Business Instant Messaging
Wire (Messaging)
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Wire Swiss GmbH · wire.com
Compare with Threema Work → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Wire, a business instant messenger from Wire Swiss GmbH (Zug, Switzerland), is strongest on encryption & access control: end-to-end encryption is the default mode for text, voice, video and files, the code is open source on GitHub, and the vendor states it holds no keys and no backdoors. Deployment & data custody scores 7-8, held back by unevidenced export or migration paths and by on-prem sitting in a custom tier. It is weakest on channels, threads & search — no channels, threads or search appear anywhere in the evidence — and on retention, discovery & co-determination, where no audit log, legal hold, admin export or configurable retention is evidenced. That range is a genuine split: the works council scores 4, crediting deletion-on-delivery and consent-based, self-hosted analytics, while the compliance counsel scores 1 because that same deletion leaves nothing for a subpoena to find. Integrations sits flat at 4. Sovereignty spans 4-6 — servers in Germany and Ireland and a published subprocessor list, but a Swiss contracting entity and unknown ownership. Pricing is computable to 100 people (€7.45/person/month annual, €8.94 monthly); beyond that, custom.
Speaks for it
- End-to-end encryption is the default mode for text, voice, video and files, under MLS, with 100% open-source code on GitHub
- The vendor states plainly it has no access to encryption keys and uses no backdoors, backed by certificate-based ID Shield device verification
- On-premises deployment support, federation and data-sovereignty options make customer custody achievable (deployment & data custody 7-8)
- SMB pricing is computable up to 100 people — €7.45 per person/month billed annually or €8.94 monthly — with SSO & SCIM included
- Works-council-friendly defaults: consent-based, self-hosted Countly analytics, no productivity scoring, and messages deleted from servers on delivery
Held against it
- No channels, threads or search are evidenced anywhere in the evidence (channels, threads & search 2-3)
- No audit log, legal hold, admin export or customer-configurable retention appears, and encrypted messages are deleted from servers immediately on delivery (retention, discovery & co-determination 1-4)
- Integration evidence stops at deployable bots, one named GitHub integration and SSO/SCIM, with no documented REST API or webhooks (integrations 4)
- The contracting entity is Wire Swiss GmbH in Zug, Wire Germany GmbH exists only as an Article 27 representative, and ownership is unknown
- Federation, ID-Shield, data sovereignty and on-premises sit in a custom-priced Enterprise tier for more than 100 people, with VAT treatment unstated
Best for
- You need confidential messaging where default end-to-end encryption and a no-backdoors statement matter more than searchable history
- Your organization can negotiate custom Enterprise terms for on-premises or federated deployment and wants customer custody
- Your works council favors minimal retention and consent-based, self-hosted analytics
- Your team is 100 people or fewer and wants SSO/SCIM inside the priced SMB tier
Avoid if
- You need to retrieve decisions months later — the evidence evidences no search, threads or channels, and self-deleting messages are a marketed feature
- You carry eDiscovery, legal-hold or administrative audit-log obligations
- You need a documented REST API or webhooks to build workflows on
- Your procurement requires an EU contracting entity
The scores
Channels, threads & search
Show reasoningHide reasoning
How this is scored
The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.
0 — Flat group chats with no threads; search covers recent messages only, and history is capped.
3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.
5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.
8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.
10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.
The Team Lead
Threads, channels and search are simply not evidenced anywhere — the messaging list is calls, screen sharing, sketch, file sharing and self-deleting messages, and self-deleting is the opposite of the archive I need. Custom folders, availability status and 500–2000-participant chats put it above a flat group chat, but nothing here says I can find last spring's decision in eighteen months. 1 2
The Security Officer
Group chats up to 500–2000 participants, file sharing, self-deleting messages and audio/video messages are evidenced, but the evidence is completely silent on channels, threading, mentions and — damningly for an archive — search. A product that cannot show me search cannot find a decision made eighteen months ago, and silence here is the answer. 1 2
The Works Council Advocate
Messaging, file sharing, audio/video messages and 500–2000-participant chats are confirmed, but the evidence is silent on channels, threading, mentions and search entirely — I cannot confirm a decision from eighteen months ago could be found again. A chat log nobody can search is not a record, it is a rumour. Scored just above the flat-chat floor for what is evidenced, held down by what is not. 1 2
The Compliance Counsel
Nothing on the evidence evidences a channel model, threading, or search at all — it names group conversations (up to 500 participants), file sharing and self-deleting messages, and stops there. For a criterion that turns on finding a decision from eighteen months ago, silence on search is decisive, and self-deleting messages plus server-side deletion on delivery point the wrong way for an archive. 1 2 4
The Platform Engineer
The evidence gives me group conversations up to 500 (2000 with MLS), file sharing, self-deleting messages and custom folders, but not one word on threading, mentions, reactions, or search — and search that finds an eighteen-month-old decision is architecturally doubtful when servers delete message payloads on delivery. Threading absent and search unevidenced puts this at the basic-chats anchor, nothing higher. 2 4
The Skeptic
The evidence evidences group chats up to 500 people, file sharing and self-deleting messages — and not one word about channels, threads or search; that word never appears, so a decision made eighteen months ago is retrievable by nothing this sheet shows. Worse, messages are deleted from Wire's servers 'immediately upon delivery', so there is barely an archive to search. A flat-messenger profile with ephemeral history, well below the channels-and-threads anchor. 2 1 4
Encryption & access control
Show reasoningHide reasoning
How this is scored
What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.
0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.
3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.
5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.
8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.
10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.
The Team Lead
End-to-end encryption on text, voice, video and files, MLS co-developed and open source on GitHub, ID Shield doing certificate-based identity checks so nobody fumbles fingerprints, guest links with passwords, and the vendor stating plainly it holds no keys and no backdoors. Docked one because admin-revocable session management and key handling for the encrypted history backup aren't spelled out, but this is the strongest crypto story in the category. 1 2 3 4
The Security Officer
This is the rare product that writes down what I demand in writing: end-to-end encryption of text, voice, video and files, open MLS cryptography auditable on GitHub, certificate-based ID Shield plus manual device verification, and the plain statement 'Wire does not have access to encryption keys and does not use backdoors.' It misses 10 only because no evidence shows an admin revoking sessions or devices, and the 'cannot decrypt' statement is asserted rather than itemised. 1 2 3 4
The Works Council Advocate
This is the rubric level 10 case in full: MLS end-to-end encryption as the only mode, open source on GitHub, ID Shield automatic certificate-based device checks so ordinary people survive key management, and the vendor stating plainly it has no access to keys and no backdoors. Multi-device E2EE across 8 devices, SSO/SAML and SCIM, guest links with passwords and password-restricted guest roles complete the picture. 1 2 3 4
The Compliance Counsel
This is the rare case where the vendor states plainly what it cannot reach — 'Wire does not have access to encryption keys and does not use backdoors' — backed by fully open source MLS cryptography, certificate-based identity verification (ID Shield), manual device verification, encrypted history backup and password-protected guest links. End-to-end encryption is the default mode for text, voice, video and files, not an optional bolt-on. 1 2 3 4
The Platform Engineer
This is the full ten: end-to-end encryption as the default mode for text, voice, video and files, MLS as the underlying open protocol co-developed publicly, open-source code on GitHub, certificate-based identity verification via ID Shield, encrypted history backup for multi-device key survival, and a plain vendor statement that Wire has no access to keys and no backdoors. SSO/SAML, SCIM and password-gated guest roles round out access control. 1 2 3 4
The Skeptic
The sentences I hunt for exist verbatim: content is 'encrypted on the sender's device and decrypted only on the recipient's device' across text, voice, video and files, and 'Wire does not have access to encryption keys and does not use backdoors' — backed by MLS, an open standard, 100% open source on GitHub, manual device verification plus automatic certificate-based ID Shield, and encrypted history backup. Docked one point because admin-revocable session management is never named and the trade-offs of E2EE for search/discovery are not spelled out. 4 3 2
Retention, discovery & co-determination
panel disagrees
Show reasoningHide reasoning
How this is scored
The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.
0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.
3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.
5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.
8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.
10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.
The Team Lead
The privacy policy says encrypted messages are deleted from Wire's servers immediately on delivery, so the server-side archive a subpoena or works agreement would ask about barely exists; no per-channel retention, no admin export in a documented format, no audit log evidenced anywhere. Countly analytics are consent-based and self-hosted, which is the one thing keeping this off the floor. 2 4
The Security Officer
Messages are deleted from servers immediately upon delivery, which keeps the archive out of strangers' hands but also means there is no customer-side retention policy, no discovery export, and no admin audit log anywhere in this sheet — a subpoena lands on scattered devices, not a manageable store. The one mercy is that the only analytics (Countly) is consent-based, self-hosted and EU-based, so a works council has little to switch off. 2 4
The Works Council Advocate
The deletion posture is what I fight for: messages leave the servers on delivery, retention is purpose-bound, self-deleting messages exist, and the vendor confirms no automated decision-making, no profiling and consent-based, self-hosted Countly analytics that share nothing — no individual activity scoring anywhere. But the legal-object half is absent from the evidence: no audit log of administrative actions, no documented admin export, no eDiscovery or legal hold, and an availability status with no evidenced user control. Deletion by default keeps it above the middle; the missing audit trail keeps it below it. 2 3 4
The Compliance Counsel
There is no evidenced admin export, no legal hold, no audit log of administrative actions and no customer-configurable retention — the only retention statements are the vendor's own privacy-policy deletion clocks (90-day logs, 365-day usage data). Worse, server-side message copies are deleted on delivery and self-deleting messages are a marketed feature, so a subpoena would find nothing to produce; only consent-based self-hosted Countly analytics and the absence of any productivity scoring keep this just off the floor. 2 4
The Platform Engineer
The archive as a legal object barely exists here: retention means self-deleting messages and a purpose-based deletion rule, with no per-channel retention, no audit log, no legal hold, and no export-for-discovery capability evidenced anywhere in the evidence. Credit where due on the works-council side — analytics is self-hosted, consent-based Countly with no vendor data sharing and no productivity scoring — but eDiscovery and audit are simply silent, and that caps it at the bottom anchor that matches. 2 4
The Skeptic
As a legal object there is almost nothing: no configurable retention, no admin export, no audit log, no legal hold — the only retention rule on file is the server deleting messages upon delivery, which is the opposite of a discovery posture. The works-council side is genuinely clean, to be fair: consent-based self-hosted Countly analytics, a no-automated-decision-making declaration and no productivity scoring anywhere. 4 2
Deployment & data custody
Show reasoningHide reasoning
How this is scored
Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.
0 — Cloud-only, proprietary, with export limited to a partial archive.
3 — Cloud-only, but with a documented full export in an open-ish format.
5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.
8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.
10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.
The Team Lead
Open-source code on GitHub, comprehensive on-premises deployment support marketed at government customers, federation and multi-tenancy in the enterprise list — custody can genuinely be the customer's. The top anchor needs a documented migration path in and out, and the evidence never mentions export at all. 1 2 3
The Security Officer
Custody can genuinely be the customer's: 'comprehensive on-premises deployment support', federation, multi-tenancy and data sovereignty are offered, and the source code is 100% open on GitHub. What holds it at 8 is pure silence on export and migration — nothing in the evidence documents how a customer walks out with their history, and an exit I can't evidence is an exit the vendor controls. 1 2 3
The Works Council Advocate
Custody is genuinely achievable: 100% open source code on GitHub, comprehensive on-premises deployment support 'every step of the way' in the government offering, plus federation and multi-tenancy. What holds it back is that the evidence documents no export or migration path — an exit is implied by self-hosting rather than written down — and on-prem sits in an unpriced enterprise tier. Seven, not eight. 1 2 3
The Compliance Counsel
Custody is genuinely obtainable: the source code is fully open on GitHub, with comprehensive on-premises deployment support, federation and data-sovereignty editions — self-hosting removes the vendor from my archive entirely. What the evidence never evidences is a documented export or migration path in and out, which the top anchor demands and my exit planning requires. 1 2 3
The Platform Engineer
This is the part I came for: 100% open-source code on GitHub, an on-premises deployment offered with 'comprehensive' support, real federation over MLS, and a deployment-options page — custody can plausibly be the customer's. What keeps it off the top anchor is that on-prem and data sovereignty sit behind a custom-priced Enterprise tier rather than a documented self-hosting path, and the evidence is silent on any export or migration route in and out. 1 2 3
The Skeptic
Open-source code on GitHub, 'comprehensive on-premises deployment support' and federation listed at enterprise tier are real custody options, not slideware. But the evidence never documents an export or migration path out, so the exit story is assumed rather than evidenced, and on-prem sits behind a custom-priced enterprise conversation. 3 1 2
Integrations & extensibility
Show reasoningHide reasoning
How this is scored
Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.
0 — No API, no webhooks, no bots.
3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.
5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.
8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.
10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.
The Team Lead
Admins can deploy third-party bots, GitHub is listed as an integration, and SSO with SCIM provisioning is real — but there is no documented REST API, no webhooks, no slash commands, no app framework, no rate limits in the evidence. As an identity hookup it's fine; as a platform to build the day's work around, it's thin. 1 2
The Security Officer
The admin console can deploy third-party bots, a GitHub integration is listed, and SSO/SCIM are evidenced — slightly more than bare webhooks. But there is no documented REST API, no webhooks, no slash commands, no rate limits and no app framework in the evidence, so I cannot credit extensibility a buyer could actually build on. 1 2
The Works Council Advocate
Admins can deploy third-party integrated apps (bots), GitHub is listed, and SSO with SCIM provisioning is real — but that is the whole integrations story the evidence tells. No documented REST API, no webhooks, no slash commands, no rate limits, no sandbox. Just enough to be more than a closed app, nowhere near a platform. 1 2
The Compliance Counsel
The admin console can deploy third-party integrated bots and SSO with SCIM provisioning is priced into the SMB tier, but the evidence evidences no REST API, no webhooks, no slash commands and no documented limits — a single listed GitHub integration is the entire visible catalogue. 2
The Platform Engineer
There is a bot capability the admin console can deploy and one named native integration (GitHub), plus SSO and SCIM — but no documented REST API, no webhooks, no slash commands, no rate limits, and nothing resembling an app framework with auditable permissions. That lands between the webhook-only anchor and the documented-API anchor: real bot accounts and provisioning, but the extensibility surface is unevidenced and probably a partner conversation. 1 2
The Skeptic
Exactly one integration is named (GitHub), bot deployment appears as an admin-console line, and SSO/SCIM is evidenced — beyond that, silence: no documented REST API, no webhooks, no framework, no rate limits, no sandbox. 'MS Teams alternative' is a use-case slogan, not an integration surface. 2 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.
The Team Lead
Servers in Germany and Ireland plus a fully published subprocessor list where the one US processor (Stripe) is named with its legal basis — that's anchor-8 hygiene — but the contracting entity is Swiss, not EU, ownership is unknown, and EU residency isn't confirmed as a standard commitment. Switzerland may be adequacy-recognised; for an EU procurement it still isn't an EU entity. 2 3 4
The Security Officer
Servers in Germany and Ireland, a published subprocessor list with locations and transfer safeguards, and ISO 27001/27701 certification are close to the 8 anchor — but the contracting entity is Wire Swiss GmbH in Zug, with Wire Germany GmbH a mere Article 27 representative, and Stripe processes payments in the USA. A Swiss entity with GDPR exposure and a transparent chain earns a solid middle score, not a high one. 3 4
The Works Council Advocate
The substance is largely there: servers in Germany and Ireland, a full published subprocessor list with locations, and the one US processor (Stripe) named with its transfer safeguards and DPF certification. But the contracting entity is Wire Swiss GmbH in Zug, with Wire Germany GmbH existing only as an Article 27 representative — the anchor's named failing condition — and ownership is unknown. European in substance, not in contracting party; five. 3 4
The Compliance Counsel
Message hosting sits in Germany and Ireland with a published, located subprocessor list in which the one US processor (Stripe) is named alongside its transfer safeguards — but the contracting entity is Wire Swiss GmbH in Zug, Wire Germany GmbH exists only as an Article 27 representative, and ownership is unknown. The on-premises and data-sovereignty editions are the escape hatch that keeps this above the middle of the scale. 1 3 4
The Platform Engineer
Hosting is EU as standard (servers in Germany and Ireland, AWS EU) and the subprocessor list is genuinely published down to Stripe in the USA with DPF certification named — better than most. But the contracting entity is Wire Swiss GmbH, with Wire Germany GmbH existing only as an Article 27 representative, so the EU-entity condition fails, and the sovereignty pipeline could not confirm data residency on the vendor's own pages; the on-prem option that would moot all this is gated behind Enterprise sales. 3 4
The Skeptic
Servers named in Germany and Ireland and a full subprocessor table with locations and DPF/SCC legal bases — Stripe in the USA is named rather than hidden, which is better than most. But the contracting entity is Swiss, not EU, Wire Germany GmbH is only an Article 27 representative, ownership is unknown, and the self-hosted option that would remove the question is gated behind unpriced Enterprise. 3 4 1 2
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.
5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.
8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.
10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.
The Team Lead
Free (5 people) and SMB (€7.45/person/month annual, €8.94 monthly, up to 100) are public with the billing period stated, and guests plus SSO/SCIM sit in the priced tier rather than behind an upsell. But everything my compliance team would ask about — data sovereignty, federation, ID-Shield, on-prem — is 'Custom' above 100 people, and history limits, storage and VAT treatment go unstated. 2
The Security Officer
€7.45 per person/month (€8.94 monthly) with SSO, SCIM and guest roles included is genuinely computable up to 100 people — better than the usual trick of hiding SSO in an unpriced tier. But data sovereignty, federation, ID-Shield and on-premises sit in a custom-priced Enterprise tier, and VAT treatment, terms and storage limits are unstated, so the invoice a regulated buyer actually needs remains a sales conversation. 2
The Works Council Advocate
Free (5 people), SMB at €7.45/person/month annual or €8.94 monthly with SSO, SCIM and guest roles included, billing period stated — so a 100-person invoice is computable. But every organisation above 100 people, which is where the works councils I represent live, gets 'Custom', holding federation, data sovereignty and on-prem hostage to a sales conversation, and VAT, minimum terms and guest pricing are unstated. A clean five, no more. 2
The Compliance Counsel
Free and SMB tiers are priced per person with billing periods stated (€7.45 annual, €8.94 monthly) and SSO/SCIM included at the paid tier — but everything a regulated buyer like me actually needs, data sovereignty, federation, on-premises support, sits in unpriced 'Custom' Enterprise terms, and VAT treatment plus history and storage limits are unstated. 2
The Platform Engineer
Free (5 users), SMB at €7.45/person/month annually or €8.94 monthly with billing period stated and SSO/SCIM included — but everything a compliance-driven buyer actually wants priced (federation, ID-Shield, data sovereignty, on-prem deployment support) sits in an unpriced Enterprise tier above 100 people. VAT treatment, storage limits, guest pricing and minimum term are all unstated, so the annual invoice is not computable from public pages alone. 2
The Skeptic
Per-user maths is public and clean up to 100 people — €7.45/person/month billed annually, €8.94 monthly, and SSO/SCIM included at that tier rather than enterprise-gated. But federation, data sovereignty, ID Shield and on-prem all sit in 'Wire for Enterprise — Custom', VAT treatment and minimum term are never stated, so the invoice for the regulated 300-person buyer this product courts is a sales conversation. 2
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in CH | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 3 Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 4 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. The claim appears only in marketing copy on the security and MLS pages, not in a DPA or subprocessor list, and the unnamed hosting providers hold US federal certifications (FedRAMP, FIPS 140-2) suggesting an American provider.
- Weak sourcing — Subprocessors. Zendesk is US-headquartered and is the only provider explicitly named; the hosting providers are not named, though their FedRAMP and FIPS 140-2 certifications suggest a US provider, and the push services APN/FCM (Apple/Google) are used for notifications but Wire states no message data is shared with them.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 18 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 10 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 9 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 support fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (14)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage wire.com Checked 15 Sep 2026 Details →
- 2 Pricing wire.com Checked 15 Sep 2026 Details →
- 3 Security page wire.com Checked 15 Sep 2026 Details →
- 4 Privacy policy wire.com Checked 30 Sep 2026 Details →
- 5 Imprint wire.com Checked 30 Sep 2026 Details →
- 6 Channels, threads & search — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 7 Channels, threads & search — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 8 Encryption & access control — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 9 Encryption & access control — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 10 Retention, discovery & co-determination — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 11 Retention, discovery & co-determination — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 12 Deployment & data custody — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 13 Integrations & extensibility — found from sitemap wire.com Checked 1 Oct 2026 Details →
- 14 Integrations & extensibility — found from sitemap wire.com Checked 1 Oct 2026 Details →