Markdown platform
HedgeDoc, its database and configuration are deployed reproducibly and updated through controlled procedures.
We design, install and operate HedgeDoc as a collaborative Markdown platform - including database, upload storage, identity integration, backups and clearly defined service levels.
Companies worldwide trust WZ-IT
The following are trademarks of their respective owners: HedgeDoc (the HedgeDoc project). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
HedgeDoc combines a browser-based Markdown editor with real-time collaborative editing. Teams can create notes, technical documentation, diagrams and presentations and share them through graduated note permissions.
WZ-IT designs more than the application itself. We align the reverse proxy, database, upload storage, authentication, email delivery, monitoring, backups and recovery with your existing infrastructure and required access model.
We inventory the version, database, notes, uploads, authentication paths, domain and dependencies of an existing HedgeDoc, CodiMD or older HackMD installation and plan the test migration and cutover.
The migration depth depends on the source system and its version. Before a migration or upgrade, we review the official release notes and validate data, permissions, media and authentication in a test run.
Production HedgeDoc operations connect the application, database, real-time connections, upload storage, authentication and email delivery. We design and operate these components as one platform while taking the selected release branch into account.
HedgeDoc, its database and configuration are deployed reproducibly and updated through controlled procedures.
Collaborative editing, note permissions and WebSocket connections are designed around teams and access paths.
Local accounts or documented external login methods, email delivery and upload storage are integrated in a controlled way.
Monitoring, updates, consistent backups and restore tests cover the application, database, media and configuration.
We distinguish platform operations, content organisation and business approvals transparently.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Architecture and deployment | WZ-IT | HedgeDoc, database, reverse proxy, TLS, WebSocket paths, upload storage and reproducible deployment. |
| Runtime and updates | WZ-IT | Maintenance of the agreed release branch with release-note review, backups and controlled updates. |
| Monitoring and backups | WZ-IT | Monitoring and consistent protection of the database, media, configuration and agreed secrets. |
| Migration and release selection | Shared | WZ-IT assesses data and version paths; the customer confirms required functions, test data and approval of the target system. |
| Identity and note permissions | Shared | We configure supported login methods and technical permissions; the intended access model is agreed together. |
| Content and sharing decisions | Customer | The customer remains responsible for note content, permitted user groups, publications, retention and deletion rules. |
| Integrations and customisations | Optional WZ-IT service | Import tools, identity integrations and additional automation are specified as a separate project module. |
Edit notes collaboratively in the browser and merge changes from multiple participants in real time.
Share notes with graduated read and write permissions, review previous revisions and restore them when required.
Extend Markdown content with supported diagrams and embedded content or present it as slides using reveal.js.
Configure local accounts or supported external sign-in methods such as SAML and OAuth-based providers for the required access model.
Store image uploads in the file system or through supported S3, MinIO or Azure storage targets, depending on the architecture.
Monitor the application, database and uploads, protect them with versioned backups and apply updates through tested maintenance and recovery procedures.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
Compute, applications, storage and response are shown separately. You can see what ongoing operations include and which requirements need a technical assessment.
We also design custom HedgeDoc architectures, integrations and migrations. Contact us for a technical assessment.
One managed standard HedgeDoc application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€7.99 excl. VAT per additional 100 GB per month, including daily encrypted offsite backup with 7-day retention. Billing is based on provisioned capacity, not actual usage.
We also implement custom backup schedules and retention periods. For example: daily backups retained for 30 days and one monthly backup retained for 12 months. Scope, storage requirements and additional costs are agreed separately.
+€299 excluding VAT per workload and month
Standard hosting runs on a single instance without high availability. Availability for custom architectures is agreed separately.
Zero downtime on request
Distributed operation with several instances, a database cluster and rolling updates, so that a node failure causes no interruption. Only for applications suited to it; design and price after technical assessment.
This page covers installation and the agreed platform operations for HedgeDoc. Custom code, the access layer and special confidentiality requirements remain clearly separated responsibilities that can be added when needed.
Maintain the application
Keep custom extensions, interfaces and dependencies controlled, updated and supportable.
from €699.90 excl. VAT / month
View serviceSecure access
Add identity-based access and private network paths as a separate operational layer.
from €349.90 excl. VAT / month
View serviceOperate confidentially
For professional secrecy holders, define contractual, access and infrastructure requirements in a dedicated operating model.
from €499.90 excl. VAT / month
View serviceThree relevant adjacent paths instead of a long list of further products.
All prices are net and exclude statutory VAT. The offers are addressed to businesses.
View the overall systemEnquiry
Briefly describe the current state and objective for HedgeDoc. We assess infrastructure, integration, and ongoing operations.
User count alone is not enough. Concurrent editors, note size, WebSocket connections, uploads, diagrams and external login methods shape compute, database and storage requirements.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Small team with internal Markdown notes | S or M, PostgreSQL | A suitable starting point for few concurrent editors and a manageable upload volume. |
| Multiple teams with media and external login | M or L, PostgreSQL, separate upload storage | Concurrent editing, media volume and authentication paths are assessed beforehand. |
| Many parallel sessions or a substantial migration | L or custom sizing | WebSocket load, database, upload paths, import volume and release compatibility shape the target design. |
| Business-critical or particularly isolated environment | Custom architecture | Recovery objectives, redundancy, private access and the behaviour of active real-time sessions are designed separately. |
Data migration, special identity integrations, separate environments and complex storage or redundancy architectures are not included in the general workload price.
HedgeDoc can run as a managed workload or in a customer environment. The release branch, login methods and upload storage are assessed beforehand.
Dedicated workload with agreed compute, upload storage, backups, monitoring and service level.
Operations in the customer's account with existing network, email, storage and identity services integrated.
Integration with customer servers, virtualisation, database, directory and backup infrastructure.
Access to internal identity and storage services over defined private connections, NetBird or VPN.
HedgeDoc connects browser sessions with notes, uploads and login services. Access, WebSocket connections, data storage and recovery are therefore designed as one end-to-end data path.
Internal or external users, shared notes, presentations and shared links.
TLS, domain, proxy headers, WebSocket paths, protection rules and optional private access.
Local accounts or documented SAML and OAuth-based login methods together with graduated note permissions.
Markdown editor, real-time editing, revisions, diagrams, presentations and media references.
Notes, users, revisions and configuration on a supported database selected for the target environment.
File system or documented S3, MinIO or Azure targets with agreed capacity and backup coverage.
External login services, email delivery, status and metrics endpoints and operational alerting.
Before production, we document the release branch, authentication paths, default permissions, upload target, backup scope and a tested recovery procedure.
Answers about licensing, release branches, migration, login, permissions and operations.
Yes. The HedgeDoc source code is released under AGPLv3. The official repository and its licence notices are authoritative. The HedgeDoc logo has separate usage rules; WZ-IT is an independent service provider.
The official project currently describes HedgeDoc 1.x as stable and maintenance-only and HedgeDoc 2 as a rewrite that is not yet feature-complete. Before deployment, we review the current project status, required functions and release notes and select the target branch together instead of treating a development state as production-ready by default.
In principle, yes, but not every version path is officially guaranteed. The HedgeDoc migration notes identify safe paths only for certain older CodiMD and HackMD versions. We therefore inventory the version, database, notes, uploads and authentication and run a test migration before cutover.
HedgeDoc documents local accounts, SAML and several OAuth-based providers. We validate the specific provider, required attributes and group rules against the selected release branch; this does not imply a blanket enterprise RBAC promise.
HedgeDoc 1.x distinguishes owners, signed-in users and guests and provides several note modes (permissions documentation). We configure default permissions and anonymous use around the agreed model; business sharing decisions remain with the customer.
The database, upload storage, configuration and relevant secrets must be considered consistently. We protect the agreed data and test recovery because a database dump without media and operating parameters does not recreate a complete instance.
Redundant infrastructure can be designed, but real-time sessions, WebSocket connections, the database and upload storage must be tested together. We derive the architecture from recovery and availability objectives and do not make a blanket HA promise for every release branch.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures HedgeDoc, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with HedgeDoc
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.