Video Conferencing
Livestorm
Provenance unknown Report an errorPanel rating · 6 judges · How to read the stars
Category median
Sovereignty: 1 of 4 dimensions proven
0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.
by Livestorm SAS · livestorm.co
Report an error on this page Is this your product? →
Read this page as one judge. Each weighs the same scores by what they care about.
The panel's verdict
Livestorm positions itself as "the webinar leader, designed in Europe", a webinar platform for marketing teams. The strongest reading is reach and accessibility, clustering at 3-4 on dial-in by phone, live translations and interpretation via Interprefy. Integrations sit at 3 with no spread: SAML SSO, CRM integrations and a verified Claude connector are evidenced, while we found no public information on calendar integration, a documented API or self-hosted deployment. The weakest reading is recording governance, at 1 with no spread — AI transcription is documented, so transcripts plainly exist, yet we found no public information on who may record, participant notification, retention or storage. Meeting core and encryption and access score 1-2, features named without published behaviour. Sovereignty scores 2-3: the captured pages pair an EU-hosted claim with a Livestorm Inc. copyright at a Claymont, Delaware address, while the vendor is listed as Livestorm SAS. The security officer sits at the low end of meeting core, encryption and access, reach and sovereignty, reading certificates and hosting claims as posture rather than mechanism. No prices appear on the captured pages.
Speaks for it
- Reach and accessibility scores cluster at 3-4, the highest-scoring criterion in the table.
- Dial-in by phone, live translations and live interpretation via Interprefy are named on the page.
- SAML SSO, CRM integrations and a verified Claude connector are evidenced.
- ISO 27001 certification and GDPR compliant by design are stated on the page.
Held against it
- Recording governance scores sit at 1 with no spread.
- We found no public information on who may record, participant notification, retention, storage location or admin policy controls.
- We found no public information on participant capacity, screen sharing, breakout rooms or host moderation controls.
- We found no public information on encryption mechanisms, key handling, waiting rooms or admission controls beyond a private-events label.
- The captured pages pair an EU-hosted claim with a Livestorm Inc. copyright at a Claymont, Delaware address, while the vendor is listed as Livestorm SAS.
Best for
- You run marketing webinars for international audiences and need phone dial-in, live translations and interpretation via Interprefy.
- Your events are slide-led and gated, matching the PowerPoint embedding and private events the pages evidence.
- Your stack already centres on CRM integrations, SAML SSO and a Claude connector.
Avoid if
- You need documented recording and transcript governance — consent, notification, retention and admin controls — for a works council review.
- You must plan events against published capacity, moderation and breakout-room behaviour under load.
- You need documented encryption, key handling and admission controls before running sensitive conversations.
- You require one clear contracting entity and a published subprocessor list before signing.
The scores
The meeting itself
Show reasoningHide reasoning
How this is scored
Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.
0 — Small meetings only, no screen sharing worth the name, no moderation controls, and the call degrades without telling anyone.
3 — Standard meetings with screen sharing and mute-all, but low participant limits, no breakout rooms and no bandwidth adaptation stated.
5 — Meetings at the scale most teams need with screen sharing, breakout rooms, host moderation, and documented behaviour on constrained connections.
8 — Large meetings and webinars with published capacity limits, per-participant moderation and waiting rooms, layout control, simulcast or adaptive bitrate stated, and reliable behaviour on mobile networks.
10 — Scale and control are engineering claims the vendor stands behind: capacity published per plan and per region, selective forwarding with adaptive quality documented, live streaming, hardware-room support, and diagnostics an admin can read after a bad call.
The IT Administrator
The pages position this as a webinar product, but I found no public information on participant capacity, moderation controls, screen sharing, breakout rooms or what happens on a poor connection. What is shown — dial-in, PowerPoint embedding, interpretation, transcription — is feature naming, not behaviour under load, and I cannot plan a single critical event from it. 1
The Security Officer
The pages position this as "the webinar leader" with telephone dial-in and PowerPoint embedding, but I found no public information on participant capacity, screen sharing, breakout rooms, moderation controls, or documented behaviour on a constrained connection — the mechanics of the call itself are not evidenced here. 1
The Works Council Advocate
The positioning is a webinar platform with PowerPoint embedding, private events, and phone dial-in, but I found no public information on participant capacity, screen sharing, host moderation, waiting rooms, or what happens to the call on a weak connection — and those are the behaviours a council needs documented before members rely on the room. The meetings plainly exist, but nothing is published about how they behave under load or how they are controlled. 1
The Educator
The page evidences a webinar product — private events, PowerPoint embedding, AI transcription — but we found no public information on participant capacity, screen sharing, breakout rooms, host moderation or behaviour on a weak connection. For a class of thirty splitting into groups, that silence on breakouts and on constrained-network handling is decisive, so only the presentation features count. 1
The Accessibility Advocate
PowerPoint embedding and private, gated events are the only session mechanics the captured page evidences; I found no public information on participant capacity, host moderation controls, breakout rooms, or behaviour on a weak connection. For a product positioned as the webinar leader, that is thin evidence to run a meeting on. 1
The Skeptic
The captured positioning is a webinar platform — PowerPoint embedding, private events, "the webinar leader, designed in Europe" — but I found no public information on participant capacity, moderation controls, breakout rooms, video quality under load, or what happens on a bad connection. Slide embedding is named; screen sharing as a working capability is not, and no capacity number stands behind the webinar claim. 1
Encryption & meeting access
Show reasoningHide reasoning
How this is scored
What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".
0 — Transport encryption only, undocumented; meetings joinable by anyone with a link and no lobby.
3 — TLS in transit and encryption at rest, with the vendor holding all keys; access control is a passcode.
5 — The above plus a lobby or waiting room, host-controlled admission, per-meeting passcodes, and a clear statement that the vendor can technically access media.
8 — Optional end-to-end encryption for meetings with the trade-offs named (which features stop working), documented key handling, SSO-gated joining, and per-meeting access policies.
10 — End-to-end encryption available without surrendering the product — its cryptography documented or open source, key management explained, identity verification for participants, and the vendor stating plainly what it can and cannot see.
The IT Administrator
The capture states ISO 27001 certification and GDPR compliance by design, but I found no public information on what is actually encrypted, on key handling, or on what the vendor can technically see. "Private events" is the only access control shown; nothing appears on waiting rooms, per-meeting passcodes or end-to-end encryption. 1
The Security Officer
I read "GDPR compliant by design" and ISO 27001 as compliance paperwork, not mechanism: I found no public information on what is actually encrypted, who holds the keys, or whether a lobby, per-meeting passcodes and host-controlled admission exist. SAML single sign-on gates the workspace, not who can walk into a meeting room; "private events" is a label with no documented behaviour. 1
The Works Council Advocate
SAML single sign-on and private events are documented, which says something about who gets in, but I found no public information on what is actually encrypted, who holds the keys, host-controlled admission, or whether the vendor can technically access meeting media. On this criterion the mechanism is everything, and none is published. 1
The Educator
ISO 27001 certification and GDPR compliance are stated, but we found no public information on how media is encrypted, who holds keys, or any lobby, waiting room or admission control beyond a private-events label. A certification badge is not a documented mechanism, and my learners on borrowed phones deserve to know who can technically see the stream. 1
The Accessibility Advocate
Access gating is evidenced through private events and SAML SSO, but I found no public information on the encryption mechanism, key handling, waiting rooms, or a plain statement of what the vendor can technically see. An ISO 27001 certificate is a posture, not a documented meeting-access mechanism. 1
The Skeptic
The page offers ISO 27001 and "GDPR compliant by design", which is a certificate and a slogan, not a mechanism: I found no public information on what is encrypted in transit or at rest, who holds keys, or lobby and admission controls. "Private events" is the only access-related feature named, and no end-to-end option is documented with its trade-offs. 1
Reach & accessibility
Show reasoningHide reasoning
How this is scored
Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.
0 — A desktop client is the only way in; guests must create an account.
3 — Browser joining exists but is degraded, guests can join by link, and there is no dial-in and no accessibility statement.
5 — Full-feature browser joining without an install, guest access by link, mobile apps, and a stated accessibility posture.
8 — Telephone dial-in with numbers listed, live captions, keyboard-navigable and screen-reader-tested interface, and documented low-bandwidth behaviour.
10 — Reach is designed for: browser parity with the client, dial-in across the regions the customer operates in, live captions and translation, a published accessibility conformance report, and a usable experience on a poor mobile connection.
The IT Administrator
Dial-in by phone, AI transcription, live translations and interpretation via Interprefy are all confirmed, which is real reach. But the capture lists no dial-in numbers and I found no public information on browser joining without an install, guest access by link, accessibility conformance, or low-bandwidth behaviour. 1
The Security Officer
Telephone dial-in and live translations via Interprefy are published, which serves reach, but I found no public information on browser joining without an install, guest access without an account, captions, keyboard operation, or any accessibility statement. 1
The Works Council Advocate
Dial-in by phone and live translations, with interpretation through a named partner, are genuine reach features that lift this above the bottom anchors. But I found no public information on browser joining without an install, guest access by link, mobile apps, live captions, keyboard and screen-reader operation, or any accessibility statement at all. 1
The Educator
Dial-in by phone, live translations and interpretation via Interprefy are genuinely promising for people in dead spots. But we found no public information on joining from a browser without an install, guest access without an account, live captions, or any stated accessibility posture — half my class would be joining blind. 1
The Accessibility Advocate
Dial-in by phone, AI transcription and live translations via Interprefy are exactly the reach features I look for, stated plainly on the page. But I found no public information on browser joining without an install, keyboard or screen-reader operation, or any accessibility statement — and a transcription feature is not a published conformance report. 1
The Skeptic
Dial-in by phone, live translations and interpretation via Interprefy are named on the page, which is real multilingual reach, but no dial-in numbers are listed and I found no public information on joining from a browser without an install, guest access without an account, captions, keyboard operation, or an accessibility statement. 1
Recordings, retention & admin control
Show reasoningHide reasoning
How this is scored
A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.
0 — Anyone can record, storage location unstated, no retention rule, no admin policy.
3 — Host-only recording with a notification, but storage region unstated, retention manual, and no organisation-wide policy control.
5 — Admin policy over who may record, participant notification and consent prompt, stated storage region, and manual deletion that works.
8 — Automatic retention and deletion per policy, recordings encrypted at rest with access logged, transcription handled with its own retention rule, and attendance or analytics features that can be switched off for co-determination.
10 — Built for a works agreement: every recording, transcript and analytics feature independently switchable and documented, retention executed and evidenced, an audit trail of who accessed which recording, and no participant-level behavioural scoring at all.
The IT Administrator
AI transcription exists, so transcripts about everyone in the room are being made, yet I found no public information on who may record, participant notification, where recordings are stored, retention rules, deletion or any admin policy control. GDPR compliance by design is a posture, not governance a works council can read or switch off. 1
The Security Officer
AI transcription means participants' speech becomes stored text, yet I found no public information on who may record, whether anyone in the room is told, where recordings and transcripts live, for how long, or what an administrator can switch off. Nothing here would survive a works-council conversation. 1
The Works Council Advocate
This is what I weigh hardest, and I found no public information on who may record, participant notification or consent, retention periods, organisation-wide policy, or any switch to turn features off — while AI transcription and attendee-level UTM tracking are both documented as present, with nothing published about deactivating either. Reading behavioural tracking with no stated opt-out, my conclusion is that co-determination here would start from zero documentation. The storage story is also unclear: an EU-hosting claim sits beside a Delaware street address on the captured pages. 1
The Educator
AI transcription is offered, which makes the governance silence loud: we found no public information on who may record, whether participants are notified, retention rules, or organisation-wide admin policy. The only adjacent signal is a general EU-hosted claim. 1
The Accessibility Advocate
AI transcription is evidenced, so recordings and transcripts plainly exist in this product, yet I found no public information on who may record, whether participants are notified, where recordings are stored, how long they live, or any organisation-wide policy control. GDPR-compliant-by-design is a claim, not a retention rule a works council can hold. 1
The Skeptic
"AI Transcription" is the only feature touching recorded material, and I found no public information on who may record, whether participants are told, where recordings are stored, retention rules, admin policy, or access logging. A transcript with no stated shelf life is exactly what a works council will ask about first. 1
Integrations & deployment
Show reasoningHide reasoning
How this is scored
Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.
0 — No calendar integration, no SSO, no API; cloud-only with no alternative.
3 — One calendar integration and basic SSO, no API worth building on, cloud-only.
5 — Calendar integration for the major suites, SAML or OIDC SSO, a documented API for scheduling, and room-system support.
8 — The above plus SCIM provisioning, embedding via SDK, webhooks for meeting events, and either a self-hosted option or a documented private-cloud deployment.
10 — Deployment is the customer's choice: a genuine on-premises or private-cloud option with the same features, open protocols or open source, embeddable SDKs, and identity integration that does not require the vendor's directory.
The IT Administrator
SAML SSO and CRM integrations are confirmed, plus a connector for an AI assistant — useful, but the middle of this category is calendar, API and room systems, and I found no public information on any of them. Nothing on SCIM provisioning, SDKs, webhooks or any self-hosted option appears; cloud-only is what the pages show. 1
The Security Officer
SAML single sign-on, CRM integrations and a Claude connector are named, but I found no public information on calendar integration for the major suites, a documented API, provisioning, webhooks, or any self-hosted deployment — cloud-only is all that is visible. 1
The Works Council Advocate
SAML single sign-on and CRM integrations with marketing-stack tracking are evidenced, which is a modest breadth beyond a single calendar hook. But I found no public information on calendar integration, a documented API, room-system support, or any self-hosted or private-cloud deployment — a cloud service only, as far as the pages show. 1
The Educator
SAML SSO, CRM integrations, a Claude connector and UTM tracking are evidenced. We found no public information on calendar integration, a documented API, provisioning, or any self-hosted deployment — the evidence points to the vendor's cloud only. 1
The Accessibility Advocate
SAML SSO and CRM integrations are evidenced, and a verified Claude connector is listed. I found no public information on calendar integration, a documented scheduling API, SCIM provisioning, embedding via SDK, or any self-hosted or private-cloud deployment. 1
The Skeptic
SAML SSO and CRM integrations are named, plus a verified Claude connector and UTM tracking, which fits a marketing-stack product. I found no public information on calendar integration, a documented API, SCIM provisioning, an SDK, or any self-hosted or private-cloud option. 1
European sovereignty
panel opinion
Show reasoningHide reasoning
How this is scored
Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.
0 — Non-EU vendor and contracting entity, media routed through unstated regions, subprocessors unnamed.
3 — EU data residency for storage while media relays or metadata remain non-EU, or the contracting entity sits outside the EU.
5 — EU hosting and an EU contracting entity, but parts of the chain — relays, analytics, support tooling, transcription — are non-EU without an explained safeguard.
8 — Media and metadata processed in the EU on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.
10 — Sovereign end to end and evidenced: media never leaves the EU, every subprocessor European, certification published, and an on-premises option that removes the question entirely.
The IT Administrator
The captured pages give different signals: an "EU-hosted, ISO 27001 certified" claim alongside a footer naming Livestorm Inc. at a Claymont, Delaware address, while the vendor is listed as Livestorm SAS. I found no public information on subprocessors or on where media and metadata are relayed, and an unexplained US entity next to an EU-hosting claim is exactly what I cannot sign off on. 1
The Security Officer
The captured pages give different signals: an "EU-hosted, ISO 27001 certified" statement sits beside a hosting address on record in Claymont, Delaware, USA and a copyright naming Livestorm Inc. I found no public information on where media and metadata are processed, no subprocessor list beyond the Interprefy interpretation link, and no statement of which entity would actually hold the contract — and this buyer weights that heavily. 1
The Works Council Advocate
The pages claim EU hosting with ISO 27001 and GDPR compliance, yet the contracting entity shown is Livestorm Inc. at a Delaware address, and the captured pages give different signals for where the service actually sits; no subprocessor list is published beyond the named interpretation partner. For a buyer who weighs this heavily, an EU-hosting claim paired with a contracting entity outside the EU and no named infrastructure lands in the middle of the scale, not above it. 1
The Educator
The captured page pairs an EU-hosted claim with ISO 27001 and GDPR statements against a Claymont, Delaware address and a Livestorm Inc. copyright, and we found no public information naming subprocessors or the infrastructure carrying media and metadata. EU residency alongside a contracting footprint outside the EU, with the chain undocumented, is where I land. 1
The Accessibility Advocate
The page claims EU hosting and describes the product as designed in Europe, yet the same capture carries a Livestorm Inc. copyright and a Delaware address, and the independent pipeline shows no sovereignty attributes on record. I found no public information on named infrastructure, a subprocessor list, or where media relays and metadata are processed. 1
The Skeptic
The page claims "EU-hosted", ISO 27001 and GDPR compliance, but the captured footer names Livestorm Inc. at 2093 Philadelphia Pike, Claymont, DE 19703 USA while the vendor record names Livestorm SAS — the captured pages give different figures for the contracting entity, and I do not choose between them. I found no public information on subprocessors, media relay locations, or where the AI transcription is processed; an EU-hosted badge beside a Delaware address is not something a buyer can contract on. 1
Pricing transparency
not rated — the vendor publishes no price
Show reasoningHide reasoning
How this is scored
Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.
0 — No public prices at all; every tier is a sales conversation.
3 — A per-host headline exists, but participant caps, dial-in minutes or recording storage are unpriced or unmentioned.
5 — Per-host prices public with billing period stated and capacity limits given, but at least one commonly needed piece (webinar capacity, dial-in, storage) sits in an unpriced add-on.
8 — Every tier and add-on priced publicly with per-host maths, capacity limits, dial-in rates, storage allowances, minimum term and VAT treatment stated.
10 — Complete price computability: a calculator producing the annual invoice for a given host count, meeting size and recording volume, including overage and per-region dial-in.
The IT Administrator
I found no public information on prices at all — no per-host figure, no tiers, no capacity limits, no dial-in rates, no storage allowances, no term or VAT treatment. A buyer cannot compute any annual invoice from what was captured; any price is a sales conversation. 1
The Security Officer
The captured pages show no prices of any kind, and I found no public information on tier pricing, participant caps, dial-in rates or recording storage allowances, so no part of an annual invoice can be computed from what is public. 1
The Works Council Advocate
I found no public prices at all: no per-host figure, no tier names or limits, no billing period, no dial-in or storage rates, nothing with which a buyer could compute an annual invoice. Every commercial term is a conversation with sales as far as the captured pages show. 1
The Educator
We found no public prices at all — no per-host figure, no capacity limits, no dial-in rates, no storage allowances, nothing a buyer could multiply into an annual invoice. Every tier looks like a sales conversation. 1
The Accessibility Advocate
The captured page shows no prices at all — I found no public information on host pricing, billing period, capacity limits, dial-in rates or recording storage. A buyer cannot compute even a rough annual invoice from this capture. 1
The Skeptic
No price appears anywhere in the capture: I found no public information on per-host figures, tiers, billing period, participant caps, dial-in rates, recording storage, or VAT treatment. A buyer cannot compute any invoice from this page; it is a sales conversation. 1
European sovereignty — proven facts
1 of 4 dimensions provenBuilt only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.
| Legal entity | Not determined | — | uncited Report an error |
|---|---|---|---|
| Ownership | Not determined | — | uncited Report an error |
| Data residency | Not determined ⚠ unverified | — | uncited Report an error |
| Subprocessors | US CLOUD Act reach ⚠ unverified | 0/2 pts | 2 Report an error |
Where this could be wrong
- Evidence ages. The oldest capture behind this page is from 29 Sep 2026. Vendors change pricing and policies without notice; every fact reflects its source as of the capture date shown in the registry.
- Weak sourcing — Data residency. Not confirmed on the vendor’s own pages as captured.
- Weak sourcing — Subprocessors. AWS is a US-headquartered provider even though the page places the storage in Ireland, and the privacy policy (S2) separately acknowledges some service providers are located in the United States.
- AI can misread a source. Extraction and judgement are automated; a citation guarantees traceability, not infallibility. If something here is wrong, say so — no account needed, every report is decided within 5 business days, and accepted corrections are published.
What we left out
A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.
- 30 product facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 12 compliance facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 7 data facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 integrations facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 legal facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 6 support facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 2 hosting facts could not be confirmed on the vendor’s page as captured and were left out of this page and of the panel’s material. Know more? Tell us
- 1 pricing fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 subprocessors fact could not be confirmed on the vendor’s page as captured and was left out of this page and of the panel’s material. Know more? Tell us
- 1 sovereignty dimension could not be confirmed on the vendor’s own pages and is shown as unknown. Know more? Tell us
- 6 of the readings below were written against an earlier fact sheet — a fact has been corrected, added or pulled since. Until the panel next runs on this product you are reading the older judgement. Know more? Tell us
Sources (12)
The pages every claim on this page was read from — each one checked, dated, and kept verifiable.
- 1 Vendor page livestorm.co Checked 29 Sep 2026 Details →
- 2 Legal notice — found from the homepage livestorm.co Checked 30 Sep 2026 Details →
- 3 Privacy policy — found from the homepage livestorm.co Checked 30 Sep 2026 Details →
- 4 The meeting itself — found from sitemap livestorm.co Checked 1 Oct 2026 Details →
- 5 The meeting itself — found from sitemap support.livestorm.co Checked 1 Oct 2026 Details →
- 6 Encryption & meeting access — found from sitemap support.livestorm.co Checked 1 Oct 2026 Details →
- 7 Reach & accessibility — found from sitemap livestorm.co Checked 1 Oct 2026 Details →
- 8 Reach & accessibility — found from sitemap support.livestorm.co Checked 1 Oct 2026 Details →
- 9 Recordings, retention & admin control — found from sitemap support.livestorm.co Checked 1 Oct 2026 Details →
- 10 Recordings, retention & admin control — found from sitemap developers.livestorm.co Checked 1 Oct 2026 Details →
- 11 Integrations & deployment — found from sitemap livestorm.co Checked 1 Oct 2026 Details →
- 12 Integrations & deployment — found from sitemap livestorm.co Checked 1 Oct 2026 Details →