Business Instant Messaging
Threema Work
EU-Made Report an error0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Threema GmbH · threema.ch
Compare with Wire (Messaging) → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Threema Work is a Swiss end-to-end encrypted business messenger whose scoring splits between cryptography and custody on one side and workplace tooling on the other. Its strongest criterion is encryption & access control: default E2EE with a zero-knowledge statement, Perfect Forward Secrecy, open source, independent audits, 2FA and MDM are evidenced, docked only for undocumented key handling and absent SSO. Deployment & data custody follows at 7-8 on an OnPrem tier with self-hosting, air-gapped operation and white-labeling — though no export or migration path is documented and OnPrem is priced only CUSTOM. The weak ends are channels, threads & search (2-3: no channels, threads or search in the evidence) and retention, discovery & co-determination (2-4: no message retention policy, audit log or discovery export, so under zero-knowledge the vendor cannot produce the archive). Sovereignty is the genuine split: judges crediting Swiss FADP entity law and the absent subprocessor list scored low, while judges weighting Zurich hosting and the OnPrem option scored high. Integrations runs min 4 to max 4; pricing transparency 5-6.
Speaks for it
- Default end-to-end encryption with a zero-knowledge vendor statement, Perfect Forward Secrecy, open source, independent audits, 2FA and MDM (encryption & access control 8-9)
- OnPrem tier with self-hosting, air-gapped operation and white-labeling of all apps (deployment & data custody 7-8)
- Cloud service runs on Threema's own servers in two ISO 27001-certified data centers in Zurich
- Real server-side API surface — admin API, broadcast API with bots, feeds and scheduled messages (integrations 4)
- Core at EUR 3.00 and Professional at EUR 5.00 per user monthly with annual payment stated, plus a 30-day free trial
Held against it
- No channels, threads, mentions or search documented anywhere in the evidence (channels, threads & search 2-3)
- No message retention policy, audit log, legal hold or discovery export evidenced, and zero-knowledge means the vendor cannot produce the archive (retention, discovery & co-determination 2-4)
- OnPrem priced only CUSTOM and AAD sync an unpriced additional charge, so the self-hosted invoice is not computable
- Contracting entity Threema AG is Swiss under Swiss FADP with GDPR "may additionally apply", and no full subprocessor list is published beyond Livestorm (webinars, hosted in Ireland)
- No SSO, webhooks, slash commands, SCIM or app framework appear in any tier
Best for
- You need a messenger whose vendor structurally cannot read message content — default E2EE with a zero-knowledge statement, open source and independent audits
- Your organisation can self-host and wants air-gapped operation with white-labelled apps (OnPrem)
- You are comfortable with Swiss data custody — own servers in two ISO 27001-certified Zurich data centers, a DPA, a DPO and an Art. 27 GDPR representative in Bonn
- You need secure one-to-many communication — broadcast feeds, bots and scheduled messages — more than a searchable team archive
Avoid if
- You need to retrieve decisions made months ago — ask the vendor: the public pages we read do not show it
- You face eDiscovery, legal hold or retention duties — ask the vendor: the public pages we read do not show it
- You depend on SSO, SCIM, webhooks or an app framework — ask the vendor: the public pages we read do not show it
- You must budget the self-hosted deployment before signing — OnPrem is priced only CUSTOM and AAD sync carries an unstated additional charge
The scores
Channels, threads & search
Show reasoningHide reasoning
How this is scored
The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.
0 — Flat group chats with no threads; search covers recent messages only, and history is capped.
3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.
5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.
8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.
10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.
The Team Lead
What's evidenced is flat group chats with reactions, polls, calls and edit/delete — no channels, no threads, no mentions, and no search documented anywhere, so I can't confirm my team could find last spring's decision at all. No export of a conversation into a human-readable form is evidenced either; this is a consumer messenger pattern, not a workspace, which is why it sits near the bottom rather than mid-scale. 1 2
The Security Officer
Group chats, polls, reactions, file sharing and edit/delete are evidenced, but the evidence says nothing about threads, channels, search, or exporting a conversation in human-readable form. For a product whose whole pitch is that the server cannot read anything, that silence matters: I have no evidence a decision made eighteen months ago can be found or extracted by the organisation that made it. 1 2
The Works Council Advocate
Group chats, reactions, polls and file sharing are confirmed, but the evidence shows no threads, no channels, no mentions, and no search capability at all — eighteen months back, a decision here is found by scrolling, if the client still holds it. External communication is only a 'coming soon' EasyConnect. This sits between the flat-chats anchor and the basic-search anchor, closer to the bottom. 1 2
The Compliance Counsel
Flat group chats, direct messages, file sharing, polls and reactions are evidenced, but no channels, no threads, no mentions, and no search capability appears anywhere in the registry. For a decision made eighteen months ago, the evidence gives me nothing to find it with. 1 2
The Platform Engineer
This is a messenger wearing a work badge, not a workplace chat: flat group chats, file sharing, reactions and polls, with no threads, no channel model and — telling — search is never mentioned anywhere in the evidence. Eighteen-month-old decisions live in scrollback, not in a queryable archive. I give it the 3 because reactions, editing and broadcast feeds beat a plain attachment list, but the search silence is information. 1 2
The Skeptic
Flat group chats with reactions, polls, message editing and file sharing, but no channels, no threads, no mentions, and not one word about search — and given the zero-knowledge claim the vendor structurally cannot search the archive server-side, so an eighteen-month-old decision is unfindable by design. No conversation export is evidenced either. Structure sits below the anchor-3 bar (no channels, no documented search); feature richness sits above rubric level 0, so I split at 2. 1 2
Encryption & access control
Show reasoningHide reasoning
How this is scored
What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.
0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.
3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.
5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.
8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.
10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.
The Team Lead
E2EE is the default, the code is open source with regular independent audits and perfect forward secrecy, and the zero-knowledge statement says plainly that not even Threema can read message content — that's the 10-side of the crypto half. It holds at 8 rather than higher because the access-control half is unevidenced: no SSO, no per-channel roles, no guest scoping, and nothing showing an admin can revoke a session — central user management and MDM are device policy, not room-level control, and identity verification isn't mentioned. 1 2
The Security Officer
This is the product's spine: end-to-end encryption as the default mode with a zero-knowledge statement in plain words — "not even Threema has access" — plus perfect forward secrecy, open source and independent audits, which is exactly the vendor-cannot-decrypt statement I demand. It stays below the top because the evidence evidences no device or key verification, no admin-revocable sessions, and no documented key handling; MDM and central management are named but never as session revocation. 1 2
The Works Council Advocate
End-to-end encryption is not an option, it is the product, with the vendor stating plainly that 'not even Threema has access', plus Perfect Forward Secrecy, open source code and regular independent audits. I dock a point only because the evidence is silent on device verification, cross-device key handling and admin session revocation — everything else here is what I would demand in a works agreement. 1 2
The Compliance Counsel
End-to-end encryption is the first-class mode, not an option: zero-knowledge with the vendor stating plainly it cannot read content, Perfect Forward Secrecy, open source, and regular independent audits, with MDM central access control and two-factor authentication. Only the missing documentation of identity verification and cross-device key management keeps this off the top anchor. 1 2
The Platform Engineer
End-to-end encryption is the default, not an option, backed by a plain zero-knowledge statement ('not even Threema has access'), Perfect Forward Secrecy, open source and regular independent audits. Device/session control is there operationally via 2FA, PIN-protected confidential chats and MDM-centralised access. It misses a 10 only because identity verification and cross-device key handling aren't evidenced in the evidence. 1 2
The Skeptic
The sentence I hunt for is actually here: end-to-end encryption is the default mode with the vendor stating plainly what it cannot decrypt ('not even Threema has access'), backed by Perfect Forward Secrecy, open source, independent audits, 2FA and PIN-protected chats. Held at 8, not 10, because identity verification and key handling are asserted as principles rather than documented mechanisms, and SSO appears in no tier at all — the closest is AAD sync at an unstated 'additional charge'. 1 2
Retention, discovery & co-determination
Show reasoningHide reasoning
How this is scored
The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.
0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.
3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.
5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.
8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.
10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.
The Team Lead
No message retention policy, no export format, no audit log and no eDiscovery appear anywhere in the evidence — the only retention facts are website cookies, forms and truncated 10-day logs, which say nothing about the message archive. The off-hours policy and the absence of any productivity analytics are works-council-friendly, but an archive I cannot produce for a lawyer is a liability in discovery, not just a privacy feature. 1 3
The Security Officer
Every retention statement in the evidence concerns Threema's own website forms and logs; for the customer's message archive there is no retention policy, no export format, no audit log and no legal hold anywhere. The off-hours policy is the single control a works council would recognise, and it does not make an archive governable. 1 3
The Works Council Advocate
The only retention numbers in the whole sheet are for website cookies, forms and truncated IP logs — nothing on message retention policy, admin export, eDiscovery or an audit log for the product itself. On the plus side for co-determination: no activity analytics or individual scoring is evidenced anywhere, and there is an off-hours policy plus availability status, which is exactly the presence control I ask for. Absence of the legal-tooling half pulls this down to just above the manual-copy anchor. 1 3
The Compliance Counsel
No message retention policy, no per-channel retention, no discovery export, no audit log and no legal hold is evidenced — the only retention facts concern website visitor data such as contact forms, cookies and server logs. Zero-knowledge architecture means the vendor cannot produce my archive at subpoena time and no client-side export is offered to compensate, while edit and delete of messages carries no history. 1 3
The Platform Engineer
The only retention numbers in the evidence are for Threema's own website forms and logs — nothing on message retention policy, admin export, audit trail or legal hold for the customer's tenancy. The off-hours policy is a genuine works-council olive branch, and zero-knowledge means there's little metadata to subpoena, but eDiscovery here means 'ask every user for their phone'. 1 2 3
The Skeptic
Every retention statement in the evidence governs the vendor's website — cookies, server logs, support forms — while the messaging archive gets no retention policy, no audit log, no legal hold, no discovery export; under zero-knowledge the vendor cannot produce an eDiscovery output even under subpoena. The lone works-council gesture is an off-hours policy, real but lonely. That is rubric level 0 plus one point. 1 3
Deployment & data custody
Show reasoningHide reasoning
How this is scored
Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.
0 — Cloud-only, proprietary, with export limited to a partial archive.
3 — Cloud-only, but with a documented full export in an open-ish format.
5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.
8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.
10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.
The Team Lead
OnPrem self-hosting with air-gapped operation and white-labeling, plus an open-source claim, is a real custody option rather than a checkbox. It stops short of 8 because no export or migration path in or out — complete export including files and metadata — is documented anywhere in the evidence; custody I can hold but not leave with is only half of sovereignty. 1 2
The Security Officer
A genuine self-hosted OnPrem edition with air-gapped operation and white-labelling of all apps is evidenced, which puts real custody within the customer's reach. But no export or migration path in or out is documented anywhere in the evidence, and "Open Source" is unscoped — client apps or server, it does not say. 1 2
The Works Council Advocate
OnPrem self-hosting with air-gapped operation, white-labeling and an admin API is genuine custody, not a checkbox, and the cloud runs on the vendor's own servers in named Zurich data centres. But the evidence evidences no export or migration path in or out, no federation, and OnPrem is priced 'custom' rather than sold as a first-class public deployment — so a real exit is asserted, not documented. 1 2
The Compliance Counsel
Custody is genuinely available: an OnPrem plan with self-hosting, air-gapped operation, white-labeling and its own 6-hour support tier, on own servers in named Zurich data centres. But the OnPrem licence is priced only as CUSTOM and no export or migration path in and out is documented, so the exit story is unproven. 1 2 3
The Platform Engineer
This is what I want to see: an OnPrem plan with self-hosting, white-labeling of all apps and air-gapped operation, plus open source and vendor-owned Swiss servers for the cloud. It holds at 8 rather than 9–10 because the evidence evidences no open protocol or federation, no documented upgrade path for a self-hosted instance, and no migration/export path in or out — 'custom' on the pricing page is not documentation. 1 2
The Skeptic
OnPrem is a first-class tier with air-gapped operation and white-labeling, and the cloud service runs on Threema's own servers in Zurich — custody is genuinely transferable. It stays at 8 because 'Open Source' is a bare bullet with no scope stated, the migration path and complete export in and out of OnPrem are undocumented, and OnPrem is priced only as 'CUSTOM' — the vendor does not yet document the exit it enables. 1 2 3
Integrations & extensibility
Show reasoningHide reasoning
How this is scored
Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.
0 — No API, no webhooks, no bots.
3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.
5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.
8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.
10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.
The Team Lead
There is a genuine API surface: integration API, admin API, broadcast API with bots, scheduled messages and gateway credits, plus AAD sync at an extra charge. But no webhooks, no slash commands, no SSO, no app framework, no documented rate limits, and the AI bridge is 'coming soon' — this is a messaging pipe, not a platform, so it lands between the anchors. 1 2
The Security Officer
An integration API, an admin API for automated administration, a broadcast API with bots, and gateway credits are evidenced, plus AAD sync at an unstated additional charge. No webhooks, slash commands, SSO, documented rate limits or sandbox appear anywhere, so this is a thin but real API surface rather than a framework. 1 2
The Works Council Advocate
There is a real API surface — integration API, admin API, Broadcast API with bots and feeds, MDM, metered gateway credits — but no webhooks, no slash commands, no app framework, no SCIM, no documented rate limits or sandbox, and directory sync with AAD costs extra without a stated price. This is automation plumbing above the webhook anchor, well short of the documented-API-platform anchor. 1 2
The Compliance Counsel
There is real surface: an integration API, Broadcast API with bots and feeds, an admin API, MDM and AAD sync. But no webhooks, no slash commands, no SSO statement, no documented rate limits or sandbox, and the AI bridge is still 'coming soon'. 1 2
The Platform Engineer
There is a real API with gateway credits metered per license, bots, feeds, a broadcast API and an admin API for automated user management, which is more than a webhook toybox. But there's no webhook/event framework, no slash commands, no app-directory permissions model, no rate-limit documentation, and directory sync (AAD) is a surcharged bolt-on. AIBridge for AI integration is still 'coming soon'. 1 2
The Skeptic
There are real server-side APIs — admin API, broadcast API, bots, feeds, scheduled messages — but nothing lives in the chat itself: no webhooks, no slash commands, no app framework, no SCIM, and no SSO in any tier; AAD sync is directory replication at an extra, unquoted charge and AIBRIDGE is 'coming soon'. That covers roughly half of the anchor-5 list, so I split between 3 and 5. 1 2
European sovereignty
panel opinion
panel disagrees
Show reasoningHide reasoning
How this is scored
Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.
The Team Lead
Swiss vendor running exclusively on its own servers in two named ISO 27001 datacenters in Zurich, with real GDPR engagement (Art. 27 representative in Bonn, a DPO) and a named subprocessor, plus an OnPrem option that largely removes the question. It misses the top because the contracting entity and primary law sit outside the EU (Swiss FADP), ownership is unknown, and the only disclosed subprocessor covers webinar tooling rather than a published full chain. 1 2 3
The Security Officer
Hosting is named and certified — Threema's own servers in two ISO 27001 colocation data centers in Zurich — but the contracting entity is Swiss, not EU, and the pipeline found no published subprocessor list beyond Livestorm for webinar registration. The OnPrem option would remove the question entirely, but on the cloud product this is a third-country arrangement dressed with an Art. 27 GDPR representative in Bonn. 1 3
The Works Council Advocate
The contracting entity Threema AG is Swiss, not EU — they even need an Art. 27 GDPR representative in Bonn — and hosting is on their own servers at a named ISO 27001 colocation partner in Zurich, which is geographically European but contractually outside the EU. Only one subprocessor (Livestorm, Ireland, webinars) is disclosed, and the pipeline itself marks product subprocessor exposure unknown. Switzerland on own infrastructure is better than most non-EU setups, but the entity and the undisclosed chain keep this just above the bottom anchors. 3 1
The Compliance Counsel
The vendor's own pages state own servers in two ISO 27001-certified data centres in Zurich, a named Swiss controller, an Art. 27 GDPR representative in Bonn, and one named subprocessor (Livestorm, hosting in Ireland) — stronger custody than the pipeline's 'unknowns' suggest. But the contracting entity sits outside the EU and no full subprocessor list for the messaging service is published. 1 3
The Platform Engineer
Swiss is not EU, so the literal anchor caps this below 8 — Threema AG is the contracting entity under Swiss FADP — but the custody story is unusually strong: own servers in two named ISO 27001 data centres in Zurich, an Art. 27 GDPR representative in Bonn, a DPO, a DPA, GDPR compliance claims. I dock it because the pipeline found no published full subprocessor list (only Livestorm, for webinars) and ownership is unknown; the OnPrem option is what keeps me comfortable despite that. 1 3
The Skeptic
The contracting entity is Threema AG, Switzerland, under Swiss FADP with GDPR only 'may additionally apply' and an Art. 27 representative in Bonn — an entity outside the EU is rubric level 3's own wording, and the pipeline's computed 3 agrees. Own-server hosting in Zurich is stable but not EU, and the only named subprocessor (Livestorm, Ireland) touches webinars, not the messaging service; no full subprocessor list is published. 1 3
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.
5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.
8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.
10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.
The Team Lead
Core at EUR 3 and Professional at EUR 5 per user per month on annual billing are public, with tier limits spelled out (gateway credits, support response times). But OnPrem is 'CUSTOM', AAD sync is an unquantified 'additional charge', and VAT treatment is nowhere stated — I can compute the SaaS invoice for a headcount, but not the one for the self-hosted deployment this product is actually best at. 1 2
The Security Officer
Core at EUR 3/user/month with annual payment stated and Professional at EUR 5 are public. But the OnPrem tier — the one carrying the sovereignty and air-gap — is priced only as "CUSTOM", AAD sync is an unpriced "additional charge", and VAT treatment is nowhere stated, so the invoice for the deployment a security buyer actually wants is not computable from public pages. 1 2
The Works Council Advocate
Core at EUR 3 and Professional at EUR 5 per user per month, with annual billing stated, lets a buyer compute the SaaS invoice for any headcount. But the compliance-relevant choices — self-hosted OnPrem at 'custom', and AAD sync as an unpriced additional charge — sit behind a sales conversation, and minimum term and VAT treatment are unstated; only a 30-day trial is public. 2 1
The Compliance Counsel
Core (EUR 3/user/month, annual payment) and Professional (EUR 5/user/month) are public with tier boundaries like gateway credits and support response times. The deployment I would actually buy — OnPrem — is CUSTOM, AAD sync is 'additional charge' with no figure, and VAT treatment and minimum term are unstated, so the annual invoice is not computable. 1 2
The Platform Engineer
Core at EUR 3.00/user/month and Professional at EUR 5.00/user/month are public with the billing period stated, which is decent. But the OnPrem tier — the one I care about — is 'CUSTOM', AAD sync is 'additional charge' with no number, and VAT treatment and guest/external pricing (EasyConnect) are unstated. I can price the SaaS invoice, not the deployment I'd actually buy. 1 2
The Skeptic
Core at EUR 3 and Professional at EUR 5 per user monthly with annual payment stated is computable — but the data-sovereignty capability sits in an OnPrem tier priced only 'CUSTOM' and AAD sync is 'additional charge' with no figure, so a compliance-conscious buyer cannot derive their annual invoice. VAT treatment and minimum term are unstated. That is rubric level 5 almost verbatim. 1 2
European sovereignty — proven facts
0 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 11 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors, Legal entity. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 28 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 14 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 13 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 5 subprocessors facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 3 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 data fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 3 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (16)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Product page threema.ch Checked 15 Sep 2026 +1 earlier capture: 11 Sep 2026 Details →
- 2 Pricing threema.ch Checked 15 Sep 2026 Details →
- 3 Privacy policy threema.ch Checked 15 Sep 2026 Details →
- 4 Security / trust page threema.com Checked 30 Sep 2026 Details →
- 5 Imprint threema.com Checked 30 Sep 2026 Details →
- 6 Data processing agreement (dpa) threema.com Checked 30 Sep 2026 Details →
- 7 Channels, threads & search — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 8 Channels, threads & search — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 9 Encryption & access control — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 10 Encryption & access control — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 11 Retention, discovery & co-determination — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 12 Retention, discovery & co-determination — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 13 Deployment & data custody — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 14 Deployment & data custody — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 15 Integrations & extensibility — found from sitemap threema.com Checked 1 Oct 2026 Details →
- 16 Integrations & extensibility — found from sitemap threema.com Checked 1 Oct 2026 Details →