Accans

Updates.

Tracked changes to the vendor database and the tool.

7 database vendors added

A candidate list of European managed-database and DBaaS providers (35 names) independently verified: 7 new vendors (MySQL, Firebird SQL, SQLite, TiDB, Dragonfly, ScyllaDB, RethinkDB), the rest already catalogued or not genuine EU alternatives.

Added

  • 7 vendors added to the database category: MySQL, Firebird SQL and SQLite (self-hostable), TiDB, Dragonfly and ScyllaDB (vendor-hosted, with a commercial cloud offering), and RethinkDB (community-governed, still active despite its reputation as discontinued).
  • 28 of 35 candidates rejected: several European DBaaS providers and open-source engines were already catalogued under a different category (e.g. OVHcloud, Scaleway, STACKIT, Qdrant, CockroachDB), and a few candidates were just sub-products of already-catalogued vendors (Amazon Aurora/RDS, Google Cloud SQL, Azure SQL Database).

4 vendors added, TigerData record corrected

A data-platform/analytics candidate list (35 names) independently verified: 4 new vendors, and an incorrect existing record (TigerData/TimescaleDB) corrected — it was wrongly recorded as Swedish/EU with no cited source, when the company is actually headquartered in New York, US.

Added

  • 4 vendors added: Databend and Apache Iceberg (data-platform), Milvus (database), Incus (virtualization — community-governed fork of LXD).
  • 30 of 35 candidates rejected: 24 were already known (often the same existing cloud-iaas/storage vendor with an "Analytics" suffix), "Ververica Streaming Platform" turned out to still be Alibaba-owned despite its EU framing, Greenplum has been closed-source since 2024, and "Chimp Analytic Engine"/"Velocity Stream" were fabricated products with no findable source.

Fixed

  • TigerData (TimescaleDB) carried no source citation at all and was recorded as Swedish/EU; independent research confirms a New York, US headquarters and a partially non-open license (the core engine is Apache-2.0, but the widely-used Community edition is under the non-OSI Timescale License). Headquarters country, open-source status and sovereignty mode corrected.

13 vendors added to customer-data-platform

A second submitted CDP candidate list (35 names) independently verified: 13 new vendors, including two country corrections that moved a vendor from "non-EU" to "EU".

Added

  • 13 vendors added to customer-data-platform: ContactPigeon (Greece), NGDATA Lily (Belgium — the candidate list wrongly claimed a US headquarters), Tracardi (Poland), Tealium Customer Data Hub, Treasure Data CDP, Optimove (Israel, not the US as claimed), Blueshift SmartHub CDP, Redpoint Global (rgOne), Klaviyo CDP, Simon Data, Zeta Global Marketing Platform, Lemnisk (India, not the US) and Evam Streaming CDP (Turkey, not the UK).
  • 22 of 35 candidates rejected: 6 EU candidates (BlueConic, Bloomreach/Exponea, Clerk.io, Mapp/Webtrekk, Splio, Actito) were already catalogued, just under the marketing or e-commerce category instead of customer-data-platform; 3 candidates turned out not to have an EU headquarters despite the claim (Teavaro = UK, Meiro = Singapore, Insider = Turkey); "Twosense / Acxiom Real-Time CDP" was a fabricated pairing of two unrelated companies; Lytics is no longer available as a standalone product following its acquisition.

6 DNS privacy resolvers added

A sixth submitted candidate list (DNS privacy resolvers) independently verified: 6 new vendors, 19 rejected — often because a small individually-run service had since shut down or never existed.

Added

  • 6 vendors added to dns-privacy: UncensoredDNS/Censurfridns (Denmark, active since 2009), Freifunk München DNS, Dismail.de Secure DNS, dnsmasq, Stubby and SmartDNS.
  • 19 of 25 candidates rejected: 5 were already catalogued (Knot Resolver, PowerDNS, CoreDNS, BIND9, NSD, some filed under cdn-dns), several small individually-run European DNS services turned out to have shut down (Swiss Privacy Foundation DNS since 2015, Snopyta) or never existed ("Grote Netwerken / Captn DNS", "Tungsol DNS", "Amaze DNS" — each sourced with only a bare github.com link), and "Nebula DNS Connectors" turned out to be Slack's mesh-VPN tool Nebula, unrelated to DNS.

13 vendors added across data integration and ETL

A fifth submitted candidate list (data integration/ETL) independently verified: 13 new vendors, 32 rejected — most because they were already catalogued, sometimes under a different category.

Added

  • 13 vendors added spread across data-integration (TimeXtender, Logstash, Apache Camel, Redpanda, Dagster, Vector, AWS Glue, Azure Data Factory, Google Cloud Dataflow), data-platform (Apache Spark, Apache Beam), data-governance (BiG EVAL) and customer-data-platform (Multiwoven).
  • 32 of 45 candidates rejected: over 20 were already catalogued (often under a different category than claimed — Boomi and MuleSoft, for instance, sit under api-management, not data-integration), a few were fabricated or mislabelled products ("Halaxy / DataVirtuality", Squidex described as an ETL tool when it's actually a CMS), and two EU vendors (Stambia/Semarchy, Denodo) turned out to have since moved their headquarters to the US — the same ADR-001 rule already applied to Optimizely and Dashlane.

16 vendors added across cloud infrastructure

A fourth submitted candidate list (cloud IaaS) independently verified: 16 new vendors spread across cloud-iaas, virtualization and network-infrastructure, 24 rejected as already catalogued or nonexistent.

Added

  • 6 European IaaS/VPS vendors added to cloud-iaas: Bleu (Orange/Capgemini sovereign cloud), Delska, Infomaniak Public Cloud, Nine Internet Solutions, VNET Cloud, Prometeus.
  • 5 open-source virtualization tools added to virtualization: oVirt, KubeVirt, Virt-Manager, MicroCloud (Canonical), plus Open vSwitch added to network-infrastructure.
  • 5 US benchmarks added: AWS European Sovereign Cloud and Oracle EU Sovereign Cloud (separate, EU-incorporated legal entities with a US ultimate parent), Vultr, Akamai Connected Cloud (formerly Linode), CoreWeave.
  • 24 of the 40 candidates rejected: already catalogued under a different name or category (incl. Apache CloudStack, Proxmox VE, Ceph, LINSTOR, Gcore, Scalingo, Greenhost), nonexistent or linked to the wrong URL (e.g. "Netcetera Cloud", "Hydro66" pointing to an unrelated company), or a vendor with a falsely claimed EU headquarters while its real parent company sits in Russia (Serverspace/ITGLOBAL.COM).

Fixed a scoring bug for self-hosted software; removed 2 WordPress-only plugins

Self-hostable and community-distributed open-source vendors were incorrectly scored as the worst possible case on data residency. Koko Analytics and Statify (WordPress plugins) have been removed from analytics: they aren't a standalone service.

Removed

  • Removed Koko Analytics and Statify from analytics: they are WordPress-only plugins that only work inside a WordPress site, not a standalone analytics service — and that category is meant to be platform-agnostic.

Fixed

  • The data-residency score (DRS) ignored self-hostable or community-distributed open-source software: without an explicit EU country code among the hosting regions (e.g. a vendor whose only region was "self-host" or "GitHub"), such a vendor scored the worst possible 100 ("no EU hosting") — when self-hosting is precisely what lets you choose where the data lives. Around 59 catalogue vendors were incorrectly shown red because of this. The scoring engine now always treats `sovereignty_mode: self-host`/`oss-distributed` as a data-residency score of 0.

51 vendors added to analytics and AI security

5 web-verified community submissions (Verde Holding Kft., Hungary) and 46 new vendors in the analytics and ai-security categories, after independently verifying two submitted candidate lists.

Added

  • 5 vendors from Verde Holding Kft. (Hungary/Slovakia) added after verification via their own privacy-policy pages: Felhő, Overit, Bizonylat, időpontok and Podpisat.
  • 22 vendors added to ai-security (including Mindgard, LLM Guard, Presidio, Arize AI, Cisco AI Defense) after independently web-verifying a submitted candidate list — over half the original list was dropped as already catalogued, nonexistent, or miscategorised.
  • 24 vendors added to analytics (including GoatCounter, Koko Analytics, Contentsquare, Smartlook, Snowplow) via the same independent verification, including corrections to incorrectly claimed headquarters countries.

27 vendors added — knowledge base reaches 3,500

New EU vendors Storyteq, AtroDAM, Razuna, Phrasea, Comosoft LAGO, Sharedien, Picturepark, Sliplane, Platform.sh, anynines, lowcloud, DanubeData, Encore and Raynet One, plus international benchmarks. With this, the knowledge base reaches its 3,500-vendor target.

Added

  • 27 vendors added across digital-asset-management, cloud-paas and endpoint-management — the knowledge base now stands at 3,500 vendors.

13 vendors added across 2 categories

New EU vendors LingoHub, Gridly, Prompsit, Tilde, SimpleLocalize, Gingout, Pangea Global, eTranslation and PassSecurium, plus international benchmarks.

Added

  • 13 vendors added across translation and password-manager — the knowledge base now stands at 3,473 vendors.

18 vendors added across 2 categories

New EU vendors CERRIX, Swiss GRC, Enactia, Matproof, Copla, Actecil, Recruitis, Adeptiq, CVWarehouse, HROffice, Altamira Recruiting and HireHive, plus international benchmarks.

Added

  • 18 vendors added across compliance-grc and recruitment-ats — the knowledge base now stands at 3,460 vendors.

72 vendors added across 6 categories

New EU vendors Pixelmator Pro, Cinema 4D, TVPaint, eYou, W Social, BeReal, CounterMail, CTemplar, Caliopen, Ligo, fynk, Contractify, Bigle Legal, Bind Legal, Bird, Spryng, LOX24 and PAFnow, plus dozens of international benchmarks.

Added

  • 72 vendors added across design, social-media, email-personal, time-tracking, legal-tech and sms-api, plus a process-mining-rpa supplement — the knowledge base now stands at 3,442 vendors.

53 vendors added across 6 categories

New EU vendors A-Trust, TrustPro, Agrello, Oneflow, Subnoto, Paperless.io, SIGN8, inSign, Infomaniak kChat, Realtime Register, Webland, easyname, Northmill Bank, Rocker, Solaris, Saldo Bank, Wallester, Tinaba, Zen.com, VeloBank, ActivoBank and Tinybird, plus dozens of international benchmarks.

Added

  • 53 vendors added across testing-qa, esign, messaging, domain-registrar, fintech-banking and data-platform — the knowledge base now stands at 3,370 vendors.

65 vendors added across 6 categories

New EU vendors GBTEC, Tailent, Tebis, GRAITEC, HiCAD, Shapr3D, VariCAD, HIGHRESAUDIO, STAGE+, Klassik Radio Plus, HERE Technologies, Sinergise, Airbus Defence & Space, Mercateo, VORTAL, AddVue, Keelvar, Sana Learn, Scheer IMC, time4you, SoftDeCC, Sanoma Learning and Gility, plus dozens of international benchmarks.

Added

  • 65 vendors added across process-mining-rpa, cad-engineering, music-streaming, gis-geospatial, procurement and education-lms — the knowledge base now stands at 3,317 vendors.

46 vendors added across 6 categories

New EU vendors Telebugs, UXCam, dunDNS, Alpega Group, AEB SE, PSI Logistics, PULPO WMS, Ehrhardt Partner Group, Logistics Reply, Davanti, Talkspirit, Jamespot, eXo Platform, Framasoft, Easiware, eDesk and IncludeOS, plus dozens of international benchmarks.

Added

  • 46 vendors added across error-tracking, dns-privacy, supply-chain-operations, office-productivity, helpdesk-support and virtualization — the knowledge base now stands at 3,252 vendors.

52 vendors added across 6 categories

New EU vendors Cerascreen, F-Secure VPN, Avira Phantom VPN, PrivateVPN, Goose VPN, Everteam, Pydio Cells, DocLogix, Fabasoft, Woosmap and ViaMichelin, plus dozens of international benchmarks.

Added

  • 52 vendors added across health-personal, data-integration, vpn, ai-cowork, document-management and maps — the knowledge base now stands at 3,206 vendors.

44 vendors added across 5 categories

New EU vendors Livesignage, Cloudchipr, Meshcloud, Kontakt.io, Actility ThingPark and Royal TS, plus dozens of international benchmarks.

Added

  • 44 vendors added across digital-signage, finops, iot-embedded, remote-desktop and writing-tools — the knowledge base now stands at 3,154 vendors.

43 vendors added, knowledge base passes 3,100

New EU vendors Sender, Cludo, Seznam, Calendesk and Feature Upvote, plus dozens of international benchmarks.

Added

  • 43 vendors added across transactional-email, enterprise-search, search-engine, scheduling-booking, telephony-voip and product-feedback — the knowledge base now stands at 3,110 vendors.

45 vendors added across 6 categories

New EU vendors Piano, DNS.SB, LibreDNS, Ziteboard, Dastra and XTM Cloud, plus dozens of international benchmarks.

Added

  • 45 vendors added across tag-management, dns-privacy, whiteboarding, compliance-grc, endpoint-management and translation — the knowledge base now stands at 3,067 vendors.

50 vendors added, knowledge base passes 3,000

New EU vendors sms.to, Movavi, WorkIO, Xpert-Timer, Envirotech and Wolters Kluwer Enablon, plus dozens of international benchmarks.

Added

  • 50 vendors added across sms-api, music-streaming, photo-video, time-tracking, recruitment-ats and esg-sustainability — the knowledge base now stands at 3,022 vendors.

47 vendors added across 6 categories

New EU vendors ProcessMind, Exeura, KYP.ai, FeatBit, Confidence, TGGL and Key-Systems, plus dozens of international benchmarks.

Added

  • 47 vendors added across process-mining-rpa, error-tracking, fintech-banking, feature-flagging, domain-registrar and legal-tech — the knowledge base now stands at 2,972 vendors.

18 vendors added across backup and cloud storage

New EU vendors Degoo, NordLocker and UrBackup, plus international benchmarks such as Mega, Cohesity and Macrium Reflect.

Added

  • 18 vendors added across backup-personal, cloud-storage-personal and storage-backup — the knowledge base now stands at 2,925 vendors.

6 vendors added across 2 categories

New EU vendors Haiilo, CatalystOne, Jobrad, Rydoo and Pluxee, plus the open-source benchmark TimeTrex.

Added

  • 6 vendors added across hr and procurement — the knowledge base now stands at 2,907 vendors.

18 vendors added across 5 categories

New EU vendors Templafy, Dashlane and F-Secure ID Protection, plus benchmarks such as Apache JMeter and Keeper Security.

Added

  • 18 vendors added across ai-cowork, document-management, email-personal, testing-qa and password-manager — the knowledge base now stands at 2,901 vendors.

17 vendors added across 5 categories

New EU vendor Linbit DRBD/LINSTOR, plus benchmarks such as Esri ArcGIS, Canvas LMS and Viber.

Added

  • 17 vendors added across gis-geospatial, virtualization, education-lms, messaging and helpdesk-support — the knowledge base now stands at 2,883 vendors.
  • Moved Blackboard Learn, D2L Brightspace and Schoology from elearning-tools to education-lms (academic LMS, not corporate-training tools).

12 vendors added across 3 categories

New EU vendors Perfect Privacy and PrivadoVPN, plus benchmarks such as Thriva and Procurify.

Added

  • 12 vendors added across health-personal, procurement and vpn — the knowledge base now stands at 2,866 vendors.

12 vendors added across 5 categories

New EU vendor Remote Utilities, plus benchmarks such as Securiti, Fider and Archera.

Added

  • 12 vendors added across remote-desktop, compliance-grc, product-feedback, writing-tools and finops — the knowledge base now stands at 2,854 vendors.

11 vendors added across 5 categories

New EU vendors Bucket (Reflag) and Cozero, plus benchmarks such as BrightSign and SparkPost.

Added

  • 11 vendors added across feature-flagging, error-tracking, esg-sustainability, digital-signage and transactional-email — the knowledge base now stands at 2,842 vendors.

49 vendors added across 4 categories

New EU vendors ArangoDB, OrientDB, openDesk and Zensai, plus dozens of benchmarks across office-productivity, data-platform, database and elearning-tools.

Added

  • 49 vendors added across office-productivity, data-platform, database and elearning-tools — the knowledge base now stands at 2,831 vendors.

10 vendors added across 4 categories

New EU vendors Piwik PRO Tag Manager, TAGGRS, Whiteboard.fi and Sketchboard, plus benchmarks such as Apple Freeform and Zoom Phone.

Added

  • 10 vendors added across tag-management, dns-privacy, whiteboarding and telephony-voip — the knowledge base now stands at 2,782 vendors.

17 vendors added across 5 categories

New EU vendors Jamendo and Acronis True Image, plus benchmarks such as AWS IoT Core and Baidu.

Added

  • 17 vendors added across backup-personal, music-streaming, iot-embedded, search-engine and enterprise-search — the knowledge base now stands at 2,772 vendors.

17 vendors added across 5 categories

New EU vendors 360Learning and LearnUpon, plus benchmarks such as Greenhouse and WPS Office.

Added

  • 17 vendors added across photo-video, recruitment-ats, sms-api, elearning-tools and office-productivity — the knowledge base now stands at 2,755 vendors.

16 vendors added across 5 categories

New EU vendors Legora, Lunar and Sumeria, plus benchmarks such as NinjaOne and Calendly.

Added

  • 16 vendors added across endpoint-management, legal-tech, fintech-banking, process-mining-rpa and scheduling-booking, and a duplicate listing (Teamtailor ATS) removed — the knowledge base now stands at 2,738 vendors.

German and French added as new languages

The site is now also reachable via /de and /fr. Translation of the full vendor catalogue follows over the coming days.

Added

  • German (/de) and French (/fr) added as new languages alongside Dutch and English. Navigation and page structure are fully available; vendor descriptions not yet translated show the English text in the meantime.

20 vendors added across 5 categories

New EU vendors EcoVadis, Sustainalytics, Scribens, Reverso and Elastic Email, plus benchmarks such as Firebolt and NoviSign.

Added

  • 20 vendors added across esg-sustainability, writing-tools, data-platform, digital-signage and transactional-email — the knowledge base now stands at 2,723 vendors.

14 vendors added across 5 categories

New EU vendors Ensighten, econda, Klaxoon and ISL Online, plus benchmarks such as Raygun, Splashtop and DevCycle.

Added

  • 14 vendors added across tag-management, whiteboarding, remote-desktop, error-tracking and feature-flagging — the knowledge base now stands at 2,703 vendors.

24 vendors added: Networking & Monitoring

3 EU vendors (Shinken, collectd, SmokePing) and 21 non-EU additions, including New Relic, Honeycomb and ThousandEyes.

Added

  • 24 vendors added to Networking & Monitoring — the knowledge base now stands at 2,689 vendors.

Open-source page: collapsible per category, with its own pages

The open-source page now shows categories collapsed and in alphabetical order, and each category now has its own page listing its open-source vendors.

Changed

  • Open-source vendors per category are now collapsible, sorted alphabetically, with a dedicated page per category.

27 vendors added: Low-code & No-code

7 EU vendors (including Novulo, Thinkwise and OpenLowCode) and 20 non-EU additions, including Microsoft Power Apps, Bubble and Webflow. Also corrected the Screenbird description again after vendor follow-up.

Added

  • 27 vendors added to Low-code & No-code Application Development — the knowledge base now stands at 2,665 vendors.

Fixed

  • Screenbird's description corrected again: e-mail has run via Cloudflare (not Resend) since mid-September, uploaded files are stored in Cloudflare R2 in Western Europe, and the core content consists of files, playlists and schedules (not "recordings").

16 vendors added: Performance Management / EPM

7 EU vendors (including Talentia Software, Perdoo and SAP Analytics Cloud) and 9 non-EU additions, including open-source OLAP engines and benchmarks like OneStream and Prophix.

Added

  • 16 vendors added to Performance Management / Enterprise Performance Management (EPM) — the knowledge base now stands at 2,638 vendors.

Community submissions: UseClick and Hourtick added

Two vendor self-submissions, independently re-verified: UseClick (Germany, cookie-free link analytics) and Hourtick (Denmark, time tracking for people and AI agents). The submission form now also optionally asks for a privacy-policy and DPA link.

Added

  • 2 vendors added via community submissions — the knowledge base now stands at 2,622 vendors.

Fixed

  • The non-European vendor list on category pages looked cluttered from text pills wrapping to a second line — now one tidy row per vendor.

29 vendors added: Data Governance & Metadata Management

3 EU vendors (Dawex, Dataedo, Data Contract CLI) and 26 non-EU additions, including open-source catalogs like DataHub and Apache Atlas and benchmarks like Precisely and BigID.

Added

  • 29 vendors added to Data Governance & Metadata Management — the knowledge base now stands at 2,620 vendors.

4 vendors added: Customer Data Platforms

CrossEngage (Germany, part of Spotler Group) and three non-EU additions: Census, Zingg and GrowthLoop.

Added

  • 4 vendors added to Customer Data Platforms — the knowledge base now stands at 2,591 vendors.

Consent management cleaned up and 8 vendors added

Usercentrics, Cookiebot and consentmanager.net were catalogued twice (also under cybersecurity/compliance-grc) — now cleaned up. Also 8 new vendors, including Cookie-Script, Sirdata and Tarteaucitron.js.

Added

  • 8 vendors added to Consent Management Platforms — the knowledge base now stands at 2,587 vendors.

Fixed

  • Usercentrics, Cookiebot and consentmanager.net were catalogued twice — consolidated under Consent Management.

16 vendors added: CDN, DNS & Domains

5 new EU vendors (incl. Knot DNS, Knot Resolver, Varnish Cache, Traefik) and 11 non-EU open-source building blocks and benchmarks (incl. BIND9, CoreDNS, Envoy Proxy, Akamai, Fastly).

Added

  • 16 vendors added to CDN, DNS & Domains — the knowledge base now stands at 2,582 vendors.

CDN/DNS category cleaned up: hosters and registrars removed

Removed Combell, Hostnet, OVH DNS and TransIP from CDN, DNS & Domains — their DNS is only bundled on top of hosting/domain registration, and they were already correctly catalogued under their own category. Moved Openprovider and WEDOS to Domain Registrars and Web Hosting respectively.

Fixed

  • Cleaned up CDN, DNS & Domains: removed 4 duplicate hoster/registrar entries, moved 2 to their correct category — the knowledge base now stands at 2,555 vendors.

10 vendors added: Business Intelligence

6 new open-source BI tools (incl. Apache Superset, Metabase, Lightdash) and 4 non-EU benchmarks (Palantir Foundry, Sisense, Sigma Computing, Domo).

Added

  • 10 vendors added to Business Intelligence — the knowledge base now stands at 2,559 vendors.

18 vendors added: business email & groupware

13 new self-hosted mail server/groupware tools (incl. Postfix, Dovecot, Mail-in-a-Box, CipherMail), 2 new French email services (Mailo, Ecomail) and 3 non-EU benchmarks (Zoho Mail, Amazon WorkMail, Fastmail). Also: corrected the Screenbird description — its US sub-processors do process narrowly-scoped customer data.

Added

  • 18 vendors added to Business Email & Groupware — the knowledge base now stands at 2,549 vendors.

Fixed

  • Screenbird: its US sub-processors (Stripe, Anthropic, Resend) do process narrowly-scoped customer data — data location reverted to EU + US.

28 vendors added: API management, BPM & workflow, browsers

11 new vendors in API Management (incl. Ory Oathkeeper, Zuplo, Hoppscotch), 14 in BPM & Workflow (incl. Temporal, Apache Airflow, Prefect) and 3 new browsers (Ecosia, DuckDuckGo Browser). The knowledge base now stands at 2,531 vendors.

Added

  • 28 vendors added to API Management, BPM & Workflow and Browsers — the knowledge base now stands at 2,531 vendors.

Past 2,500 vendors: 14 AI coding tools added

12 new vendors in AI Coding (including Aider, Cline, Tabby and Goose) and 2 in AI (llama.cpp, LiteLLM). Qodo was incorrectly listed as 'EU' in the supplied list — independently checked: Tel Aviv, Israel.

Added

  • 14 vendors added to AI Coding and AI — the knowledge base now stands at 2,503 vendors.

Cleaner navigation, clear Donate button added

Moved Map and About to the footer (already listed there), renamed Reports to Pricing, and added a dedicated Donate button. On the support page, the donation amounts now sit right under the intro instead of below three paragraphs of explanation.

Changed

  • Top nav: removed Map and About (already in the footer), Reports → Pricing, new Donate button.
  • Support page: donation buttons now sit directly under the intro and stand out more visually.

Score bug fixed: an EU country's own code was wrongly read as non-EU

A customer pointed out that Screenbird's hosting location was wrongly scored as 'mixed'. While checking this, we found the scoring engine itself didn't recognise a specific EU country's own code (like 'DE') as EU hosting — fixed for every vendor, with no data changes needed. Also corrected Mindbreeze and Explain Everything based on their own privacy policies.

Fixed

  • The scoring engine now recognises specific EU country codes (e.g. 'DE', 'FR') as EU hosting, not just the generic 'EU' token.
  • Mindbreeze: hosting region corrected to EU-only (core data sits exclusively in Germany/Austria/Switzerland).
  • Explain Everything: hosting region corrected to US-only (no EU data centre available, contrary to what was listed earlier).

20 more vendors: domain registrars, SMS, DNS privacy and more

Added 20 more verified vendors, including Kaleyra (Italian HQ, but owned by India's Tata Communications — a good example of why we track HQ and parent company separately) and FDN DNS (a French nonprofit DNS resolver).

Added

  • 20 vendors added across domain-registrar, sms-api, transactional-email, dns-privacy, process-mining-rpa and error-tracking.

87 new vendors across the 10 thinnest categories

Filled out the 10 categories with the fewest vendors (from enterprise search to testing/QA) with 87 verified, real vendors — including Elasticsearch, Datafari, ConfigCat, AB Tasty, Kameleoon, DataDome and TestRail as EU alternatives.

Added

  • 87 vendors added across enterprise-search, whiteboarding, tag-management, feature-flagging, finops, product-feedback, consent-management, captcha, elearning-tools and testing-qa.

New page: support this tool

A dedicated page explaining why the tool stays free, why we depend on donations, and what your contribution actually funds.

Added

  • New /support page with the full explanation of our donation and funding model, linked from the homepage and the footer.

82 new vendors added

Major addition after comparing the catalogue against three external lists of well-known enterprise software, customer data platforms and AI-security tools: 82 missing vendors added, including Oracle CX Cloud, SugarCRM, HashiCorp Vault and a range of customer data platforms and AI red-teaming tools.

Added

  • 82 new vendors added after independent verification (enterprise software, customer data platforms, AI security).

Fixed

  • Fixed a bug where previously added vendors (such as Screenbird) appeared on category pages but not on the map.

Source re-verification, round 11: 60 vendors

Round 11: 18 corrections, including eleven community open-source projects wrongly marked "vendor-hosted", and Garden.io (headquarters turned out to be Germany, with an Israeli parent company since its 2024 acquisition).

Fixed

  • 18 vendor facts corrected after independent verification.

Source re-verification, round 10: 60 vendors

Round 10: 15 corrections, including Erxes (headquarters turned out to be California, not Mongolia), Evernote and Etherpad (both had their controlling entity's country confused with their own headquarters), and three community open-source projects.

Fixed

  • 15 vendor facts corrected after independent verification.

Source re-verification, round 9: 60 vendors

Round 9: 11 corrections, including the same internal inconsistency found five more times (a US country paired with the wrong region code) and four community open-source projects wrongly marked "vendor-hosted".

Fixed

  • 11 vendor facts corrected after independent verification.

Source re-verification, round 8: 60 vendors

Round 8: 16 corrections. Biggest catch: Debian's legal entity is US-based, not German, and the "Dutch" Deel listing turned out to be a local office — the real headquarters is San Francisco. Also seven community open-source projects wrongly marked "vendor-hosted".

Fixed

  • 16 vendor facts corrected after independent verification.

2 new vendors: Screenbird and Voronai

Two Dutch vendors added after a community submission: Screenbird (digital signage) and Voronai (customer data platform). Both independently verified, not taken on the vendor's word alone.

Added

  • Screenbird (NL) added to digital signage.
  • Voronai (NL) added to customer data platform.

Source re-verification, round 7: 60 vendors

Round 7: 18 corrections. Biggest catch: CyberArk is headquartered in Israel, not the US (acquired by Palo Alto Networks in February). Also CrateDB (US, not Austria) and five community open-source projects wrongly marked "vendor-hosted".

Fixed

  • 18 vendor facts corrected after independent verification.

Categories now sorted alphabetically

The categories page listed categories sorted by EU-vendor count. Now sorted alphabetically instead, by the name as shown on screen.

Fixed

  • Categories on /categories are now in alphabetical order.

Source re-verification, round 6: 60 vendors

Round 6: 9 corrections, including an incorrect UK parent on three Combell listings and on Complianz (team.blue, actually Belgian) and Concourse CI (correctly a distributed open-source project, not a company with a headquarters).

Fixed

  • 9 vendor facts corrected after independent verification.

Sovereignty badge now on the map and alternatives dashboard too

The badge now appears everywhere you browse vendors: the alternatives dashboard (rows, expanded alternatives, search results) and the map's vendor pop-up too.

Added

  • Sovereignty badge on the alternatives dashboard and the map.

Sovereignty badge now on category and country pages too

The badge already appeared on vendor pages and in the report; now it shows next to every vendor on category and country pages too, so you can scan a whole list at a glance.

Added

  • Sovereignty badge on category and country pages.

Sovereignty badge on vendor pages and the report

Right under every vendor's name there is now one clear mark: EU sovereign, self-host/open source, EU-hosted with a non-EU parent, or non-EU. The same badge now also appears in the paid report's vendor table.

Added

  • Four-tier sovereignty badge, computed from existing facts (no new database field).

Source re-verification, round 5: 60 vendors

Round 5: 11 corrections, including CiviCRM and Checkly (both actually US, not Belgium/Germany), Checkmk (no US parent at all — it's stayed German-owned throughout its history), and two open-source projects (Ceph, CapRover) wrongly marked "vendor-hosted".

Fixed

  • 11 vendor facts corrected after independent verification.

Source re-verification, round 4: 60 vendors

Round 4: 13 corrections, including Blomp (US, not UK), two "self-host" listings (BookStack, Cachet) that used a generic EU placeholder despite a real registered company behind them, and three open-source projects (Blocky, BRouter, BookWyrm) wrongly marked "vendor-hosted" instead of distributed open source.

Fixed

  • 13 vendor facts corrected after independent verification.

Source re-verification, round 3: 60 vendors

Round 3: the next 60 vendors checked. 5 corrections, including two missing parent companies (Auth0/Okta, Aware Health/Aeon) and two internal inconsistencies (a US headquarters paired with the wrong region code). A not-yet-completed acquisition (Bahnhof/Telenor) was deliberately left unrecorded.

Fixed

  • 5 vendor facts corrected after independent verification.

Source re-verification, round 2: 59 vendors

Round 2 of the ongoing re-verification pass: the next 59 vendors (alphabetically) checked against independent sources. 7 corrections, including Anytype (Berlin, not Switzerland), AppFlowy (Singapore, not the US), and Alpine Linux (reclassified as an open-source project with no fixed headquarters). A premature merger (Aleph Alpha/Cohere) was removed from the data since it hasn't closed yet.

Fixed

  • 7 vendor facts corrected after independent verification.

Full-catalogue source re-verification begins (round 1: 60 vendors)

We've started an ongoing re-verification pass across the whole catalogue: 93% of vendors had a check date but no actual source behind it. Round 1 checked the first 60 (alphabetically) against independent sources and found 8 corrections (e.g. 4me turns out to be US-based, not Dutch) plus one duplicate (About You Cloud/Commerce = SCAYLE), now merged.

Removed

  • Merged a duplicate entry: About You Cloud and About You Commerce were both SCAYLE.

Fixed

  • 8 vendor facts corrected (country, parent company, or sovereignty model) after independent verification.

EU adequacy-decision status now shown on every vendor page

Every vendor page and report now shows whether the European Commission has found the headquarters country's data protection adequate — a real, citable EU legal fact. The US deliberately does not get a simple yes/no: the EU-US Data Privacy Framework only covers individually certified companies, so that status is marked separately as "conditional".

Added

  • EU adequacy-decision status added as a fact on the vendor page and in the report, with a separate status for the US (DPF-certified companies only).

9 European vendors close three categories with no EU options

The previous update noted that Customer Data Platform, FinOps and Product Feedback had zero European vendors. Targeted European research found nine after all: Upvoty, Featurebase, Sleekplan and ProductLift (product feedback), Holori and Cycloid (FinOps), and Mediarithmics, Zeotap and Commanders Act (Customer Data Platform).

Added

  • 9 European vendors added to Customer Data Platform, FinOps and Product Feedback.

Six new categories and more European AI-security vendors

After a systematic review of our 90 categories, six missing software types turned up: Customer Data Platform, Feature Flags & Experimentation, FinOps, Enterprise Search, Product Feedback and Digital Whiteboards. 25 new vendors were added, and targeted research for European AI-security vendors surfaced Giskard (France) and Lakera (Switzerland). Along the way, two duplicate entries were caught and removed before going live.

Added

  • Six new categories with 25 vendors, plus Giskard and Lakera added to AI Security.

Fixed

  • Miro and Mural moved to the new, more specific "Digital Whiteboards" category.

New "AI Security" category with 22 verified vendors

AI security tools (prompt-injection defence, AI red-teaming, AI governance) are a fast-growing market that wasn't in our knowledge base yet. We've added 22 vendors — every fact independently checked, never taken at face value. One vendor from the source turned out to be just a coming-soon page and was deliberately left out; another's obvious domain turned out to belong to a completely different company.

Added

  • New "AI Security" category with 22 vendors (1 European: NeuralTrust from Barcelona), each with source citations and a technical hosting signal.

euBackups added

euBackups (a German backup service for MSPs and businesses, built on Acronis, with backups stored in Germany) was submitted by the vendor itself. Before adding it, we independently checked every fact against their own legal notice, privacy policy and data processing agreement — never taking the submission at face value.

Added

  • euBackups added to the storage/backup category, with source citations and a technical hosting signal.

Explanation of our four verification labels added to "About this tool"

Vendor pages have shown badges like "Confirmed in registry" or "Vendor-stated" for a while — but nowhere explained what they actually mean. The "About this tool" page now spells out all four labels in plain language.

Added

  • An overview of the four verification labels (vendor-stated, confirmed in registry, technically measured, not yet checked) on the "About this tool" page.

Ownership chain and ultimate parent company now shown on the vendor page

A vendor's "ultimate parent company" has been in our data for a while but was never actually shown anywhere — now fixed. For Sitecore Content Hub, the full ownership chain has also been researched and added.

Added

  • New "Ultimate parent company" and "Sovereignty model" facts on the vendor page, plus an "Ownership chain" section where this has been researched.

Certifications cross-checked against an independent registry (CSA STAR)

For 103 vendors, the CSA STAR certification is no longer just "vendor-stated" but confirmed against the official CSA STAR registry — linking to its own registry entry instead of the vendor's generic page.

Added

  • Certification badges show "Confirmed in registry" once a vendor is independently found in the CSA STAR registry, linking directly to that entry.

Technical hosting signal: independent evidence, not sourced from the vendor

Established which network serves each vendor's website via a DNS lookup, for 2,216 of 2,227 vendors — the first evidence type that doesn't rely on anything the vendor itself publishes. Note: this is about the website, often behind a CDN, not necessarily where the service or data is actually hosted.

Added

  • New "Technical hosting signal" section on the vendor page and, for the first time, in the paid PDF report — badged "technically measured", the strongest provenance level.

Provenance badges on compliance evidence, now also in the PDF report

Every compliance field and certification now shows explicitly how it was established — today that's honestly always "vendor-stated", since that's what the research has done so far. The paid report shows compliance evidence for the first time.

Added

  • Provenance badge on every DPA/subprocessor/security/EU-hosting link and every certification on the vendor page.
  • The paid PDF report now also shows compliance evidence per vendor, with the same provenance badges.

Compliance evidence extended to 580 vendors (round 10)

Researched the next 200 most-recommended vendors again, including several previously-rejected vendors that came back this round with new, better evidence. One rejection rule in the merge script turned out too narrow (it only checked one field while the same bad page reappeared under a different field) and has been broadened.

Added

  • 580 vendors with compliance evidence in total (516 European, 64 non-European): 242 DPAs, 63 subprocessor lists, 463 security pages, 150 EU-hosting pages and 38 vendors with certifications.

Fixed

  • A rejection rule for one vendor's bad page previously checked only one field; it now checks every field at once.

Compliance evidence extended to 561 vendors (round 9) — plus a fix for three earlier rejections that had silently failed

Researched the next 200 most-recommended vendors again. In the process we found a bug in the merge script that had left three fields we had reported as rejected (Codefresh, Teamhood, Checkmk) quietly live ever since their own rounds. Fixed, and existing installations will pick this up automatically.

Added

  • 561 vendors with compliance evidence in total (497 European, 64 non-European): 228 DPAs, 61 subprocessor lists, 456 security pages, 150 EU-hosting pages and 37 vendors with certifications.

Fixed

  • Fixed a bug that had left three previously-rejected vendor fields (Codefresh, Teamhood, Checkmk) live by mistake.

Compliance evidence extended to 540 vendors (round 8) — plus a fix that backfills earlier rounds

Researched the next 200 most-recommended vendors again. In the process we found that a bug in the merge script had silently skipped one 20-vendor research batch per round ever since round 2. Fixed, and every previously missed round was re-checked with the same rigor and added.

Added

  • 540 vendors with compliance evidence in total (476 European, 64 non-European): 220 DPAs, 60 subprocessor lists, 445 security pages, 148 EU-hosting pages and 37 vendors with certifications.

Fixed

  • Fixed a script bug that had been skipping one research batch per round since round 2; the missed findings were checked and added retroactively.

New: Contact page

Added a separate Contact page for press, collaboration and other general enquiries — distinct from the vendor submission page. Linked from the footer.

Added

  • Contact page (NL/EN) with an email address for general enquiries.

Compliance evidence extended to 520 vendors (round 7)

Researched the next 200 most-recommended vendors again. Manual review removed six loose links that turned out not to be real evidence (among them a bare link overview instead of actual content, a data processing agreement belonging to a separate sibling product, and a page that only incidentally contained the word "security" in a menu). For Internxt, the combined legal page was partly legitimate: the security and subprocessor content was genuinely there, but the DPA and EU-hosting claims were not.

Added

  • 520 vendors with compliance evidence in total (457 European, 63 non-European): 208 DPAs, 58 subprocessor lists, 428 security pages, 147 EU-hosting pages and 36 vendors with certifications.

Fixed

  • Codefresh: updated the vendor description — the codefresh.io marketing site was folded into parent company Octopus Deploy's site in 2026; existing customers still log in under the Codefresh name.

Fix: Aiven does not host exclusively in the EU

A reader flagged that Aiven runs on any cloud platform. That's correct: Aiven offers free region selection across six cloud platforms (AWS, Google Cloud, Azure, DigitalOcean, OVH, UpCloud) in over 100 regions worldwide. The catalogue's cloud-iaas record for Aiven wrongly said "EU hosting only"; this has been corrected to EU, US and APAC.

Fixed

  • Aiven's hosting regions corrected from EU-only to EU, US and APAC.

Fix: self-hostable vendors were incorrectly scored as "hosted by the vendor"

A reader flagged a contradiction on edgeContinuum's page: it said "closed source and hosted by the vendor", while the vendor actually runs on infrastructure the customer controls. Investigation found this affected 68 vendors in the catalogue, and not just the text — the key-management and source/runtime scores also didn't account for self-hosting. Both have been corrected.

Fixed

  • Self-hostable, closed-source vendors now score better on key management and source/runtime sovereignty, and the description correctly states that you control the hosting location and keys yourself.

Three new vendors: Affinity Photo, Ollama, Peakto

Reviewed which software visitors type in during an assessment that the catalogue was still missing. Added: Affinity Photo (photo editing, UK/owned by Australia's Canva — catalogued as a recognisable non-EU vendor so EU alternatives can be shown), Ollama (locally-run open AI language models, open source) and Peakto (French photo catalogue management, a strong EU-owned find). Two other candidates turned out to be out of scope (physical alarm security) or already present under a different name (an Israeli, now US-owned, security company).

Added

  • Affinity Photo (Design), Ollama (AI) and Peakto (Photo & Video) added to the catalogue.

New vendor: edgeContinuum (Spain)

Added via the submission form: edgeContinuum, a Spanish cloud orchestration platform for self-managed virtual machines, Kubernetes and PostgreSQL, also suited to on-premises and air-gapped environments. Independently verified before adding (it was a self-submission by the vendor): category corrected to 'cloud-iaas' and the hosted-in-the-EU claim was not carried over for lack of hard evidence.

Added

  • edgeContinuum added to the cloud infrastructure category.

Compliance evidence extended to 471 vendors (round 6)

Researched the next 200 most-recommended vendors again. This round, eight loose links were removed that turned out, on manual review, not to be real evidence (among them an install page, a vendor's own homepage, and a marketing page about cybersecurity services rather than the vendor's own security policy). A reader flagged missing DPA evidence for BigBlueButton; that has been added.

Added

  • 471 vendors with compliance evidence in total (410 European, 61 non-European): 193 DPAs, 57 subprocessor lists, 388 security pages, 144 EU-hosting pages and 31 vendors with certifications.

Compliance evidence extended to 410 vendors (round 5)

Researched the next 200 most-recommended vendors again. This round's page-context review found no false certification claims, but caught eight loose links that only coincidentally contained a keyword without being real evidence (among them a review-site name misread as "trust", and two vendors where every field pointed to the same generic terms-of-service page); those were removed before the data was merged.

Added

  • 410 vendors with compliance evidence in total (351 European, 59 non-European): 163 DPAs, 50 subprocessor lists, 348 security pages, 128 EU-hosting pages and 30 vendors with certifications.

Compliance evidence extended to 344 vendors (round 4)

Researched the next 200 most-recommended vendors again, same method as the previous three rounds. Both certification claims in this round turned out, on manual review, to be a direct, first-person claim by the vendor itself (CELUM and elastic.io, both ISO/IEC 27001) and were kept.

Added

  • 344 vendors with compliance evidence in total (289 European, 55 non-European): 137 DPAs, 44 subprocessor lists, 296 security pages, 110 EU-hosting pages and 30 vendors with certifications.

Compliance evidence extended to 270 vendors (round 3)

Researched the next 200 most-recommended vendors, same method and rigor as the previous two rounds: every link was fetched and checked for content. Two certification claims were rejected after manual review: CrateDB's claim pointed to a different vendor's (Keboola) security page, and Kontainer's page only mentioned controls "based on" ISO 27001 and SOC 2, not its own certificate.

Added

  • 270 vendors with compliance evidence in total (217 European, 53 non-European): 107 DPAs, 41 subprocessor lists, 237 security pages, 94 EU-hosting pages and 28 vendors with certifications.

Correction: TYPO3's headquarters is the TYPO3 Association in Switzerland, not the German commercial arm

An attentive reader pointed out that TYPO3 GmbH (Düsseldorf, Germany) is the commercial arm, while ownership and governance of TYPO3 CMS — including the trademark — sits with the TYPO3 Association, registered in Baar (ZG), Switzerland. The country has been corrected to Switzerland and the classification to EFTA.

Fixed

  • TYPO3: headquarters DE → CH, classification eu-strict → efta, with sources (the Association's by-laws, the TYPO3 brand page, the company structure page, TYPO3 GmbH's legal notice).

Compliance evidence extended to 197 vendors (round 2: the most recommended)

Following the first round (the largest cloud, SaaS and security vendors), compliance evidence has been extended to the 96 next vendors most often shown as European alternatives. Same method: every link was fetched and checked for content, and every certification claim was read in page context before inclusion — two claims were rejected here because they referred to a hosting partner's certification (AWS) or to contract text that only "commits to comply with" rather than showing the vendor's own certificate.

Added

  • 197 vendors with compliance evidence in total (146 European, 51 non-European): 78 DPAs, 32 subprocessor lists, 173 security pages, 68 EU-hosting pages and 22 vendors with certifications.

Compliance evidence per vendor: DPA, subprocessors, security page, EU hosting and certifications

Vendor pages now show a Compliance evidence block linking to the vendor's own public documents: the data processing agreement (DPA), the subprocessor list, the security page or trust center, the page describing EU hosting and the page listing certifications such as ISO/IEC 27001, SOC 2, SecNumCloud or HDS. We only record what we actually found on the vendor's site; every link was fetched and checked for content on the check date. A missing link means not found publicly, not not compliant.

Added

  • First round: 101 vendors (55 European, 46 non-European), including the major cloud, SaaS and security vendors and their European counterparts. Found: 57 DPAs, 27 subprocessor lists, 86 security pages, 46 EU-hosting pages and 22 vendors with certifications.
  • The statistics page shows the coverage of compliance evidence (with DPA link, with subprocessor list, with certifications), also in the citable Dataset metadata.

Changed

  • Certifications are listed only when the vendor claims them on the linked page itself; a third party's certified data centre or "ISO 27001 compliant" wording does not count as a certification.

40 vendors from an enterprise application landscape added, each with sources and a check date

An application landscape of a large organisation was compared with the knowledge base: of 81 tools named, 17 were already listed, 40 are now added and 24 were deliberately left out (internal or unverifiable names, network functions, or telecom BSS without a fitting category). Every new record carries its check date and the public sources that substantiate jurisdiction, ownership, data location and the GDPR data-processing agreement, so the page can feed a DORA or NIS2 third-party file.

Added

  • European: Nokia Altiplano (FI), Atoll by Forsk (FR), DataMiner by Skyline (BE), Kibana by Elastic (NL), Nexthink (CH), InSocial (NL), Youforce by Visma Raet (NL, owned by Visma NO), FIQAS Abillity (NL), iProtect by TKH Security (NL) and Axxerion/Spacewell Workplace (BE, owned by Nemetschek DE).
  • Non-European, with European alternatives: Microsoft Active Directory, Azure Virtual Desktop, Cisco Webex, Amazon CloudFront, Google Firebase, Salesforce Commerce Cloud, Kubernetes, OpenStack, Apache Tomcat, HAProxy, NETSCOUT, Cacti, RANCID, Wireshark, SecureCRT, RUCKUS One, Exabeam, Layer7 API Gateway (Broadcom), IBM Security Verify Access, K2view, Coalesce, BlueConic, Khoros, Akana (Perforce), Amdocs CRM, ActixOne (Amdocs), Rhino (Metaswitch/Alianza), Conviva, Avaya Communication Manager and SAM Seamless Network.

Changed

  • Miro, Mural, Figma, Lucid, Whimsical, ClickUp, monday.com and Trello (added on 19 September) now show their sources too.
  • Airtable: the Bending Spoons acquisition closed on 4 September 2026; the 'closing not yet confirmed' note is replaced by the final ownership statement, sourced to the press release and SEC filing.
  • Nexthink was added as a European alternative to Ivanti, Jamf Pro, Microsoft Configuration Manager, Microsoft Intune and Omnissa Workspace ONE.

Faster pages, less repetition on vendor pages and product data in the shop

Every page is now built ahead of time and served directly instead of rendered per visit. Vendor pages repeat less boilerplate and link to their category page. The English homepage carries the tool's English name. The shop, the statistics page and the changelog have cleaner structured data; llms.txt is linked from the footer.

Category pages: why the category matters, related categories and check date

Every category page now explains in two sentences what data flows through it and what to check in a vendor, shows the date of the last check and points to related categories. Non-European vendors state their number of EU alternatives. Shorter page titles and a page-specific preview when shared on social media.

Category overview: how we count, and better discoverability

The overview of all categories now explains how we count and what "European" means, with the date of the last check and links to the methodology and the statistics. Each category now names its total. Sharing a page on LinkedIn or Mastodon shows the right title and link; the sitemap reports the real verification date per page.

Software by category and by country, and knowledge base statistics

New overview pages: per category every European vendor with country, owner and open-source status, plus the non-European vendors with their alternatives; per country every vendor by category with a note on the legal position. The statistics page shows the current knowledge base figures, including verification coverage, with a citation line.

Check date and sources per vendor; independence statement

Every vendor page now shows when the record was last checked and, for records since September 2026, the public sources used. The About page and the footer state explicitly what keeps us independent: no money from vendors, no sponsored listings, no paid labels and no affiliate links.

Why now: NIS2, DORA and CLOUD Act on the home page; 39 European vendors added

The home page explains why a sovereignty assessment matters now: NIS2 and DORA put vendor risk on your organisation, the CLOUD Act affects US vendors, and the GDPR and Data Act set requirements for data location and switching. The text about our verification now states exactly what we check, and verification is free for every vendor. Non-European vendor pages ask for missing European alternatives. In eleven thin categories 39 verified European vendors were added, from data platforms and AI assistants to planning, procurement and data governance.

Enterprise software: 9 new categories and 214 vendors

A check of 120+ common enterprise products (data platforms, ERP satellites, integration, network, security and infrastructure) showed 92 were missing and that BI, data platforms, data governance, planning, procurement, supply chain, process mining, network management and endpoint management had no category at all. They exist now, including 111 European counterparts with curated alternative lists. Every fact (headquarters, owner, hosting) was web-verified per vendor.

Added

  • Categories: Data Platform & Warehouse, Business Intelligence, Data Governance & MDM, Planning & EPM, Procurement & Spend Management, Supply Chain & Asset Management, Process Mining & RPA, Network & Firewall Management, Endpoint & Device Management.
  • 103 non-European incumbents, including Databricks, BigQuery, Redshift, Microsoft Fabric, Oracle Database, SQL Server, Power BI, Tableau, Qlik, Collibra, Informatica, Fivetran, Confluent, MuleSoft, Boomi, Coupa, Anaplan, Kinaxis, Blue Yonder, IBM Maximo, Windchill, UiPath, Automation Anywhere, Splunk, Microsoft Sentinel, Defender, SentinelOne, Zscaler, Netskope, Tenable, Qualys, Rapid7, Proofpoint, Mimecast, Delinea, Saviynt, FortiGate, FortiManager, Panorama, Check Point, Cisco Catalyst Center and ISE, Aruba, Juniper Mist, F5, NetScaler, Infoblox, BlueCat, Configuration Manager, Jamf, Workspace ONE, Hyper-V, OpenShift, Veeam, Commvault, Rubrik, NetApp, Dell PowerStore, SolarWinds, SCOM, Ansible, Puppet, Terraform, Control-M, Automic.
  • 111 European vendors as alternatives, including Exasol and Keboola (data), Luzmo, Board, Bissantz and Knowage (BI), Stibo Systems, DataGalaxy and Dawiso (governance), Axual, Alumio and HiveMQ (integration), Pigment, LucaNet and CCH Tagetik (EPM), Basware, Onventis and Esker (procurement), RELEX, Slimstock, ORTEC, Generix and Körber (supply chain), Celonis, QPR and Fluxicon (process mining), Stormshield, genua, LANCOM, Securepoint, OPNsense, MikroTik and EfficientIP (network), baramundi, Aagon, Relution and FileWave (endpoint), Heimdal, Outpost24, Holm Security, Nexus, Mailinblack, Libraesva, Omada and Systancia (security), SEP sesam, Atempo and Keepit (backup), Redwood, Rudder, CFEngine and JS7 (automation).

Changed

  • Snowflake and Exasol moved to Data Platform; Jedox to Planning & EPM and Toucan Toco to Business Intelligence (they sat under web analytics and were even shown as Google Analytics alternatives); Microsoft Intune to Endpoint & Device Management with a proper UEM alternatives list.
  • Foreign ownership recorded where the owner sits in a different country than the HQ, including Basware, Mercell, Medius and ORTEC (US), Pagero (Canada), Zeenea (India), Alcatel-Lucent Enterprise (China), macmon and EfficientIP (US), One Identity (US via Clearlake).

Fixed

  • SAP S/4HANA Cloud was recorded as US-based, US-only hosted and non-GDPR; it is a product of SAP SE (Walldorf) with EU data centres in Frankfurt, Amsterdam and St. Leon-Rot.

Submit a vendor and the 'verified by hand' mark

Missing a European vendor or spotted an error? Use the new Submit a vendor page, or the correction link on every vendor page. We verify every submission against public sources before it enters the knowledge base. That is now visible too: every vendor carries the 'verified by hand' mark and the About page explains what we check.

Choose your report variant right at the results

The assessment results now show the three report variants side by side, with who they are for and a recommendation. Your vendor selection is carried over to the order and the sample report can be viewed everywhere.

Vendor pages explain what the assessment does

Every vendor page now shows the sovereignty profile across five dimensions, explains why digital sovereignty matters with that vendor and what the free assessment delivers. The assessment button pre-selects the vendor in step 1.

Sample report and more compact free results

The results and the shop now link to a sample report, so you can see what the report contains before ordering. The free results show the two most relevant European alternatives per vendor; the rest are in the report.

Unrecognised applications help the knowledge base grow

If you paste an application list and the knowledge base does not know a name, that name is counted so we can add the missing vendors. Only the name is kept, no IP address, session or selection. This sits under the same telemetry toggle in the footer.

Board questions and migration path now in the report

The discussion questions for the board and the three-phase migration path are now part of the paid report and no longer shown on screen. The free results show the scores, the heatmap, the risk drivers and the European alternatives, and point to the report for the advice.

Order the report right above your results

After an assessment, the option to order the report now sits at the top of the results page, with what the report adds to what you see on screen and the price. The button at the bottom stays.

Annual product: ten whitelabel reports, at your own pace

The monthly cap on the annual product is gone. An access link now covers ten whitelabel reports within twelve months, each with its own vendor selection, whether you build them in one week or spread them over the year. Per report that is cheaper than the single report.

Changed

  • The access page shows how many of the ten reports have been used.
  • The 'Support this tool' buttons now sit directly under the header of every page instead of in the footer.

Annual product: whitelabel reports, at most 3 per month

The annual product has changed. Instead of a download of the full dataset, the access link now gives twelve months of access to the report builder, with at most three whitelabel reports per calendar month. The knowledgebase itself is not for sale on its own; that is what the business licence is for.

Changed

  • The access page shows how many reports were used this month; the counter resets on the first of the month.

Removed

  • Dataset download (ZIP with CSV and JSON) from the annual product.

Nine desktop and prosumer tools added

A pasted application list showed eight common tools missing. They are now in the knowledgebase with verified origin and ownership: Alfred (UK), BBEdit (US), Goodnotes (Hong Kong), Fing (Ireland, part of Belgium's Lansweeper), MacWhisper (Netherlands), OrbStack (US), Docker Desktop (US), Spark by Readdle and Tailscale (Canada).

Added

  • Goodnotes with European note-taking alternatives (Bear, Joplin, Anytype, Nextcloud Notes, CryptPad, Zettlr, Capacities, Carnet); Tailscale with NetBird and WireGuard as European mesh-VPN alternatives.
  • Fing records the majority stake in Lansweeper by the UK's Bridgepoint announced in July 2026 (closing expected by end of 2026).

Paste an application list into the assessment

Searching per category is a lot of work when you already have an inventory. On the vendor step you can now paste a list, for example an export from your asset or licence register. The tool recognises the names (including variants such as 'Office 365', 'MS Teams' or 'Azure AD'), lets you choose when several vendors match and shows what was not found. Everything happens in your browser; nothing is uploaded.

Added

  • 'Support this tool' buttons in the footer of every page.
  • 'Paste an application list' panel at the top of the vendor step, with three groups: recognised, several possibilities, not found. The same panel is in the report order form and in the report builder.

Changed

  • Printing the results page yields only the summary (score and maturity band); the full report is the paid product.

Order a report or the dataset: pay once, delivered immediately

The tool stays free. If you want to keep or forward a report, or use the dataset yourself, you can now order it: a dated report on your own vendor selection, the same report without Accans branding and under your own name, or twelve months of access to the current dataset with unlimited whitelabel reports. Payment is a one-off via Mollie; the download link and the invoice arrive automatically by e-mail. No account, no subscription.

Added

  • 'Report and dataset' page with the three products, the licence terms and the business data licence.
  • 'Order report' button on the assessment results: the selected vendors are carried into the order form.
  • Order status page that shows the download link by itself after payment, even if the e-mail does not arrive.
  • 'Support this tool': buttons for a one-off contribution via Mollie.

Search on /alternatives now finds every vendor; 454 European providers linked as alternatives

Searching the alternatives dashboard for Jottacloud returned 'no applications found' — although Jottacloud is in the knowledge base and is even listed as an alternative to Dropbox, Google Drive, iCloud and OneDrive. The search box only covered the 418 non-EU services, and only their Dutch description. It now searches all 1,912 vendors by name, description (NL and EN) and category. In addition, 521 European providers turned out to be linked nowhere as an alternative; 454 of them are now added, data-driven, to the lists of their non-EU counterparts.

Added

  • Search hits outside the dashboard list (European providers, or non-EU services without a list) appear as a card linking to the vendor page and the EU alternatives from the same category.
  • No result? You get a suggestion ('Did you mean …?'), a clear button and, with a category filter active, a button to search all categories.
  • A link to /en/alternatives?q=… pre-fills the search box, so search engines and colleagues can link straight to a query.
  • 57 non-EU services that had no alternatives list yet (including WordPress self-host, Hugging Face, Zulip, Grafana) now have one; the dashboard shows 475 services instead of 418.

Changed

  • Lists were completed with the European providers from the same category, up to 20 per list, fully European ownership and open source first. Helsing (defence AI) is deliberately not listed as an alternative.
  • The counters are clarified: the map counts EU-based vendors (one marker per vendor, products listed separately); the dashboard counts non-EU services with curated EU alternatives.

Fixed

  • HubSpot Content Hub (headquartered in Ireland) now records its US parent HubSpot Inc., and therefore ranks last in its alternatives lists.

Alternative lists caught up: 53 lists were missing European providers from their own category

Claude Code showed two European alternatives, yet clicking Mistral Code showed four. The cause: every catalogue expansion added European providers, but the hand-curated lists of the US incumbents did not grow with them — Claude Code named 2 of 5 European coding assistants, Twilio 1 of 7 European SMS APIs, Grammarly 1 of 5. All 53 lagging lists in small categories are now complete, with fully European ownership and open source listed first. A new automated check keeps them in step.

Fixed

  • Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Windsurf: now also JetBrains AI Assistant, Lurus Code and Poolside. Copilot/Claude (cowork): Delos, nexos.ai, Nextcloud Assistant, Noota. Twilio/Vonage: 46elks, Messente, seven, SMSAPI, TextMagic, tyntec. Grammarly: DeepL Write, Writefull, CKEditor, Surfer SEO. Plus captcha, consent, transactional email, error tracking, API management, DNS, registrars, fintech, helpdesk, database.

Stripe now under Payments (and no longer as an 'EU vendor'); CyberArk and osTicket corrected

Stripe sat under ERP & Finance with accounting packages as its 'alternatives', and a second Stripe entry registered the company as Irish — hence European. Stripe, Inc. is a US company (Delaware) dual-headquartered in San Francisco and Dublin; a European office does not make it a European vendor. There is now one Stripe under Payments, with fourteen European payment processors as alternatives. SumUp moves to Payments for the same reason. CyberArk showed two flags (US and UK): the company is American and has been part of Palo Alto Networks since February 2026. osTicket was European in one category and American in the other; its maker Enhancesoft is American. A new automated check requires entries of the same vendor to share the same origin.

Fixed

  • Stripe: one entry under Payments (US); the misleading 'Stripe (EU)' entry removed; alternatives are now European payment processors.
  • SumUp → Payments. CyberArk: both entries US (Palo Alto Networks). osTicket: both entries US (Enhancesoft) and no longer shown as an EU alternative.

Map: one pin per vendor, with all its categories

Vendors active in several categories — Adyen and Mollie (e-commerce and payments), TransIP and Combell (cloud, DNS and web hosting), Signicat — appeared two or three times on the map, because each category is its own record in the database. That is intentional for the alternative lists, but confusing on the map. The map now shows one pin per vendor per country; the country list and detail panel list all categories, with an active category filter first.

Changed

  • Map groups records per vendor and country; the subtitle count now reflects unique vendors.

Adyen and Mollie visible again as alternatives to Stripe; 29 alternative lists repaired

The May cleanup gave Adyen and Mollie two entries each (e-commerce and payments), moved Directus to the US and removed a duplicate Soffos entry — but 29 alternative lists still pointed at the old names and therefore silently hid those alternatives. That is repaired: Adyen and Mollie are back under Stripe, and Adyen was removed as an 'alternative' to accounting and ERP packages, where a payment processor does not belong. The two Adyen entries are intentional: one as the checkout layer for webshops, one as the processor for large merchants; the descriptions now make that distinction clear. A new automated check prevents lists from pointing at removed names again.

Fixed

  • Stripe → Adyen and Mollie restored; Collabora Online → SoftMaker Office restored; Adyen removed from 15 ERP/accounting lists, Directus (US) from 11 CMS lists.
  • Mollie, TransIP and Combell are deliberately listed in several categories (checkout vs. payment processing; cloud vs. DNS vs. web hosting); their descriptions now make that distinction clear. TransIP, like Combell, is part of team.blue (Hg Capital, UK) — now recorded as such.

New ESG & Sustainability category, plus Vanta, Norm Ai and Sumsub with EU alternatives

With the CSRD, ever more European organisations must report on sustainability, and that business data deserves a European home. The new ESG & Sustainability category holds eleven European providers — including osapiens (Mannheim), Sweep, Greenly, Plan A, Tanso, Normative, Position Green, Coolset, Ecochain, IntegrityNext and Prewave — alongside US incumbents Workiva and Watershed with curated alternatives. Compliance-automation vendors Vanta and Norm Ai (US) were added with European alternatives such as Secfix, Kertos, Compleye and Cyberday, and KYC provider Sumsub (London) with Fourthline, Veriff, Ondato, iDenfy, WebID, Klippa and Signicat. IDnow is listed with the note that it has been US-owned since 2025.

Added

  • ESG & Sustainability category (13 providers, 11 European).
  • Compliance & GRC: Vanta, Norm Ai (US) + Secfix, Kertos, Compleye, Cyberday (EU).
  • Identity/KYC: Sumsub (GB) + Fourthline, Veriff, Ondato, iDenfy, WebID, Klippa, Signicat, IDnow (US-owned since 2025).
  • New personal category Health & DNA: Superpower, Function Health, Evvy, Maximus, 23andMe, AncestryDNA, Nebula (US) and MyHeritage (IL, US-owned) with European alternatives Neko Health, Werlabs, Blodkollen, Kry/Livi, Lykon, Aware, GoSpring, Dante Labs, tellmeGen and 24Genetics. Health data is a special category under the GDPR — jurisdiction matters most here. Oura is deliberately absent: legally American since February 2026.

Community trends are now on by default (opt-out)

The anonymous counters behind Community trends were doubly off until now: both the operator and the visitor had to enable them, leaving the page with barely any data. Measuring is now on by default. Nothing changes in what is counted: aggregated totals only, no personal data, no IP addresses, no cookies, and small groups are merged (k-anonymity). If you prefer not to take part, switch it off in the footer; that choice is remembered in your browser.

Changed

  • Telemetry is opt-out instead of double opt-in; the footer now states explicitly that data is shared and how to switch it off.

Change review: 88 new EU providers, 2 ownership changes, 3 licence corrections

A targeted review with parallel agents and a news scan mapped what changed since summer — not what was already there. Ownership: Aleph Alpha merged into Canada's Cohere; Brevo is now held by a UK/US private-equity consortium. Licences: MongoDB (SSPL) and n8n (Sustainable Use License) are source-available, not open source, and are now recorded consistently. No new open→closed licence changes were found — the trend actually reversed. The sweep across all 78 categories added 88 European providers over two passes, focused on the 2026 sovereign-cloud wave (Clarence, S3NS, DEEP, Lyceum), eIDAS 2.0 identity (Duna, Ver.iD, Sybol), digital asset management (9) and the EuroStack office initiative Euro-Office. One candidate was deliberately rejected after verification (Passwork: Russian ties despite Spanish registration).

Added

  • Sovereign cloud: Clarence (LU, air-gapped, EC Cloud III), S3NS (FR, Thales — on Google technology, stated explicitly), DEEP/POST Luxembourg (LU), Lyceum (DE, GPU cloud).
  • Euro-Office (EuroStack consortium, open source), Twake (LINAGORA), Wero (EPI, European payment scheme), BirdyChat (LV, DMA-interoperable messenger), NymVPN (CH), Mave and Jet-Stream (NL, video).
  • Identity & legal: Duna, Ver.iD (NL), Sybol (ES), Engity (DE), Bayshore and LawX (DE). Compliance: Formalize (DK). Payments: Flatpay (DK). CRM/marketing: Folk (FR), Splio (FR), Keila (DE).
  • Digital asset management (9): Mediaflow (SE), Kontainer (DK), Pixelboxx, ATAMYA, pixx.io, DALIM (DE), Tedial (ES), Hyphen-Italia (IT), Filecamp (CH). Also: Kreezalid, Synera, involve.me, Uniqkey, Mirro, SilentShield, Messente, seven, 46elks and Airtable (US, Italian acquisition pending).
  • Second pass over the thinly-searched categories (47, from curated EU directories): uptime monitoring was a blind spot — Hyperping (FR), Oh Dear (BE), UptimeRobot (SK), Checkly, Uptrace, Statuspal, Uptimia, Monibot (DE), Phare (EE), PingPing (NL), Testomato (CZ), Odown (FI), updown.io (FR), Semonto (BE) and GlitchTip (DE, error tracking). Hosting: cloudscale.ch, Servebolt (NO), T Cloud (Telekom), Virtua.Cloud, Clouding (ES), HostPress, TimmeHosting. Analytics: fusedeck, digistats (CH), Sitesights, Alceris (DE), Stormly (NL), tinylytics (PL), Analyzati (ES). Also: EmailConnect, Timing, timr, Cryptee, Impossible Cloud, Intercolo, Cubbit, Calligra Suite, Capacities, smasi, Notefox, BlueSpice, OpenNebula, Automatisch, elastic.io, next layer, Buddy and Radicle.

Changed

  • Aleph Alpha: owner → Canada (merger with Cohere, April 2026). Brevo, Brevo CRM and Newsletter2Go: owner → Oakley Capital (UK) / General Atlantic (US), late 2025.
  • MongoDB and n8n (2 entries) no longer recorded as open source: SSPL and the Sustainable Use License are source-available, not OSI-approved — consistent with CockroachDB, Sentry and MinIO.
  • ONLYOFFICE: Workspace Cloud discontinued (2 March 2026), DocSpace continues. Aiven: Cassandra, AlloyDB Omni and Dragonfly discontinued.

Ownership audit: 16 jurisdiction fixes and 8 new EU vendors

A web-verified, multi-agent review (Haiku 4.5) surfaced misclassified vendors. Fifteen EU/EFTA-based providers (incl. APPUiO, Bacula Systems, Locize, Efecte, KrakenD, Sygic, Hornetsecurity, Connective, Talend, Transifex, Henchman, Homerun, Pixlr, Tails, Dinero) were wrongly flagged as 'outside the EU' — their region is corrected to EU, with the actual foreign parent recorded separately (the signal that matters for the US CLOUD Act). Payload CMS is now marked as a US provider. FortKnoxster was removed after pivoting to crypto. Eight new EU providers were added in thinly-covered categories.

Added

  • Eight new EU providers: Poolside (FR, AI coding), Noota (FR, AI cowork), Better Stack (CZ, error tracking), TRUENDO (AT, consent), DNS4EU (CZ, privacy DNS), MailerSend (LT, transactional email), Giskard (FR, open-source AI testing) and Black Forest Labs (DE, AI).

Removed

  • FortKnoxster removed — acquired by SYS Labs (Canada) and pivoted to crypto (SuperDapp); no longer an identity product.

Fixed

  • Region corrected from 'outside EU' to EU for 15 EU/EFTA-based providers; foreign owners (US/UK/AU/MY) are recorded separately via ultimate_parent_country rather than via the region.
  • Payload CMS classified as a US provider (US HQ, owned by Figma).

Passbolt corrected (LU) and added to password-manager category

Passbolt was already in the catalogue under cybersecurity, but with the wrong jurisdiction (FR instead of LU) and an overly terse description. It is a Luxembourg-based open-source credential manager (AGPL-3.0) by Passbolt SA, aimed at IT and DevOps teams. Alongside the correction, a second entry was created under password-manager so users looking for an EU alternative to 1Password, Bitwarden, LastPass or RoboForm now find Passbolt there directly.

Added

  • Passbolt as a second entry under password-manager (alongside the existing cybersecurity entry), linked as an alternative to 1Password, Bitwarden, LastPass and RoboForm.

Fixed

  • Passbolt: HQ corrected from FR to LU (Passbolt SA, Belvaux, Luxembourg), AGPL-3.0 license made explicit, description expanded.

Gap analysis round 2: 75 new EU vendors across 40 categories

Systematic scan of the remaining business categories in two blocks of twenty, using Haiku finders and Sonnet verify. The catalogue now lists 1,771 vendors. Includes Elastic (NL, apparently never recorded as a database), Kestra (FR, workflow orchestration), Lovable (SE, AI development), Haystack/deepset (DE, open-source RAG), Snom (DE, VoIP), TSplus (FR, remote desktop), Graphisoft ArchiCAD (HU, CAD), Bacula Systems (CH, backup), Rebelle (SK, natural-media design), Locize (CH, developer TMS), seven previously missing European form/survey tools (AidaForm, easyfeedback, Edkimo, empirio, Crowdtech, QUESTIONSTAR, SmartSurvey), and esign alternatives Penneo (DK) and Buypass (NO).

Added

  • Databases and data: Elastic (NL, AGPLv3-restored), Kestra (FR, Apache-2.0 orchestrator).
  • Remote desktop & VoIP: TSplus (FR), RealVNC (GB), Snom (DE), Equada (DE), Nomado (BE), Voiped Telecom (NL).
  • GIS & CAD: Oslandia (FR, open source), OPENGIS.ch (CH), Coexya (FR), Eurosense (BE), Pix4D (CH), Lutra Consulting (GB), Graphisoft ArchiCAD (HU), Graebert ARES (DE), ELITECAD (AT), Cadwork (CH), Leica Geosystems (CH).
  • Compliance, GRC & HR: DataGuard (DE), Orbiq (DE), EuroComply (PT), Talentech (NO), Eploy (GB), Vouch (NO), Breathe HR (GB), Ubisecure (FI).
  • Scheduling, time-tracking & low-code: Calenso (CH), Cronofy (GB), Reservio (CZ), Agendize (FR), solidtime (AT, open source), Time Cockpit (AT), timeBuzzer (DE), WeWeb (FR), Cerberus Testing (FR, open source).
  • AI & design: Lovable (SE), Haystack/deepset (DE, open source), Rebelle (SK), ArtFlow (PL).
  • Backup & translation: Bacula Systems (CH, AGPLv3), Xopero (PL), Locize (CH), Apertium (ES, open source), Protemos (UA).
  • Forms & surveys: AidaForm, Edkimo, empirio.ai, easyfeedback, QUESTIONSTAR (all DE), Crowdtech (NL), SmartSurvey (GB) — this category was chronically under-supplied with EU alternatives.
  • Marketing, esign & CMS: Omnisend (LT), AGNITAS (DE, open source), Membrain (SE), Quarticon (PL), sproof (AT), Commfides (NO), Penneo (DK), Buypass (NO), Jahia (CH), Microweber (BG, open source), Roadiz (FR, open source).
  • Other: Beckhoff Automation (DE, IoT), KEBA (AT, IoT), Joker.com (DE, domain registrar), Tine 2.0 (DE, email/groupware), APPUiO (CH, virtualization), Keelearning (DE, LMS), Hornbill (GB, ITSM), Linphone (FR, open source collaboration), SendRec (RO, open source collaboration), Elestio (IE, DevOps), World4You (AT, webhosting), Coolhousing (CZ, webhosting).

Gap analysis: 21 new EU vendors added in the thinnest categories

Targeted gap scan on the twelve categories with the fewest EU alternatives. Twenty new vendors added, plus Otobo as a second open-source OTRS fork. Includes sovereign AI workspaces (Delos in Paris, nexos.ai in Vilnius, Nextcloud Assistant), captcha alternatives to reCAPTCHA (Private Captcha from Estonia, Captcha.eu from Austria, Myra EU CAPTCHA from Munich), writing tools (DeepL Write, Writefull, ProWritingAid, CKEditor), API management (Frends from Finland, Locoia from Germany, STOA from France), and transactional email (AhaSend from the Netherlands, MessageFlow from Poland).

Added

  • AI Cowork: Delos (FR, sovereign French AI workspace platform), nexos.ai (LT, founded by Nord Security founders), Nextcloud Assistant (DE, open source, self-host).
  • Writing tools: DeepL Write (DE), Writefull (NL, academic), ProWritingAid (GB), Surfer SEO (PL), CKEditor (PL, open source).
  • API Management: Frends (FI), Locoia (DE), STOA (FR, open source).
  • CAPTCHA: Private Captcha (EE), Myra EU CAPTCHA (DE), Captcha.eu (AT) — all GDPR-compliant and cookieless.
  • SMS API: tyntec (DE, Tier-1 CPaaS). Digital Signage: ScreenCom (NL). Consent Management: Cookie Information (DK). AI Coding: Lurus Code (DE). Transactional Email: AhaSend (NL), MessageFlow (PL). ITSM: Otobo (DE, second active OTRS fork alongside Znuny).

Second audit pass: 67 corrections on vendors skipped in the previous round

Reviewed 1,223 vendors that were skipped in the previous audit using a cheaper overnight loop (Sonnet 4.6, split across six ticks): 78 confirmed findings, of which 67 changes applied. Includes new ownership structures (Harvest to Bending Spoons IT, MailerLite to Vercom PL, Fondy to TBC Bank GB, MariaDB commercial arm to K1 US, PAYONE under Worldline FR), licence rug-pulls from open source to source-available (CapRover, Chatwoot, Invoice Ninja, OpenKM, Planka, Rasa, TheHive), and removals (legacy SchildiChat Desktop, standalone Sofort, Juke, iRedMail Easy).

Changed

  • 42 new ownership corrections for vendors whose parent had moved to a different jurisdiction — including Nets → Nexi (IT), Nmbrs → Visma (NO), SnelStart → EG (DE), Magnolia → GENUI (DE), Roundcube → mailbox.org (DE), Signaturit → Namirial (IT), SMSAPI → LINK Mobility (NO), Sympa → US, Tidal → US, Topicus Healthcare → CA.
  • 10 headquarters corrections (SigNoz was mis-classified as DE, actually US; Vendure is Vienna, not Prague; Corteza is IE, not SI; Quire is TW; NoMachine is LU; WEDOS relocated CZ → LU).
  • 10 licence changes: CapRover, Chatwoot, Invoice Ninja, OpenKM, OTRS, OXID eSales, Planka, Rasa and TheHive lost open-source status (Fair Use, custom EULA or open-core with commercial core). Descriptions updated with the date and nature of the licence change.
  • Rebrand corrections: Gardener (SAP) → Gardener (NeoNephos Foundation), Lectora (eLearning Brothers) → Lectora (ELB Learning), Restorepoint → Skylar Compliance, MobilePay + Vipps → single 'Vipps MobilePay' entry, myLoc → myLoc a WIIT Company, Trilium Notes → Trilium Notes (TriliumNext), windream → dataglobal.

Removed

  • 5 vendors removed due to discontinuation, absorption or duplication: SchildiChat Desktop (now 'legacy'), Sofort as standalone (folded into Klarna), JUKE (Talpa discontinued the service), iRedMail Easy (hosted version), MobilePay (merged into Vipps).

Full audit of acquisitions, ownership and licences

All 1,700 records reviewed via a layered agent swarm: 320 changes applied, including 153 ownership corrections, 73 headquarters corrections, 39 removals of discontinued or absorbed products, and 17 licence changes where formerly open-source projects moved to source-available or proprietary.

Changed

  • 153 ultimate parents and EU classifications updated — e.g. DocuWare (owned by Ricoh, JP), DomainFactory (owned by GoDaddy, US), Doxis/SER Group (TA Associates majority, US), Dokobit (folded into Signicat, NO/EEA).
  • 73 headquarters corrections including Dynatrace and Bruker (operational HQ moved to the US) and Duplicati (incorporating entity Duplicati Inc is US-based).
  • 26 product rebrands applied: Doxis4 → Doxis, HubSpot CMS → HubSpot Content Hub, All 4 → Channel 4, Bugsnag → SmartBear Insight Hub, Byte → Hypernode, and more.

Removed

  • 39 vendors removed that have shut down or been absorbed: Boxcryptor (assets to Dropbox, closed January 2023), BullGuard (NortonLifeLock, phased out), Buttercup (project ended June 2025), Hotjar (merged into Contentsquare, July 2025), BrutX (streaming closed 2022), ZenMate (absorbed into CyberGhost), Reaction Commerce (ended), Pootle (closed May 2023) and 31 others. Platform.sh also removed in favour of its successor Upsun.

Fixed

  • 17 projects previously marked as open source corrected to open-core or proprietary: Airbyte (ELv2), Anytype, Cal.com (AGPL → commercial licences for enterprise), Camunda, CockroachDB (BSL), Directus (BSL), FusionAuth, Kopano, Meilisearch (commercial clauses), MinIO (AGPLv3 but recalibrated), Mirth Connect, NocoDB, ONLYOFFICE, Proton Pass, Sentry (FSL), Talend, Chartbrew.

New category: Digital Asset Management

Twenty DAM vendors added — from OpenText, Adobe and Cloudinary to European alternatives such as WoodWing, Bynder, CELUM and Fotoware — with verified ownership structures and hosting regions.

Added

  • Digital Asset Management (DAM) category with 20 vendors: European options WoodWing (NL), Bynder (NL), CELUM (AT), censhare (DE), 4ALLPORTAL (DE), Wedia (FR), QBank (SE), Fotoware (NO), Papirfly (NO), Frontify (CH), Pimcore (AT) and ResourceSpace (GB, open source) alongside OpenText, Adobe Experience Manager Assets, Cloudinary, Acquia DAM, Sitecore Content Hub, Canto, Aprimo and Brandfolder.

Changed

  • Pimcore marked as open-core instead of open source — the core is proprietary (POCL licence) since version 12 (2025).
  • Ownership recorded: Bynder has a US parent (Thomas H. Lee Partners, majority since 2023) and Wedia is no longer publicly listed since late 2024 (Cathay Capital, Paris).

Vendor database cleaned up and expanded

Nine records with incorrect headquarters information corrected, 27 new European vendors added, and the schema extended with sovereignty metadata so each vendor's positioning is explicit and honest.

Read ADR-001 on EU provenance →

Added

  • 27 new EU vendors — including Didomi, Axeptio and consentmanager.net (consent management), Dynatrace and Pandora FMS (monitoring), Make.com and SeaTable (low-code), memoQ, Phrase TMS and Wordbee (translation), Trade Republic (fintech), Aircall (helpdesk) and Nedap Healthcare.
  • Three new per-vendor metadata fields: ultimate parent company (e.g. Wrike is owned by Symphony Industrial), sovereignty mode (vendor-hosted-eu / self-host / oss-distributed / vendor-hosted-non-eu) and a sharper EU classification (EU-27 / EEA / EFTA / EU-adjacent).
  • Nine invariant tests in CI that prevent regressions — no EU sentinel without a sovereignty mode, no duplicate (name, category) pairs, no non-HTTPS websites, etc.

Changed

  • Hologic, Carestream Health, Wrike and WordPress (self-host) moved from EU to US — these are US incumbents, not European alternatives.
  • RustDesk (China), Logseq (Singapore) and Synology Drive on-prem (Taiwan) corrected to the developer's actual country; sovereign only when used locally or self-hosted.
  • Bitrix24 corrected to Cyprus (legal entity) with explicit disclosure of Russian origin.
  • Wire (Switzerland), Directus (US, BSL-licensed) and SumUp (UK post-Brexit) reclassified.
  • 57 Swiss vendors tagged EFTA, 29 Norwegian/Icelandic as EEA, 4 Ukrainian as EU-adjacent.

Removed

  • Misleading and duplicate records removed: a second Epic record labelled EU (real HQ is Verona WI), a duplicate SumUp and Directus entry, a duplicate SoftMaker Office, and Adyen/Mollie from the ERP category (they are payment processors, not ERP systems).