Project Management & Collaboration
Taiga
EU-Made Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 3 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Kaleidos Open Source SL · taiga.io
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Taiga is a free and open-source project management tool from Kaleidos Open Source SL, offered as a cloud service with a self-hosting option. Its strongest scoring is sovereignty, where judges credited documented Madrid hosting at Digitalrealty's INTERXION MAD3 datacenter, ISO/IEC 27001:2013 and ENS certifications, and a Data Processor Agreement inside the public Terms of Service. Reporting and onboarding effort cluster at 4-5 — custom real-time reports with a CSV URL link on one side, a self-serve register path with a project import function on the other — though no dashboards, time, budget or utilization evidence appears anywhere. It is weakest on support & documentation, where the only evidenced channels are support@taiga.io and GitHub issue tracking, and collaboration depth, where 'Define team roles & permissions' is the whole multi-person story and assignments, comments, dependencies and workload are unevidenced. Integrations sits at 3-4 on 'Various integrations (partly through Zapier)' naming none. No split between the judges was large enough to flag — these ranges are score spread, not flagged splits.
Speaks for it
- sovereignty scores 5-7 on documented Madrid hosting at Digitalrealty's INTERXION MAD3 with ISO/IEC 27001:2013 and ENS certifications.
- A Data Processor Agreement sits inside the Terms of Service, and datacenter personnel are designed out of remote access to customer data.
- Onboarding effort scores 4-5 on a self-serve register form, social login and a project import function, with no sales gate evidenced.
- reporting scores 4-5 on custom real-time reports with a CSV URL link to your own data editor.
- 100% open source, with a self-hosting option for larger teams that need data on their own servers.
Held against it
- Support & documentation scores 2-3, evidenced only as support@taiga.io plus GitHub issue tracking, with no help center, chat, SLA or changelog anywhere in the capture.
- Collaboration depth scores 2-4, where 'Define team roles & permissions' is the only multi-person fact and assignments, comments, dependencies, workload and guest access are unevidenced.
- integrations scores 3-4, where 'Various integrations (partly through Zapier)' names nothing and no documented API or webhooks appear.
- sovereignty tops out at 7 because ownership and subprocessor exposure are marked unknown in the evidence and SCC language implies third-country transfers to payment, hosting, CRM and emailing providers.
- No cloud price, tier or billing period appears anywhere in the evidence despite payment forms proving a paid offering exists (pricing transparency 1-3, uncounted).
Best for
- You need a 100% open-source project management tool you can self-host with data on your own servers, and can live with email-plus-GitHub support.
- Your reporting needs end at refreshable CSV-URL exports into your own data editor rather than dashboards or time, budget and utilization tracking.
- You want EU-documented cloud hosting — Madrid, ENS and ISO-certified facility, DPA in the Terms of Service — and can verify ownership and subprocessors yourself during procurement.
Avoid if
- You need deep team planning — ask the vendor: the public pages we read do not show it
- You need a defensible support model with SLAs, a help center or response times for a large deployment — the evidence's own provenance also flags 'verify project liveness' (support & documentation 2-3).
- Your integration plan depends on a documented API, webhooks or named connectors — ask the vendor: the public pages we read do not show it
- You must know cloud seat prices, tiers and billing periods before evaluating — ask the vendor: the public pages we read do not show it
The scores
Collaboration depth
Show reasoningHide reasoning
How this is scored
How much real multi-person project work the tool carries: shared planning, assignments, dependencies, workload, comments, guest access.
0 — A personal task list; a second user has no defined place in it.
3 — Tasks can be shared and assigned, but planning stays per-person — no shared timeline, workload or dependency view.
5 — Solid shared projects with assignments, comments and at least one team-level planning view; gaps appear in cross-project or capacity planning.
8 — Team-level planning is first-class: cross-project views, workload/capacity, dependencies, guest or client access with sane permissions.
10 — Handles the full span from two freelancers to a structured department in one model — planning, capacity, permissions and client involvement all without workarounds.
The Data Protection Officer
The only multi-person evidence in the entire sheet is 'Define team roles & permissions' — real, but nothing evidences shared timelines, dependencies, workload views, comments, or guest access, so I cannot go above the shared-assignments tier. For a 'Project Management & Collaboration' product, the evidence is silent on almost everything this criterion measures, and silence caps it. 1
The Bootstrapper
Team roles & permissions give a second user a defined place in a shared project, so it clears the personal-list floor. But the evidence evidences no assignments, comments, shared timeline, dependencies, workload or guest access — team-level planning is asserted by category, not shown. 1
The Enterprise Architect
Confirmed as a shared project tool with team roles and permissions, but that is where the evidence stops. Nothing in the evidence evidences assignments, comments, dependencies, cross-project views, workload/capacity or guest access, so I cannot credit the team-level planning an 8-anchor product would show. 1
The UX Purist
Roles & permissions and a pitch at "larger teams or multiple small teams" prove a second user has a defined place, but nothing in the capture evidences assignments, comments, shared timelines, dependencies, workload or guest access — the machinery that separates team planning from a shared list is invisible. 1 2
The Integrator
The only collaborative machinery the evidence evidences is 'Define team roles & permissions' and public/private projects — a real multi-user product, but nothing on assignments, comments, shared timelines, dependencies or workload. Silence on every planning view beyond per-project means I can't go above shared-but-shallow. 1 2
The Skeptic
One marketing line — 'Define team roles & permissions' — is the entire multi-person story; the evidence is silent on assignments, comments, shared timelines, dependencies, workload and guest access. Roles imply a second user has a place in the tool, but I don't credit features the marketing couldn't be bothered to name. 1
Reporting
Show reasoningHide reasoning
How this is scored
Whether the tool can answer questions about the work: progress, time, budgets, utilization — and export the answer.
0 — No reporting beyond looking at the board.
3 — Fixed per-project status views only; nothing aggregates across projects and nothing exports cleanly.
5 — Useful standard reports (progress, tracked time) with basic filters and CSV export, but limited customization and no budget/utilization depth.
8 — Configurable cross-project reporting incl. time, budgets and utilization, with dashboards and reliable exports.
10 — Reporting is a product in itself: custom report builder, scheduled delivery, API access to every metric the UI shows.
The Data Protection Officer
'Custom real time reports in your own data editor with CSV URL link' gives exportable, arguably customizable reporting, which clears the standard-reports anchor. But there is no evidence of cross-project aggregation, time tracking, budget or utilization depth, or dashboards, so the 8 anchor is unreachable on this record. 1
The Bootstrapper
One real fact: custom real-time reports with a CSV URL link — better than fixed status views and exportable. No dashboards, time tracking, budgets, utilization or API access to metrics anywhere in the evidence, so it stops at useful-with-CSV. 1
The Enterprise Architect
'Custom real time reports in your own data editor with CSV URL link' gives me real exports and some customization. But no dashboards, time, budget or utilization reporting — let alone scheduled delivery or API access to metrics — are evidenced; this is export-and-pivot, not reporting as a product. 1
The UX Purist
"Custom real time reports in your own data editor with CSV URL link" is one promising sentence, and a clean export URL clears the fixed-per-project floor — but there is zero evidence of time tracking, budgets, utilization or cross-project aggregation to earn a 5. 1
The Integrator
'Custom real time reports in your own data editor with CSV URL link' is a genuinely useful, refreshable data endpoint — more than fixed status views. But it's the single reporting fact on the evidence, with zero on time, budgets or utilization, and a CSV-URL-only exit doesn't earn more than the mid anchor from me. 1
The Skeptic
'Custom real time reports in your own data editor with CSV URL link' reads as 'here's a CSV, go do the reporting yourself' — an export pipe dressed as a reporting product. No evidence anywhere of time, budget or utilization reporting, dashboards, or anything aggregating across projects. 1
Integrations
Show reasoningHide reasoning
How this is scored
How well the tool connects to the rest of the stack: native integrations, calendar/comms hooks, API and webhooks, import/export paths.
0 — A closed box — no API, no integrations, CSV out if anything.
3 — A handful of marquee integrations, no public API or an API that covers a fraction of the product.
5 — The common set (calendar, Slack/Teams, file storage) plus a documented public API; automation platforms partially covered.
8 — Broad native catalogue, well-documented API and webhooks, first-class automation-platform support and real import paths from competitors.
10 — Ecosystem-grade: everything in 8 plus the tool is itself extensible (apps/plugins, AI/MCP surfaces) and exit via API export is complete.
The Data Protection Officer
'Various integrations (partly through Zapier)' plus a project import/export function is genuine automation-platform coverage, but 'various' is unnamed and the evidence evidences no public API, no webhooks, and no calendar/Slack/storage hooks. A connector fabric without a documented API in the evidence lands between the marquee-integrations anchor and the common-set anchor. 1
The Bootstrapper
"Various integrations (partly through Zapier)" is the whole story — a handful plus partial automation-platform coverage. No documented public API, no webhooks, no named calendar/Slack/storage hooks, and import/export without a single competitor importer named. 1
The Enterprise Architect
'Various integrations (partly through Zapier)' plus project import/export is a partial stack. No documented public API, webhooks, calendar/Slack/file-storage set or competitor import paths appear anywhere in the evidence, so it sits between 'a handful of integrations' and the full common set. 1
The UX Purist
The entire connectivity story is one vague line — "Various integrations (partly through Zapier)" — with no named native integrations, no API and no webhooks documented anywhere in the capture; a Zapier crutch holding up an undocumented integration set is exactly the anchor-3 shape. 1
The Integrator
Integrations are hand-waved as 'Various integrations (partly through Zapier)' — no named catalogue, no documented API, no webhooks anywhere in the evidence, and that's the part I care about most. Real project import/export, 100% open source and self-hosting with customization are the stack-friendly facts that lift it just off the floor. 1
The Skeptic
'Various integrations (partly through Zapier)' — 'various' with zero names is hand-waving, and Zapier is the only concrete connectivity in evidence, alongside a bare 'project import and export function'. No documented API, no webhooks, not one named integration. 1
Onboarding effort
Show reasoningHide reasoning
How this is scored
Time and friction from signup to first real value for a small team, without paid services.
0 — No self-serve path — onboarding starts with a sales call and an implementation project.
3 — Self-serve exists but the first project requires configuration a newcomer cannot judge yet (workflows, custom fields, permissions) before anything works.
5 — A team gets a first project running within a day; trial requires payment details or key steps live behind docs.
8 — Signup to working project inside an hour: guided setup, sensible defaults, templates, trial without payment details.
10 — Minutes to value even for non-tool-people, importers pull existing work in, and the tool teaches its own advanced features as the team grows into them.
The Data Protection Officer
A free, open-source product with a self-host option means there is no sales-gated path and a project import function exists to pull work in — but the evidence says nothing about guided setup, templates, defaults, or trial terms, so I cannot credit hour-to-value. Within-a-day with the importer is plausible; anything faster is unevidenced. 1 2
The Bootstrapper
Free open-source tagline, project import/export and >20 languages mean a small team can plausibly start without payment details. But nothing evidences guided setup, templates or defaults, and the self-host route lives behind docs — a day, not an hour, and the evidence can't tell me which. 1
The Enterprise Architect
The free, open-source nature and a project import function suggest a self-serve day-one path. But the evidence is silent on guided setup, templates and trial terms, and the vendor's own on-premise description reads as an implementation project for larger teams — I will not assume the hour-to-value an 8 requires. 1
The UX Purist
A free self-serve register form with social login and a project importer is the right shape for minutes-to-value, but the evidence is silent on guided setup, templates, defaults or trial terms — I won't credit an hour-to-first-project I can't see, and the self-host path pitched at teams who "want to customize" is a different, heavier sport. 1 2
The Integrator
A self-serve register form and a free, open-source download mean no sales call stands between a team and the product. But the evidence is silent on guided setup, templates, importers or trial mechanics, so I can't credit an hour-to-value I have no evidence for. 1 2
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where the company and the data actually sit: legal entity, ownership control, data residency, and subprocessor exposure to non-EU jurisdictions.
0 — Non-European vendor, data on US infrastructure under US law, no DPA worth the name.
3 — DPA and GDPR language present, but hosting defaults to the US or ownership sits outside Europe — compliance paperwork over substance.
5 — EU data residency is available and contractually fixed, but the vendor or its controlling owner is non-European, or core subprocessors put data within CLOUD Act reach.
8 — European company under European control with EU-resident data and a public DPA; remaining exposure is limited to identifiable subprocessors (e.g. a US hyperscaler's EU region) and is documented.
10 — European company, European control, EU-only data residency on European infrastructure, subprocessor list free of extraterritorial reach — verifiable, not asserted.
The Data Protection Officer
Where the data lives is actually answered: AITIRE CLOUD in Digitalrealty's INTERXION MAD3 in Madrid, with ENS/ISO-certified facilities, no datacenter-personnel access to customer data, a processor DPA embedded in the public Terms of Service, and full GDPR rights plus blocking-on-retention rules. I stop short of 8 because the subprocessor exposure is undocumented — no subprocessor list, SCC boilerplate implying third-country transfers to payment/CRM/emailing providers, an off-site backup whose location is never stated, and the 'KALEIDOS INC SUCURSAL EN ESPAÑA' entity naming hints at a non-EU parent; the 100% open-source self-host escape hatch keeps this at 7 rather than lower. 3 2 1
The Bootstrapper
Madrid hosting at INTERXION MAD3, Spanish entities, a DPA inside the Terms of Service, SCC language and datacenter personnel locked out is real substance. But ownership is unverified — "KALEIDOS INC SUCURSAL EN ESPAÑA S.L." hints at a foreign parent — subprocessors appear only as categories, and contractual residency fixation isn't shown; self-hosting is the escape hatch. 2 3
The Enterprise Architect
Madrid hosting at Interxion MAD3 with ISO 27001/ENS certifications, Spanish S.L. entities, a Spanish address, SCCs and restricted personnel access is real, documented EU substance. But ownership control is unevidenced — the 'Kaleidos Inc sucursal en España' naming hints at a non-EU parent — the DPA is only referenced inside the Terms of Service, and the datacenter sits under US-owned Digital Realty, so verifiable European control falls short of an 8. The self-host option is my clean exit and sovereign fallback. 1 2 3
The UX Purist
Madrid hosting on an ENS/ISO-certified datacenter, Spanish legal entities, SCCs and a DPA embedded in the public Terms of Service are substance, not stickers — but ownership and subprocessor exposure are formally unknown, and the "KALEIDOS INC SUCURSAL EN ESPAÑA" branch name leaves European control unverified, capping it below 8; the 100% open-source self-host path is a genuine exit hatch, though it cannot carry the cloud offering. 1 2 3
The Integrator
Cloud data sits verifiably in Madrid (INTERXION MAD3, ENS-certified) with a DPA in the Terms of Service and Spanish legal entities — good. But ownership is unconfirmed ('KALEIDOS INC SUCURSAL EN ESPAÑA' reads like a US parent's branch) and the privacy policy's SCC language concedes third-country transfers; the 100% open-source on-premise option is the card that keeps this respectable. 2 3 1
The Skeptic
Credit where due: Madrid datacenter on Interxion, Spanish legal entities and a Spanish postal address, DPA in the ToS. But the entity list includes 'KALEIDOS INC SUCURSAL EN ESPAÑA' — that 'Inc' smells like a US parent — and SCC transfer language confirms data leaves the EEA to unnamed recipients; ownership is marked unknown in this very sheet, so control is unverified. 2 3
Support & documentation
Show reasoningHide reasoning
How this is scored
Whether a stuck user gets unstuck: docs quality, support channels and their availability per plan, and the health of the learning surface.
0 — No docs beyond marketing pages; support is a contact form that may answer.
3 — Docs exist but are thin or stale; support on entry plans is effectively email-only with slow turnaround.
5 — Searchable help center covering the core product; chat or email support on all plans with reasonable response times.
8 — Deep, current docs incl. onboarding guides and templates; fast chat support not gated to top tiers; visible changelog.
10 — Docs, academy, community and support so good they are a reason to buy; SLAs published, support quality independent of plan.
The Data Protection Officer
Support is an email address plus GitHub issue tracking for bugs and enhancement requests — real channels, but effectively email-only with no response-time commitment. No help center, no chat, no SLAs, no changelog appear anywhere in the evidence, which matches the thin-docs anchor and cannot exceed it. 2 3 1
The Bootstrapper
Support is an email address plus GitHub issues — no chat, and no help center, academy or changelog evidenced anywhere in the captured pages. A stuck user has nowhere to search, which is below the "docs exist but thin" bar. 1 2 3
The Enterprise Architect
Support is an email address plus GitHub issue tracking, which for 200 seats is not a support model I can defend in procurement. No help center, chat, SLAs, response times or changelog are evidenced anywhere in the evidence. 1 2 3
The UX Purist
A dedicated support@taiga.io and a public GitHub bug/enhancement channel beat a bare contact form, but the capture evidences no help center, no guides, no chat, no SLA and no changelog — software that can't show how it teaches itself gets no credit for teaching. 1 2 3
The Integrator
The entire evidenced support surface is support@taiga.io plus bug filing through GitHub repositories — no help center, no chat, no response times, no changelog, no plan gating visible. For a tool whose docs I'd need to live in, email-only with a public issue tracker is the very bottom of the 3 band. 1 2 3
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Can a buyer determine the real, payable cost of the tool for their team before talking to anyone?
0 — No public pricing at all — every number sits behind "contact sales".
3 — Some tiers are public, but a deciding factor (seat minimums, mandatory add-ons, billing-period surcharge, tax treatment) only surfaces at checkout or in fine print.
5 — Self-serve tiers are publicly priced and the billing-period difference is stated, but the headline number still needs qualifying — e.g. annual-only headline, taxes excluded without saying so, or an opaque enterprise tier doing real work.
8 — Every self-serve tier is fully priced with billing periods and tax treatment plain on the page; only genuinely custom enterprise work lacks a number.
10 — Every tier including enterprise has a public price or published price formula, and the headline number is the number on the invoice.
The Data Protection Officer
No pricing facts of any kind were captured — no tiers, no numbers, no billing periods, no tax treatment — even though the privacy policy's collection of 'economic data such as billing address' via payment forms proves a paid cloud offering exists. The self-hosted core is genuinely zero-cost by nature, which buys a point above the floor, but a buyer cannot determine the payable cloud cost from this record. 1 2
The Bootstrapper
The privacy policy proves a paid cloud service exists — payments via payment service providers — yet no tier, number or seat price appears anywhere in the evidence; I'd have to email someone to price 3 or 30 seats. Only the self-host path is fully priceable at zero because it's 100% open source, which alone keeps this off the floor. 1 2
The Enterprise Architect
'Free and open-source' makes the self-host license cost transparently zero, but the privacy policy confirms payments exist while no tier, price, billing period or tax treatment for the cloud is evidenced. I cannot determine the payable cost of 200 cloud seats from this sheet. 1 2
The UX Purist
"Free and open-source" makes the entry cost genuinely $0 and self-hosting is free, yet a payment form in the privacy policy proves paid tiers exist — and not one price, tier boundary or billing period appears anywhere captured, so the deciding factor stays invisible until checkout. 1 2
The Integrator
'The free and open-source project management tool' is a real €0 price for the self-hosted path. But the evidence also shows a payment form and not one cloud tier number, billing period or tax treatment — the payable cost of the hosted product, which is what a small team would actually buy, is undeterminable from this evidence. 1 2
European sovereignty — proven facts
3 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Incorporated in ES ⚠ unverified | 3/3 pts | 4 Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | EU only ⚠ unverified | 3/3 pts | 3 Report an error |
| Subprocessors | EU only ⚠ unverified | 2/2 pts | 3 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 15 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Legal entity. The privacy policy names a second joint controller, KALEIDOS INC SUCURSAL EN ESPAÑA S.L. — a Spanish branch of a company named KALEIDOS INC — but the contracting entity for the service is the Spanish TAIGA CLOUD SERVICES, S.L.
- Weak sourcing — Data residency. The security page covers only the cloud service (tree.taiga.io); the location of the off-site backups is not specified, and on-premise deployments run on customers' own servers.
- Weak sourcing — Subprocessors. AITIRE CLOUD's own headquarters are not stated (only its Madrid datacenter and EU-programme commitments); the privacy policy also references unnamed payment gateways, hosting, CRM and emailing providers whose jurisdictions are unknown.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- We found no public information on pricing on the pages we read (taiga.io, taiga.io/privacy-policy, taiga.io/security, taiga.io/terms-and-conditions). If the vendor publishes it somewhere else, send us the page. Know more? Tell us
- 1 compliance fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (4)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.