Project Management & Collaboration
OpenProject
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by OpenProject GmbH · www.openproject.org
Compare with Jira → Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
OpenProject — OpenProject GmbH of Berlin, GPLv3, Project Management & Collaboration — scored strongest on sovereignty and pricing transparency, and weakest on reporting, a flat 0, and collaboration depth. Pricing is unusually concrete — per-user prices, 25/100/250 seat minimums printed, a worked $2,175/year example — but tax and billing-period treatment go unstated and Corporate is on request. No split between the judges was large enough to flag; the widest spreads are onboarding effort, over how far the free Community edition offsets the 25-seat paid floor, and support & documentation, between crediting published per-tier support hours and finding no evidenced documentation.
Speaks for it
- Sovereignty scores 6-7 on substance: OpenProject GmbH in Berlin, a named German DPO, an Article 28 DPA signable in the cloud, SCCs, and an EU-hosted Enterprise Cloud.
- GPLv3 with code public on GitHub makes on-premises self-hosting a permanent exit from the cloud product.
- Pricing transparency scores 6-7: every self-serve tier's per-user price sits on the page with seat minimums (25/100/250) and a worked example of $2,175 for 25 Basic users over a year.
- Self-serve entry is real: a free Community edition with no seat minimum and 14-day trials on cloud and on-premises that are 'risk-free without cancellation'.
- The admin surface is evidenced: fine-grained role-based access at individual project level, two-factor authentication, configurable session timeouts, and AES-256 encryption at rest including backups.
Held against it
- Reporting scores 0 with no spread — no report, dashboard, time, budget or export fact appears anywhere in the registry.
- Collaboration depth scores 2-3: role-based access is the only evidenced multi-user capability, with assignments, comments, shared timelines, dependencies and guest access all unevidenced.
- No help center, guides, changelog or support channel type is evidenced; support consists of published business-hours windows (support & documentation 2-4).
- The sole documented API checks whether a new release exists for self-hosted installs, and the Nextcloud Hub/openDesk integrations sit behind the 250-minimum Corporate tier priced on request.
Best for
- You need an EU-hosted cloud with a signable Article 28 DPA, SCCs and a named data protection officer for procurement review.
- You want a self-hostable GPLv3 tool as a permanent exit path and have the operations staff to run it.
- You want to cost seats without a sales call, using published per-user prices and printed seat minimums.
- You qualify for the vendor's special rates for educational institutions or NGOs.
Avoid if
- You need dashboards, time tracking, budgets or export paths — reporting scored 0 in the computed table.
- Your workflow depends on assignments, comments, shared timelines, dependencies or guest access — ask the vendor: the public pages we read do not show it
- You need a documented product API, webhooks or broad integrations — the only evidenced API is a release-version checker and Nextcloud/openDesk are gated to Corporate.
- You have fewer than 25 users and want paid support — the cheapest paid tier requires 25 minimum users and the free Community tier shows no support hours.
The scores
Collaboration depth
Show reasoningHide reasoning
How this is scored
How much real multi-person project work the tool carries: shared planning, assignments, dependencies, workload, comments, guest access.
0 — A personal task list; a second user has no defined place in it.
3 — Tasks can be shared and assigned, but planning stays per-person — no shared timeline, workload or dependency view.
5 — Solid shared projects with assignments, comments and at least one team-level planning view; gaps appear in cross-project or capacity planning.
8 — Team-level planning is first-class: cross-project views, workload/capacity, dependencies, guest or client access with sane permissions.
10 — Handles the full span from two freelancers to a structured department in one model — planning, capacity, permissions and client involvement all without workarounds.
The Data Protection Officer
Fine-grained role-based access at individual project level proves multi-user projects with defined places for a second user, so this is no personal list — but the registry evidences nothing about assignments, comments, shared timelines, dependencies, workload or guest access. The captured feature surface is all security and SSO, no collaboration. 4
The Bootstrapper
Fine-grained role-based access at individual project level tells me a second user has a defined place in a shared project, but the evidence evidences nothing about assignments, shared timelines, dependencies, workload or guest access. That clears rubric level 0 and stalls well short of 3. 4
The Enterprise Architect
The evidence confirms multi-user plumbing — fine-grained role-based access at individual project level and Google SSO — but not a single confirmed fact about shared planning: no assignments, no timeline, dependency or workload views, no comments, no guest access. I don't score category labels; I score evidence, and here a second user has a role but no evidenced shared planning model. 3 4
The UX Purist
Fine-grained role-based access at individual project level proves a second user has a defined seat, so this clears rubric level 0 — but that is the entire collaboration case the evidence makes. No assignment, comment, timeline, dependency or workload capability appears anywhere; planning depth is an empty screen from where I stand. 4
The Integrator
The only multi-user evidence in the registry is fine-grained role-based access at individual project level — real scaffolding, but nothing on assignments, comments, shared timelines, dependencies, workload or guest access. Everything above a shared-project floor is unevidenced, so I cannot go higher than the floor. 4
The Skeptic
The only multi-user machinery this sheet evidences is fine-grained role-based access control at project level — permissions, not collaboration. Not one fact covers assignments, comments, dependencies, timelines, workload or guest access, and the pricing page itemizes tier features without ever naming a collaborative one. Absence is the finding. 2 4
Reporting
Show reasoningHide reasoning
How this is scored
Whether the tool can answer questions about the work: progress, time, budgets, utilization — and export the answer.
0 — No reporting beyond looking at the board.
3 — Fixed per-project status views only; nothing aggregates across projects and nothing exports cleanly.
5 — Useful standard reports (progress, tracked time) with basic filters and CSV export, but limited customization and no budget/utilization depth.
8 — Configurable cross-project reporting incl. time, budgets and utilization, with dashboards and reliable exports.
10 — Reporting is a product in itself: custom report builder, scheduled delivery, API access to every metric the UI shows.
The Data Protection Officer
No report, dashboard, time, budget, utilization or export capability appears anywhere in the registry — the feature pages captured (pricing and security) list none, so I score by the absence anchor. Tellingly, the privacy policy documents log retention more thoroughly than anything here documents reporting on work. 2 4
The Bootstrapper
Not one fact on this sheet evidences a report, dashboard, time view, budget view or any export — even the pricing page's plan-by-plan feature list never mentions reporting. Silence scores as absence: nothing beyond looking at the tool itself. 2
The Enterprise Architect
The registry contains zero reporting facts — no progress, time, budget, utilization, dashboard or export capability appears anywhere on the captured pages, including the feature-bearing pricing and security pages. As far as this sheet is concerned, looking at the tool is the only reporting there is. 2 4
The UX Purist
Nothing on the evidence answers 'where is the work?' — no progress, time, budget or utilization view, no dashboard, no export path. The only API mentioned checks for new software versions, which reports on the vendor, not on the project; silence here is the answer. 3
The Integrator
The registry contains no reporting, dashboard, time-tracking, budget or export fact of any kind — the entire evidenced product surface is permissions, sessions and 2FA, and the only API on the evidence checks whether a new version exists. Absence is the whole answer; that's a 0. 3 4
The Skeptic
The pricing page itemizes every tier's features and the security page itemizes admin capabilities; neither mentions a single report, time view, budget, dashboard or export. The only 'API' on record is a release-version checker for self-hosted installs. Nothing here can answer a question about the work. 2 3 4
Integrations
Show reasoningHide reasoning
How this is scored
How well the tool connects to the rest of the stack: native integrations, calendar/comms hooks, API and webhooks, import/export paths.
0 — A closed box — no API, no integrations, CSV out if anything.
3 — A handful of marquee integrations, no public API or an API that covers a fraction of the product.
5 — The common set (calendar, Slack/Teams, file storage) plus a documented public API; automation platforms partially covered.
8 — Broad native catalogue, well-documented API and webhooks, first-class automation-platform support and real import paths from competitors.
10 — Ecosystem-grade: everything in 8 plus the tool is itself extensible (apps/plugins, AI/MCP surfaces) and exit via API export is complete.
The Data Protection Officer
A handful at best: Google SSO, OpenID Connect to Nextcloud Hub and openDesk on the top tier, mobile apps, and a release-check API for self-hosters that covers a fraction of the product. No evidence of a documented product API, webhooks, calendar or Slack/Teams hooks, or import paths. 2 3
The Bootstrapper
Google SSO and iOS/Android apps exist, but the only native integrations named — Nextcloud Hub and openDesk — are locked behind the 250-minimum-seat Corporate tier, and the one documented API merely checks for new release versions on self-hosted installs. A handful of marquee hooks, no public product API or webhooks in evidence. 2 3
The Enterprise Architect
The only API in evidence is a release-version checker for self-hosters, and the Nextcloud Hub/openDesk hooks sit behind the 250-seat Corporate tier alongside Google SSO and mobile apps. No documented public product API, no webhooks, no calendar or comms integrations, no import/export paths — a handful of marquee connectors and an API covering a sliver of the product. 2 3
The UX Purist
A handful of marquee hooks — Google SSO, Nextcloud/openDesk via OpenID Connect gated to the 250-user Corporate tier, mobile apps — plus a version-check API that covers zero of the product. That is rubric level 3 almost verbatim; public GPLv3 code on GitHub is extensibility in principle, but the evidence documents no plugin or product-API surface to hang it on. 2 3 4
The Integrator
The evidenced native catalogue is two corporate-gated integrations (Nextcloud Hub via OIDC, openDesk) plus Google SSO and mobile apps, and the sole 'API' is a version-check endpoint — solidly rubric level 3. I nudge to 4 only because GPLv3 with code public on GitHub means the ecosystem cannot be closed: no product API, webhooks or import paths are evidenced, but the source itself is the integration surface and the exit. 2 3 4
The Skeptic
A literal handful: Google SSO, iOS/Android apps (running on Google Firebase) and Nextcloud/openDesk hooks — the latter gated to the 250-seat, on-request Corporate tier. The sole API evidenced is a release-version checker; no calendar, Slack/Teams, storage, webhook or documented product API appears anywhere. Marquee names, no real API — the anchor-3 definition, minus even the partial API. 2 3
Onboarding effort
Show reasoningHide reasoning
How this is scored
Time and friction from signup to first real value for a small team, without paid services.
0 — No self-serve path — onboarding starts with a sales call and an implementation project.
3 — Self-serve exists but the first project requires configuration a newcomer cannot judge yet (workflows, custom fields, permissions) before anything works.
5 — A team gets a first project running within a day; trial requires payment details or key steps live behind docs.
8 — Signup to working project inside an hour: guided setup, sensible defaults, templates, trial without payment details.
10 — Minutes to value even for non-tool-people, importers pull existing work in, and the tool teaches its own advanced features as the team grows into them.
The Data Protection Officer
Self-serve is real and clean: a free Community edition with no seat minimum, and 14-day cloud or on-premises trials 'risk-free without cancellation' — no payment-details hostage. But nothing evidences guided setup, templates or importers, and the permanent free path means operating your own server. 2
The Bootstrapper
The free Community edition has no seat minimum and the 14-day trials are 'risk-free without cancellation', which reads as no card up front. But nothing evidences guided setup, templates or importers, and the genuinely free route is self-hosting — sysadmin work, not signup — so first real value lands somewhere inside a day, not an hour. 2
The Enterprise Architect
Self-serve is real: a free Community tier with no seat minimum and 14-day trials on both cloud and on-prem, risk-free without cancellation. But nothing evidences guided setup, templates, defaults or importers, the cheapest paid tier demands 25 seats and Premium jumps to 100, and the self-host path presupposes infrastructure a newcomer can't judge yet — a day-one tool, not an hour-to-value one. 2
The UX Purist
A genuinely free Community tier with no user minimum and a 14-day trial that is 'risk-free without cancellation' means no sales call and no card — real friction removed. But nothing evidences guided setup, templates or importers, and the on-premises mode is a deployment project, not minutes-to-value; I can credit the fast door, not the first hour behind it. 2
The Integrator
There is a genuine self-serve path — a free Community edition with no minimum and a 14-day 'risk-free without cancellation' trial — but nothing evidences guided setup, templates or importers, and the cheapest paid plan carries a 25-user minimum, which is real friction for exactly the small team this criterion is about. 2
The Skeptic
Self-serve is real: a free Community edition with no minimums and a 14-day trial 'risk-free without cancellation', which at least implies no card upfront. But the evidence is silent on guided setup, templates and importers, and the paid ladder starts at 25 minimum users — a five-person team cannot buy in at all. Day-one value is asserted by trial length, not evidenced. 2
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the company and the data actually sit: legal entity, ownership control, data residency, and subprocessor exposure to non-EU jurisdictions.
0 — Non-European vendor, data on US infrastructure under US law, no DPA worth the name.
3 — DPA and GDPR language present, but hosting defaults to the US or ownership sits outside Europe — compliance paperwork over substance.
5 — EU data residency is available and contractually fixed, but the vendor or its controlling owner is non-European, or core subprocessors put data within CLOUD Act reach.
8 — European company under European control with EU-resident data and a public DPA; remaining exposure is limited to identifiable subprocessors (e.g. a US hyperscaler's EU region) and is documented.
10 — European company, European control, EU-only data residency on European infrastructure, subprocessor list free of extraterritorial reach — verifiable, not asserted.
The Data Protection Officer
Substance over paperwork: OpenProject GmbH in Berlin, a named data protection officer, an Article 28 DPA signable in-product with SCCs, EU-resident Enterprise Cloud data, concrete deletion guarantees (90-day logs, instance purge six months after contract expiry), AES-256 at rest including backups, and a GPLv3 self-hosting escape hatch. 2 3 4
The Bootstrapper
Berlin-based GmbH, GDPR/BDSG baseline, an Article 28 DPA signable inside the product, EU-hosted Enterprise Cloud, and self-hosting as a full escape hatch. But 'all sub-processors are based in the EU' is vendor marketing, and the privacy policy itself names Google Firebase, hCaptcha (Delaware) and InnoCraft (New Zealand) — documented extraterritorial exposure that keeps this below the clean 8. 3 4
The Enterprise Architect
OpenProject GmbH in Berlin operating under GDPR/BDSG, an Article 28 DPA signable in-app, SCCs, a named DPO, EU-only cloud residency, and a GPLv3 self-host escape hatch — this survives procurement. 3 4
The UX Purist
A Berlin GmbH with EU-hosted Enterprise Cloud, an Article 28 DPA signable in-product, SCCs and external audits — plus GPLv3 self-hosting as a total exit — is substance, not paperwork. 2 3 4
The Integrator
The on-premises option under GPLv3 means full sovereignty is achievable by self-hosting, which keeps this at 7 rather than lower. 2 3 4
Support & documentation
Show reasoningHide reasoning
How this is scored
Whether a stuck user gets unstuck: docs quality, support channels and their availability per plan, and the health of the learning surface.
0 — No docs beyond marketing pages; support is a contact form that may answer.
3 — Docs exist but are thin or stale; support on entry plans is effectively email-only with slow turnaround.
5 — Searchable help center covering the core product; chat or email support on all plans with reasonable response times.
8 — Deep, current docs incl. onboarding guides and templates; fast chat support not gated to top tiers; visible changelog.
10 — Docs, academy, community and support so good they are a reason to buy; SLAs published, support quality independent of plan.
The Data Protection Officer
Support windows are published per plan (Mon-Fri, 9:30-4 ET on Basic) plus a security contact and advisories mailing list, which I credit. But no help center, documentation depth, chat channel or changelog is evidenced anywhere, and the free Community tier shows no support at all. 2 4
The Bootstrapper
Credit where due: every paid tier publishes its business-hours window right on the pricing page, and there's a security contact plus an advisory mailing list. But not a single fact evidences a help center, documentation, chat or SLA, and the free Community tier I'd actually run at 3 seats shows no support hours at all. 2 4
The Enterprise Architect
Support windows are published per tier — Mon-Fri business hours, as narrow as 9:30-4 ET on Basic — with a security contact and advisory mailing list, which is more structure than most publish. But the evidence evidences no help center, no docs of any kind, no changelog and not even a support channel type; published hours without a knowledge base does not get my two hundred users unstuck. 2 4
The UX Purist
Tiered support hours are published for every plan and there is a security contact plus an advisories mailing list — more than a contact form. But the evidence evidences no help center, no guides, no templates, no chat, no response times and no changelog; a GitHub repo is not a learning surface, and a stuck user's path to unstuck is undocumented. 2 4
The Integrator
No documentation surface is evidenced anywhere in the registry — no help center, no changelog, nothing I could point an integration engineer at — and support is business-hours-only, tier-gated (Basic gets the shortest window) with no channel stated. The security@ address and an advisory mailing list are the one healthy signal, which keeps me just above 0. 2 4
The Skeptic
The entire support record is four business-hours windows that literally scale with plan price, plus a security contact and advisory mailing list. Not one captured page evidences documentation, a help center, a changelog, chat, or any response-time commitment. Docs here aren't thin — they're unevidenced. 2 4
Pricing transparency
Show reasoningHide reasoning
How this is scored
Can a buyer determine the real, payable cost of the tool for their team before talking to anyone?
0 — No public pricing at all — every number sits behind "contact sales".
3 — Some tiers are public, but a deciding factor (seat minimums, mandatory add-ons, billing-period surcharge, tax treatment) only surfaces at checkout or in fine print.
5 — Self-serve tiers are publicly priced and the billing-period difference is stated, but the headline number still needs qualifying — e.g. annual-only headline, taxes excluded without saying so, or an opaque enterprise tier doing real work.
8 — Every self-serve tier is fully priced with billing periods and tax treatment plain on the page; only genuinely custom enterprise work lacks a number.
10 — Every tier including enterprise has a public price or published price formula, and the headline number is the number on the invoice.
The Data Protection Officer
Self-serve tiers carry public per-user prices with seat minimums stated on the page and even a worked example ($2,175/year for 25 Basic users), and the BIM add-on surcharge is public. Missing pieces: billing-period treatment (the example is annual with no monthly/annual split stated), tax treatment, and the Corporate tier doing real work behind 'on request'. 2
The Bootstrapper
The page answers instead of qualifying: every self-serve tier priced per user, seat minimums (25/100/250) printed rather than buried, a worked $2,175 example, discounts and free trials stated. Docked because Corporate is 'on request', tax treatment and monthly-vs-annual billing are never stated, and the 25-seat floor means my 3-seat team's cheapest paid reality is 25 users — disclosed, but still a value cliff. 2
The Enterprise Architect
Every self-serve tier carries a public per-user price with seat minimums stated plainly and a worked example that reconciles ($7.25 x 25 x 12 = $2,175), so I can cost 200 seats without a sales call. Docked for unstated tax treatment, an unclarified billing period behind the monthly figure, and Corporate 'on request' withholding the integrations an enterprise buyer actually wants. 2
The UX Purist
Every paid tier is priced per user with seat minimums stated on the page, a free tier exists, the BIM surcharge is public, and there is a worked example — $2,175 for 25 Basic users over a year — whose arithmetic matches the headline exactly. Kept from 8: billing-period options and tax treatment are never stated, and Corporate is on request; the 25-seat floor is a barrier for small teams, but at least it is an honest one. 2
The Integrator
Unusually open: every tier's per-user price sits on the page with seat minimums stated up front rather than in fine print (25/25/100/250), the BIM add-on is priced, discounts are named, and there's a worked example totalling $2,175 for 25 users over a year. What blocks rubric level 8 is that billing-period treatment (annual vs monthly) and taxes are never stated, and Corporate is quote-only. 2
The Skeptic
Unusually concrete for a vendor: per-user prices, seat minimums stated on the page (25/100/250), a quantified BIM surcharge, a free tier and a worked $2,175/year example. But billing-period differences and tax treatment are never stated, and the Corporate tier — the only home of the Nextcloud/openDesk integrations — is 'on request'. The headline number is close to the invoice, not the invoice. 2
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in DE | 3/3 pts | 5 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | Not determined ⚠ unverified | — | uncited Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 20 Aug 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency, Subprocessors. Not confirmed on the vendor’s own pages as captured.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 43 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 12 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 11 pricing facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 8 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 4 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 sovereignty dimensions could not be confirmed on the vendor’s own pages and are shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (15)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor homepage www.openproject.org Checked 5 Oct 2026 +3 earlier captures: 15 Sep 2026, 11 Sep 2026, 20 Aug 2026 Details →
- 2 Vendor pricing page www.openproject.org Checked 5 Oct 2026 Details →
- 3 Privacy policy www.openproject.org Checked 5 Oct 2026 Details →
- 4 Security page www.openproject.org Checked 5 Oct 2026 Details →
- 5 Imprint www.openproject.org Checked 5 Oct 2026 Details →
- 6 Collaboration depth — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 7 Collaboration depth — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 8 Reporting — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 9 Reporting — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 10 Integrations — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 11 Integrations — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 12 Onboarding effort — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 13 Onboarding effort — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 14 Support & documentation — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →
- 15 Support & documentation — found from sitemap www.openproject.org Checked 5 Oct 2026 Details →