whats-best.ai
Search Sign in

Video Conferencing

Nextcloud Talk

EU-Made Report an error

Panel rating · 6 judges · How to read the stars

Category median

Sovereignty: 1 of 4 dimensions proven

0–5 in half steps. 5 means the rubric's top anchor is met on the evidence.

by Nextcloud GmbH · nextcloud.com

Compare with Jitsi Meet → Report an error on this page Is this your product? →

Read this page as one judge. Each weighs the same scores by what they care about.

No written verdict for this product

The panel scored Nextcloud Talk, but the summary our synthesizer wrote did not survive our own contradiction check — twice. Rather than print a paragraph we cannot stand behind, we print none. Every score, rationale and source below is unaffected; read them and draw the conclusion yourself.

Know this product well? Tell us what the verdict should say

The scores

The meeting itself

Show reasoning
How this is scored

Whether the call works: participant capacity, video and audio quality under load, screen sharing, breakout rooms, moderation, and what happens on a bad connection.

0 — Small meetings only, no screen sharing worth the name, no moderation controls, and the call degrades without telling anyone.

3 — Standard meetings with screen sharing and mute-all, but low participant limits, no breakout rooms and no bandwidth adaptation stated.

5 — Meetings at the scale most teams need with screen sharing, breakout rooms, host moderation, and documented behaviour on constrained connections.

8 — Large meetings and webinars with published capacity limits, per-participant moderation and waiting rooms, layout control, simulcast or adaptive bitrate stated, and reliable behaviour on mobile networks.

10 — Scale and control are engineering claims the vendor stands behind: capacity published per plan and per region, selective forwarding with adaptive quality documented, live streaming, hardware-room support, and diagnostics an admin can read after a bad call.

Report an error

The IT Administrator

The capacity honesty is rare and I credit it — '6-10 participants, up to 20 if all participants have a good network connection and do not use video' for private setups, 'thousands' with the enterprise backend — but screen sharing, mute-all, adaptive behaviour on a bad connection and post-call diagnostics are nowhere on this sheet, and the webinar lobby that would serve as a waiting room is gated behind the HPB. 1

Report an error

The Security Officer

Breakout rooms and webinars-with-lobby exist, and published scaling is candid — 6-10 participants for a private setup, thousands only at enterprise — but the evidence is silent on screen sharing, mute-all or any host moderation, and says nothing about behaviour on a constrained connection beyond admitting video caps you at 20. Between the 3 and 5 anchors: breakout rooms without the moderation and screen-sharing basics that rubric level 5 demands. 1

Report an error

The Works Council Advocate

Breakout rooms and a webinar lobby exist, and scale is honestly published — 6-10 participants for a private setup, thousands per call at enterprise. But the evidence says nothing at all about screen sharing, mute-all or other moderation controls, or adaptive behaviour beyond the candid note that a private setup only reaches 20 people 'if all participants have a good network connection' — silence is information, so I sit at the anchor, not above it. 1

Report an error

The Educator

Breakout rooms and webinar lobbies are evidenced, and I respect the honest capacity statement — a private setup handles 6-10 participants, up to 20 without video on good connections — but the evidence says nothing about screen sharing, mute-all or per-participant moderation, and no adaptive-bitrate or bad-connection behaviour is documented. 1

Report an error

The Accessibility Advocate

Breakout rooms, a lobby and a stated scale range are real, but the evidence never evidences screen sharing at all, and the only constrained-connection behaviour on record is 'up to 20 if all participants have a good network connection and do not use video'. No adaptive bitrate, no diagnostics, no per-plan capacity — I cannot credit a call the evidence won't show me. 1

Report an error

The Skeptic

The only capacity numbers on file are '6-10 participants, up to 20 if all participants have a good network connection and do not use video' for a private setup, and a vague 'thousands' for enterprise — nothing tied to a plan. Breakout rooms exist and the constrained-connection honesty is welcome, but the webinar lobby needs the High Performance Backend, and screen sharing, mute-all, waiting rooms and any bandwidth-adaptation claim are simply absent from the evidence. 1

Report an error

Encryption & meeting access

panel disagrees Show reasoning
How this is scored

What is actually encrypted and against whom, plus who can get into a meeting. Judged on documented mechanism rather than on the word "encrypted".

0 — Transport encryption only, undocumented; meetings joinable by anyone with a link and no lobby.

3 — TLS in transit and encryption at rest, with the vendor holding all keys; access control is a passcode.

5 — The above plus a lobby or waiting room, host-controlled admission, per-meeting passcodes, and a clear statement that the vendor can technically access media.

8 — Optional end-to-end encryption for meetings with the trade-offs named (which features stop working), documented key handling, SSO-gated joining, and per-meeting access policies.

10 — End-to-end encryption available without surrendering the product — its cryptography documented or open source, key management explained, identity verification for participants, and the vendor stating plainly what it can and cannot see.

Report an error

The IT Administrator

All I get on crypto is a marketing-grade 'multi-layered encryption' line on a feature list — no statement of what meeting media is protected against, no key handling, no E2EE for calls, no SSO-gated joining. Self-hosting means the vendor never touches my data, which is real, but the cryptography itself is undocumented on this sheet, and admission control is a lobby that requires the HPB. 1 2

Report an error

The Security Officer

"Multi-layered encryption" is a marketing phrase, not a mechanism: no end-to-end statement for meetings, no key handling, and signaling can run through a High Performance Backend hosted by unnamed partners. The only concrete cryptography I can verify is push notifications encrypted and re-signed by the vendor's proxy, with a lobby available only for webinars that buy the HPB. Nothing here tells me what the server operator or the hosted HPB can see of the media. 1 3

Report an error

The Works Council Advocate

Admission control is real (webinar lobby, and a recording-consent prompt), and the vendor states plainly that 'Nextcloud employees never gain access to your data as we do not offer hosting' — a stronger can/cannot-see statement than most — with open source so the claims can be inspected. But there is no documented end-to-end encryption, no key handling, no SSO-gated joining and no per-meeting passcode mechanism; 'multi-layered encryption' is a marketing phrase, not a documented mechanism, and this criterion is judged on mechanism. 1 2

Report an error

The Educator

'Multi-layered encryption' is a slogan, not a mechanism, and access control is documented only as a lobby that requires the HPB. What is documented is architectural: no hosting is offered, employees never gain access to your data, and no user data is transferred to the vendor — the against-whom question answered by design rather than cryptography, with no E2EE or key handling anywhere in the evidence. 1 2 3

Report an error

The Accessibility Advocate

'Multi-layered encryption' is a marketing phrase, not a documented mechanism, and no E2E meeting mode, key handling or per-meeting passcode appears anywhere. What carries it to the middle is architecture: 100% open source and on-premises, with the vendor stating plainly it never hosts and never touches customer data. 1 2

Report an error

The Skeptic

'Multi-layered encryption' appears once, in a bug-bounty marketing sentence — no page says which meetings are end-to-end encrypted, with what key handling, or which features stop working when it's on. The one substantive statement is that Nextcloud hosts nothing and its employees never gain access to customer data, which inverts the vendor-holds-keys problem but is a deployment fact, not a documented crypto mechanism. Access control tops out at a webinar lobby that requires the HPB; no passcodes, no SSO-gated joining anywhere. 1 2

Report an error

Reach & accessibility

Show reasoning
How this is scored

Whether everyone who needs to join can: browser without an install, dial-in, low bandwidth, guests without accounts, captions and keyboard operation.

0 — A desktop client is the only way in; guests must create an account.

3 — Browser joining exists but is degraded, guests can join by link, and there is no dial-in and no accessibility statement.

5 — Full-feature browser joining without an install, guest access by link, mobile apps, and a stated accessibility posture.

8 — Telephone dial-in with numbers listed, live captions, keyboard-navigable and screen-reader-tested interface, and documented low-bandwidth behaviour.

10 — Reach is designed for: browser parity with the client, dial-in across the regions the customer operates in, live captions and translation, a published accessibility conformance report, and a usable experience on a poor mobile connection.

Report an error

The IT Administrator

Web, desktop and mobile clients are confirmed, phone dial-in exists via the SIP bridge (needs HPB), and live transcription with translation is a genuine reach win. But no dial-in numbers are listed, guest-by-link is only implied by 'public video conferencing', and there is no accessibility statement, keyboard-operation or screen-reader evidence at all — silence I score as absence. 1 4

Report an error

The Security Officer

Web, desktop and mobile are covered, live transcription with translation exists, and there is a real telephone path — but dial-in requires the separately deployed HPB and no numbers or rates are listed. There is no accessibility statement, no keyboard or screen-reader evidence, and no documented low-bandwidth behaviour anywhere in the evidence; silence here is information. 1 4

Report an error

The Works Council Advocate

Web, desktop and mobile clients, phone dial-in via the SIP bridge, and live transcription with translation are all evidenced — genuine reach. But there is no accessibility statement anywhere in the evidence, no keyboard or screen-reader claim, no confirmation guests join by link without an account, and the dial-in carries no numbers because it rides on the customer's own SIP setup; that absence keeps it at the mid-anchor rather than 8. 1 4

Report an error

The Educator

Phone dial-in via the SIP bridge, live transcription with translation, mobile apps and a web platform are evidenced — real inclusion tools. But the evidence is silent on guests joining without an account, has no accessibility statement, no keyboard or screen-reader evidence, and no low-bandwidth mode, and dial-in requires the HPB. 1 4

Report an error

The Accessibility Advocate

My deaf colleague gets something real — live transcription with translation, explicitly optional — and dial-in via the SIP bridge, except dial-in requires the separately deployed HPB. My screen-reader colleague gets nothing: no accessibility statement, no conformance report, not one word on keyboard operation; for them the product is unevidenced, and an unevidenced capability is a missing one. 1

Report an error

The Skeptic

Dial-in exists only through the SIP bridge with the High Performance Backend, and no phone numbers or regions are listed; live transcription with translation is genuinely evidenced and AI is stated optional. Browser joining is implied by 'web' in the platform blurb but never confirmed as full-feature, guest access by link is unmentioned, and there is no accessibility statement of any kind. Mobile apps are the solid part. 1 4

Report an error

Recordings, retention & admin control

Show reasoning
How this is scored

A recording is personal data about everyone in the room. Who may record, who is told, where it is stored, how long it lives, and what the works council can switch off.

0 — Anyone can record, storage location unstated, no retention rule, no admin policy.

3 — Host-only recording with a notification, but storage region unstated, retention manual, and no organisation-wide policy control.

5 — Admin policy over who may record, participant notification and consent prompt, stated storage region, and manual deletion that works.

8 — Automatic retention and deletion per policy, recordings encrypted at rest with access logged, transcription handled with its own retention rule, and attendance or analytics features that can be switched off for co-determination.

10 — Built for a works agreement: every recording, transcript and analytics feature independently switchable and documented, retention executed and evidenced, an audit trail of who accessed which recording, and no participant-level behavioural scoring at all.

Report an error

The IT Administrator

Recording consent in meetings and participant CSV export are real co-determination-adjacent features, and because recordings live on infrastructure I run myself, the storage region is whatever I choose. But the evidence gives me no admin policy over who may record, no automated retention or deletion for recordings or transcripts, and no access audit trail — a works council could not read its rights off these pages. 1 2

Report an error

The Security Officer

There is a recording-consent prompt in meetings and self-hosting puts the recording on infrastructure the customer controls, which is a decent starting point. But the evidence evidences no admin policy over who may record, no retention or deletion rule for recordings or the AI transcripts, and no access logging — message expiration is a chat feature, not recording governance, and nothing here is works-council switchable. 1

Report an error

The Works Council Advocate

A recording-consent prompt in meetings, transcription AI that is 'completely optional', and recordings that live on infrastructure the works council's employer controls rather than a vendor cloud. But nothing on who may record as a matter of policy, no retention or deletion rule for recordings or transcripts, no access logging, and two features that are personal data about everyone in the room — participant CSV export during calls and AI call summaries — come with no evidenced off-switch for co-determination; attendance export without a documented kill switch is exactly what I object to. 1 2

Report an error

The Educator

Recording consent in meetings and configurable message expiration exist, and because the product is self-hosted the storage region is the organisation's own servers by definition. But there is no admin policy on who records, no retention rule for recordings and transcripts, no access logging, and the participant CSV export comes with no documented off-switch. 1 3

Report an error

The Accessibility Advocate

Recording consent in meetings is evidenced, and self-hosting puts recordings on infrastructure the customer's works council itself controls. But recording retention is neither automated nor stated (only chat message expiration exists), no access logging is evidenced, and participant CSV export during calls is attendance tracking with no stated off switch. 1 2

Report an error

The Skeptic

'Recording consent in meetings' is the entire governance record — no admin policy over who may record, no retention rule for recordings or transcripts, no access logging, no audit trail. Storage region is answered only implicitly because the customer self-hosts; the evidence never says so for recordings specifically. Call transcripts, AI summaries and participant-list CSV export are all present, and only the AI is documented as switchable. 1

Report an error

Integrations & deployment

Show reasoning
How this is scored

Calendar, identity and the wider stack — plus, in this category, whether the product can be run on the customer's own infrastructure at all.

0 — No calendar integration, no SSO, no API; cloud-only with no alternative.

3 — One calendar integration and basic SSO, no API worth building on, cloud-only.

5 — Calendar integration for the major suites, SAML or OIDC SSO, a documented API for scheduling, and room-system support.

8 — The above plus SCIM provisioning, embedding via SDK, webhooks for meeting events, and either a self-hosted option or a documented private-cloud deployment.

10 — Deployment is the customer's choice: a genuine on-premises or private-cloud option with the same features, open protocols or open source, embeddable SDKs, and identity integration that does not require the vendor's directory.

Report an error

The IT Administrator

The self-hosted story is the best in class — fully on-premise, 100% open source, airgap-capable, with hosted-HPB via partners as fallback — and the Pexip bridge is real room-system interop, with webhook-based bots. But the evidence is silent on SSO, SCIM and any SDK, and the only calendar story is Nextcloud's own apps; for a platform I have to bolt onto an existing identity stack, that silence matters. 1 2

Report an error

The Security Officer

Deployment is genuinely the customer's: fully on-premises, airgap-capable, open source, with webhook bots, a SIP bridge and a Pexip gateway for room systems and an Outlook add-in. But the evidence shows no SAML/OIDC SSO, no SCIM provisioning and no SDK — for a self-hosted stack, the absence of documented identity federation is a real gap. 1 2

Report an error

The Works Council Advocate

Deployment is genuinely ours: fully on-premises, open source, even airgap-capable, which for this criterion is the strongest form of 'run it yourself' the anchors describe. Around it sit webhooks for bots, a Pexip integration, SIP bridge and an Outlook add-in — but SSO, SCIM provisioning and an SDK are simply not evidenced, and I cannot credit capabilities the evidence does not show. 1 2

Report an error

The Educator

Deployment is top of the class — fully on-premise, 100% open source, airgap-capable — which answers the own-infrastructure question outright, and webhook bots, Pexip bridging and an Outlook add-in round it out. But the evidence is silent on SSO, SCIM provisioning and any embeddable SDK. 1 2

Report an error

The Accessibility Advocate

Deployment is genuinely the customer's: on-premises included, 100% open source, airgap-capable, with webhooks for bots, SIP bridge and Pexip room-system integration. SCIM provisioning, an embedding SDK and any SSO statement are absent from the evidence, which keeps it below the top anchor. 1 2

Report an error

The Skeptic

On-premises isn't an option here, it's the product — hostable on-premises, 100% open source, and airgap-capable, which answers the deployment half of this criterion about as well as it can be answered. But the identity and API half is unevidenced: no SSO, no SCIM, no documented scheduling API; what's actually on file is webhook bots, a Pexip bridge, a SIP bridge and an Outlook file-sharing add-in. 1 2

Report an error

European sovereignty panel opinion

panel disagrees Show reasoning
How this is scored

Where media and metadata are processed, who the contracting entity is, which subprocessors carry the traffic. Independently sourced by the sovereignty pipeline; scored here as this buyer weighs it — which in this category is heavily.

0 — Non-EU vendor and contracting entity, media routed through unstated regions, subprocessors unnamed.

3 — EU data residency for storage while media relays or metadata remain non-EU, or the contracting entity sits outside the EU.

5 — EU hosting and an EU contracting entity, but parts of the chain — relays, analytics, support tooling, transcription — are non-EU without an explained safeguard.

8 — Media and metadata processed in the EU on named infrastructure, EU contracting entity, complete subprocessor list published, any non-EU processing named with its legal basis.

10 — Sovereign end to end and evidenced: media never leaves the EU, every subprocessor European, certification published, and an on-premises option that removes the question entirely.

Report an error

The IT Administrator

As a buyer who weighs this heavily: the vendor 'do[es] not offer hosting' and its employees 'never gain access to your data', media stays entirely on infrastructure I control, and Nextcloud GmbH is a German entity with a register entry and Stuttgart address — despite the pipeline's unknowns. It falls short of the top anchors because the vendor-hosted STUN server and the partner-hosted HPB are unnamed and unlocated, and no certification or subprocessor list for the service is published. 2 4 1

Report an error

The Security Officer

The contracting entity is firmly German — Nextcloud GmbH, register HRB 227086, Stuttgart, German VAT ID — and the self-hosted/airgap model means media locality is largely the customer's own decision, which is why I score above the 5 anchor. But nothing evidences where vendor-operated pieces land: the STUN server Nextcloud itself hosts, partner-hosted HPBs with unnamed partners, and Matomo cloud for analytics; there is no product subprocessor list, so the chain is partly a black box. 1 3 4

Report an error

The Works Council Advocate

The pipeline marked residency unknown because the vendor does not state one — but the reason is that Nextcloud hosts nothing: media and metadata are processed on named customer infrastructure, in an airgap if we wish, and the vendor states no user data is transferred to it. The contracting entity is demonstrably European — Nextcloud GmbH, Stuttgart, HRB 227086, German VAT ID — though I dock it for no published certification or subprocessor documentation, and the vendor-operated public STUN server touching call setup without a stated safeguard. 1 2 3 4

Report an error

The Educator

The contracting entity is documented to the street — Nextcloud GmbH, Stuttgart, HRB 227086, German VAT — the vendor states no user data reaches it, and the on-premises and airgap options remove the media-routing question entirely. The only named touchpoints are a Nextcloud-hosted STUN server of unstated region and Matomo-cloud website analytics, and no certification is published in the evidence. 1 2 3 4

Report an error

The Accessibility Advocate

The imprint puts the contracting entity in Germany beyond doubt — GmbH, register court, VAT ID, DPO — despite the pipeline's 'unknown' caveats, and on-premises/airgap hosting removes the media-residency question entirely. Held below 8 because the evidence is silent on where the vendor-hosted STUN sits, on which partners run the hosted HPB and where, and on any product subprocessor list or certification. 1 2 3 4

Report an error

The Skeptic

Whatever the pipeline's 'unknown' fields say, the imprint is unambiguous: Nextcloud GmbH, Stuttgart, HRB 227086, German VAT ID, external DPO in Munich. Media and metadata live on infrastructure the customer chooses, down to airgap, which removes the question for the bulk of the chain. The deductions are concrete: Nextcloud itself hosts a STUN server, the hosted HPB offering runs 'by our partners' who are never named, and no certification is published. 1 3 4

Report an error

Pricing transparency

Show reasoning
How this is scored

Whether a buyer can compute the annual invoice for their host count — including the capacity, dial-in and recording storage they actually need — from public pages alone.

0 — No public prices at all; every tier is a sales conversation.

3 — A per-host headline exists, but participant caps, dial-in minutes or recording storage are unpriced or unmentioned.

5 — Per-host prices public with billing period stated and capacity limits given, but at least one commonly needed piece (webinar capacity, dial-in, storage) sits in an unpriced add-on.

8 — Every tier and add-on priced publicly with per-host maths, capacity limits, dial-in rates, storage allowances, minimum term and VAT treatment stated.

10 — Complete price computability: a calculator producing the annual invoice for a given host count, meeting size and recording volume, including overage and per-region dial-in.

Report an error

The IT Administrator

Per-user annual prices for three tiers at two volume points, net of VAT in EUR, from 100 users up — that part I can compute. What I cannot compute is the meeting: the HPB, without which webinars, dial-in and thousands-participant calls do not work, appears only as a free 30-day trial with no price, no SIP rates and no minimum term on this sheet. 2 1

Report an error

The Security Officer

Per-user prices are public for three tiers with volume breaks, in EUR per year net of VAT, from 100 users — better than a headline, but capacity limits per plan are absent, minimum term is unstated, and dial-in is entirely unpriced because it depends on an HPB whose hosted cost never appears. Recording storage is likewise unmentioned; the annual invoice for what a buyer actually needs is not computable from these pages. 1 2

Report an error

The Works Council Advocate

Three tiers are publicly priced per user per year, net of VAT, with volume steps from 100 to 200 users and published participant limits — respectable. But the High Performance Backend, without which there are no webinars and no phone dial-in, is offered only as a 30-day trial with no public price, and no minimum term appears anywhere; a buyer cannot compute the invoice for a setup that actually needs those features. 1 2

Report an error

The Educator

Per-user prices are public in EUR, net of VAT, with volume tiers from 100 users up — but the HPB that webinars and phone dial-in depend on appears only as a free 30-day trial with no published price, and there are no per-plan participant caps, minimum term or dial-in rates to compute an annual invoice from. 1 2

Report an error

The Accessibility Advocate

Per-user maths is public down to VAT treatment, billing period and a 100-user floor, so the licence invoice is computable. But the HPB — required for webinars and for the dial-in my low-connectivity users depend on — appears only as a 30-day trial through unnamed partners with no public price, and no per-plan capacity or minimum term is stated. 1 2

Report an error

The Skeptic

Per-user prices are admirably public down to VAT treatment — 71.29/104.99/204.75 EUR per user per year, net, from 100 users. But capacity is not tied to any plan tier, and the High Performance Backend — required for both webinars and phone dial-in — carries no price at all, just a 30-day hosted trial. Dial-in rates, recording storage allowances and minimum terms are absent, so I cannot compute the annual invoice for a real deployment from these pages. 1 2

Report an error

European sovereignty — proven facts

1 of 4 dimensions proven

Built only from facts shown on the vendor's own pages. A dimension we could not prove is left open, not scored as zero.

Ownership Not determined — uncited Report an error
Data residency Not determined ⚠ unverified — uncited Report an error
Subprocessors Not determined ⚠ unverified — uncited Report an error

Where this could be wrong

What we left out

A claim that does not survive our checks costs us the claim, not the page. This is what was taken off this one.

Sources (15)

The pages every claim on this page was read from — each one checked, dated, and kept verifiable.

  1. 1 Product page nextcloud.com Checked 15 Sep 2026 Details →
  2. 2 Pricing nextcloud.com Checked 15 Sep 2026 Details →
  3. 3 Privacy policy nextcloud.com Checked 15 Sep 2026 Details →
  4. 4 Imprint nextcloud.com Checked 15 Sep 2026 Details →
  5. 5 Security / trust page nextcloud.com Checked 30 Sep 2026 Details →
  6. 6 The meeting itself — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  7. 7 The meeting itself — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  8. 8 Encryption & meeting access — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  9. 9 Encryption & meeting access — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  10. 10 Reach & accessibility — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  11. 11 Reach & accessibility — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  12. 12 Recordings, retention & admin control — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  13. 13 Recordings, retention & admin control — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  14. 14 Integrations & deployment — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →
  15. 15 Integrations & deployment — found from sitemap help.nextcloud.com Checked 1 Oct 2026 Details →