1. 1

    We start from the vendor, not from a press release

    Every tool page begins with the company's own material: pricing page, terms, privacy policy, data processing agreement and sub-processor list. Where a vendor publishes a security whitepaper or a status page, we read that too. We do not build a review from other directories' summaries, because that is how a wrong "EU-hosted" claim spreads from site to site without anyone checking it.

  2. 2

    We establish where the company actually is

    "European" is the whole point of this site, so we treat it as a factual claim rather than a marketing one. For each tool we record where the legal entity is established, and separately where the data is stored. Those are often not the same: a US company with an EU data centre is still a US company subject to US law. Our directory currently classifies 306 tools as established in the EU/EEA or Switzerland, 35 elsewhere in Europe, and 12 as open source projects with no company behind them. Tools whose vendor sits outside Europe do not belong in this directory and are removed when we find them, however good the product is.

  3. 3

    A second person edits

    Our managing editor reads the draft against the sources. Reviews go back when a claim has no source behind it, when a pricing figure is older than the vendor's current page, or when the tone is more enthusiastic than the evidence supports. This is also where we check that the alternatives we suggest are genuinely comparable, rather than the ones that happen to have an affiliate programme.

  4. 4

    A third person fact-checks the compliance claims

    Anything regulatory gets checked separately: GDPR posture, data residency, sub-processors, certifications, and whether an eIDAS or ISO claim points at a real, current certificate. If we cannot verify a claim, we either drop it or say plainly that the vendor asserts it and we could not confirm it.

  5. 5

    We re-check, and we date what we re-checked

    Pricing and hosting arrangements change. Every tool page carries the date it was last reviewed, and that date only moves when someone has actually looked at the page again. A page that has not been re-checked keeps its old date, even if that looks less impressive.

How we handle affiliate income

Some links on this site are affiliate links, and we may earn a commission when you sign up through them. Two things follow from that, and we hold ourselves to both: a tool cannot buy a place in our directory or a higher rating, and the person writing a review does not know or negotiate the commercial terms for the tool they are writing about. Plenty of tools we recommend, particularly the self-hosted open source ones, pay us nothing at all.

Corrections

If something on this site is wrong, tell us and we will fix it. Email business@gcas-digital.com or use our contact form. Corrections to a factual claim are made on the page itself, and the "last reviewed" date is updated when we do.

Who does this work

Marta Kowalczyk

Marta Kowalczyk

Senior Analyst, Infrastructure & Developer Tools · Warsaw, Poland

Covers hosting, developer tooling and the practical side of moving workloads to European providers.

Ingrid Halvorsen

Ingrid Halvorsen

Managing Editor · Oslo, Norway

Runs the review process and decides when a page is ready to publish or needs another pass.

Daniel Brandt

Daniel Brandt

Privacy & Compliance Researcher · Berlin, Germany

Checks the compliance claims: where the company is established, where the data sits, and what the DPA actually says.