Tools

ZITADEL

Swiss open-source IAM with a modern UI.

Log in to add an offering to your organisation’s current stack.

Apache-2.0 · https://zitadel.com

Identity

Self-hosted

Hosting: Self-hosted

Apache-2.0 identity platform you run yourself.

Fair 4.7 Easy 3.3 Secure 4.0

Pillar Criterion Score Evidence
Easy Day-one UX Can non-technical staff use it without a project? 3 Polished console; still an IAM project. Source
Easy Operate Admin burden, updates, backups and language coverage. 2 You operate upgrades and HA. Source
Easy Integrate SSO, mail/CalDAV, APIs and common NGO connectors. 5 OIDC, SAML and modern APIs. Source
Fair Lock-in / exit Can you leave with your data in open formats, at known cost? 5 Open standards (OIDC/SAML); portable configuration. Source
Fair Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? 4 Swiss vendor; host country is your choice. Source
Fair Openness Open source or open standards? Are independent implementations possible? 5 Apache-2.0. Source
Secure IT security Authentication, encryption, patch cadence and independent audit. 4 Security depends on your deployment. Source
Secure User security 2FA, roles, phishing resistance and safe defaults. 4 Passkeys and MFA are first-class. Source
Secure Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. 4 Identity data stays on your infra. Source

ZITADEL cloud

Hosting: EU-hosted SaaS

Managed ZITADEL with European options.

Fair 4.3 Easy 4.7 Secure 4.0

Pillar Criterion Score Evidence
Easy Day-one UX Can non-technical staff use it without a project? 4 Faster than self-hosting for small IT teams. Source
Easy Operate Admin burden, updates, backups and language coverage. 5 Vendor operates the control plane. Source
Easy Integrate SSO, mail/CalDAV, APIs and common NGO connectors. 5 Easy OIDC for SaaS apps NGOs already use. Source
Fair Lock-in / exit Can you leave with your data in open formats, at known cost? 4 Standards-based; cloud still creates operational dependency. Source
Fair Sovereignty EU legal entity, EU hosting, and exposure to extra-EU lawful access? 4 Swiss company; choose region carefully. Source
Fair Openness Open source or open standards? Are independent implementations possible? 5 Apache-2.0 product with commercial cloud. Source
Secure IT security Authentication, encryption, patch cadence and independent audit. 4 Managed hardening and updates. Source
Secure User security 2FA, roles, phishing resistance and safe defaults. 4 MFA and passkeys included. Source
Secure Personal data GDPR fit: DPA, residency, sub-processors and Schrems II posture. 4 Review subprocessors and region in the DPA. Source