unlimited channels, unlimited message history at no cost — which lets a buyer compute a zero invoice for that deployment choice. I found no public information on prices for the Pro, Business and Enterprise tiers, on billing periods, or on where compliance and retention capabilities begin, so no paying headcount can be costed from public pages. 1

Report an error

The Platform Engineer

The free tier is unusually well specified — unlimited users, unlimited channels, unlimited message history at no cost — but Pro, Business and Enterprise are named only. I found no public information on per-user prices, billing periods, term minimums, VAT treatment, or which tier the compliance and admin features begin in, so an annual invoice cannot be computed from public pages. 1

Report an error

The Skeptic

The Free tier is genuinely specified — "Free Forever" with unlimited users, unlimited channels and unlimited message history — but Pro, Business and Enterprise are named with no figures on the captured page. I found no public information on per-user prices, billing periods, storage limits, or the tier where single sign-on, retention or export features begin, so no invoice above zero is computable from public pages. 1

Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (8)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Vendor page pumble.com Checked 22 Sep 2026 Details →
  2. 2 Channels, threads & search — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  3. 3 Channels, threads & search — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  4. 4 Encryption & access control — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  5. 5 Retention, discovery & co-determination — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  6. 6 Retention, discovery & co-determination — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  7. 7 Integrations & extensibility — found from sitemap pumble.com Checked 1 Oct 2026 Details →
  8. 8 Integrations & extensibility — found from sitemap pumble.com Checked 1 Oct 2026 Details →