Collaboration platform
Provide editors, CryptDrive, teams and sharing in a controlled way.
WZ-IT operates end-to-end encrypted collaboration with correctly separated main and sandbox domains, storage, upgrades and recovery.
The following are trademarks of their respective owners: CryptPad (the CryptPad project and XWiki SAS). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
CryptPad encrypts document contents in the browser. The server stores encrypted data but cannot recover lost passwords or keys.
We configure the project's recommended separation of main and sandbox domains, WebSockets, content security policy, data storage, retention and administrative access.
Infrastructure backups protect stored data from technical loss. Without the client-side keys, administrators still cannot decrypt encrypted contents.
Onboarding, recovery guidance, team policies and secure access distribution are therefore part of the deployment scope.
End-to-end encryption changes administration and recovery. Domain separation, keys, storage, registration and updates must follow that model.
Provide editors, CryptDrive, teams and sharing in a controlled way.
Document client-side keys and the absence of administrative content access clearly.
Back up files, blobs, data stores and configuration completely.
Maintain two-domain isolation, headers, updates, monitoring and abuse protection.
WZ-IT operates the platform but cannot technically reconstruct lost personal keys or forgotten document passwords.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Platform and domains | WZ-IT | Main and sandbox domains, TLS, security headers and technical services. |
| Backups and restore | WZ-IT | Back up encrypted data, configuration and server-side keys. |
| Registration and groups | Shared | We implement rules; the customer defines authorised users and teams. |
| Recovery process | Shared | Technical recovery and organisational handling of user keys are planned separately. |
| Content and sharing | Customer | Users control content, sharing links and secure retention of personal recovery data. |
| SSO and custom integration | Optional WZ-IT service | Available authentication and integration paths are assessed for the deployed version. |
Document contents are encrypted on the client before being sent to the instance.
Edit documents, spreadsheets, presentations, forms and other content together.
Organise and share documents through CryptDrive, folders and team spaces.
Separate main and sandbox domains with restrictive browser policies and monitor both paths.
Require two-factor authentication and admit new accounts through controlled invitations.
Integrate optional office editing and further components with a controlled upgrade path.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of CryptPad. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around CryptPad. Contact us for a technical assessment.
One managed standard CryptPad application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for CryptPad. We assess infrastructure, integration, and ongoing operations.
Active users, collaboratively edited pads, large files, history and retention determine resources and backup volume.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small team | S or M | Normal document editing with limited file and history volume. |
| Multiple teams and larger repositories | M or L plus storage | Teams, blobs, history and backup growth are monitored. |
| Public registration | Abuse and capacity assessment | Registration, quotas and abuse protection are designed explicitly. |
| Critical encrypted collaboration | Recovery assessment | Restore, key management and organisational emergency paths are tested. |
The standard calculator is a starting point; public instances and large storage estates require separate review.
CryptPad can be operated by WZ-IT, in your cloud or on-premises; the encryption model remains the same.
Dedicated instance with domains, backup, monitoring and service level.
Operate in your own account with existing security controls.
Local operations with internal or controlled external access.
Private platform with agreed access for distributed teams.
Content is encrypted in the browser. The server stores encrypted data and provides collaboration and synchronisation.
Users generate and process keys on their devices.
Main and sandbox origins limit access by active document content.
Registration and groups are configured in a controlled manner.
Pads, CryptDrive, teams, sharing and encrypted collaboration.
Server-side state and tasks for the platform.
Files, pads, history and secured copies.
Availability, errors, storage and abuse signals without content access.
End-to-end encryption protects content while also limiting server-side recovery and administration.
Answers about encryption, recovery and team operations.
With properly used end-to-end encryption, content is stored encrypted on the server. Metadata and operational data must be considered separately.
Not generally. The encryption model limits central recovery. Users must securely retain the intended recovery data.
The official security model separates the main application and sandbox origin to isolate active document content more strongly.
Yes. We configure registration, invitations, quotas and teams for the intended audience.
Encrypted pads and files, server-side data, configuration and relevant keys. A restore recovers the platform but cannot replace lost user keys.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures CryptPad, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with CryptPad
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.