Business Instant Messaging
Zulip
Rest of world Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 2 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Kandra Labs, Inc. · zulip.com
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Zulip (Kandra Labs, Inc.) is an open-source business instant messenger whose bench profile turns on who runs the servers. Its high point is deployment & data custody at 9: a 100% open-source auditable codebase, self-hosting offered, and a vendor-documented path to "move freely between Zulip Cloud hosting and your own servers", with importers from Slack, Teams, Mattermost and Rocket.Chat. Its low point is sovereignty at 2-3: the cloud service is "hosted and operated in the United States" by a San Francisco entity, Google Analytics and Stripe are named subprocessors, and the evidence evidences no EU residency option. Retention, discovery & co-determination sits flat at 4 — retention policies are a Standard-tier feature, but the judges found no audit log, no legal hold and unstated retention granularity. Encryption & access control at 5-6 shows granular permissions and 100+ authentication options but no end-to-end encryption of message content, only of push notifications. Judges did not meaningfully split — no disagreements above threshold — and persona-weighted totals span 4.9 (works council) to 6.5 (team lead).
Speaks for it
- Deployment & data custody scores 9 on a 100% open-source, auditable codebase with self-hosting offered
- Documented export/import tools to 'move freely between Zulip Cloud hosting and your own servers', with importers from Slack, Teams, Mattermost and Rocket.Chat
- Public per-user pricing with tier boundaries: retention policies from Standard ($6.67/user/month billed annually), SSO/SCIM at Plus ($10, 10-user minimum)
- Granular permissions by channel, role and user group, with 100+ authentication options and guest scoping
- Topic-based threading with move-message and resolve-topic operations, and history limits documented per tier (10,000 messages of search history on Free)
Held against it
- sovereignty scores 2-3: cloud services 'hosted and operated in the United States', with no EU residency option evidenced in the evidence
- Retention, discovery & co-determination scores 4: no audit log, no legal hold, retention granularity unstated
- No end-to-end encryption of message content; the sole E2EE claim covers mobile push notifications
- Named subprocessors are Google Analytics and Stripe, and Zulip declares itself the controller of personal data
- VAT treatment, minimum term and guest pricing unstated; AD/LDAP sync sits behind 'please inquire'
Best for
- You can run your own servers and want full custody of your chat data — the open-source self-hosted path with export/import removes the cloud-residency question
- Your team's conversations are long and branching, and you need topic-based threading with move-message and resolve-topic operations
- You are an open-source project, academic research group or small non-profit that may qualify for sponsored Standard access
- You are migrating from Slack, Teams, Mattermost or Rocket.Chat and need documented importers
Avoid if
- You need EU data residency from a cloud vendor — ask the vendor: the public pages we read do not show it
- You need audit logs, legal hold or eDiscovery export for a legally defensible archive
- You require end-to-end encryption of message content — only mobile push notifications claim E2EE
- You depend on an app platform with interactive components and a bot account model — the evidence evidences none
The scores
Channels, threads & search
Show reasoningHide reasoning
How this is scored
The daily surface: channel model, threading, mentions, files, and whether search can find a decision made eighteen months ago.
0 — Flat group chats with no threads; search covers recent messages only, and history is capped.
3 — Channels and direct messages with basic search, but threading is awkward or absent and file handling is a plain attachment list.
5 — Public and private channels, real threads, mentions and reactions, file sharing with previews, and full-text search across the whole history.
8 — Cross-organisation or guest channels with clear boundaries, message editing history, pinned and saved items, search with filters by channel, person and date, and a documented history limit or none at all.
10 — The archive is a working knowledge base: search that ranks well across years, threads that stay readable, channel lifecycle management (archive, rename, merge) without losing history, and export of a conversation in a form a human can read.
The Team Lead
Topic-based threading is exactly what I need to keep conversations readable, and you can move messages between channels and topics, resolve topics, and keep unlimited search history on paid plans (10k cap stated on free) — tidying without losing history. Held below 8 because the evidence says nothing about search filters by channel/person/date, pinned or saved items, message editing history, or mentions and reactions, and export is whole-organisation rather than a readable per-conversation export. 2 3
The Security Officer
Topic-based threading with move-message and resolve-topic operations is a strong daily surface, and history limits are documented rather than hidden (10,000 searchable messages on Free, unlimited on Standard). It stops short of the knowledge-base anchor because nothing evidences message-edit history, search filters, or an export a human can read — the admin export exists to seed another Zulip server. 2 3
The Works Council Advocate
Topic-based threading with move-messages and resolve-topics is the strongest threading model on this panel, and the history limit is honestly documented (10,000 messages of search history on Free, unlimited from Standard). But the evidence is silent on pinned and saved items, message-edit history and filtered search, so an eighteen-month-old decision is only reliably findable if the employer pays for Standard. 2 3
The Compliance Counsel
Channels with topic-based threading, per-channel permissions, message moving, guests with scoped user-list visibility, and unlimited search history on paid plans give me most of what a court-ready archive surface needs. But the evidence says nothing about message edit history, pins, or search filters by channel, person and date — the things that let me reconstruct who decided what and when — so I cannot put it at the top anchor. 2 3
The Platform Engineer
Channels, topic-based threading, and unlimited search history on paid plans are confirmed, plus message move/resolve and guest scoping. The evidence is silent on mentions, reactions, pins, edit history, search filters and channel lifecycle — all anchor-8 material — and the Free plan caps search at 10,000 messages. A full org export exists for archival, but nothing evidences the archive as a ranked, years-deep knowledge base. 2 3
The Skeptic
Topic-based threading is the realest thing here — messages move between channels and topics, topics resolve, and the history cap is honestly documented: 10,000 searchable messages on Free, unlimited from Standard. But the evidence never shows search filters by person or date, edit history, pins, or file previews, and I don't award those for free. 2 3
Encryption & access control
Show reasoningHide reasoning
How this is scored
What is encrypted and against whom, plus who can reach which room. Judged on documented mechanism, since "encrypted" in this category usually means the vendor holds the keys.
0 — Transport encryption only, undocumented; no role model beyond admin, guests indistinguishable from members.
3 — TLS and encryption at rest with vendor-held keys, basic roles, and guest access that mostly works.
5 — The above plus configurable roles per channel, SSO, guest accounts with scoped visibility, and a clear statement of what the vendor can read.
8 — Optional end-to-end encryption for direct messages or private rooms with the trade-offs named, device verification, session management an admin can revoke, and documented key handling.
10 — End-to-end encryption as a first-class mode — documented or open cryptography, cross-device key management that ordinary users survive, identity verification, and the vendor stating plainly what it cannot decrypt.
The Team Lead
TLS plus encryption at rest with vendor-held keys, granular permissions per channel, role and user group, SSO via SAML/OIDC with 100+ options, SCIM, guests with limited user-list visibility, and admins who can revoke or reset any user's credentials — that clears the 5 anchor. But there is no end-to-end encryption for messages anywhere in the evidence (only push notifications claim E2EE), no device verification, and no plain statement of what the vendor can read beyond 'Zulip will be the controller' — the auditable open-source codebase is the only softener. 2 3
The Security Officer
Access control is the strong half: per-channel posting and DM permissions, custom groups, scoped guests, SAML/OIDC/Entra SSO, and an admin who can revoke any user's credentials. But there is no message E2EE anywhere in the evidence — the only end-to-end encryption claimed is for push-notification payloads — no device verification, and no plain statement of what the vendor can read, which caps it below the E2EE anchors. 2
The Works Council Advocate
TLS, encryption at rest with vendor-held keys on Cloud, genuinely granular permissions (per channel, per role, per user group), scoped guests and SSO are all documented, plus admin revocation of credentials. But there is no message-level end-to-end encryption — the sole E2EE claim covers push notifications — and no statement of what the vendor itself can read. 2
The Compliance Counsel
TLS and encryption at rest, granular permissions by channel, role and user group, SSO via SAML/OIDC/Entra, scoped guests, and admin credential revocation are documented and real. What is missing is any end-to-end encryption of messages — the only E2EE claim covers mobile push notification content — and no plain statement of what the vendor can read, which matters when Zulip declares itself the controller of personal data. 2 3
The Platform Engineer
TLS, encryption at rest, admin credential revocation, SAML/OIDC/Entra SSO, and a permission model well past rubric level 5 — channel-level posting rules, user groups, per-channel and per-user customization. No end-to-end message encryption, device verification or documented key handling appears anywhere, so 8 is unreachable; 'end-to-end encrypted' push notifications is a narrow claim, not message E2EE. The 100% open-source auditable codebase is the implicit answer to what the vendor can read, and implicit is all it is. 2
The Skeptic
The only 'end-to-end encrypted' sentence in this sheet is about mobile push notifications, not message content; what's documented for content is TLS plus encryption at rest with vendor-held keys. Granular per-channel permissions, 100+ SSO options and guest scoping earn the mid mark, but there is no E2EE mode for any conversation, no device verification, and no plain statement of what the vendor can read. 2
Retention, discovery & co-determination
Show reasoningHide reasoning
How this is scored
The archive as a legal object: retention policies, export for discovery, audit, and the monitoring features a works council will ask to have switched off.
0 — No retention policy, no export beyond a manual copy, no audit log, and presence or activity analytics that cannot be disabled.
3 — Manual export of some data and a global history limit, but no per-channel retention, no audit log and no admin control over analytics.
5 — Configurable retention per channel or workspace, admin export in a documented format, an audit log of administrative actions, and status or presence that a user can control.
8 — Legal-hold and eDiscovery export including edits and deletions, retention executed per policy and evidenced, full admin audit trail, and activity analytics switchable off organisation-wide.
10 — Built to pass a works agreement and a subpoena on the same day: granular retention with documented deletion, discovery export a lawyer can use, complete audit, and no individual-level productivity scoring anywhere in the product.
The Team Lead
Message retention policies exist on the Standard plan and org admins can export all organisation data in a documented format that imports into a self-hosted server — that half is genuinely solid. But the evidence is silent on any audit log, on legal hold or eDiscovery export including edits and deletions, and on whether the usage statistics charts can be switched off organisation-wide; 'GDPR compliant HIPAA compliant' is a badge, not a mechanism. 2 3
The Security Officer
Retention policies are a priced Standard feature and org admins can export all data (password hashes excluded), which clears the export bar. But the evidence evidences no audit log of administrative actions, no legal hold or eDiscovery, unspecified retention granularity, and no user control over presence — the archive is not yet a defensible legal object. 2 3
The Works Council Advocate
The good half: message retention policies on Standard and an organisation-admin export (without password hashes) usable for archival or moving to self-hosting. The bad half for a works agreement: no audit log of administrative actions is evidenced, no legal-hold or eDiscovery export, no user-controlled presence, and account deletion leaves your messages in the log as 'Deleted User' — deletion that renames rather than removes. 2 3
The Compliance Counsel
Message retention policies are listed as a Standard-plan feature and organization administrators may export all Zulip data for archival purposes, which is the raw material of a discovery workflow. But the granularity of retention is unstated, there is no evidence the export captures edits and deletions, no legal hold, and — decisive for me — no audit log of administrative actions anywhere in the evidence; silence here means I cannot assume the trail survives the admin. 2 3
The Platform Engineer
Standard plans carry message retention policies and org admins get a documented full-data export for archival or self-hosted import, which clears rubric level 3. Nothing evidences per-channel retention granularity, an admin audit log, legal hold or eDiscovery export, and 'usage statistics charts' come with no stated off-switch — exactly what a works council asks to have removed. As a self-hoster I could audit the database myself, but the product surface shown here does not. 2 3
The Skeptic
Retention policies appear as one line on the Standard tier with no granularity shown, and the Free plan's 10,000-message search cap is the de facto retention. Org-admin export of all data for archival is real, but there is no audit log, no legal hold, and 'usage statistics charts' arrive with no evidenced switch to turn them off — a works council will ask, and the evidence has no answer. 2 3
Deployment & data custody
Show reasoningHide reasoning
How this is scored
Whether the customer can hold their own archive: self-hosting, private cloud, open source, federation, and what an exit actually looks like.
0 — Cloud-only, proprietary, with export limited to a partial archive.
3 — Cloud-only, but with a documented full export in an open-ish format.
5 — A private-cloud or dedicated-instance option, or a self-hosted edition that lags the cloud significantly; full export documented.
8 — A genuine self-hosted edition close to feature parity, or open-source core with a documented upgrade path, plus complete export including files and metadata.
10 — Custody is the customer's: open-source or source-available server, self-hosting supported as a first-class deployment, open protocol or federation, and a migration path in and out that the vendor documents rather than resists.
The Team Lead
Custody is effectively the customer's: a 100% open-source, auditable server, self-hosting offered, and 'you can move freely between Zulip Cloud hosting and your own servers' with importers from Slack, Teams, Mattermost and Rocket.Chat — migration in and out is documented rather than resisted. Only kept from 10 because there is no native federation or open protocol (Matrix is a bridge) and some cloud capabilities like AD/LDAP sync sit behind 'please inquire'. 1 2 3
The Security Officer
Custody is genuinely the customer's: a 100% open-source codebase, first-class self-hosting, and a vendor that states you 'can move freely between Zulip Cloud and your own servers' — a migration path documented rather than resisted, with importers from Slack, Teams, Mattermost and Rocket.Chat. Only the absence of any open-protocol or federation evidence keeps it off the top anchor. 1 2 3
The Works Council Advocate
This is the answer to the custody question: a 100% open-source, auditable server, self-hosting offered as a real deployment, and the vendor's own words that you 'can move freely between Zulip Cloud hosting and your own servers with our high quality export and import tools', including import from Slack and Teams. Only the absence of any evidenced federation or open protocol keeps it from full marks. 1 2 3
The Compliance Counsel
This is the product's strongest answer to my concerns: a 100% open-source auditable codebase, self-hosting offered as a first-class deployment, and an explicit, vendor-documented two-way path — full export/import between Zulip Cloud and your own servers, plus importers from Slack, Teams, Mattermost and Rocket.Chat. The only gap against the top anchor is any evidence of an open protocol or federation, so I stop just short of 10. 1 2 3
The Platform Engineer
This is the product's spine: 100% open-source auditable codebase, self-hosting offered as a deployment, and a vendor documenting migration both ways — 'move freely between Zulip Cloud hosting and your own servers' — with full export excluding only password hashes. Comprehensive server-administrator documentation and hourly-billed implementation work make this a supported deployment, not a hobby build. Only the absence of an open wire protocol or federation keeps it from 10: the Matrix bridge is a bridge, not a protocol. 1 2 3
The Skeptic
The strongest part of the product: a 100% open-source, auditable codebase, self-hosting offered, and a vendor that says you can move freely between Zulip Cloud and your own servers with export/import tools. The export is 'all Zulip data' minus password hashes and usable as a self-host import. Only the absence of any federation or open-protocol evidence, and 'please inquire' on imports from other chat products, keep it from full marks. 1 2 3
Integrations & extensibility
Show reasoningHide reasoning
How this is scored
Bots, webhooks, app framework, identity — whether the chat becomes the place work is noticed, and whether that is buildable without a partner agreement.
0 — No API, no webhooks, no bots.
3 — Incoming webhooks and a handful of native integrations; no bot framework, no documented limits.
5 — Documented REST API, incoming and outgoing webhooks, slash commands, a bot account model, and SSO.
8 — A proper app framework with interactive components, event subscriptions with retries, SCIM provisioning, documented rate limits and a sandbox.
10 — A platform: versioned API with a deprecation policy, an app directory or plugin system with permissions a customer can audit, and integrations the vendor maintains rather than lists.
The Team Lead
A documented REST API, custom webhooks, 130+ native integrations plus thousands via Zapier/IFTTT, bridges to Slack, Teams and Matrix, email bridge, an AI/LLM integration, SCIM user and group sync, and stated API rate limits — the chat can plausibly become where work gets noticed. What the evidence never evidences: a bot account model, an interactive app framework, event subscriptions with retries, a sandbox, or a versioned API with a deprecation policy. 1 2
The Security Officer
A documented REST API, custom webhooks, 130+ native integrations, SCIM user and group sync, published API rate limits, and bridges to Slack, Teams and Matrix cover most of the mid anchors. What the evidence does not evidence is a real app framework — interactive components, event subscriptions with retries, a sandbox — or any bot-account model. 1 2
The Works Council Advocate
A documented REST API, custom webhooks, 130+ native integrations, bridges to Slack/Teams/Matrix plus email, SCIM user and group sync and 100+ auth options give a solid, buildable surface without a partner agreement. Nothing evidences an app framework with interactive components, event retries or a sandbox, and AD/LDAP sync sits behind 'please inquire'. 1 2
The Compliance Counsel
A documented REST API, custom webhooks, SCIM user and group sync, API rate limits, 130+ native integrations and bridges to Slack, Teams and Matrix make the surface buildable without a partner agreement. The evidence is silent on a real app framework with interactive components, a bot account model, and any sandbox or deprecation policy, which keeps it below the platform anchors. 2
The Platform Engineer
A documented REST API, custom webhooks, 130+ native integrations, bridges to Slack/Teams/Matrix, SCIM user and group sync, and documented API rate limits put this solidly past rubric level 5. But the evidence shows no app framework, interactive components, bot account model, sandbox or API deprecation policy, and no plugin system whose permissions a customer could audit. Open source lets me extend in-tree, but that is surgery, not a platform contract. 1 2
The Skeptic
A documented REST API, custom webhooks, SCIM user and group sync, and API rate limits named in the security list put half the anchor-8 checklist on the table. But no bot account model, slash commands, event subscriptions or interactive components appear anywhere in the evidence, and '1000s of integrations via Zapier' is somebody else's directory, not a framework. 1 2
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the archive and its metadata live, who the contracting entity is, which subprocessors touch it. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it.
0 — Non-EU vendor and contracting entity, hosting unstated or non-EU, subprocessors unnamed.
3 — EU data residency offered for message content while metadata, search indexes or support tooling remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting as standard and an EU contracting entity, but parts of the chain — notifications, AI features, analytics — are non-EU without an explained safeguard.
8 — EU hosting on named infrastructure, EU contracting entity, full subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: vendor, entity, hosting and every subprocessor European, certification published, and a self-hosted option that removes the question.
The Team Lead
The cloud service is 'hosted and operated in the United States' by Kandra Labs, Inc. of San Francisco, with no EU data residency option anywhere in the evidence, Google Analytics cookies and Stripe in the chain, and the pipeline confirms legal entity, ownership and residency as unknown or US. Named EU and UK representatives, GDPR claims, and the genuinely first-class open-source self-hosted route — which removes the question entirely — are the only things lifting this off the floor. 2 3
The Security Officer
US vendor and contracting entity in San Francisco, services 'hosted and operated in the United States', and the named subprocessors — Google and Stripe — are American; no EU residency is offered anywhere in the evidence, beyond a Cork-based GDPR representative. The named subprocessors and the open-source self-hosting escape hatch keep this off the floor, but a European cloud buyer gets no safeguard beyond paperwork. 2 3
The Works Council Advocate
On the record: services 'hosted and operated in the United States', a San Francisco contracting entity, and named subprocessors Google and Stripe — the European touches are an EU representative and GDPR checkboxes. Self-hosting on our own infrastructure is the only real escape from US custody, and it exists; as a cloud purchase this is close to the bottom of the scale. 1 2 3
The Compliance Counsel
Kandra Labs, Inc. of San Francisco is the contracting entity, the services are 'hosted and operated in the United States', and the only named subprocessors — Google Analytics and Stripe — are US companies, with no EU residency option offered anywhere in the evidence. The named subprocessors and the EU/UK representatives lift it just above zero, and the open-source self-hosting option lets a determined customer remove the question entirely, but as a cloud buyer I get no European custody. 3 2
The Platform Engineer
Kandra Labs, Inc. of San Francisco hosts the cloud 'in the United States' through its service providers, with Google Analytics and Stripe named as US subprocessors — rubric level 0 territory, saved from zero only because subprocessors are named and a GDPR claim plus EU/UK representatives are on file. No EU residency option is evidenced at all, which is worse than rubric level 3's partial residency. The redemption is operational, not contractual: the open-source self-hosted route removes the question, but the cloud product as sold is US-held. 1 3
The Skeptic
The cloud archive is 'hosted and operated in the United States' by a San Francisco entity, with no EU residency offered anywhere in the evidence. Google Analytics and Stripe are named as service providers and an EU representative exists, which keeps this just off the floor — but self-hosting is a deployment story, not a sovereign cloud, and the sovereignty pipeline itself confirms every attribute as unknown. 1 3
Pricing transparency
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their headcount — including the retention, compliance and guest features they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-user headline exists, but the tier where retention control, SSO or compliance export begins is unstated.
5 — Per-user prices public with billing period stated, but at least one commonly needed capability (unlimited history, SSO, eDiscovery) sits in an unpriced enterprise tier.
8 — Every tier priced publicly with per-user maths, history and storage limits, feature boundaries, minimum term and VAT treatment stated; self-hosted licensing priced too where offered.
10 — Complete price computability: annual invoice derivable for a given headcount and deployment choice, including guest users, storage and any per-instance licence.
The Team Lead
I can compute my annual invoice from one public page: Free (10,000 messages of search history, 5 GB total), Standard at $6.67/user/month annually with unlimited history and retention policies, Plus at $10 with SSO, SCIM and guest scoping, storage and minimum-user limits all stated. Missing for 8: VAT treatment and minimum term are never stated, and AD/LDAP sync hides behind 'please inquire' rather than a priced tier boundary. 2
The Security Officer
Free, Standard ($6.67/user/month annual) and Plus ($10) are all publicly priced with storage and search-history limits and clear feature boundaries — retention lands at Standard, SSO/SCIM at Plus — so a buyer can compute most of the invoice. VAT treatment, minimum term and guest pricing are unstated, AD/LDAP sync is 'please inquire', and self-hosted licensing is not priced on these pages, which caps it below full computability. 2
The Works Council Advocate
The headline maths work publicly: $6.67/user/month annually at Standard where retention policies and unlimited history begin, $10 at Plus where SAML SSO and SCIM begin, with storage limits, history limits and the 10-user minimum stated per tier. VAT treatment, guest pricing and self-hosted licence pricing are absent, and LDAP sync is inquiry-only, so the annual invoice is computable only for the plain case. 2
The Compliance Counsel
Per-user prices with billing period, storage and search-history limits, and a ten-user minimum are public, and — unusually — the compliance-relevant features are priced: message retention policies sit in Standard at $6.67/user/month and SSO/SCIM/guest controls in Plus at $10. What keeps me below 8 is that VAT treatment is never stated, guest-user billing maths are absent, and AD/LDAP sync and non-standard chat imports are 'please inquire', so the annual invoice is computable only down to those caveats. 2 1
The Platform Engineer
Free, Standard ($6.67 annual/$8 monthly) and Plus ($10 annual/$12 monthly, 10-user minimum) are public with per-user maths, storage and search-history limits, and clear feature boundaries including where retention and SSO begin. VAT treatment is unstated, hourly consulting rates are unpriced, guest-user pricing is absent, and LDAP sync sits behind 'please inquire'. You can compute the cloud invoice for a headcount, but not the whole annual bill. 2
The Skeptic
The things I hunt for are priced, not hidden: retention starts at Standard ($6.67/user/month annually) and SSO/SCIM at Plus ($10) with a stated 10-user minimum, and history and storage limits are published per tier. Held below the top band because AD/LDAP sync is 'please inquire' on paid plans, services are billed hourly with no rates, and VAT treatment, EUR pricing and minimum term are unstated. 1 2
European sovereignty — proven facts
2 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined ⚠ unverified | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | US by default ⚠ unverified | 0/3 pts | 3 Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Data residency. Self-hosting is offered as a sovereignty alternative, but no EU region is offered for Zulip Cloud itself, and the policy adds data may go to the U.S. "and possibly other countries".
- Weak sourcing — Subprocessors. The hosting and communications providers are mentioned but not named (a "Subprocessors for Zulip Cloud" page is listed but not included in the excerpts), Stripe may process EU payments through a European entity, and Google Analytics is a website-only tool and therefore excluded.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (3)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.